AI & Technology

A Familiar Voice Is No Longer Verification

By Wael Handous

How high-value transaction teams can contain synthetic-voice fraud without slowing every legitimate deal 

The voice note arrives inside an active transaction. The accent is right, the rhythm is familiar and the speaker knows details that only the client and the deal team should know. 

There is one change: payment must go to a different bank account. 

Until recently, many experienced professionals would have treated the voice itself as reassuring evidence. That instinct is now a vulnerability. Synthetic audio does not need to fool the world; it only needs to sound credible for long enough to move one instruction through a busy workflow. 

The practical response is not to distrust every client or freeze every transaction. It is to stop treating familiarity as authorization. 

The threat has moved beyond strange emails 

Impersonation fraud succeeds because it borrows trust that already exists. A criminal does not have to invent a complete identity when a public interview, social video or voicemail may provide enough material to imitate a recognizable voice. 

The scale is no longer theoretical. The FBI’s 2025 Internet Crime Report recorded more than 22,000 complaints involving AI-related cybercrime and adjusted losses above $893 million. The report also identified more than $30 million in losses from business email compromise cases involving AI. 

The same report notes that voice cloning can be used to request wire payments. The technology changes the realism of the message, but the operational target remains familiar: persuade a person to alter money, identity or authority before anyone completes an independent check. 

A perfect fake is not required 

Teams sometimes focus on whether they can detect an artificial pause, unusual background noise or a strange pronunciation. Those clues can help, but they are not a control. 

The FBI has warned that AI-generated voices may sound nearly identical to a known contact. Its guidance is direct: independently identify a trusted number and call to verify the person before acting. The FTC gives similar advice: do not trust the voice alone; contact the person through a number you already know. 

This distinction matters. Detection asks an employee to judge whether the media is fake. Verification asks the business to prove whether the instruction is authorized. 

The second approach is stronger because it still works when the fake is excellent. 

Define the events that always trigger a pause 

Not every message deserves the same friction. A meeting confirmation and a request to redirect a large payment should not travel through the same approval path. 

A high-value workflow should automatically trigger verification when an instruction changes: bank or beneficiary details; the identity of a buyer, seller, investor or authorized signatory; the person allowed to approve or receive documents; the communication channel during a sensitive stage; an established sequence of approvals; or the timing of a payment under unusual urgency. 

The trigger should be objective. Employees should not have to decide whether the client “sounds suspicious” before using it. 

Dubai Aviation Engineering Projects offered the right public principle in its 2025 deepfake warning: verify the source and do not rush to click, share or pay. In transaction operations, that principle should become a documented step rather than a personal judgment. 

Separate the request from the confirmation 

If a bank-detail change arrives by voice note, replying to the same account does not provide independent verification. A compromised or impersonated channel cannot authenticate itself. 

The team should call a previously registered number, use a verified client portal or contact a second authorized person recorded before the change was requested. Contact details supplied inside the suspicious message should never become the verification route. 

For the highest-risk changes, one confirmation is not enough. A two-person rule can require one employee to verify the client and another to approve the operational change. The goal is not bureaucracy; it is to prevent one convincing moment from becoming an irreversible transfer. 

The process also needs a clean record. The transaction file should show what changed, who requested it, which trusted channel was used, who confirmed it, who approved it and when the decision occurred. 

That record supports recovery and accountability. It may also become important evidence: a recent Dubai Courts publication discusses the difficulty of relying on voice recordings alone and emphasizes corroborating evidence and chain of custody when deepfakes are suspected. 

Design security for the pace of real work 

Controls fail when the approved path is much slower than the shortcut. People under pressure will find a way around a process that cannot match the transaction’s operating rhythm. 

Strong teams therefore prepare before the urgent message arrives. They register trusted contact details at onboarding, identify authorized approvers, define escalation coverage outside normal hours and tell clients that payment changes will always receive an independent callback. 

This communication matters. A callback should not sound like an accusation. It should sound like a professional standard applied to every client and every sensitive instruction. 

The best control becomes part of the service promise: we protect the transaction by verifying material changes, even when the request appears to come from someone we know. 

AI should strengthen the defence 

The answer to AI-enabled impersonation is not to remove AI from the workflow. It is to use automation where it is strongest while keeping authority explicit. 

Systems can flag a new beneficiary, compare identity documents, detect conflicting transaction data, identify unusual communication patterns and preserve an audit trail. They can also ensure that a high-risk change cannot proceed until the required independent confirmation is recorded. 

What they should not do is turn a confidence score into automatic permission to move money. An anomaly score can support a decision; it should not replace accountable approval. 

Make stopping the transaction a sign of competence 

The final control is cultural. Employees must know they will be supported when they pause an urgent instruction, including one that appears to come from a powerful client or senior executive. 

Fraud uses hierarchy, urgency and familiarity to make verification feel impolite. Leadership must reverse that pressure. 

In a synthetic-media environment, professional trust needs a new operating rule: trust the relationship, verify the instruction. 

Disclosure 

Wael Handous is Founder and Group CEO of FRANK AI. No product or service is promoted in this article. 

Related Articles

Back to top button