Deepfake and cloned-voice fraud: a protocol for companies
A voice or a face no longer proves who is talking to you. Documented cases, verified figures and the protocol that protects payments even when the deepfake is perfect.
Deepfake fraud is no longer a demo. In 2024 an Arup employee in Hong Kong sent about $25.6 million after a video call in which the CFO and several colleagues were deepfakes, and in 2025 the FBI's IC3 logged 22,364 complaints mentioning AI, with $893 million in losses.
Detection tools help, but they will not stop a payment decided in minutes. What works is a process: no payment or bank-detail change on the strength of a voice or a face, a callback to a known number, dual approval above a threshold and a culture where pausing to verify is expected.
What has happened: cases and numbers
The reference case is Arup. In early 2024 a finance employee at the engineering firm's Hong Kong office joined a video call with what appeared to be the CFO and several colleagues; all were deepfakes. The employee made 15 transfers totaling HKD 200 million, about $25.6 million. Hong Kong police described the case in February 2024, and Arup confirmed in May that it was the victim.
The FBI has since documented the pattern: criminals cloning relatives' voices to fake emergencies (December 2024) and, since April 2025, impostors posing as senior US officials with texts and AI-generated voice messages to build trust and take over accounts, often moving the victim to another messaging platform. HR is a target too: in August 2025 Anthropic reported North Korean operatives using Claude to get and keep remote IT jobs at Fortune 500 technology companies.
| Source | Date | Figure |
|---|---|---|
| FBI IC3, annual report | Apr 2026 | 1,008,597 complaints and $20.877 billion in reported losses in 2025, up 26% on 2024 |
| FBI IC3, AI section | Apr 2026 | 22,364 complaints mentioned AI ($893 million), including over $30M in business email compromise and over $5M in voice-cloning "distress" scams |
| FBI IC3, Colombia | Apr 2026 | 2,222 complainants from Colombia, among the top 20 foreign countries |
| FinCEN (US Treasury) | Nov 2024 | Suspicious-activity reports describing deepfake media rose from 2023 into 2024 |
| Kaspersky, global study | Sep 2026 | 66% of messaging-scam victims believe AI was involved; 31% reported cloned or synthetic voices; 52% of successful scams end in under 30 minutes |
How these attacks work, conceptually
Four ingredients, none of them technical on the victim's side.
- Raw material. Public recordings of the person to imitate: interviews, earnings calls, conference talks, podcasts, social clips. The voice models behind this are covered in voice and audio AI in 2026.
- A pretext. A confidential acquisition, an overdue supplier invoice, a regulator's request: a story that explains why the usual procedure must be skipped.
- Urgency and secrecy. "It has to go out today", "don't mention this to anyone". Pressure removes the time to think.
- Channel switching. The conversation moves to a channel the attacker controls: from email to WhatsApp, from a text to a voice note, from a call to a video meeting. The FBI describes exactly this move.
It is the old CEO fraud with a convincing voice, and Arup adds staging: several fake participants on the same call. The targets are predictable (treasury, accounts payable, payroll, executive assistants, IT help desks), and so is the weak point: the impostor needs you to act inside their channel and on their timeline. Any control that moves the exchange to a channel you trust, or adds time, breaks the scheme.
Why detection tools alone are not enough
Deepfake detectors and watermarks are useful, but they cannot be the control that stops a payment. NIST's report on synthetic content (AI 100-4, November 2024) concludes that no single provenance or detection technique is a comprehensive solution.
Watermarks exist only when the generator applies them. Since August 2, 2026, the EU AI Act has required providers of systems that generate synthetic audio and video to mark their output, but a fraudster using an open-weight model or a service outside the EU will not comply. Marks can also be attacked: UnMarker (IEEE Symposium on Security and Privacy, 2025) cut the best detection rate of semantic image watermarks to 43%. And a live call leaves no time to upload a clip and wait for a score.
Design the protocol to work even if the fake is perfect. A control that depends on someone noticing an odd voice or a video glitch will not survive the next generation of models.
