Key facts
- Seconds of public audio (earnings calls, interviews, webinars) suffice to clone an executive's voice.
- The documented corporate pattern is a fraudulent email or meeting invite first, then a deepfake voice or video call as "verification". Reputable reporting on the widely covered 2024 Arup case describes an employee paying out roughly USD 25 million after a deepfaked video meeting (CNN, 2024).
- Detection by eye and ear is unreliable and getting worse; procedural defense beats perceptual defense.
The corporate deepfake playbook
Deepfakes rarely start the fraud; they close it. The chain: pretexting via email establishes the scenario (confidential deal, urgent payment), the target hesitates, and the deepfake, a voice call, voicemail or video meeting, supplies the human confirmation that policy said to ask for. This is why "call to verify" has weakened as a control: the caller may also be synthetic. Verification must run through channels and numbers you initiate, not channels the requester provides. Related patterns: whaling, business email compromise, social engineering and phishing.
How to defend
Payment procedures with out-of-band verification on known numbers, code words for high-value approvals, executive awareness that their public audio is cloning material, and behavioral email security that flags the fraudulent instruction before the deepfake ever gets to "confirm" it. The email is still the weakest, most detectable link in the chain.
How Sentaro helps
Sentaro cannot inspect a phone call, and does not claim to. It attacks the chain where the fraud starts: the impersonation email, the lookalike domain, the hijacked thread, the anomalous payment instruction. Stop the setup and the deepfake has nothing to confirm.