How the attack works
- The attacker researches the company: org chart, reporting lines, travel schedules, deal activity.
- They pick a moment when the real executive is unreachable — travel, earnings quiet periods, holidays.
- The employee receives an urgent, confidential request: a wire for an acquisition deposit, a legal settlement, a supplier emergency.
- Pressure and secrecy suppress verification: "this must stay between us until the announcement."
- Funds move to accounts designed for rapid onward transfer, closing the recovery window within days.
How AI voice cloning changed CEO fraud
Historically the weak point was the medium: a fake email or an unfamiliar voice. Voice cloning removed it — seconds of public audio from an earnings call or podcast suffice to produce a real-time clone of the actual executive. The employee doesn't just receive instructions attributed to the CFO; they hear the CFO. Attackers also size requests below dual-approval thresholds so a single deceived employee is sufficient. See vishing for the wider voice-fraud pattern.
How to prevent it
- Enforced callback verification for every payment request received by voice or email — dial the executive back on their registered number. The clone can't answer the real phone.
- No-exception culture from the top: executives publicly commit that no genuine request will ever punish verification.
- Verification with no amount floor, since attacks are sized under thresholds.
- Real-time synthetic-voice scoring on conferencing and phone channels as an early warning.