A supplier calls asking you to send a rush payment to a "new" account before the bank closes. Your voicemail greeting, a video from a job walkthrough, or a clip from a customer testimonial is now enough raw material for a scammer to build a synthetic voice that sounds like you, your bookkeeper, or your biggest client — and use it to ask someone on your team for money, credentials, or a favor. This isn't science fiction anymore; it's a real category of fraud the security industry has been tracking closely through 2026, and small businesses are attractive targets precisely because they tend to have fewer layers of approval between "the boss called" and "the money moved."
Why this suddenly works
Cloning a voice used to require a professional studio and hours of clean audio. That's no longer the bar. Consumer and open-source voice tools can now generate a convincing clone from a short public clip — a voicemail greeting, a webinar recording, a video posted to social media — and the output is good enough that a person on the phone, especially someone busy or under pressure, has no reliable way to tell it apart from the real thing by ear alone. Add a spoofed caller ID showing your actual business or cell number, and the illusion holds up even better.
The scam almost never depends on fooling you. It depends on fooling the person who takes the call: an office manager, a bookkeeper, a new hire who doesn't yet know your voice or your habits. The pattern security researchers describe is consistent — the call comes at a busy moment, late in the day, or right before a holiday, and it pushes urgency: wire this now, buy gift cards for a client, change the payout account for a vendor invoice that's due today.
The one habit that actually stops it
You don't need deepfake-detection software to defend against this. What actually works is boring, and that's the point: never authorize a money movement, credential change, or account change based on a phone call alone. Any request like that gets verified through a channel the caller didn't choose.
- Hang up and call back on a number you already have on file for that person or vendor — not a number the caller gives you, and not the number that just called you.
- Use a second channel. A text to a known cell number, a message in your existing project chat, or an email to an address you've used before all work better than trusting the voice on the line.
- Set a dollar threshold that requires two people. Any transfer or account change above that line needs a second human to confirm it through an independent channel, no exceptions, even if the person asking outranks everyone in the building.
This is exactly the advice security teams give large companies, and it works just as well — arguably better — for a five-person shop, because there are fewer people to train and fewer approval chains to design.
Build the policy in one afternoon
You don't need a consultant for this. Write down three things and share them with everyone who touches money, scheduling, or customer accounts:
- The trigger list. Name the specific requests that always require callback verification: wire transfers, changes to vendor payment details, gift card purchases, password resets, and any "send this before end of day" request tied to money.
- The verification method. Spell out exactly how a callback works at your business — which number to call, who to escalate to if that person doesn't answer, and what to do if the request truly can't wait (it almost never truly can't).
- A shared code phrase for your closest team members and highest-trust vendors — something only the real person would know, changed periodically, and never sent by email or text where it could leak. If a call demanding urgency can't produce it, the answer is no until it's verified another way.
Print this, put it by the phone or pin it in your team chat, and walk through it once with everyone who could plausibly get one of these calls. The goal isn't to make people paranoid about every call — it's to make the callback step so automatic that skipping it feels wrong, the same way skipping a seatbelt does.
What to do this week
Pick one afternoon and do three things: write your trigger list and callback policy, agree on a code phrase with your bookkeeper and your top two or three vendors, and tell your team the policy applies to everyone, including you. If someone calls claiming to be you and asking for an exception, that's exactly the call the policy is built to catch. A five-minute callback habit is a lot cheaper than the alternative, and unlike most security advice, this one doesn't cost a subscription.
