VERICODE vericode.com.au

The CEO on the phone is not identity proof any more

Vericode · 22 August 2025


The voice on the phone used to be the proof. You knew your boss’s voice, your mum’s voice, the tone your CFO used when something had gone wrong. That was the verification layer sitting underneath every “transfer this by close of play” instruction. Three years of cheap public AI voice models later, the proof is gone. The instruction sounds right, the voice sounds right, and the money still leaves.

The reported losses are big enough now that this isn’t an edge case any more. Deepfake CEO scams have been tied to more than US$200 million in global business email compromise losses in the first quarter of the year. Keep the qualifier on that number. It’s global, not Australian, and it’s business email compromise, not every voice scam. But the direction is hard to miss.

Business email compromise has grown up and learned to talk.

The old defence ran on friction. A dodgy payment request might come from an email address that looked wrong, a style that felt off, or a supplier story with too many moving parts. Staff could slow down because something in the channel felt false. Voice cloning takes away one of the easiest reasons to slow down. The person on the other end sounds like the person with the authority.

Australia is already showing the same pattern. Large retailers have warned about AI worker-impersonation videos. ASIC has been calling out fake celebrity finance endorsements and running takedowns. CommBank has launched new scam-checking tools. NAB is pushing biometric onboarding. ACMA has named mobile-number fraud as a compliance priority.

All of that helps. None of it answers the question sitting in the middle of the phone call.

Bank-side controls can see payment behaviour, known scams and account signals. They can slow the money, warn the customer, compare devices, payees and transaction patterns. But when an employee picks up a call that sounds like the CEO and the caller says it’s urgent, the bank hasn’t yet seen the moment that matters. The persuasion has already started.

It’s the same inside smaller businesses. A finance manager doesn’t have to be careless to feel the pressure, and a founder doesn’t have to be reckless to believe a familiar voice in the middle of a noisy week. The attack is built to arrive wearing context.

That’s why “deepfake scam” can be a misleading phrase. The fake isn’t the whole scam. It’s the last layer on top of a pretext that might already have the names, the invoices, the roles, the payment timings and the internal language. The voice is just the part that makes the assembled story feel human.

Awareness training has a role, but it can’t carry the full weight. You can’t ask a staff member to run a forensic audio test in the middle of a pressured call. “Does it sound like them?” used to be a reasonable question. Now it’s one of the weaker checks in the room.

The next phase of fraud prevention has to pull recognition apart from verification. Recognition is your gut saying the voice is familiar. Verification is a controlled way to prove the person behind the voice is actually allowed to make the request. The two used to blur together, and AI has made that blur dangerous.

None of this means every call is now suspect. It means the risky ones need a stronger step than tone, memory and confidence. A payment instruction, an account change, a password recovery, an executive escalation.. those shouldn’t rest on a voice alone.

Voice is no longer evidence of identity. We just haven’t said it out loud often enough.