In February 2024, a finance worker at a multinational company in Hong Kong attended a video call with the company’s CFO and several senior colleagues. The CFO instructed the worker to transfer $25 million to a specified account. The worker complied.
The CFO and colleagues were deepfakes. The video call was a real-time AI-generated simulation. The money was gone.
This is not science fiction. It is the new frontier of business fraud. And SMEs are not exempt.
How deepfake fraud works
Deepfake fraud has three common forms:
Voice cloning. An attacker records a few minutes of a target’s voice from public sources (podcasts, videos, conference calls) and uses AI to generate new speech. The cloned voice is then used in phone calls to authorise transfers, reset passwords, or extract information.
Video deepfakes. Real-time face-swapping technology allows an attacker to appear as someone else on a video call. The quality is now good enough to fool people who know the target.
Synthetic documents. AI-generated invoices, contracts, and identification documents are used to create false payment requests or open fraudulent accounts.
Why SMEs are targets
SMEs are attractive targets for deepfake fraud because:
- Approval processes are informal. A verbal instruction from the CEO is often sufficient to authorise a transfer.
- Staff are less trained. Smaller teams have less exposure to social engineering awareness training.
- Verification is weak. Callback verification procedures are rare in companies under 30 people.
The Hong Kong case involved a multinational. The next case will involve a 20-person company where the “CEO” calls the finance manager and asks for an urgent wire transfer.
Defences that work
Out-of-band verification. For any transfer over a defined threshold, require verification through a second channel. If the request comes by email, verify by phone. If by phone, verify by text to a known number.
Secret phrases. Establish a code word or phrase that only the real executive would know. Use it when verifying unusual requests.
Slow down. Urgency is the attacker’s friend. A genuine urgent request can wait 10 minutes for verification. A fake one cannot.
Video call protocols. For high-value decisions, require video calls to be initiated from known, pre-registered devices. Do not accept unexpected video call invitations.
At Metaluxo we include deepfake awareness in our security training programmes for SMEs. If your team has not discussed how to verify unusual requests, book a free 30-minute consultation and we will build a verification protocol for your company.