Imagine your accounts payable clerk answers the phone and hears the administrator's voice, sounding rushed. A vendor payment has to go out today, the usual approval process will take too long, and could she please wire it now and explain later? The caller ID shows the administrator's mobile number. Everything feels right, and everything is fake.
Voice cloning and caller ID spoofing have made this kind of fraud more convincing and easier to attempt. You do not need to understand the technology deeply to defend against it. You need a routine that does not depend on whether a voice sounds right.
Software can now imitate a person's voice from a relatively short audio sample. Executives, administrators and owners often leave plenty of material in public: conference talks, videos, recorded webinars, voicemail greetings and local media interviews. An attacker does not need a perfect copy. Over a poor phone line, with a sense of urgency, an approximate voice is often enough.
Caller ID is not proof of identity. Attackers can make a call appear to come from a known number, including an internal extension, a leader's mobile phone or a bank. Seeing a familiar name on the screen tells you only what the caller wanted displayed.
Most voice-based fraud aims at one of a few outcomes:
Wire or ACH transfers to a new account, often framed as an urgent vendor payment or an acquisition-related expense.
Password resets or MFA code requests, where the caller poses as a leader or a staff member locked out of an account.
Gift card purchases or payroll changes, such as redirecting a direct deposit.
Access to systems, with the caller pressing the helpdesk to bypass normal identity checks.
The voice may be convincing, but the situation usually gives it away. Look for:
Strong urgency, often with a reason the normal process cannot be followed.
Requests for secrecy, such as "do not tell anyone yet."
A change in payment details or a first-time payee.
Pressure to skip approvals because the caller outranks everyone.
Reluctance to be called back or to move the conversation to a known channel.
Any one of these is a reason to pause. Several together should settle the question.
The most effective defense is boring and consistent. Adopt it as policy for any request involving money, credentials or access.
End or pause the call politely. "I need to confirm this through our standard process. I will call you right back."
Look up the number independently. Use the number from your internal directory, a saved contact or the vendor's file, never one the caller gave you or the one that appears on caller ID.
Call back and confirm the specific request. State the amount, payee and reason, and have the person confirm them.
Require a second approver for wires, new payees and changes to bank details, no matter who is asking.
Document the verification in the payment record, including who called, who confirmed and when.
For helpdesk or IT requests, add an extra step: verify identity through a method that does not depend on the caller, such as a manager confirmation or a pre-agreed process, before resetting any password or MFA method.
Some organizations add a shared code word for high-value requests, known only to a small group and changed periodically. A code word can help, but it should supplement call-back verification, not replace it, because words can be leaked or overheard.
You can also reduce the audio available to attackers. You do not have to disappear from public life, but be thoughtful about how much recorded material is posted, and keep personal voicemail greetings short.
The routine only works if staff feel safe following it, even when the "caller" is the boss. Tell your team directly that verifying a request will never get them in trouble, and that you would rather be called back ten times than lose a payment once. Leaders should model this by thanking people who double-check.
Run a short drill twice a year. A trusted colleague or IT partner places a harmless test call asking for something that should trigger verification, and the team practices using the call-back steps. Review what happened without blame.
UnityCare IT helps healthcare and senior-living organizations build verification procedures, set up helpdesk identity checks and train staff on social engineering. If you would like a short, practical session for your finance and front-office teams, we are glad to help.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172