Digit’s field guide to AI voice cloning, fake video calls, and the fraud your employees aren’t trained to recognize — updated with 2026 data
AI Deepfake Scams for Small Business: How to Spot Them Before They Cost You
A finance employee joined a video call with her CFO, two coworkers, and a lawyer. They told her to wire $25 million to close an urgent deal.
She did.
Every person on that call was fake.
Criminals built the meeting with AI using publicly available recordings. It wasn’t a nation-state attack or movie magic. It was commercially available software. The software wasn’t the dangerous part. Trust was.
You don’t need to be a multinational company for this to happen. You just need one employee who believes the voice on the phone is really the boss.
That’s the lesson. The technology is impressive. The scam works because people trust what they see and hear.
This article isn’t about learning to spot deepfakes. It’s about building procedures that work even when the voice sounds real.
What Is an AI Deepfake, Actually?
A deepfake is AI pretending to be someone you trust.
Sometimes it’s a phone call that sounds like your CEO. Sometimes it’s a video meeting with someone who looks and sounds like your CFO. Sometimes it’s a voicemail asking you to “handle this before anyone else gets involved.”
The technology changes. The objective doesn’t.
The attacker wants an employee to trust what they hear instead of following company procedure.
Voice cloning only takes a few seconds of public audio. A podcast, webinar, LinkedIn video, conference presentation, or even a voicemail greeting may be enough to build a convincing copy. Video deepfakes are getting better too. A 2024 review of 56 studies found people identified deepfake videos correctly only about 57% of the time, barely better than chance.
Digit’s Rule 8:Urgency is a weapon. Slow down before you make a security decision.
How Criminals Get Your Voice
Most business owners think someone would have to hack their phone to clone their voice.
They don’t.
If you’ve spoken in public, there’s a good chance you’ve already provided enough audio for AI to build a convincing copy of your voice.
That audio often comes from places like:
- LinkedIn videos
- Company website videos
- Podcasts and interviews
- Webinars and conference presentations
- YouTube videos
- Facebook, Instagram, or TikTok posts
- Voicemail greetings
- Local television or media interviews
Dottie would never question hearing my voice. If I called her from across the yard, she’d come running.
People aren’t much different.
We naturally trust familiar voices. Criminals know that. They don’t need your identity forever. They only need it long enough to convince one employee to skip a verification step.
Keep creating content. Just don’t let a familiar voice become approval for a wire transfer, banking change, or password reset.
How AI Deepfake Scams Work Against Your Business
Most AI deepfake scams follow the same playbook. Once you know it, they become easier to recognize.
First, they gather information. Before anyone picks up the phone, the attacker spends time learning how your business operates. LinkedIn shows who reports to whom. Your website identifies executives. Podcasts, webinars, and videos provide voice samples. A press release about a new client or acquisition gives them a believable reason to call. None of that takes long.
Next, they create a reason to ignore normal procedures. Once they have enough information, they build a story around two things: authority and urgency. Maybe it’s a confidential acquisition. Maybe a vendor has changed banking information and payment has to go out today. Whatever the story is, the goal is the same. They want the employee to feel like following the normal approval process will create a problem instead of preventing one.
Then they make contact. That’s when the phone rings, or a voicemail arrives, or a Teams invitation pops up. The voice sounds like the CEO because it was built from public recordings. The details sound legitimate because the attacker already knows your business.
Finally, they ask for action. The last step is the one that matters. They ask the employee to do something. Send the wire. Change the banking information. Reset a password. Share credentials.
According to Group-IB, fewer than 5% of funds stolen through sophisticated vishing attacks are ever recovered.
The interesting part isn’t what the attacker did. It’s what they didn’t have to do. They never had to break into your network. They simply convinced someone that following the normal approval process was unnecessary.
The Fake Boss Call: CEO Voice Scams Explained
The phone rings. It’s your CEO.
He sounds calm, maybe even a little distracted. He’s in a meeting. He’s traveling. He’s dealing with attorneys. Whatever the reason, he needs you to handle something quickly. A wire transfer has to go out today. A vendor changed banking information. There’s a confidentiality issue, so don’t involve anyone else yet.
