woman sitting at desk working on computer

How to Identify a Deepfake Audio Call

Voice AI deepfakes are getting better. To the very discerning, it’s still possible to tell the difference. How discerning are you? You can test yourself and learn some important tips at The Wall Street JournalWSJ invited David Falkenstein, from security firm IOActive, to clone the voices of several WSJ reporters from publicly available audio on social media and podcasts. 

With the cloned voices, Falkenstein made recordings announcing several outlandish and entertaining “news” stories. Then the reporters recorded themselves using the same scripts. In the Journal’s quiz you can listen to recordings to see whether you can tell the difference between the cloned and human voices. The piece also provides instructional analysis to point out the “tells” of a deepfake recording.

As VendorInfo has reported in Protect Against Deepfake Impersonation Fraud in Accounts Payable Part I, deepfakes represent an increasing threat. In Part II, VendorInfo offers specific steps you can take to avoid deepfake fraud. The WSJ quiz lets you try your ear at discerning the voice and audio indicators. 

Go to the WSJ page here to hear the recordings and test your detection ability. 

Hurdles to Identifying Deepfakes

The tells in an audio deepfake are subtle, but are there. The challenge for accounts payable is to remain sufficiently vigilant amid busy days, with multiple tasks and piles of work to get through.

There are counterforces at work, in part due to human nature. On one hand, we want to appear capable and reliable, ready to assist a director or executive. Then too, under workload pressure we often look for ways to speed things up and, frankly, for convenience. Those tendencies can lead to shortcutting protocol in a hurry to finish a task and get on to the next one. 

Another hazard is the difficulty of sustaining a high level of alertness every minute of every day. It’s a bit like a long road trip—everyone starts out with a high level of energy, but as the miles go by, that energy wanes.

Criminals targeting an organization’s money count on these things. They employ “social engineering” to appeal to our desire to be efficient and supportive of the organization’s needs and mission. They count on us being under pressure with a lot to get done. So, while the quality of deepfakes improves, cybercriminals use it together with social engineering to fool the unsuspecting and perpetrate their scams.

Playing Good Defense

Training is vital, of course. But as Gartner has pointed out, training is not enough. It’s important to create a culture of vigilance and skepticism in accounts payable. And accounts payable staff must know they have management’s support. Beyond controls and procedures, encourage employees to think on their feet. If a caller request seems surprising or just seems a little off, accounts payable staff should trust themselves, challenge the requestor and stick to procedure.

One technique for challenging a requestor is to have and require a pass phrase. Another approach is to ask off-beat questions. This can depend on whether the caller is someone the staffer knows or not. But, for example, ask the requestor about something the real person would know, such as a recent conversation. Ask about a recent in-office event, or where you’re all going after work on Thursday. Or (if you know this) what color the person’s office is. These questions can expose a fake.

Whether it’s a company officer or an external vendor, the legitimate requestor should not object to an employee taking precautions. Simple challenges can stymie a fake caller, revealing a scam.

Of course there are other critical facets of defense. These include the process controls of independent call-back confirmation, second-person review and vendor bank account verification (BAV). The whole aim of a deepfake call to accounts payable is to persuade a staff to send funds to an illegitimate account. So AP must not circumvent these controls. Urgent requests are sometimes legitimate but urgency is also one of the “tells” of a scam. Skipping independent confirmation and failing to verify the vendor bank account ownership is how companies can lose a lot of money.

Don’t be fooled by audio deepfakes. But in case you are, by consistently following established controls, you can avoid payment fraud.

For more help, also see Protect Against Deepfake Impersonation Fraud in Accounts Payable  Part II.

Bank account verification is a critical tool in protecting your organization against payment fraud. To learn how VendorInfo’s automated vendor bank account verification can quickly be put to work for you, schedule a meeting

Share This Post