Deepfakes in bank transfers: protection against voice cloning
Learn how voice cloning fraud plays out in the Mittelstand and how you can protect your payment approval process against deepfakes with clear security rules.

Danger in the Mittelstand: how voice cloning is transforming classic CEO fraud
Classic CEO fraud, in which fraudsters pose as senior executives in order to obtain transfers, is undergoing a dangerous evolution driven by artificial intelligence. In the past, attackers mainly forged emails, but today they use deceptively realistic voice imitations in real time. According to the Wirtschaftsschutz study 2025 by the industry association Bitkom, the total damage to the German economy from data theft, espionage and sabotage amounts to 289.2 billion euros, of which 202.4 billion euros stem from cyber attacks. In the previous year's report, the total figure was 266.6 billion euros[1]. However, these sums are not a measure of payment fraud: Bitkom puts the direct outflow of money from fraud attempts at 0.9 billion euros. As a managing director, you have to take this threat seriously in order to protect your company from substantial financial losses.
The technological evolution of deepfakes
Behind this development lies a technological leap. While attackers needed hours of audio material a few years ago to laboriously rebuild a voice, today just a few seconds of speech are enough. Criminals extract these snippets effortlessly from YouTube videos, podcasts or LinkedIn posts by your executives. Using voice cloning, they generate deceptively realistic calls that even familiar ears cannot identify as fakes over the phone. They exploit the high audio quality and psychological manipulation to put your accounting staff under extreme time pressure. The best known case hit the engineering services firm Arup in Hong Kong in January 2024: after a video conference with a deepfaked CFO, employees transferred around 25 million US dollars.
- Automated reconnaissance: criminals use AI tools to map organisational charts and responsibilities in your company within seconds.
- Sinking entry barriers: creating AI voices no longer requires technical expertise and often costs only minimal amounts.
- Targeted pressure: the calls usually come shortly before the weekend, when attention drops and supposedly quick decisions are demanded.
The German Mittelstand is the perfect target for this scheme because of flat hierarchies and often inadequately documented verification chains. Conventional IT security measures are often not enough to protect your company effectively. This is where CAVRIX comes in with holistic cybersecurity: we help you establish reliable approval processes and proactively secure your infrastructure against modern AI threats.
The psychology of fraud: why voice imitations are so successful
Successful voice cloning attacks rarely rely on technology alone. Above all, they rely on psychological manipulation, also known as social engineering. Criminals use artificially generated voices to build up extreme emotional pressure. When the supposed managing director calls and demands the immediate approval of an urgent transfer in an insistent tone, accounting staff come under stress. In such moments, the rational control mode is blocked. The worry of disappointing the boss or jeopardising an important deal pushes aside healthy scepticism.
This phenomenon is based on a deeply rooted belief in authority within the German Mittelstand. Fraudsters deliberately exploit established hierarchies in order to bypass formal approval processes. Research on voice cloning shows that fraud attempts using cloned voices have long been occurring in German-speaking countries and that freely available tools reproduce voices very closely to the original[2]. Reliable figures on the success rate of such voice clones, on the other hand, do not exist. In the stress of daily work, it is virtually impossible for employees to tell the difference between the real superior and the perfect clone by ear alone.
What is particularly insidious is the coordinated interplay of different channels. In most cases, the deceptively realistic call is preceded by a forged email that backs up the process in writing, for example a supposed invoice from a trustworthy supplier. The phone call then serves as the final lever to demand immediate payment. Awareness alone is not enough to protect you against such incidents. It takes a combination of clear verification processes and robust technology. With a comprehensive cybersecurity strategy from CAVRIX, you systematically secure your communication channels and establish verification chains that withstand such manipulation.
- Creating artificial stress: the attackers demand immediate action in order to deny victims the time to think or to ask questions.
- Exploiting hierarchies: the authority of the impersonated superior psychologically overrides established security policies in the company.
- Two-channel tactics: the combination of a forged email and the subsequent voice clone call creates seemingly seamless credibility.
- Acoustic perfection: modern algorithms produce voice imitations that are barely distinguishable from the original in pitch, breathing and emphasis.
Facts and figures: the growing losses caused by forged approvals
Social engineering attacks on the German Mittelstand are no longer a rarity. Criminals use ever more sophisticated methods to obtain financial approvals. According to the Wirtschaftsschutz study 2025 by the digital association Bitkom, the total damage to the German economy from theft, espionage and sabotage amounts to 289.2 billion euros, compared with 266.6 billion euros in the previous year's report[3]. Anyone deriving fraud losses from this is mistaken: the outflow of money from fraud attempts accounts for 0.9 billion euros of that total. On the subject of deepfakes, Bitkom reports that 4 percent of companies have already suffered damage from deepfakes and that 66 percent have the impression that attackers are increasingly using AI. With the emergence of new technologies, the threat is shifting more and more towards highly precise deepfakes and voice cloning that can deceive even attentive employees.
