- Three seconds of voice and a few public photos are now enough to clone an executive convincingly.
- Fraud no longer targets technology but process: an urgent order, a hierarchy, time pressure.
- The defence is not a detection tool, it is a procedure: no unusual transfer without a second confirmation channel, no exceptions, not even for the CEO.
- SMEs are now targeted as much as large groups, with amounts sized to their cash position.
How it happens, concretely
The scenario we reconstructed at a two-hundred-person client fits in one morning. An accountant receives a message from the CFO on the internal messaging tool, then a video call. The face is right, the voice is right, the tone is that of a hurried executive closing a confidential acquisition. The requested transfer is large but not absurd. The bank details are in the body of the message. Everything is consistent, and everything is fake.
What makes the attack effective is not image quality, it is context: the acquisition discussed internally, the name of the law firm, the executive's diary showing them genuinely travelling. That information comes from LinkedIn, the company website, a podcast interview and sometimes a mailbox compromised a few weeks earlier.
Why classic procedures no longer hold
Most payment procedures rely on verbal confirmation: "Call me to validate." That was a good defence when imitating a voice was hard. It no longer is. Video, long regarded as the ultimate proof, has become the preferred vector. And hierarchical pressure does the rest: few accountants hang up on a CFO.
The second weak point is the exception. Every procedure has an emergency case where one can bypass the rules. Fraudsters know it, and build precisely that emergency.
The five measures that genuinely protect
The second channel, no exceptions
Any unusual payment order (new beneficiary, out-of-range amount, change of bank details) is confirmed through a channel different from the one used for the request, to a number known in advance, never the one supplied in the message. The rule applies to everyone, executives included. On its own, it stops almost all attempts.
The verbal password
A phrase agreed between management and finance, changed every quarter, never written in any tool. Simple, free, and very effective against a clone that knows your voice but not your secret.
The enforced delay
No transfer above a set threshold leaves on the day it is requested. Twenty-four hours are enough for the pressure to drop and for someone to ask the awkward question.
Reducing the public footprint
Fewer freely available videos of executives, fewer detailed org charts on the website, fewer absence announcements on social networks. Communication continues; the details that feed the scenario are removed.
The full-scale drill
Once a year, a simulation with management's agreement: a fake call, a fake message. Not to trap people, but so that everyone has already lived the situation before it is real. Teams that have done the drill react well; the others improvise.
"I'll call you back on your usual line in five minutes." A real executive always accepts. A fraudster insists.
What about detection tools?
Analysis solutions exist and are improving, but they chase generators that improve just as fast. They are useful for security teams and for post-incident analysis. They do not replace a robust payment procedure, which depends on no technology and never breaks down.
"Deepfake fraud rarely succeeds because of technology. It succeeds because nobody dared to say no."
Conclusion
Deepfakes have made obsolete the idea that a voice or a face proves an identity. The answer is neither panic nor a race for tools, but an organisation where no single person, however senior, can trigger an unusual payment. It is inexpensive, quick to set up, and protects well beyond deepfakes.
FAQ
Is an SME really a target?
Yes, and increasingly so. Requested amounts are sized to the company, and SMEs often have fewer internal controls than a large group.
What if a fraudulent transfer has already gone out?
Contact the bank immediately to attempt a recall, file a complaint, and inform your insurer. The first hours count: after twenty-four hours the funds are usually dispersed.
Should we remove all videos of our executives?
No. Communication remains necessary. Instead, reduce operational details: diaries, travel, confidential projects, names of financial partners.
How do we train teams without alarming them?
With a short session, a cloned call example listened to together, then the second-channel rule explained as a protection for them: nobody will ever blame them for checking.