Your phone rings. It is your CEO's voice — same cadence, same laugh, same urgency before a board meeting — asking you to wire $48,000 to a new vendor account before noon. You recognize the voice instantly. That is the problem: so does the attacker. With as little as three seconds of scraped audio, commodity AI tools can now clone a voice well enough to fool the person who hears it every day, and an estimated 40% of business email compromise attacks now include some AI-generated voice, video, or text.
Business email compromise (BEC) was already the FBI's second-costliest cybercrime category, with $3.05 billion in reported U.S. losses across nearly 25,000 complaints in 2025 — an average of roughly $123,000 per incident. AI has made the con cheaper to run and harder to spot: a convincing voice clone sails past the "does this sound like my boss?" check that used to be your last line of defense. The good news is that the controls that stop deepfake BEC are mostly procedural, not technical — and a small business can put them in place this week.
How a Deepfake BEC Attack Actually Works
Forget the Hollywood version with hackers in hoodies. A modern AI-driven BEC attack is a short, disciplined play in three acts.
Act 1: Harvesting your voice and routines
Attackers start by collecting training material, and small businesses leak more of it than they realize:
- Public audio and video. Podcast interviews, webinar recordings, "meet the founder" clips, voicemail greetings, and earnings-style update videos all provide clean voice samples. Thirty seconds from a single video is plenty.
- Meeting artifacts. Screen-shared recordings, transcribed calls, and email signatures reveal who approves payments, what vendors you pay, and how requests are normally worded.
- Compromised inboxes. A single phished mailbox exposes invoice threads, approval chains, and the exact tone your vendors and executives use — which generative AI then mimics.
Act 2: Building the pretext
With that dossier, attackers pick one of three proven scripts:
- Executive impersonation. A voice call or voicemail from "the owner" authorizing an urgent wire, often framed as confidential — an acquisition, a tax payment, a vendor dispute that must be settled quietly.
- Vendor impersonation. An email thread, increasingly with AI-polished writing, announcing changed bank details for a real supplier. Your next legitimate invoice payment goes to the attacker's account. Vendor-side compromise has overtaken the classic "CEO fraud" as the dominant BEC flavor.
- The video-call ambush. In the most audacious variant, a finance staffer joins a video call where every other participant is an AI-generated fake. One widely reported incident ended with a $25 million wire before anyone realized the CFO on screen never existed.
Act 3: The urgency trap
Every variant ends the same way: a manufactured deadline. "Before noon." "Before the auditor lands." "Do not loop in anyone else — this is sensitive." Urgency exists to short-circuit exactly one thing: your verification process. If you have no written process, urgency wins by default.
Why Small Businesses Are the Sweet Spot
Large enterprises lose bigger sums per incident, but small businesses get hit more often relative to their defenses. Three structural reasons:
- One person owns the whole payment flow. When the same person receives the invoice, approves it, and releases the wire, there is no second pair of eyes for a fake to get past.
- Vendor relationships run on email and trust. Bank-detail changes arrive as casual email replies and get typed straight into the accounting system — no callback, no dual approval.
- Detection tools top out around 85% accuracy. No deepfake detector reliably catches current-generation synthetic audio, and most small firms have no detection tooling at all. Procedure is the control; software is the backstop.
The FBI's 2025 data logged more than 22,000 AI-related fraud complaints with nearly $900 million in adjusted losses — and that counts only cases victims recognized and reported. Quiet vendor-payment diversions surface weeks later, when the real supplier asks why an invoice is overdue.
The AP Controls Checklist: Nine Controls That Stop Deepfake BEC
You do not need an enterprise security budget. You need written rules that no voice, video, or email can override. Implement these in order.
1. Out-of-band verification for every payment change
This is the single highest-value control, and the FBI and CISA recommend it explicitly: any new payee, changed bank account, or off-cycle wire must be confirmed through a different channel than the one that delivered the request.
- Request arrived by email? Call the vendor on a previously known number — never a number in the suspicious message.
- Request arrived by voice call? Confirm by email to a known address, or in person.
- Set up the verification process at the start of each vendor relationship, not during a crisis. Agree in advance who can request changes and how you will confirm them.
A callback to a number you already had on file defeats voice clones, email compromise, and video fakes simultaneously — the attacker cannot intercept a call to the real person.
2. Two-person authorization above a threshold
No single person should be able to initiate and release a payment above a written threshold. Pick a number that fits your volume — many small firms use $5,000 or $10,000 — and require a second approver for anything above it.
The rule must be absolute: no exceptions for urgency, seniority, or confidentiality. "The CEO said to skip the process" is precisely what a cloned CEO would say. Put the no-exceptions clause in writing so your bookkeeper can point to it under pressure.
3. A vendor master-change procedure
Most BEC losses flow through one weak point: someone edits bank details in the accounting system on the strength of an email. Lock that down:
- Only named staff may edit vendor payment records.
