The chief financial officer appears on screen. His voice is familiar, his tone urgent, his request seemingly legitimate: settle a confidential transaction before the banks close. Yet a fraudster may be behind this meeting. With synthetic voices and manipulated videos, seeing and hearing no longer prove identity. Looking ahead to September 2026, the challenge is less about spotting every fake than preventing a convincing impersonation from triggering a payment. Documented cases, particularly from 2024, shed light on this threat; the developments considered here for 2026 are forward-looking analysis.
An old scam with new persuasive power
CEO fraud predates artificial intelligence. Its script relies on three levers: authority, urgency and secrecy. A supposed executive requests an exceptional transfer, often for an acquisition or a sensitive transaction. The employee is asked to step outside the usual process precisely because the situation is said to be unusual.
Generative AI strengthens this mechanism. Public appearances, corporate videos or audio messages can provide usable material for impersonating someone. Quality depends on the tools and recordings available, but the fraudster does not necessarily need a perfect copy: a brief exchange, poor audio and a victim under pressure may be enough.
The case disclosed in Hong Kong in February 2024 left a lasting impression. According to police, an employee had made transfers totaling approximately US$25 million after a video conference in which several participants were digital imitations of colleagues. Engineering group Arup confirmed in May that it was the company involved. This case demonstrates what is possible in practice, not how common such fraud is.
The trap is set before the call
The cloned voice is often just the final stage of the attack. Beforehand, fraudsters may study the organizational chart, spot an executive’s travel plans, identify people authorized to make payments or exploit a compromised email account. A genuine invoice, a supplier’s name and an accurate deadline then make the request credible.
The problem should therefore not be reduced to deepfake detection alone. A fake executive can secure a payment without sophisticated video if the message arrives in a hijacked, genuine conversation. Conversely, a highly convincing impersonation can fail when faced with a procedure that prohibits any change of payee based solely on verbal instructions.
Looking ahead to September 2026, the most concerning potential scenario would combine these techniques: automated reconnaissance, personalized messages and an audio or video intervention just as an employee hesitates. This does not mean every suspicious call will be run by autonomous AI. The risk lies primarily in the growing ease with which fraudsters could put these components together.
The essential rule: step outside the prescribed channel
The first response should be to pause the request and reestablish contact through a known channel. The number provided in a suspicious message must never be used to verify that same message. Call the executive back using the internal directory, or the supplier using the number already stored in the supplier database, not the one shown on a new invoice.
This independent check must cover the transaction itself: amount, payee, purpose and bank details. Simply asking “is that really you?” offers little protection if the person then confirms a misunderstood request. For sensitive transactions, confirmation must be recorded in an internal tool, with a usable audit trail.
Using multiple channels is not enough if they all depend on the same compromised account. An email and a workplace chat accessible with the same credentials do not always constitute two independent pieces of evidence. The procedure must provide a separate, trusted channel and, if the person responsible remains unreachable, a clear rule: the payment waits or goes through a designated alternate.
Transfers protected by multiple safeguards
An effective system looks less like a magic detector than a series of checks. Each should reduce the possibility of a single person, swayed by a voice or a face, committing company funds.
- Separate payee setup from payment. The person who adds a payee must not be able to authorize the first payment to that payee alone.
- Verify changes to bank details. Any new IBAN must trigger confirmation with an established contact, even if the invoice and signature appear authentic.
- Require genuine dual approval. The second approver checks the supporting documents and the verification performed; they do not merely click a button.
- Set rules for exceptions. Limits, a security waiting period and an emergency approval process must be defined in advance, with no improvised exemptions granted over the phone.
These controls are more effective when integrated into accounting software and banking tools. An instruction in a document is easy to bypass; a technical block forces the exception to be addressed. Thresholds must, however, reflect operational needs: too many unnecessary approvals encourage rubber-stamping and workarounds.
Why the human eye is not enough
Lip-sync discrepancies, odd intonation, unstable facial outlines: these clues can raise suspicions. They do not constitute a reliable authentication method. Video compression and poor connections also produce anomalies with genuine callers. Conversely, a fake can look perfectly natural during a brief sequence.
Detection tools can help security teams examine content, but their performance varies depending on the manipulation and recording conditions. They may miss fraud or wrongly flag a legitimate communication. Their findings should inform an investigation, not become an automatic green light for a transfer.
A shared verbal password is no lasting guarantee either: it can be disclosed, recorded or elicited through deception. For sensitive approvals, transaction-specific authorization in a controlled system is preferable. Strong authentication protects access to that system without replacing checks on the payee.
Giving employees the right to slow down
The decisive vulnerability often remains hierarchical. Refusing a request apparently made by one’s boss requires explicit support from management. Management must make clear that no urgency, secrecy or video conference exempts anyone from checks. An employee who suspends a suspicious payment should be supported, not penalized for failing to act quickly.
Internal exercises should therefore test procedures rather than catch people out: whom to call back, where to report concerns, how to block a payment? If a fraudulent transfer goes through despite these measures, the bank must be contacted immediately to try to stop it or recall the funds, security teams must be alerted, and messages and logs must be preserved. Recovery is never guaranteed.
What now? Looking ahead to September 2026, the prudent assumption is that impersonation will become more accessible, not that detection will become infallible. The best-prepared organizations will be those that have made their payments independent of a caller’s persuasive power. The right question will no longer be “is that really my director on screen?” but “has this transaction been authorized through a process that can withstand someone impersonating my director?”.


