The Voice on the Phone Sounded Exactly Like Your CFO. It Was Not.
Artificial intelligence has made fraud faster, cheaper, and far harder to detect. Deepfake audio, cloned voices, and machine-generated phishing emails have become a distinct threat category in 2026, now accounting for an estimated 8 percent of cyber claims. The scenario plays out simply enough: a finance employee receives a call or email that looks and sounds like leadership, approving an urgent wire transfer. The voice is convincing, the request references real transactions, and the employee acts quickly because the tone carries urgency. The money moves, and by the time anyone realizes what happened, it is gone.
These attacks no longer require a sophisticated criminal operation. The AI tools that power voice cloning and text generation are widely available, inexpensive, and improving rapidly. A short clip of someone’s voice, pulled from a conference recording, a podcast appearance, or even a voicemail greeting, can be enough to generate a convincing imitation. For small businesses, where requests often move quickly and informally, the conditions are especially favorable for this kind of fraud.
Why Small Teams Are Especially Vulnerable
Large organizations tend to have formal approval workflows, segregation of duties, and multiple layers of verification before money moves. A wire transfer at a larger company typically passes through several hands and several systems before it clears. Small businesses rarely operate that way. In a company with 10 or 20 employees, the owner might approve a payment by text message, a bookkeeper might process wires with a single confirmation, and the pace of daily operations discourages slowing down to double-check something that looks routine.
That speed and informality is exactly what deepfake attacks exploit. When a convincing voice or email asks for something that looks like a normal business request, the instinct is to handle it quickly and move on. The attackers know this, and they design their approach around it. The request is usually time-sensitive, carries a tone of authority, and references enough real detail to feel legitimate. By the time doubt creeps in, the action has already been taken.
Simple Habits That Stop Sophisticated Attacks
The encouraging part of this problem is that it responds well to a few straightforward practices. The most effective defense is a second-channel verification step. Before any payment is moved, any bank account information is changed, or any sensitive data is shared in response to a request, verify it through a separate, known communication channel. If you receive a call asking you to wire money, hang up and call the person back on a number you already have on file. If you get an email requesting a payment change, confirm it by phone or in person. That one step, which takes seconds, defeats the vast majority of deepfake and social engineering attempts.
Beyond verification, building a culture where slowing down is acceptable matters. If an employee feels pressure to act immediately on a financial request, they are more likely to skip the verification step. Making it clear that confirming before acting is not only allowed but expected gives your team permission to pause, even when the request sounds urgent. Train your team on what these attacks look like, update that training as the tactics evolve, and make the verification step part of your standard process rather than an afterthought.
Does Your Insurance Cover This?
Not every policy does, and this is worth checking carefully. Social engineering fraud, which is the broader category that deepfake attacks fall into, is not always covered under a standard cyber policy. Some policies include it as a built-in coverage, others offer it as an optional endorsement, and some exclude it entirely. The same is true for crime policies, which may or may not address funds transfer fraud or impersonation schemes depending on how the policy is written.
If your business moves money by wire, processes payments based on emailed instructions, or has employees with authority to approve transactions, this coverage question is worth answering now rather than after a loss. donegan can review your cyber and crime coverage to confirm whether social engineering and funds transfer fraud are covered, and help you close the gap if they are not. The technology behind these attacks will keep improving. Making sure your defenses, both procedural and financial, keep up with it is one of the most practical things you can do this year.
Frequently Asked Questions
What is a deepfake attack in a business context?
A deepfake attack uses artificial intelligence to impersonate a trusted person, typically through cloned audio or video, to trick an employee into taking a harmful action such as wiring money or sharing sensitive data. The technology has become accessible enough that small businesses are now regular targets.
Does my cyber insurance cover deepfake fraud?
It depends on your policy. Social engineering and funds transfer fraud coverage is sometimes included in cyber policies, sometimes available as an endorsement, and sometimes excluded. Reviewing this specific coverage with your agent is important, especially if your business processes payments electronically.
What is the single most effective defense against deepfake fraud?
Second-channel verification. Before acting on any financial request received by phone or email, confirm it through a separate, known communication method such as calling the person back on a number you have on file. This simple step defeats the vast majority of impersonation attempts.

