Cairitech IT Support and Services Logo

Leader in IT Support & Cybersecurity Across Ontario

Cairitech IT Support and Services Logo
CairiTech blog cover image

The Voice on the Phone Was Your CFO's — The Person Behind It Wasn't

Powered By CairiTech

Quick answer

A deepfake voice scam uses artificial intelligence to clone a trusted person's voice or face, then tricks your staff into approving a payment or handing over data. These attacks are no longer rare — by 2026 an estimated 40% of business email compromise attempts involve AI-generated deepfakes, up from under 5% in 2023 (Digital Applied). In one widely reported case, multinational engineering firm Arup lost $25 million when a finance employee joined a video call where every "colleague," including the CFO, was an AI fake (CNN, May 2024).

September is prime season for it: teams are back from summer, invoice queues are long, and a rushed approval feels normal. CairiTech, an Aurora, Ontario managed IT and cybersecurity provider, helps Greater Toronto Area businesses build the verification habits and controls that stop a convincing fake from draining a real bank account.

3 min read posted on 09/06/26

What is a deepfake voice scam?

A deepfake voice scam is a fraud in which criminals use AI-cloned audio — and sometimes video — to impersonate someone you trust and pressure you into moving money or sharing credentials. Instead of a clumsy spoofed email, you get a phone call or Teams meeting where the "boss" sounds exactly right, uses the correct names, and asks for something urgent. The technology that makes this possible has become cheap and fast: commodity tools can clone a usable voice from roughly three seconds of audio for under $20 (Digital Applied). A short clip from a webinar, a voicemail greeting, or a LinkedIn video is all the raw material a scammer needs.

Why are these attacks spiking in 2026?

They are spiking because the tools got good, cheap, and easy at the same time. The average loss from an AI-augmented business email compromise incident now exceeds $4.1 million, compared with about $1.3 million for traditional phishing (Digital Applied), and the FBI's Internet Crime Complaint Center logged roughly $2.9 billion in reported BEC losses in 2024 alone — a figure investigators say captures only a fraction of the real total. For a criminal, a deepfake is simply a better return on effort: the attack tools cost under $100, and one successful wire can pay for years of fraud. The uncomfortable part is that detection has not kept up — audio-detection accuracy that looks strong in a lab drops to 50–65% on a compressed phone call, so you cannot rely on "I'll just be able to tell."

Why is September a high-risk month for finance fraud?

September is high-risk because routines are still rebuilding after summer, and that is exactly the window attackers watch for. Key approvers are catching up on a backlog, temporary summer coverage may still be unwinding, and a large project invoice or a "we need this wired before end of day" request blends right into the pile. Scammers time their calls to moments when a staffer is most likely to act first and verify later. The same seasonal pressure we flagged in Half Your Team's on Vacation — That's When the Fake Invoice Arrives applies in reverse each fall, when everyone is back but not yet back in rhythm.

Which Ontario businesses are most at risk?

Firms that move large sums on tight deadlines — construction, Architecture, Engineering, and Construction (AEC) practices, manufacturers, and property-management companies — are the most exposed. These businesses run high-value invoices, progress draws, and vendor payments as routine, so a fraudulent "supplier change" or "urgent draw" does not look unusual. Property managers handle deposits and owner disbursements; builders push six-figure subcontractor payments; manufacturers pay international suppliers. Arup itself is an engineering firm, which is why that $25 million case should land hard for every GTA design and construction shop.

How do you stop a deepfake payment scam?

You stop it with process, not just detection — because the whole point of a deepfake is to beat human judgment in the moment. The controls that actually work:

  • A mandatory call-back rule: any payment or banking-detail change is verified using a phone number you already have on file, never the number or link in the request.

  • A verbal code word shared in advance for urgent finance requests, so a cloned voice alone is never enough.

  • Dual approval on wire transfers and any new-payee setup above a set threshold.

  • Phishing-resistant multi-factor authentication on email and finance systems, so a stolen password does not open the door — see our note on why your password is the key under the doormat.

  • Staff training that names deepfakes specifically, so "the CFO called and it sounded like him" triggers verification, not compliance.

Here is how the old threat and the new one compare:

Traditional BEC (email)

Main channel

Spoofed or hacked email

Tell-tale signs

Odd grammar, wrong address, off tone

Attacker cost

Low

Average loss per incident

~$1.3 million

Best defence

Email filtering + verification

AI deepfake BEC (voice/video)

Main channel

Cloned voice call or fake video meeting

Tell-tale signs

Few — voice and face look and sound right

Attacker cost

Under $100 in tools; ~3 sec of audio

Average loss per incident

~$4.1 million

Best defence

Call-back rule + code word + dual approval

Don't let a convincing fake write a real cheque

Deepfakes are designed to beat the one thing every business relies on: trust in a familiar voice. The fix isn't paranoia — it's a handful of simple rules that make "it sounded exactly like her" no longer good enough to move money. If you're not sure your payment process would catch a fake, that's worth an hour of a specialist's time. Book your free discovery call with CairiTech today.

FREE REPORT: IT Buyers Guide

What You Should Expect To Pay For I.T. Support For Your Business (And How To Get Exactly What You Need Without Unnecessary Extras, Hidden Fees And Bloated Contracts)

Frequently asked questions

Can you tell a deepfake voice from a real one?

Usually not reliably by ear. Detection tools reach only 80–85% accuracy on clean lab audio and fall to 50–65% on compressed phone calls (Digital Applied), so a verification process — not your instincts — is what protects you.

How cheaply can a criminal clone someone's voice?

Very cheaply. Dark-web tools can clone a usable voice from about three seconds of audio for under $20, and a full attack kit runs under $100 (Digital Applied).

Does multi-factor authentication stop deepfake fraud?

It helps but is not enough on its own. MFA stops attackers from logging into your accounts, but a deepfake fraud often skips the login entirely and simply convinces a real employee to send money, so you also need payment-verification rules.

What should an employee do if a payment request feels off?

Stop and verify through a known channel before acting. Hang up, call the person back on a number already on file, and confirm — a legitimate request always survives a call-back, and a fraudulent one falls apart.

Written by the CairiTech team — Greater Toronto Area managed IT and cybersecurity specialists, serving Ontario businesses (including AEC firms) since 1990. Head office: 1-2 Vata Court, Aurora, ON. Phone: +1 (416) 361-1441.

Popular Reads You Don’t Want to Miss

Blog Cover Image: Cyber Resilience Is Now a Business Requirement for Ontario Manufacturers & Builders

March 29, 2026

Cyber resilience is no longer optional for Ontario manufacturers and builders. Learn how downtime, cyber risk, and outdated IT can quietly threaten your operations—and what smart business leaders are doing in 2026 to stay secure, compliant, and competitive. [Read more]

Blog Cover Image: Inside Look: How Hackers Use AI To Attack Your Business

January 17, 2025

If you think hackers are only targeting Fortune 500 companies, think again. Thanks to artificial intelligence, cybercriminals now have the power to scale their attacks like never before - and small business owners are at the top of their hit list. Here’s how hackers are weaponizing AI... [Read more]

LOCATIONS

Canada

1-2 Vata Court, Aurora, ON

United States

39288 Calle Tonala, Indio, CA

Copyright 2026. Cairitech. All rights reserved.