Cybersecurity · September 2026

Deepfake and cloned-voice fraud: a protocol for companies

A voice or a face no longer proves who is talking to you. Documented cases, verified figures and the protocol that protects payments even when the deepfake is perfect.

$25.6M Arup case, Hong Kong (2024)$893M AI-linked losses (IC3, 2025)52% of successful scams: under 30 min
In short

Deepfake fraud is no longer a demo. In 2024 an Arup employee in Hong Kong sent about $25.6 million after a video call in which the CFO and several colleagues were deepfakes, and in 2025 the FBI's IC3 logged 22,364 complaints mentioning AI, with $893 million in losses.

Detection tools help, but they will not stop a payment decided in minutes. What works is a process: no payment or bank-detail change on the strength of a voice or a face, a callback to a known number, dual approval above a threshold and a culture where pausing to verify is expected.

What has happened: cases and numbers

The reference case is Arup. In early 2024 a finance employee at the engineering firm's Hong Kong office joined a video call with what appeared to be the CFO and several colleagues; all were deepfakes. The employee made 15 transfers totaling HKD 200 million, about $25.6 million. Hong Kong police described the case in February 2024, and Arup confirmed in May that it was the victim.

The FBI has since documented the pattern: criminals cloning relatives' voices to fake emergencies (December 2024) and, since April 2025, impostors posing as senior US officials with texts and AI-generated voice messages to build trust and take over accounts, often moving the victim to another messaging platform. HR is a target too: in August 2025 Anthropic reported North Korean operatives using Claude to get and keep remote IT jobs at Fortune 500 technology companies.

Figures as published by each source. IC3 counts complaints filed with the FBI, mostly from the United States; we found no comparable public series for Colombia.
SourceDateFigure
FBI IC3, annual reportApr 20261,008,597 complaints and $20.877 billion in reported losses in 2025, up 26% on 2024
FBI IC3, AI sectionApr 202622,364 complaints mentioned AI ($893 million), including over $30M in business email compromise and over $5M in voice-cloning "distress" scams
FBI IC3, ColombiaApr 20262,222 complainants from Colombia, among the top 20 foreign countries
FinCEN (US Treasury)Nov 2024Suspicious-activity reports describing deepfake media rose from 2023 into 2024
Kaspersky, global studySep 202666% of messaging-scam victims believe AI was involved; 31% reported cloned or synthetic voices; 52% of successful scams end in under 30 minutes

How these attacks work, conceptually

Four ingredients, none of them technical on the victim's side.

  • Raw material. Public recordings of the person to imitate: interviews, earnings calls, conference talks, podcasts, social clips. The voice models behind this are covered in voice and audio AI in 2026.
  • A pretext. A confidential acquisition, an overdue supplier invoice, a regulator's request: a story that explains why the usual procedure must be skipped.
  • Urgency and secrecy. "It has to go out today", "don't mention this to anyone". Pressure removes the time to think.
  • Channel switching. The conversation moves to a channel the attacker controls: from email to WhatsApp, from a text to a voice note, from a call to a video meeting. The FBI describes exactly this move.

It is the old CEO fraud with a convincing voice, and Arup adds staging: several fake participants on the same call. The targets are predictable (treasury, accounts payable, payroll, executive assistants, IT help desks), and so is the weak point: the impostor needs you to act inside their channel and on their timeline. Any control that moves the exchange to a channel you trust, or adds time, breaks the scheme.

Why detection tools alone are not enough

Deepfake detectors and watermarks are useful, but they cannot be the control that stops a payment. NIST's report on synthetic content (AI 100-4, November 2024) concludes that no single provenance or detection technique is a comprehensive solution.

Watermarks exist only when the generator applies them. Since August 2, 2026, the EU AI Act has required providers of systems that generate synthetic audio and video to mark their output, but a fraudster using an open-weight model or a service outside the EU will not comply. Marks can also be attacked: UnMarker (IEEE Symposium on Security and Privacy, 2025) cut the best detection rate of semantic image watermarks to 43%. And a live call leaves no time to upload a clip and wait for a score.

Rule of thumb

Design the protocol to work even if the fake is perfect. A control that depends on someone noticing an odd voice or a video glitch will not survive the next generation of models.