- Rise in CEO fraud case numbers of 31 percent in 2023: the loss statistics from Allianz Trade showed a clear increase at the time, and since 2024 the case numbers have been declining slightly again.
- Significantly higher losses per case: in the same statistics, the loss amounts tripled in 2024 and rose by a further 81 percent in 2025. The average loss is in the single-digit millions, while major losses reach the clearly double-digit millions.
- The trend towards more targeted deepfake attacks: instead of broad phishing waves, attackers increasingly rely on tailor-made, AI-generated voice imitations that are precisely matched to the decision makers in your company.
The consequences for affected SMEs go far beyond the direct financial loss. In addition to immediate liquidity shortages, your business faces considerable reputational damage if sensitive financial data or fraudulent transactions become public. Regulatory requirements such as the NIS2 Directive also increase the pressure on the management level: in the case of inadequate security and approval processes, there is a risk of personal liability for the management in the event of serious cyber incidents. It is therefore essential for you to establish preventive verification chains.
Effective protection requires a combination of organisational approval processes and technical safeguards. By implementing CAVRIX Cybersecurity, your company gains not only proactive security management but also the support it needs to make your defences resilient against highly developed social engineering attacks.
The weak points in the workflow: why purely digital processes often fail
Classic ERP systems and digital approvals suggest a high level of security. Yet when criminals deliberately manipulate the human approval chain, these workflows reveal critical gaps. One main problem is the pitfall of unsecured approval emails. If an attacker slips in a forged payment instruction by email that appears to come from the managing director, a single click is often all it takes to cause a disaster. Generative AI dramatically increases this danger: according to the Bundesamt für Sicherheit in der Informationstechnik (BSI, the German Federal Office for Information Security) in its 2024 status report, AI-supported attacks are increasing massively and easily bypass purely digital filters. Criminals deliberately exploit media discontinuities to create confusion.
Communication gaps in the home office become particularly apparent in decentralised working. The quick, informal word in the corridor is no longer possible. It is often replaced by picking up the phone. This is exactly where fraudsters strike with modern voice cloning. They fake the voice of a familiar executive within seconds to feign urgency for a pressing foreign transfer. If the multiple eyes principle is poorly applied in daily work, the control process fails. Instead of obtaining a formal second approval through a secure, independent channel, employees trust the deceptively realistic voice of the supposed superior on the phone.
- Missing out-of-band verification: payments are confirmed via the same digital channels (for example email) through which the order arrived.
- Insufficient employee awareness: trust in supposedly familiar voices on the phone overrides existing approval policies.
- Inadequate technical safeguards: there is a lack of automated controls that immediately block suspicious behavioural patterns or unauthorised changes to account data in the ERP system.
As a managing director in the Mittelstand, you need to be able to rely on seamless processes. CAVRIX supports you with tailor-made solutions. Through our services in the field of cybersecurity, we establish proactive monitoring and raise your teams' awareness with continuous security training. Combined with clearly defined verification chains, we close the security gap between people and machines before damage occurs.
Effective verification chains: how your approval processes hold up
When the voice of your managing director on the phone pushes for the quick approval of a special payment, only a cool head helps. According to the current status report on IT security in Germany published by the Bundesamt für Sicherheit in der Informationstechnik (BSI, the German Federal Office for Information Security) in 2024, AI-generated deepfakes and highly developed vishing represent a strongly growing threat to the Mittelstand. A careless click endangers more than just your budget. What is legally relevant above all is Paragraf 30 Absatz 2 Nummer 10 BSIG, which requires affected entities to use secured voice, video and text communication. There is, however, no statutory obligation to deploy anti-fraud software. In addition, the labelling obligation for deepfakes under Article 50 paragraph 4 of the EU AI Regulation applies from 2 August 2026. To protect yourself from devastating losses caused by voice cloning, you have to redefine the organisational basis of trust from the ground up. The solution lies in a seamless verification chain.
Three indispensable rules for your approval processes
- Mandatory call-back procedures (out-of-band verification): for every special approval given by phone, you must make a call-back via an established communication channel that is independent of the caller, such as a known internal landline number.
- Confidential code words: for unforeseen ad hoc approvals, establish a secret code word agreed offline that is never exchanged digitally or by email.
- Immutable amount limits: define strict limits up to which telephone instructions are permitted at all. Any payment above that requires, without exception, the four eyes principle (dual control) in written form.
Such organisational rules only take effect, however, if your entire workforce is aware of them and the technical infrastructure is right. CAVRIX supports your mid-sized business within the scope of cybersecurity with continuous security training and the Managed IT service to make your team resilient against modern social engineering attacks. Via the integrated Command Center, you retain full control over your security posture and NIS2 compliance at all times.
