Someone Called Sounding Exactly Like Your Boss
The uncomfortable fact underneath this article is that a recognisable voice has stopped being evidence of identity. Cloning a voice convincingly now takes roughly thirty seconds of source audio, and for most people that audio is already public — a podcast appearance, a webinar recording, a video on a company page, a voicemail greeting, a few seconds of a social media clip.
This isn't a hypothetical aimed at large corporations. The tooling is cheap and general, which means it scales down to businesses of any size. If you're an owner whose voice appears anywhere online, you are a viable target.
How the attack actually runs
The version we'd expect to see against a small business is not a single dramatic phone call. It's a sequence, and each step exists to make the next one feel already-agreed.
- Research. Public sources establish who handles payments, who they report to, who the suppliers are, and what's plausibly in progress.
- A voicemail, left deliberately when the office is closed, in a voice the recipient recognises. It's vague and unremarkable — approving something, mentioning a supplier, saying it'll be followed up.
- An email the next morning referencing that call as settled context. Not making the request cold, but confirming a decision that appears to have already been made.
- Pressure framed as ordinary business: a payment cutoff, an end-of-month deadline, a supplier waiting.
What makes it effective is that no single step asks the recipient to believe anything remarkable. The voicemail alone would be ignored. The email alone would be questioned. Together they manufacture the feeling of a conversation you were part of.
The callback rule
The defence is a rule rather than a detection skill, which is what makes it reliable. Nobody has to be good at spotting a synthetic voice — an unfair thing to ask of anyone, and getting harder each year.
For any instruction involving money moving or credentials changing: hang up, and call back on a number you already hold. Not a number from the email, not a number the caller reads out, not the number in the signature. A number from your own records, your own phone's contacts, or a previous invoice you know was genuine.
The rule works because it doesn't depend on the quality of the impersonation. A perfect clone of a voice cannot answer a phone number the attacker doesn't control.
Two things worth adding
A shared phrase, agreed in advance and never sent by email or text, is a cheap second layer for genuinely urgent requests. It costs nothing and takes one conversation to set up.
And a dual-authorisation threshold — above some amount, two people approve, always — removes the whole class of attack that depends on isolating one person under time pressure. Pick a number that reflects what your business could absorb losing.
Say it out loud to your staff
The single most useful thing an owner can do here is tell their team, explicitly and in advance: I will never ask you to move money urgently without you being able to verify it, and you will never be in trouble for calling me back to check. Say it before it matters.
Most successful versions of this scam work not because the impersonation was flawless, but because someone junior didn't want to appear to distrust their boss. That is a culture problem, and it's fixable in one sentence.
If you want to see how the email half of this reads in practice, our spot-the-phish quiz includes a message built on exactly this pattern. And if you'd rather have someone put the wider controls in place and keep them there, that's what managed IT support is for.
Rather have someone handle it? This is part of our managed it support service across Middlesex, Somerset and Mercer County.
Need a hand?
We handle this for New Jersey businesses and homes
Whether it's a one-off problem or ongoing support, we're happy to take a look — and to tell you honestly if you don't need us.