We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Threats

Threats

Deepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director

Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

A voice note from the boss, and the bank closes at four

The finance lead at a 40-person Dubai trading company has worked for the managing director for nine years. She knows his voice: the way he clears his throat before a number, the habit of saying "quickly, quickly" when something is late. On Thursday at 2:50 in the afternoon a WhatsApp voice note arrives from his number. He is travelling. He sounds tired and a little irritated.

The note says a supplier in Turkey is holding a container until a balance of 310,000 dirhams is settled, the bank closes at four, and he needs her to push the transfer through now. A second message follows with the supplier's account details as a photo. Then: "I am boarding, cannot talk. Please confirm when done."

She hesitates, but the voice is his. The throat clearing is there. The "quickly, quickly" is there. It is 3:05.

What saves the company is not instinct. It is a rule the finance lead wrote herself two years earlier after a near miss with a fake invoice: nothing above 50,000 dirhams moves on a phone request without a call back to the number in the directory. She calls it. The managing director answers from a hotel lobby in Riyadh. He has not sent a voice note in a week. The container does not exist.

What the heck does this mean

Deepfake fraud is the old boss-needs-a-wire scam with a new engine. Someone takes a sample of a real person's voice or face, feeds it to software that can produce new speech or video in that likeness, and uses the result to pressure an employee into moving money or handing over access.

Voice cloning is the audio version. A few minutes of a public webinar or a voicemail greeting is enough raw material. The output can say anything, including the throat clearing.

CEO fraud, or executive impersonation, is the playbook: urgency, secrecy, a plausible business reason, and a time limit that lands right before a bank cutoff or a holiday.

Multi-channel pressure is what makes 2026 different. The voice note comes on WhatsApp, the account details come as a photo, the follow-up comes by email, and the whole thing is timed so that the one person who could confirm is on a plane.

What did not change: the money still moves because a human approved it. That is the control point, and it is yours.

The numbers that matter

Phishing by voice and text outperformed email by 40% in the simulations analyzed for the Verizon 2026 Data Breach Investigations Report. The phone is the channel people trust, which is exactly why it is the channel being attacked.

Total reported cybercrime losses reached $20.9 billion in the FBI IC3 2025 Annual Report, up 26% in a year. Those are only the cases somebody bothered to report, and a finance lead who caught the fake in time never files one.

One in four malicious breaches was AI-enabled, and those breaches cost about $6.0 million on average, according to the IBM 2026 Cost of a Data Breach Report. The software that clones a voice is cheap. The mistake it produces is not.

What to do this week

  1. Write the callback rule today, in one paragraph, and have the managing director sign it: no payment or bank change above your threshold is executed on a call, voice note or video alone. Callbacks go to the directory number, never to the number that just called. (CIS 14 Security Awareness and Skills Training)
  2. Agree a spoken code word between the owner and anyone who can move money, and change it quarterly. Low tech. Works. A clone does not know the word. (CIS 14 Security Awareness and Skills Training)
  3. Require two approvers in the banking platform itself for transfers above the threshold, so the rule is enforced by the bank's software and not by memory under pressure. (CIS 6 Access Control Management)
  4. Remove payment approval rights from anyone who does not need them, starting with the owner's phone. The fewer people who can approve a transfer, the fewer people a clone can impersonate. (CIS 6 Access Control Management)
  5. Rehearse the near miss. Have someone in the leadership team leave a "boarding, cannot talk" voice note for the finance team and see what happens. Debrief kindly. (CIS 14 Security Awareness and Skills Training)
  6. Put the bank's recall number and the insurer's hotline on the same card as the callback rule, with the instruction to call within the hour if a transfer was approved on a fake request. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment asks the questions a deepfake exploits: who can approve a transfer, from which device, with how many approvers, and whether the callback rule exists outside one person's head. The Cyber Hygiene Test takes three minutes and gives a first answer. For a second pair of eyes on your payment controls, book 15 minutes with an engineer.

Questions people ask

How much audio is needed to clone a voice? Less than you would like, and less every year. Public demonstrations have produced convincing clones from short clips, and your voice is already out there if you have ever recorded a webinar, a podcast, a voicemail greeting or a sales video. Assume the voice can be faked. Build your controls so that it does not matter whether it was.

What is a callback verification policy? It is a written rule that no payment, bank-detail change or urgent transfer is executed on the strength of a call, voice note or video alone. The person who received the request hangs up and calls the requester back on a number already stored in the company directory, or confirms through a second channel the requester did not choose. The policy names who can approve, what threshold triggers it, and states that urgency is never a reason to skip it.

Are deepfake losses covered by cyber insurance? It depends on the wording. Losses from tricking an employee into sending money usually fall under social engineering or funds transfer fraud coverage, which is often sublimited well below the main policy limit and may require that you followed a verification procedure. Read that section of your policy this week, and ask your broker in writing whether a cloned voice is treated any differently from a fake email.

Trust the person. Verify the request. The two have never been the same thing, and a good clone only makes the difference easier to see.

Questions people ask

How much audio is needed to clone a voice?

Less than you would like, and less every year. Public demonstrations have produced convincing clones from short clips, and your voice is already out there if you have ever recorded a webinar, a podcast, a voicemail greeting or a sales video. Assume the voice can be faked. Build your controls so that it does not matter whether it was.

What is a callback verification policy?

It is a written rule that no payment, bank-detail change or urgent transfer is executed on the strength of a call, voice note or video alone. The person who received the request hangs up and calls the requester back on a number already stored in the company directory, or confirms through a second channel the requester did not choose. The policy names who can approve, what threshold triggers it, and states that urgency is never a reason to skip it.

Are deepfake losses covered by cyber insurance?

It depends on the wording. Losses from tricking an employee into sending money usually fall under social engineering or funds transfer fraud coverage, which is often sublimited well below the main policy limit and may require that you followed a verification procedure. Read that section of your policy this week, and ask your broker in writing whether a cloned voice is treated any differently from a fake email.

Controls this post maps to

CIS 14 Security Awareness and Skills TrainingCIS 6 Access Control ManagementCIS 17 Incident Response Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.