- Every change requires the out-of-band callback from control 1, documented with date, time, and who confirmed.
- Review the vendor master quarterly. Stale vendors, duplicate names with different account numbers ("Acme Inc" vs. "Acme Inc."), and recently changed records deserve a second look.
4. Kill voice and video as approval channels
Make it policy: a voice call can support a payment process, but it can never replace it. The same goes for video calls and voice notes. Approvals live in your accounting system or a documented approval thread — never in a phone call, however familiar the voice.
One practical trick: establish a family-style code word or challenge question for payment approvals with each key vendor and executive. A low-tech shared secret defeats high-tech impersonation because the attacker cannot guess what was never written down in email.
5. Phishing-resistant MFA on email and banking
Attackers who compromise a real mailbox inherit its trustworthiness — their messages pass every authentication check because they come from the genuine account. CISA's guidance is direct: protect high-value accounts with phishing-resistant multi-factor authentication such as FIDO2 security keys, not just SMS codes.
At minimum: MFA on every business email account, every banking portal, and every payment platform. No shared logins — shared credentials mean you cannot tell who approved what.
6. Shrink your public voice and video footprint
You cannot un-publish the internet, but you can stop feeding the models:
- Remove voicemail greetings that state names and titles; a generic greeting works fine.
- Gate webinar and meeting recordings behind logins instead of public links.
- Brief executives that podcast clips, conference talks, and social video are voice-clone source material — not a reason to hide, but a reason the other controls are non-negotiable.
- Discourage unsanctioned AI tools that upload meeting recordings to third-party services; every shadow upload is a dossier entry waiting to be harvested.
7. Train on the actual attack, not the concept
Annual slide-deck security training does not survive contact with a panicked Tuesday morning. Instead:
- Play staff a real cloned-voice demo so "it sounded exactly like you" stops being hypothetical.
- Run a tabletop exercise: walk through what each person does when an urgent wire request arrives, step by step, including who they call and what they say.
- Rehearse the sentence that stops fraud: "I need to verify this through our normal process — I will call you back." Make it culturally safe to slow down a request from the top.
8. Reconcile fast and review payment patterns
Speed of detection bounds the size of the loss. Wires can sometimes be recalled within 24–72 hours through the FBI's IC3 Recovery Asset Team process — but only if you notice in time.
- Reconcile operating and payroll accounts daily or weekly, not monthly. A same-week review catches a diverted payment while recovery is still possible.
- Watch for pattern breaks: a vendor paid twice in one cycle, round-number wires to new payees, payments just under your approval threshold, or a familiar vendor's name paired with subtly different banking details.
- Keep a clean, timestamped payment log outside your email. When every legitimate payment is recorded in one version-controlled ledger, an unauthorized wire stands out immediately instead of hiding in inbox noise.
9. Have a written incident response plan
Decide before an incident: who calls the bank, who files the IC3 complaint at ic3.gov, who preserves evidence (full email headers, call logs, the original invoice thread), and who notifies the impersonated vendor. Print the one-page plan and keep it where the person who pays bills can reach it without logging into anything — because the compromised system may be the one they normally use.
Common Mistakes That Void Good Controls
Even firms with written policies fail in predictable ways. Audit yourself against this list:
- Verifying inside the attacker's thread. Replying "is this legitimate?" to the compromised email, or calling the number in the signature block of the fraudulent message. Verification must be out-of-band and out-of-thread, every time.
- Grandfathering "known" vendors. Skipping callbacks for long-term suppliers. Vendor mailboxes get compromised too — tenure is not authentication.
- Threshold shopping. Approvers who split or nudge payments to stay under the dual-authorization limit, or attackers who learn your threshold and invoice just below it. Review near-threshold payments explicitly.
- Treating AI-written email as a tell. Five years ago, broken English flagged a scam. Generative AI now writes flawless, stylistically matched business prose. Judge requests by process compliance, not prose quality.
- Filing the policy and forgetting it. Controls that nobody rehearses decay within a quarter. Re-run the tabletop exercise when staff change roles, and re-confirm vendor banking details annually.
How Bookkeeping Fits Into Fraud Defense
Fraud controls and bookkeeping are the same discipline wearing different hats: both are about knowing exactly where your money went and why. A business that reconciles weekly, keeps vendor records tidy, and logs every payment with its supporting invoice will spot a diverted wire in days; a business that reconciles quarterly may not notice until the real vendor sends a collections letter.
That is also why plain-text, version-controlled accounting earns its keep here. When your ledger is a transparent file history rather than a black-box database, you can see precisely when a vendor's account number changed, who changed it, and which payments followed — the exact audit trail a bank investigator or insurer asks for first.
Simplify Your Financial Management
As you tighten your payment controls against deepfake fraud, maintaining clear, auditable financial records is what makes those controls enforceable — a verification policy only works if the books show every payment it was supposed to govern. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.





