A deepfake video call cost Arup $25M. The same playbook is hitting SMBs every week — and most security programs haven’t caught up.

In early 2024, an accountant at the engineering firm Arup sat down for what looked like a routine video conference. The CFO was on the call. So were several other colleagues. Everyone looked right. Everyone sounded right. The only problem: none of them were real. A finance worker wired roughly $25 million to attackers who had fabricated the entire meeting with deepfake video and cloned voices.

That case made global headlines. The quieter story is the one playing out at thousands of small and mid-sized businesses every week: an “executive” emails an AP clerk asking for a wire transfer, a “vendor” calls about updating payment details, a “Microsoft technician” leaves a voicemail that sounds exactly like your IT director. Generative AI has turned social engineering from a craft into a production line, and most security programs have not caught up.

The Numbers Have Shifted

For most of the last decade, phishing emails were easy to spot. Bad grammar, mismatched sender domains, generic greetings. The defenders’ advantage was that attacks were expensive to personalize at scale. An attacker could blast a million generic “Nigerian prince” emails, or send a hundred highly targeted ones. They chose the first.

That trade-off is gone. Large language models let attackers produce clean, fluent, locally appropriate phishing copy in any language. Voice cloning tools need as little as ten seconds of audio to mimic a specific person. Deepfake video has moved from research demos to real-time face-swaps on a commodity laptop. The cost of a targeted attack has dropped by orders of magnitude, and the volume has followed.

A 2024 study by IBM’s X-Force found that AI-generated phishing emails had a click-through rate about 70% higher than the human-written kind. A separate analysis from the UK’s National Cyber Security Centre warned that the average employee can no longer tell the difference. We are past the point where user-reported “this email felt weird” is a reliable defense.

What the Attack Looks Like Now

Three patterns are showing up over and over in incident reports.

1. The impersonated vendor. Attackers research a company’s real suppliers, then email the AP team from a look-alike domain saying banking details have changed. The invoice is real, the dollar amount matches a known contract, and the signature line includes a plausible employee whose LinkedIn profile they scraped last week. AI writes the email in flawless English, including the small talk about the recipient’s recent promotion.

2. The cloned executive. Voice cloning needs a target’s voice from a podcast, earnings call, or public video. Most executives in a public company have hours of this content online. The attacker calls an employee, often outside business hours, with a calm “I’m in a meeting, can you do me a quick favor” request. The request is usually a gift card purchase, a wire transfer, or the disclosure of an MFA code.

3. The deepfake meeting. The Arup case is the template. A fabricated Teams or Zoom meeting with multiple fake participants, all of whom look and sound like real colleagues. The goal is usually authorizing a financial transaction or harvesting credentials. The sophistication has been climbing through 2025 and 2026.

Phishing email and voice-cloning workflow
AI-generated phishing and voice cloning have moved social engineering from craft to production line.

Why SMBs Are the Soft Target

Big banks and tech firms have spent twenty years building layered defenses. They still get hit, but the cost per attempt is high enough to push attackers elsewhere. A 50-person marketing agency or a regional medical practice has none of that. The CEO’s voice is on the company website. The accounting team’s job titles are on LinkedIn. The whole org chart is one Google search away.

The defender’s math is also worse. A large enterprise can absorb a six-figure loss. A small business that loses $200,000 to a fraudulent wire transfer is often looking at layoffs, or closing. Ransomware actors know this, which is why attacks on companies under 200 employees have roughly doubled in the last two years.

What Actually Works

There is no silver bullet, but a few practical moves close most of the gap.

Use a verbal callback on any out-of-band financial request. If the CFO emails asking for a wire transfer, call her back on a number you already have. Not a number in the email. A cloned voice sounds real on a first listen, but the attacker cannot answer your callback because they do not control your executive’s actual phone. This one habit stops the majority of BEC fraud in incident data, and it costs nothing.

Treat any change-of-payment-details request as hostile by default. Require that changes be confirmed through a known channel, with a second person signing off. The friction is real. It is also the reason your finance team has not already been robbed.

Train on the new reality, not the old one. Most security awareness programs were built around 2015 phishing: bad grammar, obvious scams, hover-to-preview. Update the curriculum. Show staff real AI-generated phishing samples. Run a tabletop exercise that uses voice cloning. The goal is not to make people paranoid; it is to make them skeptical in a structured way.

Lock down public executive content where you can. You do not have to delete the CEO’s podcast appearances. But you can stop posting new high-quality video of their face and voice on public pages, and you can coach executives to use work accounts for sensitive calls. Audio and video of a person walking through an airport is enough to build a convincing clone.

Adopt phishing-resistant MFA. Hardware security keys (FIDO2/WebAuthn) and platform-bound passkeys cannot be phished by a fake login page, no matter how convincing. They are the single highest-ROI control most small businesses are still not using.

Hardware security key and passkey authentication
Phishing-resistant MFA (FIDO2 / passkeys) is the highest-ROI control most SMBs are still skipping.

The Honest Take

AI has not invented a new category of attack. Social engineering has always worked because humans are the easiest part of any system to fool. What AI did was make the cost curve bend sharply in the attacker’s favor. The defenses that worked when attacks were expensive and rare are eroding, and the ones that work now (out-of-band verification, hardware MFA, structured skepticism) require actual process change, not just another product.

The companies that are handling this well are the ones that stopped expecting email to be a trustworthy channel for money, credentials, or sensitive instructions. That is a cultural shift more than a technical one, and it is the work of the next few years.

If you do one thing this week, pick the highest-risk workflow in your business (the one where a single email or phone call can move money or grant access) and add a verbal callback step. It will feel slow. It is also the reason you will not be in the next incident report.