The pattern is now familiar enough that finance teams recognise the description. A junior finance executive gets a call, or joins a video meeting, with someone who looks and sounds like a senior leader. The instruction is urgent, confidential, and involves moving money to an account nobody has paid before. The pretext is good enough that the person on the receiving end does not doubt it.
Coverage of these cases tends to focus on the technology, which is the least useful part of the story. Synthetic voice built from a few minutes of public audio is no longer remarkable, and video is following. Assume the impersonation will be convincing. Assume your staff will not detect it in the moment, because expecting an accounts payable clerk to out-perform a detection model in real time is not a control.
What the fraud actually depends on
Every case we have looked at needed three things: a plausible authority, a reason for urgency, and a payment path that a single person could complete.
The third one is yours to remove. The first two are not.
That reframing matters because most of the advice circulating focuses on awareness training about deepfakes, which addresses the parts you cannot control while leaving the part you can control untouched.
The control that works
An out of band verification step on any payment that is new, urgent, or above a threshold, using a contact route the requester did not supply.
Read that last clause carefully, because it is where implementations fail. If the verification call goes to the number in the email signature, or the number the caller gave, it verifies nothing. It has to go to the number already in your HR record, dialled by the person doing the verifying.
Three refinements that close the remaining gaps. Verification cannot be waived by seniority, because seniority is exactly what the pretext is claiming. Verification cannot be done over the same channel the request arrived on. And the person verifying must be permitted to delay the payment without consequence, which is a cultural control rather than a technical one and is the one most organisations quietly fail.
Where the technology does help
Not in detection. In authentication.
Phishing resistant multi factor authentication on email and finance systems removes the account takeover variant, where the request genuinely does come from your CFO's mailbox because someone else is in it. Number matching and hardware keys defeat the push fatigue attacks that typically precede these frauds.
Domain controls, SPF, DKIM and DMARC set to reject, remove the lookalike domain variant. We still find DMARC at p=none on organisations that have had these controls on the roadmap for two years. It is a weekend of work and it retires an entire class of attack.
And a payment platform that enforces the verification step in software beats a policy that asks a person to remember it, because at 18:40 on the last day of the quarter people remember what the system requires and forget what the policy says.
What to do about executive audio
Very little, and that is the point. You cannot remove your leadership from public life, and a policy that tries will be ignored. The realistic position is to accept that anyone who speaks publicly can be cloned, and to build a process that does not care.
There is one exception worth acting on. Recorded internal town halls, all hands sessions and training videos are usually held with far weaker access controls than customer data, and they contain hours of clean audio of exactly the people an attacker wants to impersonate. Treat that library as sensitive. It is the cheapest thing on this list.
How to test whether you are actually protected
Ask your finance team a single question: what is the largest payment one person can complete today without a second person confirming it through a route the requester did not supply?
If there is a number, that is your exposure. If nobody knows the number, that is worse.
We run this as a controlled exercise during social engineering engagements, with the finance director's written authorisation and a hard stop before any money moves. It is uncomfortable, it takes half a day, and it tells you more than a year of awareness training.












