The “Deepfake CEO” Scam: Why Voice Cloning Is the New Business Email Compromise (BEC)

Photo of Brian Largent

Brian Largent

CEO, ArcLight Group

February 15, 2026 10 min read
Share:
Free cybercrime security scam vector

The phone rings at 4:47 on a Friday afternoon. It’s your CEO. You know the voice. You’ve heard it in Monday meetings for three years. She’s stressed, talking fast, and she needs you to wire $280,000 to a new vendor before close of business so a deal doesn’t fall apart over the weekend. She’ll explain on Monday. Just get it done.

Except it isn’t her. It’s thirty seconds of a LinkedIn video, a ten dollar AI voice tool, and a spoofed caller ID. By the time she walks back into the office on Monday, the money is gone, the account is closed, and the FBI is telling you the wire is unrecoverable.

This is the version of Business Email Compromise I’m spending more time talking about with Tulsa business owners in 2025. It isn’t theoretical. It’s the same playbook attackers have been running through email for a decade, now with a voice on top of it. And it’s working.

BEC Isn’t New. The Voice Layer Is.

Let me back up, because if you only know BEC as “that phishing thing,” you’re underestimating it.

Here’s the scenario I walk clients through. An attacker gets into someone’s email at your company. Maybe it’s a clicked link, maybe it’s a reused password from a breach somewhere else. They don’t do anything loud. They set up a quiet forwarding rule, and they watch. For weeks.

They learn how your invoicing works. They see who your biggest customer is. They see what your invoices look like, the language you use, the dollar amounts that are normal, which bank you use. They figure out when your bookkeeper is on vacation.

Then, from your real email address, on your real domain, they send your biggest customer an invoice for half a million dollars with new wire instructions. Because it’s a legitimate email sent through your actual mail server, it sails right through every spam filter on both sides. Your customer pays it. The money hits a mule account and is gone in under an hour.

Now your customer is out $500,000, and they’re looking at you. It came from your system. Are you going to make them whole? And even if your insurance covers part of it, do you think that customer is ever fully trusting you again? Can they go to a competitor easily? If they can, they probably will.

That is regular BEC. No AI required. I wrote about the downstream cost of this sort of incident in detail in What Ransomware Actually Costs Beyond the Ransom, because the same dynamics apply.

The “deepfake CEO” scam takes that same playbook and adds urgency through voice. That’s the only real difference. Attackers realized email filters have gotten better, so they went around them. A phone call from your boss doesn’t go through a spam filter.

Why This Is Different From Regular Phishing

Regular phishing is cold. Even when the email looks convincing, there’s a half-second where you can stop and check the sender’s domain, hover over the link, read the header. The medium itself gives you time.

A phone call takes that time away. Your boss is on the line. She sounds rushed. She sounds like her. The part of your brain that processes “is this person real” doesn’t get to run, because the part that processes “the boss is asking me for something and I want to be helpful” runs first.

Three things make voice-based BEC uniquely dangerous:

  • No filter between you and the attack. Email spam filters catch a lot. Phone calls don’t go through any of that. Caller ID is trivially spoofable.
  • Hierarchy pressure. Most employees are conditioned to say yes to leadership. Very few feel empowered to tell the CEO “prove you’re you.” Attackers know this and use it.
  • Timing. These calls come right before a weekend, right before a holiday, right at the end of the day. Anything that shortens the verification window.

I can train your staff to spot a suspicious email all day long. Training them to hang up on their own CEO is a much harder conversation. That’s what makes this category of attack worth its own playbook.

The Employee Problem, And Why I Can’t Judge Them

I need to be honest with you about something. I fell for one of my own phishing tests.

I was driving to the office one morning, stopped at a red light. An email popped up on my phone: “Your Microsoft 365 password has expired. Click here to reset.” I tapped it. It went straight to our own phishing training platform. My whole team got the notification. I still get teased about it, and that was a couple years ago now.

I run a cybersecurity company. I know better. And I still clicked, because I was busy and the light turned green and I wanted to get it handled before I walked in the office.

That’s the thing I need every business owner to understand. Your employees are not the problem because they’re stupid or untrustworthy. They’re the problem because they’re human, they’re busy, and people make mistakes. You can’t fire your way out of this. You have to build systems that assume a smart person is going to have a bad two seconds.

The pattern I see constantly is the “Hi Susie, this is Bob from tech support” call. Somebody phones Susie in accounting. They sound official. They say her computer has a problem and they need to fix it. They tell her to go to a website and install a “support tool.” That tool is remote access software. Now they’re on her machine. From her machine, they enumerate credentials and start moving laterally through your network. Same thing applies on the voice BEC side. The tools have changed. The human lever hasn’t.

Defenses That Actually Work

I’m going to skip the fluffy advice and tell you what I actually put in place for clients. This is the short list, in order of what I’d do first.

1. A callback rule with teeth

Any request involving money movement, wire changes, vendor banking updates, or sensitive data must be verified by calling the requester back on a known number. Not the number they called from. Not a number in the email signature. The number in your internal directory.

Write this into policy. Make it a terminatable offense to skip the callback. Tell your staff out loud: “If I ever call you and ask for a wire, I expect you to hang up and call me back. I will not be offended. If I am offended, I am not me.”