The verification protocol, step by step

For finance, HR and executive assistants. Adapt the thresholds to your size; keep the principles.

Slash recommendation, built on FBI and FinCEN guidance and adapted to companies.
SituationControlWho
Payment request by call, voice note, video or chatHang up and call back on a number already on file, never one given in the messageTreasury, accounts payable, assistants
Payment above a set thresholdTwo approvers; the second confirms through a channel other than the request'sFinance
Supplier asks to change bank detailsWritten request, callback to the contact in your supplier file and a second approver; no payment to the new account before thenAccounts payable, procurement
Employee asks to change payroll accountOnly through the HR system with the employee's usual login, or in personHR, payroll
Executive request outside the usual flowCode word or challenge question agreed in person, never sent by messageAssistants, finance
Known person writing from a new number or accountTreat as unverified and confirm through a channel verified beforehandEveryone
Password or MFA reset requested by phoneCallback to the registered number and manager approval; MFA codes are never sharedIT help desk
Remote hire or contractorLive identity check before any system accessHR, IT
Any doubtPause: anyone may stop a payment to verify it, without penaltyEveryone, backed by management

Two principles sit above the table: no payment or bank change is approved on the strength of a voice or a video alone, whoever seems to be speaking, and verification happens on a channel you chose, never the one the request came from.

Pause-and-verify culture, training and simulations

A protocol only works if people feel safe applying it to a senior voice, so the signal must come from the top: the CEO and CFO tell their teams in writing that they will never ask for a payment or bank change by voice or video alone, and that being verified is expected.

  • Train finance, HR, assistants and help desk staff with real cases (Arup, the FBI warnings), not generic slides.
  • Run a tabletop exercise: an urgent request from the "CFO" arrives on a Friday afternoon. Who calls whom, and who can stop the payment?
  • Run controlled phishing and voice-pretext simulations agreed in advance with management, HR and legal, with written consent from anyone whose voice or image is used.
  • Measure behavior, not attendance: share of staff who verified, time to escalate, payments stopped.

Slash runs controlled phishing and social-engineering tests from COP 5 million (see the pentest page); for the technical side, read how AI changes pentesting.

If the money already left: incident response

  1. Call your bank immediately and request a recall or freeze of the transfer at the first suspicion: a false alarm is easier to undo than a transfer that has moved on.
  2. Preserve evidence: call logs, numbers, voice notes, meeting links, chats, emails with headers and transaction details. Don't delete anything or confront the impostor.
  3. Contain: freeze related pending payments, reset credentials that may be compromised, and warn the impersonated executive and the teams likely to be targeted next.
  4. Report. In Colombia, to ColCERT, the national cyber emergency response team (it has incident and phishing reporting channels), and through a criminal complaint; CONPES 3995, the national digital security policy, also lists the National Police's CSIRT (CSIRT PONAL). If personal data were compromised, Ley 1581 of 2012 requires informing the SIC, through the security-incident module of the national database registry (RNBD). If a US bank or subsidiary is involved, the FBI's IC3 takes complaints. In France and elsewhere in the EU, use the national channels and involve your DPO.
  5. Learn: identify the control that failed or was bypassed, update the protocol and share the lesson without blaming the person who was deceived.

Context, not legal advice: review your case with counsel.

Colombia. Ley 2502 of 2025 (signed July 28, 2025) amended Article 296 of the Criminal Code on falsedad personal (impersonation): when it is committed with artificial intelligence, the fine increases by up to one third, provided the conduct does not constitute another offence. The law defines deepfakes and orders a public policy against AI misuse within two years. In a payment fraud, your lawyer will assess which offences apply.

European Union. Article 50 of the AI Act has applied since August 2, 2026. Providers of systems that generate synthetic audio, images, video or text must mark output in a machine-readable, detectable way (systems already on the market have until December 2, 2026), and deployers must disclose the deepfakes they publish, with lighter duties for evidently artistic or satirical work. Breaches can cost up to 15 million euros or 3% of worldwide annual turnover.

Fraudsters don't label their fakes, so these rules mostly give victims and authorities a legal basis. For your own company they cut the other way: if you use an executive's synthetic voice or avatar in marketing or training, get written consent and label it where the AI Act applies. More in our 2026 regulatory map.

