AI Security, Privacy and Compliance

How Do You Protect Your Business From AI Voice-Cloning and Deepfake Scams?

Last updated 24 July 2026 · 6 min read

Direct Answer

Protect your business from AI voice-cloning and deepfake scams by treating any urgent, unusual, or secretive request to move money or change payment details — no matter how convincing the voice or video sounds — as something that must be verified through a second, independent channel before anyone acts on it. The scam works by cloning a real person's voice (a CEO, a supplier, sometimes a family member) from a few seconds of public audio and using it to create urgency and bypass normal scepticism; the defence isn't learning to detect a clone by ear, which is increasingly unreliable, but a callback-to-a-known-number rule and a payment-change verification step that no one is allowed to skip, regardless of how senior or panicked the caller sounds.

Detailed Explanation

Most of this site's AI-security content covers a business's own use of AI tools — what to share, what not to share, how to police it. This page covers the opposite direction: AI being used against the business, by someone impersonating a real person the business already trusts.

AI voice-cloning and deepfake scams use a short sample of someone's real voice or video — often pulled from something already public, like a company video, a webinar recording, or a social media clip — to generate convincing audio or video of that person saying something they never said. In a business context, the most common version is a fake urgent call or voice message from a "CEO," "director," or known supplier, instructing someone to make an unusual payment, change bank details, or bypass a normal approval step, relying on the target's trust in the voice and the pressure of urgency to short-circuit normal scepticism.

This isn't a hypothetical: the Australian Cyber Security Centre names voice cloning and deepfakes explicitly as a current social-engineering technique, and Scamwatch's own guidance on how scammers use technology and AI covers the same pattern. It's the inbound mirror of the outbound risk covered in what can go wrong when an AI agent can take real actions — that page is about a business's own AI systems causing harm; this one is about AI being weaponised against the business from outside.

Building the Verification Habit

1. Set a rule that urgency never skips verification. The entire scam depends on creating enough pressure — "wire this before the bank closes," "don't tell anyone, it's confidential" — that the target acts before thinking to check. A simple, non-negotiable rule ("any request to move money or change payment details gets verified through a second channel, no exceptions, regardless of who's asking or how urgent it sounds") removes the judgement call in the moment when judgement is most compromised.

2. Verify through a channel the caller doesn't control. If the request came by phone, don't confirm by calling the number the caller gave you or replying to the same call — hang up and dial a number already on file (from a previous invoice, a saved contact, the company directory). If it came by video call, a second confirmation through an unrelated channel (an internal chat message, an in-person check) closes the loop a convincing video alone can't.

3. Put a second person in the loop for payment changes and unusual transfers. A rule that no single person can both receive an unusual payment instruction and action it — someone else has to independently confirm it — means a scam has to fool two people through two different channels, not one person under pressure on a single call.

4. Treat any request for secrecy as a red flag, not a reason to comply. Legitimate urgent business requests don't usually come with "don't mention this to anyone else" attached — that instruction exists specifically to stop the target getting a second opinion, and should trigger more scrutiny, not less.

5. Brief the people most likely to be targeted. Whoever handles payments, banking changes, or has visibility of the CEO's or directors' public appearances is the most likely target — a short, concrete briefing (what this looks like, what the verification rule is, that it's fine to say "I need to call you back on your usual number") is more effective than a general "watch out for scams" policy nobody remembers under pressure.

Things to Consider

  • This overlaps with, but is distinct from, ordinary invoice and payment fraud. How do you automate vendor and supplier onboarding covers verifying a new supplier's bank details at setup — voice-cloning scams instead target an existing, already-trusted relationship, which is exactly why the verification habit above needs to apply even to requests that appear to come from someone the business already knows well.
  • A written AI usage policy is a different control for a different risk. What should an employee AI usage policy include governs how staff use AI tools at work; this page is about staff being deceived by someone else's AI use, which needs a verification process rather than a usage policy.
  • The underlying scam pattern isn't new — only the voice is. Business email compromise and CEO-impersonation fraud predate generative AI by years; what's changed is that a phone call or video, previously harder to fake convincingly than an email, is now within reach of the same scam.
  • Report incidents, even attempted ones. Reporting a suspected or attempted scam to Scamwatch, even where no money was lost, helps build the picture other businesses and regulators use to track emerging patterns.

Common Mistakes

  • Relying on "I'd recognise their voice" as the control. Recognising a familiar voice is exactly what the scam exploits — a cloned voice is designed to sound familiar, so trusting your ear is the failure mode, not the defence.
  • Having a verification rule that only applies to large amounts. Scammers calibrate the request to what looks routine for the business, which for a small business might be a few thousand dollars, not the large headline figures reported in bigger cases — apply the same verification rule regardless of amount.
  • Letting one person both receive and action an unusual request alone. If the same person who takes the call also has the authority to make the payment with no second check, there's nothing standing between a convincing call and a completed transfer.
  • Treating this as an IT problem rather than a process one. No email filter or antivirus catches a phone call — the defence is entirely procedural (verification habits, second-person checks), not technical.
  • Waiting until after an incident to write the verification rule down. A rule everyone already knows and has practised is far more likely to hold up under the pressure the scam creates than one improvised for the first time during the actual call.

Frequently Asked Questions

Can you actually tell an AI-cloned voice apart from the real person?
Not reliably, and it's getting harder every year. Early cloned-voice scams had flat intonation or odd pacing a careful listener could sometimes catch; current tools trained on a short public sample (a video call, a podcast appearance, a voicemail greeting) can reproduce tone and cadence closely enough that ear-detection isn't a defence to build a process around. Verification through an independent channel — not judgement of how a voice sounds — is the reliable control.
Is this only a risk for large businesses?
No — small businesses are targeted specifically because they're less likely to have a formal verification process for payment changes or urgent requests, and a convincing call to a bookkeeper or office manager who handles payments alone can bypass a small team's normal checks entirely. The Australian Cyber Security Centre and Scamwatch both note that social-engineering scams target businesses of every size, and a small business often has fewer people who'd notice something unusual.
What should you actually do if you suspect a call or video is a deepfake?
Don't act on the request through the same channel it arrived on. Hang up and call the person back on a number you already have on file — not one the caller provides — or confirm through a separate, pre-agreed method (an internal messaging tool, an in-person check). If money has already been sent, contact your bank immediately (fast reporting materially improves recovery odds) and report the incident to Scamwatch and, for a material loss, the police.

References

Related Questions