That’s not a coincidence. Every part of the conversation is there for a reason. The urgency keeps you from slowing down. The confidentiality keeps you from getting a second opinion. The familiar voice fills in the rest.
According to Brightside AI, hundreds of companies are targeted by CEO deepfake scams every day. In one 2025 case, a finance director in Singapore lost nearly half a million dollars after a caller using a cloned CEO voice walked them through a fraudulent transfer.
The FBI continues to report that impersonation is one of the most effective forms of business fraud because it bypasses technical controls. Your firewall can’t decide whether the person on the phone is really your CEO.
Digit’s Rule 8: Urgency is a weapon. Slow down before you make a security decision.
If someone calls asking you to send money, change banking information, or hand over credentials, hang up and verify the request using a phone number or communication method you already trust. Five minutes of verification beats months of trying to recover stolen money.
Can AI Fake a Whole Video Call? Yes. It Already Has.
If you’re wondering whether AI can fake an entire video meeting, the answer is yes.
In 2024, engineering firm Arup disclosed that an employee transferred approximately $25 million after participating in what appeared to be a legitimate video conference with senior executives. Every person on the call was a deepfake. The criminals used AI-generated video and cloned voices to convince the employee the request was genuine.
That case wasn’t important because of the dollar amount. It proved criminals could successfully impersonate multiple people in a live meeting, something that sounded like science fiction only a few years ago.
Since then, the technology has become more accessible. Deepfake attacks grew more than 2,100% globally between 2024 and 2025, according to Sumsub’s Identity Fraud Report 2025-2026. Gen Threat Labs detected more than 159,000 unique deepfake scam attempts during the last quarter of 2025 alone.
From the employee’s perspective, the meeting doesn’t seem unusual. The executive appears on screen, asks for something that sounds reasonable, and ends the call a few minutes later. Most people aren’t evaluating video quality or lip synchronization during a business meeting. They’re listening to the request.
That’s why I wouldn’t spend much time teaching employees how to spot a deepfake. I’d rather teach them what to do after the request is made. If the request involves money, banking information, credentials, or sensitive company data, verify it through another trusted method before acting.
NIST Special Publication 800-63-4 and CIS Controls v8.1 both emphasize identity verification and employee training because a convincing voice or video isn’t something your security tools can reliably evaluate.
How to Protect Your Business from AI Deepfake Scams
If I were putting together a deepfake defense for a small business, I wouldn’t spend much time teaching employees how to spot AI artifacts. I’d spend my time making sure they never have to guess in the first place.
A few procedures will stop most of these scams before they go anywhere.
Use a verification word or phrase. If someone calls requesting a wire transfer or other financial action, require a prearranged verification word. It takes five minutes to set up and gives employees another way to confirm who’s really on the other end of the call.
Require a second approval for larger transfers. Decide what dollar amount makes sense for your business, then verify the request through a second communication channel that you initiate yourself. If the caller gives you a phone number to use, don’t. Call the number you already have on file.
Respect your own financial controls. Legitimate executives understand why those procedures exist. If someone asks you to skip them because they’re in a hurry or because “this has to stay between us,” treat that as part of the scam, not proof that the request is important.
Digit’s Rule 8: Urgency is a weapon. Slow down before you make a security decision.
Bring IT into the conversation. Calls involving credentials, remote access, or banking changes deserve another set of eyes. I’d rather spend five minutes checking a legitimate request than five months trying to recover from a fraudulent one.
Practice the way criminals attack. Verizon’s 2026 Data Breach Investigations Report found employees were more likely to fall for voice and SMS phishing simulations than email. If your security awareness training only tests email, you’re preparing for yesterday’s attacks.
What Your Employees Need to Know Right Now
First, AI voice cloning is real. It doesn’t require a Hollywood budget or a government intelligence agency. A few seconds of public audio is often enough to create a convincing copy of someone’s voice. That means nobody should feel embarrassed about verifying a request, even if it sounds like the CEO. I’d rather answer one extra phone call than explain why the company wired money to a criminal.