2. MFA on everything, especially email

Voice cloning is a problem. But the bigger problem is almost always the original email compromise that feeds it. If attackers can’t get into your mailboxes in the first place, they can’t study your invoicing patterns or impersonate your vendors from legitimate accounts. Multi-factor authentication on every Microsoft 365 or Google Workspace account is non-negotiable. App-based MFA or hardware keys. Not SMS if you can avoid it.

3. Remove local admin rights and use a PAM tool

When Susie can’t install software on her own computer, “Bob from tech support” can’t talk her through installing remote access tools. That alone kills a huge percentage of these attacks.

The objection is always “but she needs to install a printer driver when she travels.” Fine. That’s what a privileged access management tool is for. She still can’t install things on her own, but when she needs to, she hits a prompt that routes to an administrator who can approve or deny in real time. Problem solved, attack surface reduced.

4. Modern EDR on every endpoint

Legacy antivirus is dead. What you want is EDR, MDR, or XDR. That stands for endpoint detection and response, managed detection and response, extended detection and response. These tools use behavioral analytics, not virus definitions. When something starts behaving like credential theft or remote access abuse, the tool can stop it and alert a human in real time.

5. Actual training, with consequences

Annual “watch this video” training is not training. Real training is ongoing micro-learning, simulated phishing emails sent throughout the year, and accountability when people fall for them repeatedly. Accountability doesn’t have to mean firing. It means coaching, more frequent tests, and in some cases restricting what that person can do until they level up.

Start running voice-based simulations too. Have a trusted outside voice call your staff and try a fake CEO request. See what happens. I promise you it will be educational.

Red Flags Every Employee Should Know

If you only teach your team five things about voice-based BEC, teach them to slow down when any of these appear:

  • Urgency plus secrecy. “I need this done right now, and don’t tell anyone else.” That is never how legitimate leadership operates.
  • New payment instructions. Any change to a wire destination, bank account, or payment method. Always. Even if everything else looks right.
  • A request that breaks normal process. If your CFO has never called you directly to approve a wire, the first time she does is not the time to say yes.
  • End-of-day or pre-weekend timing. Attackers love Friday at 4:30.
  • Emotional pressure. Anger, panic, flattery, “I’m counting on you.” Real emergencies are rare. Manufactured ones are common.

When in doubt: hang up and call back. Not reply. Call back, through a channel you control.

The Insurance Reality You Need To Know

Most business owners I talk to assume their cyber liability policy covers this. It probably does, up to a point. That point is called a sub-limit, and it’s where most policies will quietly leave you hanging.

Here’s what I see. A business has a $4 million cyber liability policy. They feel great about it. Then I dig into the policy language and find a BEC or social engineering fraud sub-limit of $100,000. Sometimes $50,000. Sometimes $250,000. That’s the cap on a voice-cloning wire fraud payout, regardless of your top-line policy number.

Then there’s ransomware sub-limit. Data exfiltration sub-limit. Reputational damage sub-limit. Each one its own ceiling.

I spend close to $10,000 a year on my firm’s cyber liability premiums. I’ve sat in rooms with other business owners who spend $1,500 and feel good about their coverage. I don’t need to see their policy to know it’s not enough. A real BEC or ransomware incident, once you add attorneys, forensics, lost revenue, notification costs, and the hit to your customer relationships, is almost never under a million dollars. I wrote more about that math in Why Cyber Insurance Isn’t Cybersecurity.

Go pull your policy out right now. Find the sub-limits page. Look at the number next to “social engineering fraud” or “funds transfer fraud.” That’s your real exposure, not the headline policy amount.

What ArcLight Clients Do Differently

I’ll tell you what the setup looks like for a typical managed services client of ours in Tulsa.

Every mailbox has MFA enforced. Every endpoint runs a modern EDR with 24/7 monitoring. Nobody has local admin rights on their workstation. Privileged access management is in place so people can still get their work done when they need to install something legitimate. Email has anti-spoofing protections configured at the DNS level (SPF, DKIM, DMARC) so it’s much harder for an attacker to send mail that looks like it came from the CEO.

On the people side, staff get phishing simulations on a regular cadence, with follow-up training when someone slips. Finance teams have a written callback policy for every wire and every banking change. The CEO has told the team out loud, in a meeting, that she will never be offended by a callback.

And we look at the insurance policy with them. If the sub-limits don’t match the risk, we tell them. I’d rather have a hard conversation about coverage today than an impossible one after an incident.

I’ve seen what happens when businesses skip these basics. I’ve walked into the aftermath. I’ve sat across from CFOs who thought their insurance had it handled. If you want to understand what that actually looks like, read What Really Happens When Your Business Gets Ransomware. The voice-cloned CEO version ends in the same place: a painful, expensive recovery that changes how your customers feel about you.

The defenses against the “deepfake CEO” scam aren’t exotic. They’re the same fundamentals I’ve been preaching for years, applied deliberately. MFA. Callback rules. Least privilege. Real training. Honest insurance. Do those five things well and you cut the attack surface on this dramatically.

If you want a real look at where your business stands against voice-based BEC and other modern social engineering attacks, get in touch. We’ll walk through your mail security, your endpoint posture, your policies around wire transfers, and your actual insurance sub-limits. No scare tactics. Just a clear picture of your real exposure and a plan for closing the gaps that matter most.

Photo of Brian Largent
About the Author

Brian Largent

Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)

Ready to harden your environment?

Get the 27-point assessment we run on every new client

Two hours. One real engineer. A written report telling you exactly where your gaps are — whether or not you ever hire us.

No hard sell. No obligation. Month-to-month after — cancel anytime.