For companies

Deepfake CEO fraud: how companies can verify high-risk calls

CEO fraud is an old scam: someone poses as a senior executive and pushes an employee to make an urgent, confidential payment or to hand over sensitive data. What has changed is the toolkit. Attackers can try to imitate a known voice with speech synthesis and display a familiar number with caller ID spoofing. Neither the voice nor the number on the screen establishes who is actually calling.

The good news: the defence does not depend on spotting the fake. It depends on a process that holds even when the call sounds completely convincing.

How a deepfake CEO fraud call typically unfolds

The following scenario is fictional, but each element is common in reported cases:

  1. Preparation. The attacker collects public material: interviews, earnings calls, conference talks, social media clips. They learn names, roles and current projects from the company website and professional networks.
  2. The pretext. A call reaches someone in finance or an executive assistant. The voice sounds like the CEO: “We are closing a confidential acquisition. I need a transfer today.”
  3. Pressure and secrecy. “Don’t involve anyone else, the deal is under NDA.” Often a supposed lawyer or advisor follows up by e-mail to make the story look consistent.
  4. The request. A payment to a new account, a change of bank details, a list of employees or access credentials.
  5. Follow-up. If the first attempt stalls, the caller escalates the urgency or switches channel.

In a case reported by CNN in February 2024, Hong Kong police said a finance employee transferred about US$25 million after a video conference in which the other participants, including a supposed chief financial officer, were deepfakes. The FBI’s Internet Crime Complaint Center has also warned that criminals use AI-generated audio to impersonate known people and obtain payments.

Why the voice and the number are not enough

  • The voice: speech synthesis can imitate a person from recordings. Quality varies with the source audio, language and model, so a call can sound slightly off – or perfectly natural. Listening harder is not a reliable control. Our guide on detecting deepfake voice calls explains why.
  • The number: caller ID is information supplied during call setup, and under some conditions it can be manipulated. A head-office number on the screen does not prove the call came from head office. See caller ID spoofing explained.
  • The context: attackers often know real project names and colleagues. Inside knowledge is not proof of identity either.

A verification process that does not depend on the voice

Agree on these rules before an urgent call arrives and make sure executives back them publicly.

1. Define what counts as a high-risk request

For example: any payment to a new or changed bank account, payments above an internal threshold, requests marked confidential or urgent, release of personnel or customer data, and changes to access rights. A high-risk request triggers verification regardless of who appears to be asking.

2. Call back through a contact you already have

End the call politely – “I’ll call you right back” – and call the person using a number from your internal directory or another record that existed before the call. Never use a number, link or contact supplied during the suspicious call or in a related e-mail.

3. Require a second approval

A single person, under pressure, should not be able to release a high-risk payment. Dual control means a second authorised person confirms the request independently.

4. No exceptions for secrecy or urgency

Confidentiality and time pressure are exactly what the scam relies on. Executives should state in writing: “I will never ask you to bypass the approval process by phone, and you will never be blamed for calling me back.”

5. Record, report, practise

Document the request, the displayed number and the time. Report suspected attempts to your security team, and practise the process with fictional scenarios so that calling back feels routine rather than rude.

Where technology can help – and its limits

Technical signals can support the process, but each answers a different question:

  • Number reputation shows whether a number has been reported for spam. It does not show who is speaking.
  • Network attestation such as STIR/SHAKEN, where available, describes what a participating provider can vouch for about the calling number. It is not a person check.
  • Verified caller identity between enrolled colleagues can confirm that a call comes from a known account or device – subject to enrollment and account security.
  • Audio analysis can flag signs of synthetic speech, with false alarms and missed fakes possible.

None of these replaces the callback and the second approval. They make it easier to decide when to apply them.

What Identity Phone is building

Identity Phone is in development for business customers. Planned capabilities include verified caller identity between colleagues and partners, a CEO-fraud approval guard that routes payment and data requests to a call-back on a verified line, and warnings about synthetic speech during the call. We do not yet have independently verified performance results, and no tool removes the need for the process above.

Finance teams in particular should also read how to verify payment requests by phone before finance acts. Companies can join the waitlist for early access.