Cyber AssessValydex™by iFeelTech
Implementation Guide

AI-Enhanced BEC Guide (2026)

Deepfake executive fraud controls for finance and operations teams

A payment-change callback procedure, approval rule and immediate response steps for impersonation attempts.

Last updated: September 24, 2026
4 minute read

The payment rule

  • Pause an unexpected change to bank details, payment destination or approval route, even if it appears to come from an executive or known vendor.
  • Verify through a phone number or contact record already on file, never the one supplied in the request.
  • Separate duties so the person changing payment details cannot be the only approver of the resulting transfer.
  • If money moved: Contact the bank immediately, preserve the request, and report the incident through the appropriate channels.

Last updated: September 24, 2026

Generative AI can make a fraudulent email, voice message or video more convincing. It does not change the most reliable control: a high-risk request must be verified through a trusted channel independent of that request. The FBI's BEC guidance recommends a secondary channel for account-information changes. Its vendor-fraud advisory says to call a business's established main line instead of numbers supplied in the suspect email. Caller ID and a familiar-sounding voice are not enough on their own.

The three requests that deserve a stop

RequestSafe response
Vendor says its bank account changedPause payment; call the previously recorded contact and confirm through a second approved person
Executive asks for an urgent, secret transferApply the same approval rule regardless of seniority or urgency
Employee asks to redirect payroll or sensitive recordsUse the established HR or identity-verification process, not the reply path in the message

A compromised real email account may pass ordinary sender checks. Email authentication and filtering help, but they do not replace a payment-control process. A deepfake detector can also be wrong; do not make the decision depend on whether a clip “looks AI-generated.”

A one-page payment-change procedure

  1. Record the request and stop the payment change until verification completes. Keep the original message, headers if available, invoice and proposed account details in a restricted case file.
  2. Look up the trusted contact in the vendor record established before this request. If the record is stale, use the vendor's independently obtained main line and verify the person who can authorize changes.
  3. Call back outside the suspect thread. Ask for the original invoice and reason for the change. Do not read the proposed bank number first and ask for a yes/no answer.
  4. Require a separate approver. The verifier records the date, contact and result; a different authorized person approves the change or transfer.
  5. Update the vendor record only after approval. Send a confirmation to the prior contact through an established channel and monitor the first payment.

The exact money threshold is a business choice. Bank-detail changes should trigger the process regardless of amount because a small “test” payment can precede a larger loss. Train substitutes so the process still works when the finance lead is absent.

If a payment or account was compromised

Contact the sending bank immediately and ask about stopping or recalling the transfer. The FBI IC3 BEC page directs victims to their bank and reporting; timing matters for possible recovery, which is never guaranteed. Preserve the emails, headers, transaction records and contact history. Ask IT to investigate mailbox access, forwarding rules, sessions and MFA; do not assume the visible sender was merely spoofed. Notify the incident lead, insurer and counsel as applicable before sending broad external statements.

For an editable response structure, use the incident-response runbook. For the first communication and containment steps, see the SMB incident-response plan. The email-security guide covers technical controls that complement payment verification.

A 20-minute rehearsal

Give finance and operations a realistic vendor bank-change request. Have them find the trusted contact, make the callback, document a mismatch and escalate without processing the payment. The exercise passes when the right people know who can pause the transfer and where to record the decision. Repeat after staffing or bank-workflow changes.

Keep the rule visible

Use the BEC verification desk reference at the point where invoices and bank changes are approved. It should support an existing finance process, not be treated as proof that email fraud is solved.

Sources checked September 24, 2026: FBI IC3 BEC guidance, FBI vendor-fraud advisory, and FTC phishing guidance for small businesses. No incident statistics or hands-on fraud-detection testing are claimed here.