Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Voice and Video Deepfakes: A New Weapon Against Businesses

A call from the president, whose voice agrees - but it's not the president. How voice cloning and deepfake videos work in attacks on companies and how to defend yourself using procedure, not intuition.

PUBLIC RESEARCH
AUTHOR
/ Penetration Tester (OSCP, PNPT)
PUBLISHED
7 July 2026
READING TIME
13 min read
TOPIC
AI Security
Voice and Video Deepfakes: A New Weapon Against Businesses

Imagine this scenario. A finance department employee answers the phone. The president is calling - the same voice, the same manner of speaking, the same “listen, I have an urgent matter for you”. He asks for an immediate transfer to the new contractor because “we are closing the transaction and there is no time for formalities.” Everything is correct: the number, the tone, the haste typical of the boss. The employee makes the transfer. The problem is that the president never called. He was talking to a deepfak - a cloned voice generated by AI from several publicly available recordings. This is not a future scenario. This is happening now, and companies are losing real money this way.

Why it works: attack on trust, not on the system

Deepfake attacks on companies are dangerous because they bypass technical security measures and hit something that cannot be patched: human trust in a recognizable voice and face. Throughout our lives we learn that when we hear a familiar voice, we are talking to a familiar person. AI just invalidated that assumption. It’s an evolution of the classic scams we know - CEO fraud (BEC) and employee vishing] - enhanced with a layer that overcomes the natural verification reflex.

How a cloned voice is created

The biggest surprise for many is how little material is needed. Modern speech synthesis tools can reproduce the tone and manner of speaking of a specific person from several dozen seconds of a recording. And there is plenty of this material everywhere:

  • recordings from conferences, webinars and interviews,
  • podcasts and public speaking,
  • videos on social media,
  • media statements and even a voicemail greeting.

The higher someone is in the hierarchy (president, financial director), the more his or her voice circulates publicly - and these are the people who are most often imitated, because their orders carry the greatest weight. Deepfake video requires more material and power, but in a videoconferencing scenario (where the image quality is already low) it can already be misleading.

Company attack scenarios

Deepfake is a tool, not a goal - it fits proven fraud patterns, adding credibility to them:

  • President fraud 2.0. A phone call or voice message “from the management” with an urgent request for a transfer, change of the contractor’s bank details or the purchase of gift cards. Haste and authority turn off your vigilance.
  • Fake video conference. An employee joins a meeting where “management” (wholly or partially generated) authorizes a transaction or instructs the disclosure of data. There are known cases of withdrawing multi-million amounts in this way.
  • Vishing the helpdesk/IT department. The attacker calls in an “employee voice” asking for a password reset or MFA bypass. This is particularly effective because the support department is, by definition, focused on helping.
  • Payment redirection. The “voice” of a trusted contractor or superior confirms the change of the account number just before a large transfer.

In all cases, deepfakes do one thing: credify an urgent, unusual request for money or access.

Why “I will be vigilant” is not enough

The natural reaction is: “I’ll know something’s wrong.” The problem is that deepfakes are designed precisely not to trigger this reflex - and the attacker adds time pressure and authority that impair critical thinking. Relying on “feel” is unreliable because:

  • the quality of clones is growing faster than our ability to recognize them,
  • when stressed and in a hurry, people trust more, not less,
  • tools to detect deepfakes exist, but they are unreliable and cannot keep up with generators - you cannot base a defense on them.

The conclusion is the same as with offensive AI: when sensory signals are no longer reliable, the defense must switch to procedures and verification through an independent channel.

How to defend yourself: processes, not intuition

The good news: Although the attack technology is new, effective defense is based on proven, simple principles. The idea is that no sensitive operation depends on a single channel - even if the voice and face match.

  • Out-of-band verification as an obligation. Each request for a transfer, change of bank details or urgent access must be confirmed by a different, known channel than the one through which it came. Did you answer the phone? Call back the official number on file - not the number on the call.
  • Callback procedure and double authorization. Financial operations above the threshold require approval by two people and a call back. This completes the attack based on a single “call from the boss”.
  • Fixed verification word/code for sensitive commands between key people - something deepfakes don’t know because it’s not in public recordings.
  • Hard payment controls. Changing the contractor’s account number should trigger mandatory, independent verification - this is one of the most common paths of loss.
  • Culture in which you can say “I’ll check”. An attacker’s greatest ally is the pressure of authority. The employee must have clear consent to verify even the “president’s” request - and be sure that he will not be punished for it.
  • Current training. Show your team what deepfakes sound and look like and practice scenarios. The awareness that “the voice is correct and it may still be a fake” is crucial today.

Summary

Voice and video deepfakes take classic financial frauds to a new level because they overcome the reflex that used to make us feel safe: recognizing a familiar person by their voice and face. It only takes seconds of a public recording to clone your boss, and the attack always targets one thing - an urgent, unusual request for money or access. Since “gut” and detection tools cannot be relied upon, the only solid defense is processes: independent channel verification, dual authorization, payment controls, and a “I’ll check first” culture. The attack technology is new; recipe for defense - surprisingly classic.

Do you want to check whether your organization can withstand a social engineering attack using a deepfake - and tighten authorization procedures? Contact us - social engineering testing and security consulting covers such scenarios.

Frequently asked questions (FAQ)

How much recording does it take to clone someone’s voice? Modern tools can reproduce the tone and manner of speaking from several dozen seconds of material. Public figures and management staff are particularly vulnerable because their voices are widely available in recordings of speeches, interviews and social media. Therefore, the defense cannot rely on “knowing by voice”.

Are there deepfake detection tools? Yes, but they are unreliable and haven’t kept up with generator development - they give false results both ways. They can be treated as an auxiliary layer, but not as the basis of defense. It is much more effective to introduce verification procedures that work regardless of whether the conversation was real or fake.

What’s the cheapest and fastest way to reduce this risk in your company? Introduce one hard rule: no transfer, change of bank details or urgent access is made solely on the basis of a phone call, voice message or video call - verification through an independent, known channel (calling back to the official number) is always required. It costs little and covers most of the real loss scenarios.

Does deepfakes only threaten large companies? No. Although high-profile cases involve large amounts of money, voice cloning is cheap and scalable, so small and medium-sized companies and private individuals are also targeted (e.g. the “grandchild” scam with a loved one’s real voice). The principle of defense is the same regardless of scale: verify sensitive requests through an independent channel.

SHARE / COPY