For companies

Verify payment requests by phone before finance acts

Finance teams are the final step between a convincing story and real money leaving the company. Attackers know this, and the phone is one of their favourite channels: a call feels personal, leaves little written record and allows them to apply pressure in real time. The safest rule is simple: no payment and no bank-detail change is released because of a phone call alone.

Common phone-based payment scams

The urgent executive

A supposed CEO or CFO calls about a confidential deal and asks for an immediate transfer to a new account. The voice may be imitated with speech synthesis; the number may be spoofed. The FBI has warned that criminals use AI-generated audio to impersonate people and obtain payments. Read more on deepfake CEO fraud.

The supplier with “new bank details”

A caller claiming to be from a known supplier announces that their bank account has changed – often in combination with an e-mail from a look-alike or compromised address. The next invoice is paid to the attacker.

The “bank” or “auditor”

Someone posing as your bank’s fraud team or an auditor asks finance staff to confirm a payment, share an authorisation code or move funds to a “safe” account.

The follow-up call that confirms a fake e-mail

An attacker sends a fraudulent payment instruction by e-mail and then calls to “confirm” it – so the victim feels they have already verified it by phone.

Controls that work regardless of how convincing the call is

1. Change vendor bank details only through verified contacts

Never act on bank details received by phone or e-mail alone. Call the supplier back on the number in your vendor master data or contract – not on a number in the request – and have a second person approve the change in the system.

2. Dual approval for new and changed accounts

Payments to a new beneficiary or to changed bank details should require a second authorised approver, independent of the person who received the request.

3. Callback on a number already on file

For any urgent, unusual or confidential payment request, end the call and call the requester on a number from the internal directory or another source that existed before the request.

4. A cooling-off period for first payments

Consider a short delay or an additional check before the first payment to a new account. Most fraud depends on speed.

5. Name the red flags in your policy

Urgency, secrecy (“don’t tell anyone”), a new account abroad, a changed payment route and pressure to bypass approval should each trigger verification. Executives should confirm in writing that they will never ask finance to skip the process.

6. Use your bank’s payee checks – and know their limits

Within the EU, payment service providers must offer a verification of payee check for euro credit transfers under the Instant Payments Regulation (EU) 2024/886. It helps detect a mismatch between the account name and the IBAN. It does not tell you whether the request itself is legitimate: an attacker can provide an account in a name that matches their story.

A short checklist for finance teams

  • Was the request received by phone, or confirmed only by phone?
  • Is the beneficiary or bank account new or changed?
  • Did I call back on a number I already had – not one from the request?
  • Has a second authorised person approved it?
  • Is anyone pressing me to skip a step? If so, slow down.

Where technology can help – and its limits

Number reputation, network attestation and audio analysis each add a signal, but none proves who is speaking or whether a request is legitimate. Verified caller identity between enrolled colleagues and partners can confirm that a call comes from a known account or device. These signals help decide when to escalate; they do not replace callbacks and dual approval. Our guides on caller ID spoofing and deepfake voice calls explain the limits in detail.

What Identity Phone is building

Identity Phone is in development for business customers. A planned CEO-fraud approval guard is designed so that payment and data requests by phone trigger a call-back to a verified line before finance acts. Verified caller identity and warnings about synthetic speech are also planned. We do not yet have independently verified performance results.

IT teams face a related problem with password resets – see help desk caller verification. Companies can join the waitlist for early access.