If the boss calls asking for money, recognising their voice may no longer be enough

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
Gartner's survey found that some surveyed security leaders had encountered deepfake-related social engineering on employee calls. The figures do not measure how many attacks succeeded or how many businesses overall were affected. For small businesses, the practical defence is to verify payments, account changes and access requests through trusted processes rather than trusting how a caller sounds.
Imagine the managing director calls your finance lead with an urgent payment request. The voice sounds right. The caller knows the supplier and the project. The request still needs checking.
That is not a new kind of business fraud so much as an old one with another performance tool. Impersonation has long arrived by email, text and phone. A generated voice or video can make the familiar-person version more convincing, but it does not change the sensible rule: a person’s apparent identity is not, by itself, approval for a consequential action.
What Gartner’s figures do—and do not—say
Gartner says it surveyed 297 senior leaders of cybersecurity functions, including CISOs or equivalents, between March and May 2026. In the previous 12 months, 41% of those respondents reported at least one social-engineering incident involving a deepfake during an employee audio call; 36% reported one during a video call.
In the same survey, 79% reported at least one email phishing, spear-phishing or business-email-compromise incident, while 58% reported vishing or smishing. Those wider figures matter: deepfakes have not replaced the familiar fraud methods businesses already face.
These are proportions of surveyed security leaders reporting one or more incidents. They are not the percentage of all businesses attacked, a count of calls made, or a measure of how many attempts succeeded. Gartner’s public announcement does not give a success rate.
The survey is still useful as a prompt to review how your business handles important requests. It is not a reason to assume that every call is suspicious or that staff must become amateur deepfake detectors.
A believable voice is not a control
For years, staff have been told to look for odd email addresses, clumsy wording, unexpected urgency and payment details that have suddenly changed. Better-generated speech and video may make some of those clues less dependable. But even a flawless imitation cannot make an unusual request legitimate.
This is why “learn to spot the fake” is a weak main defence. People are not reliable forensic tools, especially when the caller is senior, the deadline is tight, or the request arrives while they are busy. A stronger process keeps working even when the impersonation is convincing.
Authenticate the request, not the performance
Use a trusted route that was already on file. Do not rely on the phone number, link or contact detail supplied as part of the unexpected request.
Put verification into the work people already do
For supplier bank-detail changes, the National Crime Agency’s business guidance is refreshingly practical: call the genuine supplier using a number you have used before, then check the change before transferring money. A number written in a new email or dictated on a call is not an independent check.
The same idea can be adapted to other high-impact requests. A request to reset someone’s password or multi-factor authentication, grant administrator access, change a payroll destination or pay a new recipient should follow a known verification route. If the normal process requires a second approver, a senior person’s apparent voice is not a reason to skip it.
That can feel awkward when the person asking is the boss. Make the rule apply to everyone, including directors, and say so in advance. The person checking is protecting the business and the genuine colleague—not accusing anyone of being a fake.
A short checklist for a small business
- 1Check supplier bank-detail changes by calling a previously used number from your records.
- 2Require a second person to approve unusual, high-value or first-time payments.
- 3Verify password, multi-factor authentication and privileged-access changes through a separate, established identity-checking route.
- 4Pause when a request combines urgency, secrecy or pressure to bypass normal approvals. Call back using a contact method you already trust.
- 5Make it easy for staff to ask for a second check and to report a suspicious request without blame.
Make the safe option the easy one
A rule only helps if staff can follow it while busy. Keep verified supplier contact details in a record that is separate from incoming invoices and messages. Make the payment limit and second-approval route clear, including who can step in when the usual approver is away.
The second check should be genuinely separate: the approver needs to see the beneficiary, amount and reason through the normal finance process, not simply hear the same urgent story from the same caller. Leaders can help by saying openly that a call-back is expected, even when the request appears to come from them.
A brief staff exercise can reveal whether the process works: ask what someone would do if a familiar voice requested a new payment destination just before a deadline. If the answer depends on guessing whether the voice is real, improve the process rather than buying a detector and hoping.
The UK National Cyber Security Centre describes payment diversion and supplier impersonation as forms of business payment fraud. The point is not that every instance involves AI. It is that payment controls should not depend on guessing which technology an impersonator used.
A familiar voice can still be reassuring. It just should not be the thing that authorises a payment. Good controls are deliberately ordinary: verify out of band, separate preparation from approval, and give staff permission to challenge unusual instructions.
Sources and further reading
The figures below describe Gartner survey respondents’ reported incidents. The operational payment advice comes from UK public guidance.
Gartner: Deepfake social-engineering incidents reported by CISOs →
National Crime Agency: Protecting businesses against invoice fraud →
NCSC: Business payment fraud →
Found this useful? Forward it to someone who might too.
Plain-English Takeaway
Authenticate the request, not the performance: verify consequential instructions through a known, separate channel and a process that does not change just because a familiar person is asking.
Related Articles
That coding test might not be a coding test
WaterPlum, also known as Contagious Interview, used fake recruitment and technical assessments to target IT professionals. The practical defence is to treat downloaded interview code as untrusted.
Read articleYour encrypted call can still leak after it reaches your headphones
InjectEave shows how electromagnetic injection can induce analogue side-channel leakage after audio has been decrypted. It is specialist research, not evidence that criminals routinely listen to calls from 30 metres away.
Read articleThe Camera in the Room Might Not Look Like a Camera Anymore
As cameras, microphones and AI become embedded into ordinary-looking devices, workplace policies need to follow capability rather than appearance or brand.
Read article