Your phone rings. It is your CFO, or a client you have worked with for years, and their voice sounds exactly like it always does. They need a payment sent today, they are in back-to-back meetings and cannot talk long, and please keep this quiet until the deal is announced. Every detail matches what you would expect from that person. The voice on the line is not them. It is a clone, and the call is the scam.

This is the newer, harder version of invoice fraud, and it is spreading fast.

The scam that beats email training

Most staff have been trained to distrust a suspicious email: bad grammar, a strange sender address, an urgent tone. AI voice and video cloning skips all of that. A fraudster feeds a few minutes of public audio, a webinar clip, a podcast appearance, into a cloning tool, and produces a voice that a colleague or client would recognize as genuine on a call or a video conference.

The reference case is engineering consultancy Arup, which confirmed in 2024 that a finance employee authorized 15 separate transfers totaling $25.6 million after joining a video conference where every other participant, including the person who appeared to be the company’s CFO, was an AI-generated deepfake. Nobody in the room was who they appeared to be except the one employee sending the money.

AI fraud losses reported to the FBI in 2025 $893M lost across 22,364 AI-related fraudcomplaints reported to the FBI in 2025

How fast this is growing

The FBI’s 2025 Internet Crime Report was the first in its 25-year history to break out AI-related fraud as its own category, and the numbers explain why. Deepfake-enabled voice phishing attacks surged more than 1,600 percent in early 2025 compared to late 2024 in the US. Roughly 40 percent of business email compromise attacks in 2026 now include an AI-generated voice or video component, up from under 5 percent in 2023.

Share of BEC attacks using an AI voice or video deepfake, 2026 40%of BEC attacks now include a deepfake0100

None of this requires technical skill on the fraudster’s side. The cloning tools are free, widely available, and usable anonymously, which is why a scam that used to take real effort to pull off is now something almost anyone can attempt.

Confidentiality is the tell, not the risk

A cloned voice or face almost always comes with an instruction to keep the request quiet: do not loop in the rest of the team, do not mention it until the deal closes, do not call anyone else to check. That instruction is the entire point. A scammer cannot control what happens if you verify through a channel they do not have access to, so they try to talk you out of using one.

Treat a request for confidentiality around a payment or a bank detail change as a reason to verify harder, not a reason to move faster.

Verify against a record, not a voice

The single habit that survives even a convincing clone: never authorize a payment or a bank detail change based on a call or video alone, no matter how urgent or how familiar the voice sounds. Call back on a number you already had on file before the conversation started, never one given to you during the call, and check the request against a real, documented invoice.

A voice can be cloned in minutes. A specific invoice on file, with a payable link tied to that invoice record, cannot be talked into existing on the spot the way a scammer can talk someone into a wire transfer.

Verbal or video authorizationDocumented invoice + payable link
Can be faked convincinglyYes, with a few minutes of audio or videoNo, tied to a record already on file
Exists before the call happensNo, created in the momentYes, issued and dated in advance
What confirms the request is realTrusting how the person sounds or looksMatching it to an actual invoice number

A BillyPaid invoice issues with a payable link tied to that specific invoice record, so a payment always has a documented invoice behind it, something a cloned voice on a call cannot produce on demand.