Prevention through education: awareness training for finance teams
Technological safeguards form the foundation of your corporate network. But when an attacker simulates a deceptively realistic voice, the human factor decides whether the fraud attempt succeeds or fails. According to the Bundesamt für Sicherheit in der Informationstechnik (BSI, the German Federal Office for Information Security), attackers today often need just a few seconds of audio material from the victim to create a convincing copy of the voice. Regular, practice-oriented awareness training for your finance teams is therefore the most important line of defence for detecting and repelling such attacks early under real stress conditions. The aim is to establish healthy scepticism towards unusual payment requests.
- Simulated deepfake calls: realistic exercises confront your employees with deceptively realistic, artificially generated voices on the phone in order to train the ear for atypical speech patterns and reduce the moment of shock in an emergency.
- Establishing clear escalation protocols: every team member must know exactly who is to be informed immediately in a suspected case, without having to fear mistakes or delays in the usual course of business.
- Promoting an open security culture: a modern corporate culture in which questions and verifications are expressly welcome deprives social engineering of its breeding ground of time pressure and misplaced deference to authority.
This is where CAVRIX comes in with holistic training concepts for the German Mittelstand. Through the cybersecurity service offering, we provide your business not only with proactive threat detection around the clock but also with targeted training for departments at risk. Should a suspicious call or an unusual email come in, your IT managers can view, verify and coordinate critical security alerts in real time directly via the Command Center. Through this close interlocking of technological protection and trained employees, you make your payment approval processes permanently resilient against highly developed cyber threats.
Infrastructure protection with CAVRIX: your safeguard for payment traffic
As a specialist for cybersecurity, CAVRIX helps mid-sized companies harden their defence systems in a targeted way. Attacks using voice cloning and deepfakes confront managing directors in the German Mittelstand with new challenges that can threaten their very existence. According to the loss statistics of the credit insurer Allianz Trade, losses from CEO fraud rose by 200 percent in 2024 and by a further 81 percent in 2025, with major losses running into the clearly double-digit millions. Conventional protective measures are no longer sufficient to counter these highly manipulative attack scenarios successfully. You have to secure your entire digital infrastructure proactively and without gaps.
For this purpose, CAVRIX offers holistic security concepts tailored specifically to the requirements of SMEs with fewer than 500 employees. Through the seamless interplay of modern IT security solutions, we ensure that your communication channels remain resilient and that manipulation in payment traffic is detected early. We help you build technical barriers against artificially generated voices and documents.
- 24/7 monitoring: continuous monitoring via our Command Center reports unusual network activity as well as anomalies on your communication channels in real time in order to stop suspicious access immediately.
- Holistic communication protection: by protecting your email and messaging infrastructure, spoofing attempts are intercepted before harmful messages or manipulated instructions reach your employees.
- Digital verification processes: we support you in implementing verification processes for documents, images and emails so that incoming payment approvals and invoices can be checked for authenticity before execution.
To operate in a NIS2-compliant way and minimise the risk of personal liability for the management, structured protection in payment traffic is essential. CAVRIX combines Managed IT, cybersecurity and compliance in a single, seamless platform. Via our Command Center, you retain full control over your IT security status at all times. If you want to secure your approval processes and communication channels for the long term, contact us directly at info@cavrix.de for a free initial consultation.
Frequently asked questions
What exactly does voice cloning mean in the context of payment approvals?
Voice cloning means artificially replicating a human voice with the help of generative AI. Criminals use this technology in CEO fraud schemes to pose as the managing director or CFO on the phone and get accountants to approve large payments.
How much source material does an AI need to clone a voice?
Modern AI tools today often need only a few seconds of audio material from a person to create a deceptively realistic copy of the voice. Attackers usually obtain this material from public videos, podcasts or social media posts.
Why do classic approval processes fail in the face of deepfake calls?
Classic processes fail because they are based on trust in the human voice. When the supposed boss calls under artificially created time pressure, employees tend to bypass digital hurdles or the multiple eyes principle out of respect for hierarchies.
Which simple immediate measures protect against voice cloning fraud?
Introduce mandatory out-of-band verification: always call the requesting person back on a known number held internally. Secret code words for unforeseen special payments also provide an effective barrier.
What role does cybersecurity from CAVRIX play in protecting against social engineering?
The CAVRIX cybersecurity portfolio protects the IT infrastructure of your SME proactively. Through monitoring in the Command Center, suspicious patterns in email communication are detected and blocked early, before an attacker can initiate the phone call for the payment approval.
Are mid-sized companies particularly at risk from deepfake fraud?
Yes, because the Mittelstand often has more direct communication routes and flatter hierarchies than large corporations. Criminals exploit this to force quick payments with targeted calls. According to Allianz Trade, the number of such CEO fraud cases rose by 31 percent in 2023. Case numbers have declined slightly since then, while the losses per case are rising significantly.