A familiar voice over the phone is no longer a payment control
Published October 8, 2026·4 min read
Paolo Molesini did what most finance leaders would do. A WhatsApp message appeared to come from his chief executive, asking for urgent funds. A call followed from someone who sounded like a senior partner at a prominent law firm. The chairman authorised a €95 million transfer.
BigGo Finance reported on 29 September that the lawyer's voice had been cloned, and that €36 million of the sum remains unrecovered after being converted into cryptocurrency. The chairman resigned the following month. The story is being read as evidence that synthetic voice has become too convincing. That is true, but it stops short of the useful lesson.
The more important fact is that the verification step was a phone call. A chairman heard a familiar-sounding senior lawyer and treated that as confirmation. The channel itself — the sound of a known voice over the phone — can now be produced on demand. When a control depends on something an attacker can synthesise, it is no longer a control.
The control that failed was a voice call
The Fideuram process did not fail because one executive was gullible. It failed because a single, recognisable voice satisfied the approval condition for an irreversible transfer. Gartner's survey of 297 CISOs found that 41% had experienced at least one deepfake attack on employee voice calls in the past year, and 36% had seen similar attempts through video calls. Gartner's guidance was direct: high-impact requests should be re-verified through a separate, trusted process.
The attack worked across several channels. A message provided the instruction, a voice call dissolved the doubt, and the payment instruction followed. The layering is the new part. Attackers no longer need the first message to be believed; they only need it to survive long enough for a familiar voice to close the matter. Each layer looks weak on its own, but together they created enough confidence for a chairman to direct his finance department to move the money.
Put the second channel in place before the request arrives
Most payment approval policies assume that ringing the requester back is out-of-band. It is only out-of-band if the channel and the contact details were established before the instruction arrived. A call to the number in the WhatsApp message fails the test. So does a call to a number taken from an email signature. If the attacker controls the first message, they can supply the confirmation number as well.
The replacement is less technical than many security projects. Set a threshold above which a payment cannot move on one person's approval, no matter who it appears to come from. Above that threshold, a second person confirms the request through a pre-registered channel — a token, a separate meeting, or a number stored outside the payment tool — using information the requester did not include. If the second check fails, the payment waits. The rule should be written so that no single voice call can satisfy it.
This matters most in organisations where the finance team is small. In a team of three or four, the person who receives the request is often the person who enters the payment and the person who calls to check. The control has to survive an accounts payable desk where the bank portal and the invoice queue sit side by side. That is the environment the fraudsters are counting on.
The test is simple enough to run this month. Show the person who would receive such a request a realistic instruction and ask what they would check. If their answer includes I'd ring him back, you have found the gap. If they point to a pre-agreed second channel, the process is ahead of the attack.
What training can and cannot do
None of this makes awareness training irrelevant. It moves it to the job it can actually do. Training is the filter for first-contact phishing, for requests that arrive in a shared mailbox, and for the moment when someone hesitates but is told the matter is urgent. A managed awareness programme that runs simulations by role and gives people a one-click way to report suspicious mail keeps low-value attempts from becoming conversations. It also tells the finance team that pausing is the expected response when a transfer instruction arrives in a form they have not seen before.
It cannot be the approval control for a transfer instruction, because by the time the voice call happens the training moment has passed. The attacker is no longer relying on a human misreading a malformed message. The call is meant to reassure the person who is already inclined to trust the name. The moments that matter are the plausible requests with a familiar name attached.
Start from the amount you cannot afford to lose
Pick the payment amount your organisation cannot afford to lose, and ask whether a single phone call can move it. If the answer is yes, the policy is already behind the attack. Map the approval path for one payment above that amount, and write in the two channels that are allowed to confirm it. Then book a short session to walk through where the breaks are before the next request arrives.
- deepfake fraud
- payment approval
- out-of-band verification
- synthetic voice
- cyber awareness
- finance controls