The Phone Call That Wires Your Money to the Wrong Bank
Identity Access   Aug 17, 2026

The Phone Call That Wires Your Money to the Wrong Bank

On July 31, an accountant at a mid-sized U.S. private equity firm picked up the phone. The caller introduced herself as the firm’s outside counsel, ran through details about an upcoming acquisition, and walked the accountant through a routine wire transfer. The voice was right. The professional shorthand was right. The wire went out. By the time anyone realized “outside counsel” was a synthetic voice generated from fifteen seconds of YouTube audio, roughly $25 million was already in motion.

Reuters reported the campaign on August 7. Levi Strauss was named the same day, hit by an “unauthorized third party” that extracted corporate information. Google and a handful of internet-intelligence firms have linked the activity to a loose cluster of English-speaking extortion crews — groups that used to send mass phishes and now pick up the phone.

If you run a small or midsize business, this is the threat that should keep you up at night. Not ransomware itself — the *delivery mechanism* for ransomware, which is increasingly a friendly voice on the other end of a call.

Why voice works better than email

Phishing has been the number-one way attackers break into small businesses for years. Verizon’s 2025 Data Breach Investigations Report put a fine point on it: 88% of breaches at small and midsize businesses involved ransomware, and ransomware almost never arrives first. It rides in on a stolen credential or a successful phish.

What changed in the last eight months is the quality of the bait. A February 2026 poll by Sagiss and Pollfish found 72% of U.S. desk workers say phishing emails have become more convincing in the past year. The grammar is cleaner, the context tightens to whatever you’re actually working on, and the sender sounds like someone in your building. That’s AI doing what AI does — pattern-matching your org chart, your vendors, your typical phrasing.

Voice cloning pushes it past email. A 2024 IBM survey of 1,000 marketing leaders found roughly 1 in 4 had already experimented with voice-cloning tools. The same tools are commodity-priced on criminal forums. ElevenLabs and a dozen competitors offer them with a credit card and a sixty-second audio sample. Some require less. The fake “counsel” on that $25 million call was built from a public earnings call recording.

The shift matters because phone calls carry trust. We are wired to lower our guard when we hear a human voice asking us to do something routine. A phishing email that asks for an out-of-band wire transfer gets a second look. The same request, in a familiar voice, often does not.

The new playbook for small businesses

SMBs get hit four times harder than large organizations in raw breach counts, according to Verizon — and that gap is widening. The defenses that worked in 2022 don’t cover what attackers are doing now. Three shifts matter:

Treat every first-time wire instruction as suspect. The classic control here is “call back on a known number.” That’s still right, but it has to mean *a number you already had*, not one the caller gave you. If someone asks you to send money somewhere you haven’t sent money before, insist on a video call or an in-person confirmation, even if the voice sounds exactly right.

Lock down the tools voice cloners use. That public earnings call, the CEO’s podcast appearance, the all-hands Zoom recording — every minute of senior-staff audio posted online is fuel. Most of the damage in 2026 attacks has come from publicly available audio, not from leaked private material. Decide as a leadership team which voices are allowed to be in the public record, and treat the rest as sensitive even if they’re not secret.

Run phishing drills that include the phone. Most awareness training still treats phishing as an email problem. It isn’t anymore. The Sagiss poll found workers are roughly twice as likely to fall for an AI-generated voice call as for a polished phish. Your training program should test the same muscle — pause, verify out-of-band, escalate — across email, text, and voice.

You don’t need a SOC to do any of this. You need a written policy that anyone with the authority to move money knows cold, and a culture that says “weird gut feeling” is a legitimate reason to slow down.

Cybersecurity shield icon
The defenses that worked in 2022 are not the defenses that work now.

What this looks like in practice

Here is a workable routine for a 50-person company with a finance team of three:

  1. Any wire over $10,000 to a new account requires a video call or in-person confirmation with the requester, regardless of channel. Phone confirmation is not enough.
  2. Any vendor onboarding changes — new bank details, new payment terms, a different email signature — gets verified through a contact already on file, not the one in the message.
  3. Public audio of senior staff is reviewed quarterly. Anything that would give a cloner enough material to impersonate their voice gets pulled or, where it can’t be pulled (investor calls, conference panels), gets bracketed with a published note that the speaker’s voice is regularly cloned.
  4. Every quarter, run a tabletop: someone pretends to be a vendor with a new bank account, see who calls it out. The first time you do this, you’ll find the gap. The second time, you’ll close it.

None of this requires new software. It requires writing it down, repeating it, and rewarding employees who escalate instead of punishing them for slowing a $40,000 payment by ten minutes.

The bottom line

The attackers aren’t smarter. They have cheaper tools. A phishing kit that took a skilled operator a week to build in 2021 now takes an afternoon, and the voice-cloning equivalent fits in a chat prompt. That’s the entire shift: the floor has dropped out from under the small-business defender, and the controls written before 2024 assume an attacker who has to spend time and money to sound convincing.

They don’t anymore. Your controls need to assume they were convincing from the start, and your people need permission to slow the train when something feels off.

That $25 million wire started with a phone call. The next one starts with a calendar invite.

Small business team meeting
Tabletop exercises: the cheapest, fastest way to find the gap in your finance controls.
The Phone Call That Wires Your Money to the Wrong Bank
~/other/posts

Keep Reading

The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means
Aug 10, 2026 Identity Access

The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means

Last year, 63% of small businesses watched their cyber insurance premiums jump 200% or more. This year, the carriers are not just charging more. They are sending applications with a checklist that looks a lot like a security audit. For a lot of small business owners, that checklist is the first time anyone has told […]

The Network Is the Control Plane Now. Small Businesses Need to Treat It That Way.
Aug 3, 2026 Identity Access

The Network Is the Control Plane Now. Small Businesses Need to Treat It That Way.

Last week’s article looked at management consoles as the new front door. This week, the same idea is showing up in a different place: the network itself. In July, more than 30 Minnesota water systems were targeted in a coordinated cyberattack. One plant went offline. Around the same time, The Hacker News reported that attackers […]

Your Management Console Is the New Front Door. Stop Treating It Like a Back Room.
Jul 28, 2026 Uncategorized

Your Management Console Is the New Front Door. Stop Treating It Like a Back Room.

Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, the tools those teams are *not* flying blind on (legitimate admin consoles, automation platforms, and self-hosted developer tools) are getting hit with pre-authentication exploits at a pace that should reset every CISO’s priorities. On July 23, Check Point […]

Healthcare Cyberattacks Just Doubled. The Hospitals Aren’t Even the Soft Target Anymore.
Jul 20, 2026 Network Security

Healthcare Cyberattacks Just Doubled. The Hospitals Aren’t Even the Soft Target Anymore.

Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare. In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two […]