In early 2024, a finance employee at Arup’s Hong Kong office joined what appeared to be a routine video call with the company’s CFO and several colleagues. Everyone on the call looked and sounded right. He was asked to authorise a transfer of $25 million. He did. Every person on that call was a deepfake — AI-generated video and voice used to simulate real people in real time.

That incident made headlines, but the technology behind it has since become cheaper, faster and far more accessible. Deepfake attempts targeting UK businesses rose 94 percent in 2026. This is no longer a risk reserved for large organisations with CFOs and international wire transfers. It is arriving in SME inboxes and phone calls right now.

The three attack types you need to know

Voice cloning via phone call. An attacker obtains a short audio clip of your managing director — from a LinkedIn video, a podcast appearance, or a company YouTube video — and uses it to generate a convincing voice clone. They call a member of your finance team, impersonating the MD, and request an urgent bank transfer or a change to supplier payment details. The voice sounds right. The request sounds plausible. The pressure is deliberate.

Fake invoice with changed account details. This variant does not even require sophisticated technology. An attacker monitors email traffic — sometimes by compromising an email account, sometimes by spoofing an address — and intercepts a legitimate invoice exchange. They alter the destination bank account and re-send the invoice, often with a brief accompanying message claiming the supplier has updated their banking details. This is one of the most common forms of business fraud in the UK, affecting 11 percent of businesses with employees.

AI-enhanced phishing at scale. Where older phishing emails were often identifiable by odd phrasing and generic greetings, AI-generated phishing now reads like a genuine communication from a known contact. It can reference real projects, use your company’s name correctly, and apply pressure in ways that match how your business actually operates. Without verification processes, these are genuinely hard to catch.

What makes these attacks hard to spot

The defining feature of AI-enhanced fraud is that the traditional signals no longer work. You cannot rely on the voice sounding slightly wrong. You cannot rely on the email having spelling errors. You cannot rely on the payment request coming from an unfamiliar source, because the source is convincingly familiar.

This is why process matters more than instinct. Your team’s ability to spot a deepfake by eye or ear is not the right defence. The right defence is a procedure that makes a convincing impersonation useless.

The defences that actually work

Pre-shared challenge codes. Establish a rotating verbal code — changed quarterly — that must be used on any call requesting a payment change or transfer. If the caller does not know the code, the request is not acted on. Simple, low-cost, effective.

Callback verification. Any change to supplier bank details, any urgent payment request, any instruction that arrives by email or message should be verified by calling the requesting party back on a number already held in your systems — not a number provided in the suspicious communication.

No single-call authorisation. Make it policy that no payment above a certain threshold is authorised based on a single phone call or video call, regardless of who appears to be on it.

Monitor your email. Business email compromise often starts with an account that was quietly compromised weeks before it was used. KeepSafe monitors for the early indicators of credential exposure and account compromise — catching the breach before the fraudulent request arrives.

For businesses unsure where to start, Smallprint offers legal document templates that include fraud prevention policies and payment authorisation procedures — ready-made frameworks that give your team clear rules to follow without the legal cost of writing them from scratch.

The bottom line

AI has made impersonation cheap and convincing. The solution is not better pattern recognition from your staff — it is better procedures that make impersonation irrelevant. A rule that all payment changes require callback verification on a known number is not expensive to implement. The alternative is considerably more so.