Your phone rings. It is your CFO, or a client you have worked with for years, and their voice sounds exactly like it always does. They need a payment sent today, they are in back-to-back meetings and cannot talk long, and please keep this quiet until the deal is announced. Every detail matches what you would expect from that person. The voice on the line is not them. It is a clone, and the call is the scam.
This is the newer, harder version of invoice fraud, and it is spreading fast.
The scam that beats email training
Most staff have been trained to distrust a suspicious email: bad grammar, a strange sender address, an urgent tone. AI voice and video cloning skips all of that. A fraudster feeds a few minutes of public audio, a webinar clip, a podcast appearance, into a cloning tool, and produces a voice that a colleague or client would recognize as genuine on a call or a video conference.
The reference case is engineering consultancy Arup, which confirmed in 2024 that a finance employee authorized 15 separate transfers totaling $25.6 million after joining a video conference where every other participant, including the person who appeared to be the company’s CFO, was an AI-generated deepfake. Nobody in the room was who they appeared to be except the one employee sending the money.
How fast this is growing
The FBI’s 2025 Internet Crime Report was the first in its 25-year history to break out AI-related fraud as its own category, and the numbers explain why. Deepfake-enabled voice phishing attacks surged more than 1,600 percent in early 2025 compared to late 2024 in the US. Roughly 40 percent of business email compromise attacks in 2026 now include an AI-generated voice or video component, up from under 5 percent in 2023.
None of this requires technical skill on the fraudster’s side. The cloning tools are free, widely available, and usable anonymously, which is why a scam that used to take real effort to pull off is now something almost anyone can attempt.
Confidentiality is the tell, not the risk
A cloned voice or face almost always comes with an instruction to keep the request quiet: do not loop in the rest of the team, do not mention it until the deal closes, do not call anyone else to check. That instruction is the entire point. A scammer cannot control what happens if you verify through a channel they do not have access to, so they try to talk you out of using one.
Treat a request for confidentiality around a payment or a bank detail change as a reason to verify harder, not a reason to move faster.
Verify against a record, not a voice
The single habit that survives even a convincing clone: never authorize a payment or a bank detail change based on a call or video alone, no matter how urgent or how familiar the voice sounds. Call back on a number you already had on file before the conversation started, never one given to you during the call, and check the request against a real, documented invoice.
A voice can be cloned in minutes. A specific invoice on file, with a payable link tied to that invoice record, cannot be talked into existing on the spot the way a scammer can talk someone into a wire transfer.
| Verbal or video authorization | Documented invoice + payable link | |
|---|---|---|
| Can be faked convincingly | Yes, with a few minutes of audio or video | No, tied to a record already on file |
| Exists before the call happens | No, created in the moment | Yes, issued and dated in advance |
| What confirms the request is real | Trusting how the person sounds or looks | Matching it to an actual invoice number |
A BillyPaid invoice issues with a payable link tied to that specific invoice record, so a payment always has a documented invoice behind it, something a cloned voice on a call cannot produce on demand.