Second, your verification procedure only works if everyone follows it. The moment you make exceptions because someone sounds important, is in a hurry, or says the request is confidential, you’ve trained employees that the rules are optional. Criminals count on that.
Digit’s Rule 15:Security awareness training isn’t a checkbox. Neither is a smoke detector without a battery.
Third, trust your instincts, then verify them. If something feels off, don’t ignore it because the voice sounds familiar or the request came from someone with authority. Pause. Ask questions. Call IT. Follow your verification process.
Digit’s Rule 17: When something feels wrong, treat it like it might be wrong. Dottie calls it instinct. I call it evidence that hasn’t finished reporting in.
Keepnet Labs reports that 80% of organizations still don’t have a deepfake response plan. If that’s your business today, don’t beat yourself up. Start one. A morning spent training employees and reviewing procedures is a lot easier than explaining to customers, your bank, or law enforcement why the money is gone.
Conclusion: The Uncomfortable Truth About AI Deepfake Scams
I’ve worked with enough small businesses to know how this conversation usually goes.
“We’re too small for anyone to bother with.”
Criminals don’t see it that way.
They see a business where the owner answers the phone, the accounting department is one person, everyone trusts each other, and people are used to solving problems quickly. Those are strengths until someone decides to use them against you.
The good news is you don’t have to outsmart artificial intelligence.
You do have to make it difficult for someone to bypass your procedures.
If your company has a verification process that everyone follows, employees who are comfortable asking, “Can I verify this first?”, and an IT team that would rather answer one extra phone call than investigate a wire fraud, you’ve already made yourself a much harder target.
If you don’t have those things yet, start there.
We’ll help if you want us to.
At 2 Dog Digital, we offer no-charge cybersecurity assessments for North Carolina businesses. You’ll walk away with a better understanding of where you’re vulnerable and practical recommendations you can actually use, whether you become a client or not.
Give us a call or visit 2dogdigital.com.
We’ll answer the phone.
Book your free assessment at 2dogdigital.com or call us directly. We answer the phone.
FAQ
What is an AI deepfake scam?
An AI deepfake scam uses artificial intelligence to impersonate someone you trust. That might be a cloned voice on a phone call, a fake executive on a video meeting, or both. The goal is usually to convince an employee to send money, change banking information, share credentials, or bypass normal company procedures.
Can criminals really clone my voice from just a few seconds of audio?
Yes. Public recordings from LinkedIn videos, podcasts, webinars, conference presentations, interviews, and even voicemail greetings can provide enough audio to create a convincing voice clone. That's why businesses should never rely on recognizing someone's voice alone when approving sensitive requests.
How do AI deepfake scams target small businesses?
Small businesses often have fewer approval layers, fewer employees, and less formal verification procedures than large organizations. Criminals know they don't have to fool everyone. They only need to convince one employee with the authority to send a wire transfer, change banking information, or share credentials.
What should an employee do if they receive a suspicious call from the CEO?
Slow down. Don't transfer money, change account details, or provide credentials while you're on the call. End the conversation and contact the CEO using a phone number or communication method you already know is legitimate. If your company uses a verification word or phrase, use it. When in doubt, involve your IT team before taking action.
Can antivirus or a firewall stop AI deepfake scams?
Security tools are an important part of your defense, but they can't determine whether the person on a phone call or video meeting is really your CEO. That's why employee training, verification procedures, and financial controls are just as important as firewalls and endpoint protection.
Can AI fake an entire video meeting?
Yes. Criminals have already used AI-generated voices and real-time video impersonation to trick employees during live meetings. The technology continues to improve, which is why businesses should verify high-risk requests through a second trusted communication channel instead of relying on what they see or hear.
Are North Carolina businesses at risk from AI deepfake scams?
Yes. Businesses in North Carolina face the same AI-powered fraud, business email compromise, and voice phishing threats as organizations across the country. Whether you have five employees or five hundred, verification procedures and employee training are some of the most effective ways to reduce your risk.