Executives: manage your public voice and video footprint

The FBI advises limiting public audio and images of yourself, but an executive cannot vanish from public view. The aim is to know what exists and make sure none of it can move money.

  • Inventory recordings: earnings calls, interviews, podcasts, keynotes, social videos.
  • Protect personal numbers and accounts, which impostors use to open "private" channels.
  • Agree a code word in person with your assistant, your CFO and your family.
  • Tell teams, clients and key suppliers how you will and will not contact them, so the exception stands out.
  • Watch for fake profiles using your name and photo on professional networks and messaging apps.
Our rule

Assume your voice can be cloned and your face animated, and make sure no payment in your company depends on either.

Key takeaways

  • Deepfake fraud is documented: Arup lost about $25.6 million in 2024 after a video call with a deepfaked CFO and colleagues.
  • The FBI's IC3 logged 22,364 complaints mentioning AI in 2025, with $893 million in losses.
  • Detectors and watermarks help but cannot be the control: NIST finds that no single technique is a comprehensive solution.
  • The protocol: no payment or bank change by voice or video alone, callback to a known number, dual approval, code words and a pause-and-verify culture.
  • If money leaves, call the bank first, preserve evidence and report (ColCERT in Colombia); Ley 2502 of 2025 and AI Act Article 50 frame the legal side.

Sources

  1. Arup deepfake video-call scam in Hong Kong · CNN, 2024-05-16
  2. Senior US officials impersonated in malicious messaging campaign (PSA I-051525-PSA) · FBI IC3, 2025-05-15
  3. Criminals use generative artificial intelligence to facilitate financial fraud (PSA I-120324-PSA) · FBI IC3, 2024-12-03
  4. 2025 Internet Crime Report · FBI IC3, 2026-04-16
  5. Alert on fraud schemes involving deepfake media (FIN-2024-Alert004) · FinCEN, US Treasury, 2024-11-13
  6. The Great Messaging Heist (study press release) · Kaspersky, 2026-09-14
  7. Reducing Risks Posed by Synthetic Content (NIST AI 100-4) · NIST, 2024-11
  8. UnMarker: a universal attack on defensive image watermarking · arXiv (IEEE Symposium on Security and Privacy 2025), 2024-05-14
  9. AI Act, Article 50: transparency obligations · European Commission, AI Act Service Desk, 2026-08-02
  10. Ley 2502 de 2025 · Comisión de Regulación de Comunicaciones (compilación jurídica), 2025-07-28
  11. ColCERT: incident reporting · ColCERT, 2026-09
  12. Detecting and countering misuse of AI: August 2025 · Anthropic, 2025-08-27

Editorial note: this analysis reflects the public information available on the review date. Models, prices and rules change fast; every third-party figure links to its source, and our opinions are labeled as such. Spotted an error? Write to contact@slash-digital.io.

Frequently asked questions

The questions we hear often

Can deepfake detection software protect my company?

It helps, especially to analyze suspicious recordings after the fact, but it should not be the control that stops a payment. NIST concludes that no single detection or provenance technique is a comprehensive solution, and a live call leaves no time for analysis. What protects you is verification by process.

What should an employee do if the CEO calls asking for an urgent transfer?

Stay polite, end the call and call back on the number on file, or confirm through another verified channel. If the amount is above the threshold, the second approval applies as usual. A real CEO will accept the delay.

Is a code word enough?

It is a useful extra layer, recommended by the FBI for families, but it does not replace the callback or dual approval. Agree it in person, never send it by message and change it when the team changes.

Is impersonating someone with AI a crime in Colombia?

False personation (falsedad personal) was already an offence, and Ley 2502 of 2025 raises the fine by up to one third when it is committed with AI, provided the conduct does not constitute another offence. For a specific case, consult a lawyer.

Where do we report deepfake fraud in Colombia?

To your bank first, to try to recall the transfer. Then to ColCERT, the national cyber emergency response team, and through a criminal complaint. If personal data were compromised, to the SIC through the RNBD security-incident module.

Talk to Slash

Let's put it in production

Tell us your challenge. We reply within 24 business hours with an honest first read: if we can help, we'll say how; if not, we'll say who can.

I reply personally. No endless forms, no canned replies.

Message Esteban