>gabes/the letter
goodmonday2026-09-21

voice stopped being proof of identity, and your payment process never got the memo.

roughly 40% of business email compromise attempts this year arrive with a synthetic voice or face attached, against almost none three years ago. you cannot train an ear past that.

the condition is simple: voice and video used to be identity checks, and most approval workflows were quietly built on the assumption that they still are. the cost is one successful payee change, which in a company under fifty people is usually a five or six figure transfer that clears long before anyone thinks to call anybody back. the fake solution is another security awareness module telling staff to listen for something slightly off, which parks the entire defence inside a junior employee's ear at 4pm on a friday while a senior voice tells them it is urgent. the fix is procedural and boring: any new payee, or any change to bank details on an existing one, needs a second named approver and a callback to a number already on file, never the number in the request. write it into the payment workflow as a step that cannot be waived by seniority or urgency, because seniority and urgency are precisely what the attack manufactures. if one person can move money alone, that is not a trust arrangement, it is the largest unhedged exposure on your balance sheet and it is not written down anywhere.

do this: second approver and a callback on every payee change, no exceptions for rank. not this: train people to listen harder.