Sarah, an accounts payable specialist at a mid-sized manufacturing firm, receives an unexpected phone call. The voice on the line is unmistakably her CFO's - she has spoken with him dozens of times. He explains he is at an airport in Singapore, his laptop is dead, and he urgently needs her to wire $200,000 to a new supplier account within the hour or a major contract will fall through. He asks her not to email because he cannot access his phone's email app.
A finance employee receives a voice call from what sounds exactly like her CFO, urgently requesting a $200,000 wire transfer to a new vendor. The CFO is known to be traveling internationally. What verification procedure should the employee use before acting?
- A.B. Hang up and call the CFO back on a known, pre-established phone number, or verify through an out-of-band channel such as a pre-agreed code word
- B.A. Ask the caller to spell their name - a deepfake voice cannot spell
- C.C. Check if the caller ID matches the CFO's corporate number
- D.D. Request the wire transfer via email instead, since deepfakes only work over voice
Why A is correct
The correct defense against voice-clone fraud is an out-of-band verification: hang up and call back on a trusted, pre-registered number (not one provided by the caller), or use a pre-arranged verification code word for unusual financial requests. Caller ID is easily spoofed. Deepfakes can generate any spoken content including correct spellings. Deepfakes also exist for text/email; switching channels doesn't eliminate the risk.
Know someone studying for AI Security Fundamentals? Send them this one.