Key Takeaways:
- Deepfake video and voice cloning are now being used to impersonate CFOs and executives to authorize fraudulent wire transfers, not just to phish credentials.
- The FBI’s 2025 Internet Crime Report recorded $3.046 billion in business email compromise losses, and for the first time tracked AI-related fraud as its own category.
- In every documented case, the failure point is the authorization step: a human believes they recognize a familiar face or voice.
- A documented, named authorization protocol resists this kind of attack in a way an informal internal process does not, regardless of where your finance team sits.
Your accounts payable process used to have one obvious weak point: a suspicious email. That is no longer true.
In January 2024, a finance employee at the global engineering firm Arup joined a video call with people who looked and sounded exactly like the company’s CFO and several colleagues. Every one of them was an AI-generated deepfake. The employee authorized 15 wire transfers totaling $25.6 million before anyone realized the call had never been real.
This is not a warning about offshore staffing. It is a warning about what your authorization process is built on, and it is why accounts payable fraud prevention now must mean more than training employees to spot a suspicious email.
What is Deepfake Fraud?
Deepfake fraud or phishing, a fast-growing form of executive impersonation fraud, is the use of AI-generated audio or video to impersonate a real executive, colleague, or vendor contact in order to authorize a fraudulent payment or extract sensitive information.
Unlike traditional phishing, it does not rely on a bad link or a malicious attachment. It defeats the thing your team has always trusted most: recognizing a familiar face and voice.
The New Failure Point: When Fraud Looks Like Your CFO
For years, business email compromise meant a spoofed email address and a request that felt slightly off. That model still exists, but it is no longer the ceiling. Attackers now combine the old script with new tools, and the result defeats the human instincts your team has relied on for decades.
For a CFO or treasurer at a mid-size or enterprise organization, this is a live operational risk that belongs in the same conversation as your wire transfer limits and your bank reconciliation controls.
What Actually Happened at Arup
The Arup incident followed a familiar setup with an unfamiliar ending. A finance worker in the company’s Hong Kong office received an email that appeared to come from Arup’s UK-based CFO, requesting a confidential transaction. The employee was skeptical, which is exactly what good training produces.
Then the attackers escalated. They invited the employee to a video conference where the CFO and several colleagues appeared, spoke, and directed the transfer. Every participant except the employee was synthetic. Fifteen transfers followed, moving a combined $25.6 million to five Hong Kong bank accounts in a single day.
The company later stated that no internal systems were breached. This was social engineering, not a hack.
The Numbers Behind the Trend
The Arup case is not an outlier anymore, it is a preview. The FBI’s Internet Crime Complaint Center logged $3.046 billion in losses in its 2025 Annual Report, up from $2.77 billion the year before. Business email compromise wire transfer schemes account for the bulk of that figure, and they are only getting more convincing.
For the first time, the agency tracked AI-related fraud as a distinct category: more than 22,000 complaints and $893 million in confirmed losses, with the agency noting the real figure is almost certainly higher because most victims never realize AI was involved.
Separately, the Association for Financial Professionals found that 74% of organizations experienced business email compromise in 2025. The gap between attacker capability and defender readiness is widening, not closing.
Why “I Recognized the Voice” is No Longer a Control
AI voice cloning fraud prevention must start by removing the human ear as the last line of defense. Detection technology is probabilistic. It flags what looks suspicious most of the time. Payment execution is deterministic. Once a transfer is authorized, the money moves and it rarely comes back.
When your only safeguard against impersonation is a human’s confidence that they know the person on the call, you have built a control with no technical floor under it.
Where Ad Hoc Verification Breaks Down
Most finance teams already have some version of a callback rule or a second-approval step. The problem is not the rule, it is enforcement under pressure.
Treasury and finance staff report that dual-control and callback procedures get bypassed precisely when a deal feels urgent or a senior leader is traveling and unreachable through normal channels.
The control exists on paper. It fails at the exact moment a fraudster is counting on it to fail, because “just this once” is where every documented deepfake wire fraud case happened.
HELP US REACH MORE PEOPLE
Like what you’re reading?
Add Connext as a preferred source on Google — it only takes a moment and helps more professionals find our content.
- 1 Click Add as preferred source below
- 2 Sign in to your Google account if prompted
- 3 Check the box next to Connext Global to confirm your preference
- 4 Close the tab — you're done. Thank you!
The Objection Everyone Expects: Isn’t Offshore the Weak Link?
If your AP function sits with an offshore or co-managed team, does that make you more exposed to this kind of fraud?
