We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

"CEO Fraud" Using Voice Deepfakes: How to Avoid It

CEO fraud is now being carried out using voice cloning for just a few euros. For an SME, the best defense is a simple verification rule—with no exceptions.

"CEO Fraud" Using Voice Deepfakes: How to Avoid It

In summary: AI-powered voice cloning has become inexpensive, bringing “CEO fraud” back into the spotlight and putting small and medium-sized businesses in the crosshairs. The good news: a properly implemented verification process can mitigate most of the risk without requiring a significant investment.

What Happened

The threat is no longer just theoretical. On April 27, 2026, the Banque de France and the ACPR issued a warning about fake videos impersonating their own executives—including Governor François Villeroy de Galhau—to promote fraudulent investments. The authorities’ message is clear: no official at the Banque de France recommends financial products.

What has changed is the cost. A voice cloning subscription now costs between 5 and 50 euros per month, and spoofing a phone number costs just a few cents through VoIP services. An SME with 20 to 100 employees has therefore become a profitable target, just like a large corporation. According to a Yousign report published in 2026, a deepfake fraud attempt occurs every five minutes in France. A Regula study, cited by the DGSI in its January 2026 report on economic interference, indicates that 49% of companies worldwide say they have already been the target of a fraud attempt involving an audio or video deepfake.

The most widely discussed case remains that of an employee who was tricked during a completely rigged videoconference: with his executives’ faces and voices cloned, he authorized wire transfers totaling the equivalent of several tens of millions of euros. The case involved a large company, but the same mechanism works on every scale.

Does this apply to me?

The issue isn't the size of your company, but your payment process. Any company that pays invoices via wire transfer can be targeted. The vulnerable link is the person who can initiate a payment: accounting, finance, or executive support.

There are a few red flags that almost always crop up. A sense of urgency (“This has to go out today”). A request for confidentiality (“Don’t tell anyone about this just yet”). A last-minute change to the IBAN. An unusual communication channel, such as a phone call or video call when your manager usually communicates via email. A contact who puts pressure on you and cuts you off when you ask questions.

To see where you stand, test your own process. Ask an employee what they would do if, at 5 p.m. on a Friday, they received a call from the “executive” requesting an urgent and discreet wire transfer. Their answer will tell you whether your procedure holds up, or whether it relies on trust in a voice on the phone.

What to Do Now

1. Require independent double verification. No sensitive transfer is authorized without validation through a second channel specified in advance: a callback to the requester’s registered internal number, or dual signatures. This rule deprives the attack of its main weapon: voice cloning.

2. Implement a process for verifying changes to bank account information. Establish a formal written procedure: any new IBAN or change to a supplier’s account information must be verified by contacting a known representative directly—never based solely on the information provided in the message.

3. Train your teams and set up your Microsoft environment. A short awareness session and an internal “verbal password” are enough to instill the right habits. On the technical side, enable multi-factor authentication on Microsoft 365, monitor automatic email forwarding rules, and keep an eye out for unusual logins. These basic measures also help limit email spoofing, which often accompanies these scams. To learn more about targeted attacks, see our guide on spear-phishing: understanding, detecting, and protecting against it.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

The threat is real, but the solution is inexpensive. A double-checking policy and a shared sense of vigilance can thwart most attempts, even when the voice sounds perfectly credible. Well-prepared teams remain your best defense—far more so than any tool.

Frequently asked questions

Can you tell if a voice has been cloned over the phone? It’s getting harder and harder to tell just by listening. It’s best not to rely on the voice alone and to call the person back using a number you know before taking any action.

Do deepfakes target only large corporations? No. Falling costs make small and medium-sized businesses profitable targets, often because their payment procedures are less secure.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

The Services and Payment Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.
September 25, 2026
AI and Cybersecurity Illustration
Cybersecurity

AI and Cybersecurity: The 3 Key Challenges for SMEs and Mid-Sized Companies

AI and Cybersecurity: Securing Your Use of AI, Using It to Defend Yourself, and Countering AI-Powered Attacks. A Guide for Small and Medium-Sized Businesses.
September 25, 2026
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Abstract illustration of cybersecurity
Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026