On July 31, an accountant at a mid-sized U.S. private equity firm picked up the phone. The caller introduced herself as the firm’s outside counsel, ran through details about an upcoming acquisition, and walked the accountant through a routine wire transfer. The voice was right. The professional shorthand was right. The wire went out. By the time anyone realized “outside counsel” was a synthetic voice generated from fifteen seconds of YouTube audio, roughly $25 million was already in motion.
Reuters reported the campaign on August 7. Levi Strauss was named the same day, hit by an “unauthorized third party” that extracted corporate information. Google and a handful of internet-intelligence firms have linked the activity to a loose cluster of English-speaking extortion crews — groups that used to send mass phishes and now pick up the phone.
If you run a small or midsize business, this is the threat that should keep you up at night. Not ransomware itself — the *delivery mechanism* for ransomware, which is increasingly a friendly voice on the other end of a call.
Why voice works better than email
Phishing has been the number-one way attackers break into small businesses for years. Verizon’s 2025 Data Breach Investigations Report put a fine point on it: 88% of breaches at small and midsize businesses involved ransomware, and ransomware almost never arrives first. It rides in on a stolen credential or a successful phish.
What changed in the last eight months is the quality of the bait. A February 2026 poll by Sagiss and Pollfish found 72% of U.S. desk workers say phishing emails have become more convincing in the past year. The grammar is cleaner, the context tightens to whatever you’re actually working on, and the sender sounds like someone in your building. That’s AI doing what AI does — pattern-matching your org chart, your vendors, your typical phrasing.
Voice cloning pushes it past email. A 2024 IBM survey of 1,000 marketing leaders found roughly 1 in 4 had already experimented with voice-cloning tools. The same tools are commodity-priced on criminal forums. ElevenLabs and a dozen competitors offer them with a credit card and a sixty-second audio sample. Some require less. The fake “counsel” on that $25 million call was built from a public earnings call recording.
The shift matters because phone calls carry trust. We are wired to lower our guard when we hear a human voice asking us to do something routine. A phishing email that asks for an out-of-band wire transfer gets a second look. The same request, in a familiar voice, often does not.
The new playbook for small businesses
SMBs get hit four times harder than large organizations in raw breach counts, according to Verizon — and that gap is widening. The defenses that worked in 2022 don’t cover what attackers are doing now. Three shifts matter:
Treat every first-time wire instruction as suspect. The classic control here is “call back on a known number.” That’s still right, but it has to mean *a number you already had*, not one the caller gave you. If someone asks you to send money somewhere you haven’t sent money before, insist on a video call or an in-person confirmation, even if the voice sounds exactly right.
Lock down the tools voice cloners use. That public earnings call, the CEO’s podcast appearance, the all-hands Zoom recording — every minute of senior-staff audio posted online is fuel. Most of the damage in 2026 attacks has come from publicly available audio, not from leaked private material. Decide as a leadership team which voices are allowed to be in the public record, and treat the rest as sensitive even if they’re not secret.
Run phishing drills that include the phone. Most awareness training still treats phishing as an email problem. It isn’t anymore. The Sagiss poll found workers are roughly twice as likely to fall for an AI-generated voice call as for a polished phish. Your training program should test the same muscle — pause, verify out-of-band, escalate — across email, text, and voice.
You don’t need a SOC to do any of this. You need a written policy that anyone with the authority to move money knows cold, and a culture that says “weird gut feeling” is a legitimate reason to slow down.

What this looks like in practice
Here is a workable routine for a 50-person company with a finance team of three:
- Any wire over $10,000 to a new account requires a video call or in-person confirmation with the requester, regardless of channel. Phone confirmation is not enough.
- Any vendor onboarding changes — new bank details, new payment terms, a different email signature — gets verified through a contact already on file, not the one in the message.
- Public audio of senior staff is reviewed quarterly. Anything that would give a cloner enough material to impersonate their voice gets pulled or, where it can’t be pulled (investor calls, conference panels), gets bracketed with a published note that the speaker’s voice is regularly cloned.
- Every quarter, run a tabletop: someone pretends to be a vendor with a new bank account, see who calls it out. The first time you do this, you’ll find the gap. The second time, you’ll close it.
None of this requires new software. It requires writing it down, repeating it, and rewarding employees who escalate instead of punishing them for slowing a $40,000 payment by ten minutes.
The bottom line
The attackers aren’t smarter. They have cheaper tools. A phishing kit that took a skilled operator a week to build in 2021 now takes an afternoon, and the voice-cloning equivalent fits in a chat prompt. That’s the entire shift: the floor has dropped out from under the small-business defender, and the controls written before 2024 assume an attacker who has to spend time and money to sound convincing.
They don’t anymore. Your controls need to assume they were convincing from the start, and your people need permission to slow the train when something feels off.
That $25 million wire started with a phone call. The next one starts with a calendar invite.
