← SecureAZ Blog

Phishing · 8 min read · Published 7 May 2026 · Reviewed 17 August 2026

Deepfake CEO Fraud: How NZ Businesses Are Losing Six Figures

AI-generated voice and video impersonation of executives is now driving wire fraud against NZ SMEs. Here is how the scam runs, what makes it work, and how to train staff to spot it.

Deepfake CEO fraud is the next-generation business email compromise. Where the old version relied on a spoofed email asking the finance team to wire urgent funds, the current version adds a video call or voice message from the "CEO" that pushes the request through. CERT NZ and the FBI's IC3 have both flagged sharp increases in AI-driven impersonation losses across 2025 and into 2026, and NZ businesses are now turning up in the case files.

This post walks through how a deepfake CEO fraud actually unfolds, what makes it land, and the specific controls that stop it before money moves.

---

How the Scam Runs

The pattern is consistent enough that it can be described as a playbook:

  1. Reconnaissance. The attacker scrapes the CEO's voice from podcast appearances, conference recordings, LinkedIn videos, or earnings calls. A two-minute sample is enough for a credible voice clone. Video samples build a face model.
  2. Pretext. An email or text arrives at the finance team or assistant from a lookalike domain or a compromised supplier address. It mentions a confidential acquisition, regulatory matter, or urgent supplier issue.
  3. Voice or video. The follow-up is a phone call, voicemail, or short video message. The voice and image match the CEO closely enough to remove doubt under time pressure.
  4. Payment instruction. New banking details are provided, often offshore, with explicit instructions to bypass the normal approval process due to confidentiality.
  5. Money moves. By the time the real CEO is reached, funds have been transferred and routed through several accounts.

The scams that succeed share two features. They invoke confidentiality so that the staff member feels constrained from verifying. And they invoke urgency so that the verification window closes before the call is made.

Why It Works in 2026

Three things have changed in the past 18 months:

  • Voice cloning quality is now indistinguishable from the original at phone-call audio fidelity. The FBI has issued specific warnings on this.
  • Video deepfakes can be generated in near real-time on consumer hardware, making live calls plausible.
  • Public exposure of executive voices has multiplied — every podcast, every webinar, every keynote is training data for the attacker.

The defensive question is not whether the impersonation is convincing. It is convincing. The question is whether the process catches it regardless.

Process Controls That Hold Up

Technical detection of deepfakes is improving but still unreliable in real time. The controls that work are procedural:

  • Out-of-band verification. Any payment instruction arriving by email, voice, or video is verified by a callback to the executive on a known number. Not the number on the inbound message. Not a number provided in the email.
  • Two-person authorisation for new beneficiaries. Adding a new payee requires two named approvers, with both verifying through independent channels.
  • Cooling-off period for first-time payments to new beneficiaries. First payment to any new account waits 24 hours after the beneficiary is added, with confirmation from the requesting party in that window.
  • Confidentiality is never a reason to bypass. The policy must explicitly state that confidentiality requests do not override verification. Staff need permission to call the CEO directly when something feels off.
  • Documented payment authority matrix. Who can authorise what, up to what limit, by what method.

These are mundane controls. They are also the controls that have stopped six-figure transfers in real cases.

Training That Reinforces the Controls

A one-off cyber awareness module does not change behaviour for this scam. The training pattern that works:

  • Specific scenario walk-throughs using deepfake examples — short clips of cloned voices and synthetic video
  • Practice runs where staff receive simulated urgent payment instructions and are scored on whether they followed the verification process
  • Manager-led discussions after each simulation, focused on the moment where verification was skipped or completed
  • Refresher every six months with updated examples, since the attack technology moves quickly

The same training discipline that catches simpler attacks — covered in phishing training for employees — extends to deepfake scenarios. The difference is that the social engineering pressure is higher and the cues are subtler.

Technical Controls Worth Adding

While process is the primary defence, several technical controls reduce the attack surface:

  • DMARC, SPF, and DKIM enforcement on the company's own email domain to make spoofing harder
  • External email banner so staff can see when a message is from outside the organisation
  • Restricted use of executive voice and image in public marketing where alternatives exist
  • Banking platform controls — beneficiary verification, payment limits, dual approval at the bank level
  • Monitoring for newly registered lookalike domains that resemble the company or its suppliers

Reporting and Response

If a fraudulent payment goes out, the response window matters:

  1. Notify the bank immediately to attempt recall of funds in transit
  2. Report to NZ Police and CERT NZ within 24 hours
  3. Notify the company's cyber insurer — most policies require notification within 48 to 72 hours
  4. Preserve emails, voice messages, video, and call records as evidence
  5. Engage incident response support if the company holds a retainer

Recovery rates are highest when the bank is contacted within hours of transfer and the receiving institution can place a hold. Recovery falls sharply once funds have moved through more than one account.

Sector-Specific Patterns

Deepfake CEO fraud is now appearing in particular sectors:

  • Professional services — law and accounting firms with discretionary client trust account access
  • Property and construction — large supplier payments with inconsistent verification practice
  • Technology and SaaS — executives with extensive public profiles and remote-first finance teams
  • Healthcare and education — administrative staff under pressure with limited cyber training

The common thread is the gap between the executive's public profile and the maturity of the finance team's verification process.

Practical Takeaway

  1. Document a payment authority matrix with named approvers and limits
  2. Mandate out-of-band verification for any new payment beneficiary
  3. Apply a cooling-off period on first payments to new accounts
  4. State explicitly in policy that confidentiality is not a reason to bypass verification
  5. Run quarterly simulations with deepfake-style scenarios for finance and executive support staff
  6. Strengthen email authentication — DMARC, SPF, DKIM
  7. Set up bank-side controls including dual approval for beneficiary changes
  8. Document the response process for a suspected fraudulent transfer, including who calls whom

Start your free SecureAZ trial to roll out deepfake-aware phishing training and run scenario simulations across the team.

External references:

Sources & references