The honest answer is the opposite of what the question assumes. An ad hoc internal process, built on tenure and informal trust between people who have worked together for years, is more vulnerable to a convincing deepfake than a team operating under a named authorization protocol that does not bend based on who appears to be asking.
What a Documented Protocol Actually Requires
Strong payment authorization controls answer four questions in writing, before anyone needs it under pressure:
- Who is authorized to initiate a payment request?
- Which communication channel counts as valid (never the channel the request arrived on)?
- What specifically qualifies as verification?
- What dollar threshold automatically triggers a second sign-off?
A callback to a number pulled from the suspicious email is not verification. A callback to a number your organization registered independently, months earlier, is.
| Criteria | Ad Hoc Internal Process | Documented Co-Managed Protocol |
| Verification channel | Whatever channel the request arrived on | Callback to a pre-registered number only |
| Authorization | Informal, based on recognizing the requester | Named initiator, named approver, logged |
| Under pressure | Frequently bypassed for urgent requests | Enforced regardless of urgency |
| Audit trail | Rarely documented | Logged at every step |
| Consistency | Varies by employee and by day | Applied the same way every time |
Building an Authorization Protocol That Holds Under Pressure
Effective accounts payable fraud prevention is a structural problem, not a vigilance problem. No amount of employee training closes a gap that only shows up once, during the one call an employee will ever receive from a synthetic CFO. Four elements make the difference:
- Enforce dual control above a defined dollar threshold – No exceptions carved out for urgency, no matter who is asking or how the request is framed.
- Require out-of-band callback verification – Confirm every high-value request against a number your organization registered independently, never a number supplied in the request itself.
- Use a pre-agreed verification phrase for unusual or high-value transfers – Refresh it on a regular schedule so it cannot be reused or guessed.
- Apply a mandatory time delay to any first-time payee – Build in enough time for a second person to confirm the request through a separate channel before funds move.
None of this depends on an employee’s ability to spot a fake. It depends on a process that treats every request the same way, whether the voice on the call sounds right or not.
This belongs to the controller or treasurer, not to IT alone, since the vulnerability lives in the authorization decision rather than in network infrastructure.
Most organizations can draft the core protocol within a few weeks. The harder work is folding it into onboarding for every finance hire, domestic or offshore, so the callback step becomes default behavior rather than a policy nobody remembers under pressure.
Why Partner with Connext
Most finance teams inherit this exposure by accident, which is why accounts payable fraud prevention must be designed in from the start rather than added after an incident. They build an authorization process over years, informally, and it hardens around habits rather than documentation.
Connext’s co-management model starts from the opposite direction. Our dedicated, in-country AP teams follow documented authorization protocols, supported by a named team manager and full visibility into every payment step. We are also SOC 2 Type II certified and HIPAA compliant, with monitored facilities and controlled system access built into every engagement.
Instead of simply adding headcount, Connext helps you build a consistent, secure AP process that reduces risk and scales across your organization. This is what finance team fraud controls in 2026 look like when they’re built before the incident, not after it.
Talk to us about building a documented AP authorization protocol into your finance operations.
Frequently Asked Questions
Not when the function operates under a documented protocol. Exposure comes from informal, recognition-based verification, not from where the team is physically located. A co-managed team with a written authorization process is often more consistent than an internal team relying on institutional habit.
Standard controls often exist as policy without enforcement teeth. A documented protocol names who can request, which channel counts as valid, and what threshold forces a second approval, then applies it the same way regardless of urgency or seniority of the requester.
In a co-managed structure, the client retains visibility and direction over the workflow while a named in-country team manager oversees execution and compliance day by day. That shared structure supports consistent enforcement of authorization steps rather than leaving verification to individual judgment, which matters most during the exact moments a fraudster is counting on a shortcut.
At minimum, confirm SOC 2 Type II certification and, if any healthcare-adjacent data is involved, HIPAA compliance backed by a signed Business Associate Agreement. Ask specifically which controls back each certification, such as access logging or monitored facilities, rather than accepting the framework name alone as proof of readiness.
Most organizations can draft and implement the core elements, callback verification, dual control thresholds, and escalation paths, within a few weeks. The harder part is enforcing it consistently once it exists, particularly under time pressure or when a request appears to come from someone senior.
A defined dollar threshold is standard practice, since applying dual control to every transaction can slow routine payments unnecessarily. The threshold should be set low enough that a single successful fraud attempt cannot cause material damage, and reviewed periodically as transaction volume and typical payment sizes change.