The verification protocol, step by step
For finance, HR and executive assistants. Adapt the thresholds to your size; keep the principles.
| Situation | Control | Who |
|---|---|---|
| Payment request by call, voice note, video or chat | Hang up and call back on a number already on file, never one given in the message | Treasury, accounts payable, assistants |
| Payment above a set threshold | Two approvers; the second confirms through a channel other than the request's | Finance |
| Supplier asks to change bank details | Written request, callback to the contact in your supplier file and a second approver; no payment to the new account before then | Accounts payable, procurement |
| Employee asks to change payroll account | Only through the HR system with the employee's usual login, or in person | HR, payroll |
| Executive request outside the usual flow | Code word or challenge question agreed in person, never sent by message | Assistants, finance |
| Known person writing from a new number or account | Treat as unverified and confirm through a channel verified beforehand | Everyone |
| Password or MFA reset requested by phone | Callback to the registered number and manager approval; MFA codes are never shared | IT help desk |
| Remote hire or contractor | Live identity check before any system access | HR, IT |
| Any doubt | Pause: anyone may stop a payment to verify it, without penalty | Everyone, backed by management |
Two principles sit above the table: no payment or bank change is approved on the strength of a voice or a video alone, whoever seems to be speaking, and verification happens on a channel you chose, never the one the request came from.
Pause-and-verify culture, training and simulations
A protocol only works if people feel safe applying it to a senior voice, so the signal must come from the top: the CEO and CFO tell their teams in writing that they will never ask for a payment or bank change by voice or video alone, and that being verified is expected.
- Train finance, HR, assistants and help desk staff with real cases (Arup, the FBI warnings), not generic slides.
- Run a tabletop exercise: an urgent request from the "CFO" arrives on a Friday afternoon. Who calls whom, and who can stop the payment?
- Run controlled phishing and voice-pretext simulations agreed in advance with management, HR and legal, with written consent from anyone whose voice or image is used.
- Measure behavior, not attendance: share of staff who verified, time to escalate, payments stopped.
Slash runs controlled phishing and social-engineering tests from COP 5 million (see the pentest page); for the technical side, read how AI changes pentesting.
If the money already left: incident response
- Call your bank immediately and request a recall or freeze of the transfer at the first suspicion: a false alarm is easier to undo than a transfer that has moved on.
- Preserve evidence: call logs, numbers, voice notes, meeting links, chats, emails with headers and transaction details. Don't delete anything or confront the impostor.
- Contain: freeze related pending payments, reset credentials that may be compromised, and warn the impersonated executive and the teams likely to be targeted next.
- Report. In Colombia, to ColCERT, the national cyber emergency response team (it has incident and phishing reporting channels), and through a criminal complaint; CONPES 3995, the national digital security policy, also lists the National Police's CSIRT (CSIRT PONAL). If personal data were compromised, Ley 1581 of 2012 requires informing the SIC, through the security-incident module of the national database registry (RNBD). If a US bank or subsidiary is involved, the FBI's IC3 takes complaints. In France and elsewhere in the EU, use the national channels and involve your DPO.
- Learn: identify the control that failed or was bypassed, update the protocol and share the lesson without blaming the person who was deceived.
Legal context in Colombia and the EU
Context, not legal advice: review your case with counsel.
Colombia. Ley 2502 of 2025 (signed July 28, 2025) amended Article 296 of the Criminal Code on falsedad personal (impersonation): when it is committed with artificial intelligence, the fine increases by up to one third, provided the conduct does not constitute another offence. The law defines deepfakes and orders a public policy against AI misuse within two years. In a payment fraud, your lawyer will assess which offences apply.
European Union. Article 50 of the AI Act has applied since August 2, 2026. Providers of systems that generate synthetic audio, images, video or text must mark output in a machine-readable, detectable way (systems already on the market have until December 2, 2026), and deployers must disclose the deepfakes they publish, with lighter duties for evidently artistic or satirical work. Breaches can cost up to 15 million euros or 3% of worldwide annual turnover.
Fraudsters don't label their fakes, so these rules mostly give victims and authorities a legal basis. For your own company they cut the other way: if you use an executive's synthetic voice or avatar in marketing or training, get written consent and label it where the AI Act applies. More in our 2026 regulatory map.
