your bookkeeper is going to get a video call from you. your face, your voice, your way of asking. and it will ask them to move money.
in early 2024 a finance employee at arup, the engineering firm behind the sydney opera house, joined a video call with the cfo and several familiar colleagues, took the instructions, and made fifteen transfers totalling about $25 million into five hong kong accounts. every other person on that call was generated, built from video and audio the company had already published. months later a ferrari executive got a call in the ceo's voice, southern italian accent included, pushing an urgent confidential deal, and the whole thing collapsed the moment he asked the title of the book the ceo had recommended him days earlier. that is the entire defense, and it cost nothing.
the advice going around is to train your team to spot deepfakes, which asks a person to win a perception contest against software that improves every quarter, on a bad monday, under pressure from someone who sounds like their boss. the smaller the company the worse the exposure, because there is nobody standing between a convincing request and the bank login.
write one rule and put it where the money is: any payment, any change to bank details, any transfer outside the normal pattern gets confirmed by calling back a number already in your own records, never the number that called you and never a reply in the same thread. then tell whoever holds that login, in writing, that they are allowed to make you wait ten minutes. the urgency is the attack. remove it and the whole thing stops working.