The defense that matters
- A familiar voice or face does not authorize a payment, password reset or data release.
- Require independent confirmation through a previously known channel for high-impact requests.
- Keep a second approver and an exception path that works during real emergencies.
- If money moved, contact the bank immediately and activate the incident procedure.
Last updated: September 24, 2026
Synthetic audio and video can make a request feel credible, but the control is the same one that protects against ordinary impersonation: verify the request and authority, not the media. The FBI's IC3 BEC guidance recommends a secondary channel to verify account changes and immediate bank contact after fraud. The 2025 IC3 report describes AI-assisted BEC examples, but a small business should not need a loss statistic to adopt a reliable process.
Mark the decisions that need independent verification
Start with bank-detail changes, new payees, urgent transfers, payroll redirects, password resets for privileged staff, export of customer data and changes to recovery methods. Write the approver and verification method beside each. A caller asking you to bypass the normal process because their video is convincing is itself a reason to pause.
| Suspicious request | Safe response | Record |
|---|---|---|
| Supplier sends new bank details | Call the established number in vendor records; use a second approver | Person reached and approved change |
| Executive voice asks for urgent transfer | Hang up and contact the executive through the known internal channel | Decision and exception owner |
| Video meeting requests account recovery | Use established identity and help-desk procedure | Ticket and approved verifier |
| Employee asks to change payroll | Confirm through the existing HR workflow | Authorized change record |
Do not use a phone number, QR code or link supplied in the suspicious message as the independent channel. Train assistants and finance staff to say, “I will follow the verification procedure,” and make that answer acceptable even when the request appears to come from leadership.
Where detection tools help and where they do not
A media-analysis tool may provide a signal, but compression, editing and new models can change its reliability. Do not make a high-value decision based solely on a detector's “real” result. Also check the sender account, call context, transaction history and approval trail. If your team already has email filtering or meeting-security controls, configure and review them first. A new “deepfake detector” should have a documented failure mode and pilot before purchase.
Practice the response
Run a short exercise with finance, HR and IT: a familiar voice asks for a changed account under deadline pressure. Confirm that staff use a known channel, the second approver can be reached, and a blocked attempt is reported. If a transfer occurred, IC3 says to contact the originating bank promptly; preserve messages and call details and use the BEC response guide. If credentials or data were exposed, activate the incident-response plan.
First three actions
Publish the known-number callback rule, require a second approver for material changes, and rehearse one urgent executive request. These controls work against both AI-generated and ordinary fraud.
Sources checked September 24, 2026: FBI IC3 BEC guidance, FBI IC3 2025 report, and NIST's Generative AI Profile. This is process guidance, not a test of media detectors.