In January 2024, an employee at the British engineering firm Arup transferred $25.6 million to fraudsters. He believed he was on a video call with his CFO and several colleagues. Every single participant besides himself was a deepfake. What was once considered a rare edge case is, by 2026, an established attack pattern — and it increasingly targets mid-sized companies too.

How Three Seconds of Audio Become a Voice

Modern AI voice cloning can need as little as a few seconds of audio to convincingly recreate a voice — and executives leave plenty of it behind: conference talks, podcast appearances, LinkedIn videos. Attackers research the target organization, identify decision-makers, and gather publicly available audio and video material before striking. One particularly effective variant: an email "from the CFO" announces an incoming call, and shortly after, a cloned voice actually calls — leaving the recipient with no obvious reason for suspicion.

No Longer a Fringe Case

Current market data shows a clear rise in AI-driven voice phishing compared to previous years, with a noticeable increase in deepfake fraud attempts specifically targeting German companies. Security analysts now estimate that AI-powered fraud has overtaken ransomware as the top concern for many executive teams.

Mid-sized companies are especially exposed: the flat hierarchies and short decision paths that are usually a strength become a weakness when it comes to deepfake CEO fraud.

What Actually Protects You

The good news: the most effective defense is neither expensive nor technically complex. It lies in clear processes, not detection software:

  • Four-eyes principle for payment approvals above a defined threshold — no exceptions, not even under apparent urgency
  • Callback verification using a known, independently stored phone number — never the number provided in the suspicious message itself
  • Out-of-band confirmation for unusual instructions, via a second communication channel
  • A clear internal rule: no payment is approved based on a voice or video message alone

Security experts estimate these four principles stop the vast majority of deepfake fraud attempts — not because they detect the forgery, but because they simply make it irrelevant.

Conclusion

Deepfake detection is an arms race the defense side can barely win on technical grounds alone. Process discipline is a different story: if every payment instruction goes through the same approval process regardless of its apparent source, even the most convincing deepfake loses its power.