← Vercon Research

4 min read

Executive Risk·

What Boards Miss About Voice Fraud

ML
Marcus Lattimore
Director, Threat Analysis & Mitigation, Vercon
technology team working with laptops

Voice security is no longer a narrow telecom concern. It is part identity control, part fraud operations, and part customer-experience design.

A useful public reference point is CNN's "Finance worker pays out $25 million after video call with deepfake CFO" (2024-02-04), which shows why voice, identity, and approval controls now belong in the same operating conversation.

That record should be useful to managers, not just auditors. A supervisor should be able to see rising call volume, repeated destination changes, unusual after-hours activity, transcript-sensitive terms, and overage patterns without waiting for a post-incident report.

Policy should be written in plain language. Employees need to know which requests require a callback, which require a second approver, and which the system should refuse outright.

The point is not to make every call suspicious. The point is to stop treating the telephone as a low-risk side channel. In an AI-assisted fraud environment, the voice channel deserves the same management discipline as login, payments, email, and customer data access.

Referenced reporting

Links are provided for reference and are not legal advice or a guarantee of verification.

#deepfake audio#wire fraud#approval controls

Find out where your communications channels are exposed.

A Vercon Communications Security Assessment gives you an executive-readable risk report and a prioritized remediation roadmap, usually inside of four weeks.