Executives: manage your public voice and video footprint
The FBI advises limiting public audio and images of yourself, but an executive cannot vanish from public view. The aim is to know what exists and make sure none of it can move money.
- Inventory recordings: earnings calls, interviews, podcasts, keynotes, social videos.
- Protect personal numbers and accounts, which impostors use to open "private" channels.
- Agree a code word in person with your assistant, your CFO and your family.
- Tell teams, clients and key suppliers how you will and will not contact them, so the exception stands out.
- Watch for fake profiles using your name and photo on professional networks and messaging apps.
Assume your voice can be cloned and your face animated, and make sure no payment in your company depends on either.
Key takeaways
- Deepfake fraud is documented: Arup lost about $25.6 million in 2024 after a video call with a deepfaked CFO and colleagues.
- The FBI's IC3 logged 22,364 complaints mentioning AI in 2025, with $893 million in losses.
- Detectors and watermarks help but cannot be the control: NIST finds that no single technique is a comprehensive solution.
- The protocol: no payment or bank change by voice or video alone, callback to a known number, dual approval, code words and a pause-and-verify culture.
- If money leaves, call the bank first, preserve evidence and report (ColCERT in Colombia); Ley 2502 of 2025 and AI Act Article 50 frame the legal side.
Sources
- Arup deepfake video-call scam in Hong Kong
- Senior US officials impersonated in malicious messaging campaign (PSA I-051525-PSA)
- Criminals use generative artificial intelligence to facilitate financial fraud (PSA I-120324-PSA)
- 2025 Internet Crime Report
- Alert on fraud schemes involving deepfake media (FIN-2024-Alert004)
- The Great Messaging Heist (study press release)
- Reducing Risks Posed by Synthetic Content (NIST AI 100-4)
- UnMarker: a universal attack on defensive image watermarking
- AI Act, Article 50: transparency obligations
- Ley 2502 de 2025
- ColCERT: incident reporting
- Detecting and countering misuse of AI: August 2025
Editorial note: this analysis reflects the public information available on the review date. Models, prices and rules change fast; every third-party figure links to its source, and our opinions are labeled as such. Spotted an error? Write to contact@slash-digital.io.
The questions we hear often
Can deepfake detection software protect my company?
It helps, especially to analyze suspicious recordings after the fact, but it should not be the control that stops a payment. NIST concludes that no single detection or provenance technique is a comprehensive solution, and a live call leaves no time for analysis. What protects you is verification by process.
What should an employee do if the CEO calls asking for an urgent transfer?
Stay polite, end the call and call back on the number on file, or confirm through another verified channel. If the amount is above the threshold, the second approval applies as usual. A real CEO will accept the delay.
Is a code word enough?
It is a useful extra layer, recommended by the FBI for families, but it does not replace the callback or dual approval. Agree it in person, never send it by message and change it when the team changes.
Is impersonating someone with AI a crime in Colombia?
False personation (falsedad personal) was already an offence, and Ley 2502 of 2025 raises the fine by up to one third when it is committed with AI, provided the conduct does not constitute another offence. For a specific case, consult a lawyer.
Where do we report deepfake fraud in Colombia?
To your bank first, to try to recall the transfer. Then to ColCERT, the national cyber emergency response team, and through a criminal complaint. If personal data were compromised, to the SIC through the RNBD security-incident module.
More analysis to read next
Voice AI in 2026: TTS, transcription, voice agents and music
GPT-Live-1, Gemini 3.8 Live, TTS and transcription for Spanish and French, Suno v6 and the music lawsuits, voice cloning, and how to build a compliant voice agent.
CybersecurityHow AI changes pentesting
What attackers now do with AI, what Mythos, Big Sleep and XBOW find, why validation became the scarce skill and how to adapt your pentest in Colombia.
CybersecurityPentest in Colombia: what to really test
Not a scanner PDF: web apps and APIs, manual validation of every finding and a retest, priced on the outcome.
Where to next
Let's put it in production
Tell us your challenge. We reply within 24 business hours with an honest first read: if we can help, we'll say how; if not, we'll say who can.
I reply personally. No endless forms, no canned replies.