Deepfake voice fraud drained $1.1 billion from US corporate accounts in 2025. In 2026, the attacks are faster, cheaper, and more convincing than ever. Here is how they work, and what finance and security leaders need to do about it.
The call sounded exactly like the CFO. The voice, the cadence, even the slight impatience in the tone. The wire transfer instruction was specific, urgent, and entirely plausible. The finance associate on the other end of the call had no reason to question it.
That call was a fraud. The CFO never made it. A criminal did, using a voice cloned from three seconds of publicly available audio.
Deepfake CEO fraud, also called vishing executive impersonation, is the fastest-growing financial crime targeting enterprises in 2026. This post explains how it works, what the data says, and how organisations can defend against it before the next fraudulent wire instruction lands in their inbox.
What Is Deepfake CEO Fraud?
Deepfake CEO fraud is a form of business email compromise (BEC) evolved to the voice channel. Attackers use AI voice synthesis tools to clone the voice of a senior executive, then use the synthetic voice in real-time phone calls or audio messages to authorise fraudulent wire transfers, request credential resets, or instruct employees to bypass security controls. The attack exploits the inherent trust that employees place in the voices of their leadership.
The Scale of the Problem: $1.1 Billion and Rising
The numbers attached to deepfake voice fraud in 2025 and 2026 are not projections. They are documented losses:
- Deepfake voice attacks drained $1.1 billion from US corporate accounts in 2025, tripling the prior year’s figure of $360 million
- 243% surge in deepfake voice attacks over the past year
- Average loss per deepfake vishing case: approximately $600,000
- 10% or more of financial institutions have suffered deepfake vishing attacks exceeding $1 million per incident
- Deloitte projects the trajectory of deepfake fraud losses reaching $40 billion in the coming years
- A Swiss businessman was defrauded of several million Swiss francs via voice cloning in January 2026
The technology enabling these attacks is not expensive or restricted. A convincing voice clone can now be generated from as little as three seconds of audio. Every earnings call, conference keynote, podcast interview, and media appearance that a finance executive has ever recorded is raw training data for criminals.
How Attackers Execute a Deepfake Voice Fraud
Step 1: Target Selection and Audio Harvesting
Attackers identify a target organisation and select an executive whose voice is publicly available. CFOs, CEOs, and General Counsels are the most common targets because they have authority to authorise financial transactions. Public audio sources include YouTube interviews, investor calls, conference recordings, and podcasts.
Step 2: Voice Synthesis
Using commercial or criminal AI voice tools, attackers generate a synthetic voice model capable of producing real-time speech in the target’s voice. Criminal AI toolkits purpose-built for fraud, including tools tracked by INDRA CTI, have removed the technical barriers that previously required specialist knowledge.
Step 3: The Call
The attacker calls a finance associate, accounts payable team member, or IT help desk. The synthetic voice delivers an urgent instruction: a wire transfer to a new account, an emergency credential reset, or a request to bypass normal approval workflows due to time pressure. The social engineering is often reinforced by a follow-up email from a spoofed or compromised address.
Step 4: Covering Tracks
Once the transfer is made or credentials are compromised, the attacker moves quickly. Funds are often through multiple accounts within hours. By the time the real executive is informed, recovery is typically impossible.
What Happens When Organisations Are Unprepared?
Organisations without voice verification protocols and deepfake detection capabilities face several compounding risks:
- Finance teams have no way to distinguish a legitimate executive call from a synthetic one in real time
- Standard callback verification can be defeated if the attacker has also compromised the executive’s phone number or email
- HR teams receive fraudulent payroll diversion requests using the same technique
- Reputational damage extends beyond the financial loss, particularly for publicly listed companies
Before vs. After: Deepfake Defence Maturity
| Capability | Unprepared Organisation | Prepared Organisation |
| Voice verification | None, relies on caller recognition | Multi-factor verbal authentication codes |
| Wire transfer approval | Single phone authorisation accepted | Out-of-band dual approval required |
| Executive audio monitoring | Not tracked | Alerts on new public executive audio |
| Incident response for fraud | Ad-hoc, no playbook | Peris.ai IRP with dedicated BEC/fraud workflow |
| Threat intelligence | Generic advisories | INDRA CTI tracks criminal AI toolkits in real time |
How Peris.ai Protects Against Deepfake Executive Fraud
INDRA CTI monitors the criminal AI toolkit ecosystem, including voice synthesis tools and the marketplaces where they are sold and leased. When new deepfake voice fraud toolkits targeting finance executives are identified, INDRA CTI surfaces intelligence on their capabilities, infrastructure, and indicators of compromise to your security team before your organisation becomes a target.
