AI-generated voice and video have made impersonation cheaper and more convincing, but organizations should not build defenses around deepfake detection alone. The durable control is independent verification for consequential requests.
Why this matters now
The FBI has warned that malicious actors use AI-generated voice messages and other impersonation techniques to establish trust, move conversations to attacker-controlled channels, and obtain information or access. Familiarity of voice, writing style, or caller identity is no longer sufficient evidence.
Executive takeaway
Design financial, identity, access, and sensitive-data processes so no single message, call, or person can authorize a high-impact action. Verification should use a pre-established channel and trusted contact information—not details supplied in the request.
High-risk requests
- Payments, bank-detail changes, gift cards, or unusual purchasing.
- Password resets, MFA changes, privileged access, or new devices.
- Transfer of confidential documents, credentials, customer data, or legal material.
- Requests to bypass normal process because of secrecy or urgency.
- Changes to recovery contacts, executive travel, or security arrangements.
A practical verification design
- Define which actions require dual control or out-of-band verification.
- Maintain trusted contact paths independently of incoming messages.
- Use known internal systems to create and approve requests.
- Make refusal and escalation psychologically safe, regardless of apparent seniority.
- Log exceptions and test the process with realistic simulations.
- Include help desks, assistants, finance, legal, communications, and executive teams—not only security.
Shawn’s perspective
Trying to decide whether every voice is “real” puts employees in an unwinnable contest with improving synthesis technology. Process integrity scales better: even a perfect impersonation should fail when the requested action needs independent evidence and a second accountable person.
Source
FBI: Senior U.S. Officials Impersonated in Malicious Messaging Campaign