BrahmaFusion, Peris.ai’s agentic AI and hyperautomation platform, can be configured to detect the specific combination of signals that precede a deepfake vishing attack: anomalous wire transfer requests in email chains that reference a phone call as authorisation, executive name mentions combined with financial transaction keywords, and unusual patterns in help desk credential reset requests. When these signals appear together, BrahmaFusion triggers automated review workflows before a transfer is approved.
Peris.ai IRP provides the incident response framework for organisations that have already been targeted. When a deepfake fraud incident is suspected, Peris.ai IRP opens a structured case with a pre-built workflow covering evidence collection, financial institution notification, regulatory reporting requirements, and post-incident controls review.
Scenario: The $2.4 Million Phone Call
A mid-size fintech company receives a call from the CFO’s number at 4:45pm on a Friday. The voice instructs the accounts payable manager to release a $2.4 million payment to a new vendor account before close of business, citing a signed contract that will be emailed shortly.
Without deepfake defence controls, the transfer is approved.
With Peris.ai controls in place:
- BrahmaFusion detects the pattern: Friday afternoon wire request + phone authorisation + new vendor account, and flags it for secondary review
- INDRA CTI confirms that a criminal voice synthesis toolkit has been actively targeting fintech CFOs in the region that week
- The finance manager receives an automated alert requiring out-of-band confirmation via the company’s verified internal messaging system
- The real CFO is contacted. The fraud is stopped. The $2.4 million stays where it belongs.
Benefits at a Glance
| Benefit | Outcome |
| INDRA CTI criminal AI monitoring | Early warning on deepfake toolkits targeting your sector |
| BrahmaFusion pattern detection | Automated flag on high-risk transaction request combinations |
| Peris.ai IRP fraud workflow | Structured response when deepfake incidents occur |
| Vendor and partner notification | BrahmaFusion playbooks cover third-party fraud scenarios |
Final Thought
Every earnings call your CFO has ever recorded is a training dataset. Every investor presentation is source material. The voice that your finance team trusts most is now replicable from a few seconds of audio, and the tools to do it are available to criminals on underground markets today.
The organisations that survive this threat are not those with better voice recognition. They are those with better processes: verification controls, threat intelligence, and incident response capabilities that assume synthetic voices are a real and present risk.
Platforms like BrahmaFusion by Peris.ai, combined with INDRA CTI’s real-time monitoring of criminal AI toolkits, give lean security teams the intelligence and automation to stop these attacks before the wire goes out. Don’t wait for a breach to take action. Secure your organisation today. Stay Secure with Peris.ai.
Frequently Asked Questions
What is deepfake CEO fraud?
Deepfake CEO fraud is a type of business email compromise attack where criminals use AI voice synthesis to clone an executive’s voice and make fraudulent phone calls authorising wire transfers or credential changes. A convincing voice clone can be created from as little as 3 seconds of publicly available audio.
How much money has been lost to deepfake voice fraud?
Deepfake voice attacks drained $1.1 billion from US corporate accounts in 2025, tripling the prior year’s losses. The average loss per deepfake vishing case is approximately $600,000, and over 10% of financial institutions have suffered attacks exceeding $1 million per incident.
How do attackers clone an executive’s voice?
Attackers harvest publicly available audio from earnings calls, podcasts, conference recordings, and media interviews. Using commercial or criminal AI voice synthesis tools, they generate a real-time voice model. The process requires minimal technical skill and can be completed in hours.
What is the best defence against deepfake voice fraud?
Effective defence combines multi-factor out-of-band verification for financial authorisations, real-time threat intelligence on criminal AI toolkits (such as INDRA CTI), automated detection of anomalous transaction patterns (such as BrahmaFusion), and a prepared incident response workflow for when attacks occur.
How does BrahmaFusion detect deepfake fraud attempts?
BrahmaFusion analyses combinations of signals that correlate with deepfake fraud: wire transfer requests referencing phone authorisations, executive name mentions combined with financial transaction keywords, and unusual help desk credential reset patterns. When these signals appear together, it triggers automated secondary approval workflows before transactions are processed.

Leave a Reply