When the CFO on the Video Call Isn’t Your CFO
Identity Access   Sep 7, 2026

When the CFO on the Video Call Isn’t Your CFO

A finance employee at a multinational engineering firm joined a video call last year expecting to see his company’s UK-based CFO and a handful of other colleagues. Every face on that call looked right. Every voice sounded right. He walked out of the meeting and wired roughly $25 million to five bank accounts controlled by attackers. By the time he checked with headquarters, the money was gone.

Every person on that video call was a deepfake.

If you read that story and thought “that happens to big companies, not us,” I want to talk you out of that this week. Because the same tools that pulled off the Hong Kong heist are now cheap enough that a single attacker with a laptop can run the same play against a 30-person manufacturer, a regional law firm, or your local hospital’s billing office.

The math is unforgiving. Eighty-eight percent of breaches at small and mid-sized businesses now involve ransomware, according to Verizon’s 2025 Data Breach Investigations Report — more than double the rate at large organizations. Three in four SMBs say a single major cyberattack would put them out of business. And the criminals have figured out something worse than a new exploit: they’ve figured out how to make us trust them.

The trust collapse

For 30 years, the security advice for businesses was the same: train your employees to spot phishing emails, verify wire requests by phone, use multi-factor authentication. None of that is bad advice. All of it is now incomplete.

Consider what an attacker can do in 2026 with maybe $200 and a few hours of setup. They scrape a CFO’s earnings call videos, conference panels, and podcast appearances (all public) to clone their voice and face. They draft a phishing email that mimics their writing style, including the odd comma splices that manager always uses. They spin up a deepfake video model that runs in real time on a rented GPU. Then they send a finance clerk a message that sounds like the boss on her best day, referencing a project she knows is real, asking for a same-day wire to a vendor she’s heard of. When she asks to verify by video, she gets it. When she asks to verify by voice, she gets it.

The Hong Kong case is the one everyone cites, but the same playbook now hits smaller targets. A finance director in Singapore wired $499,000 after a Zoom call with a deepfake “CFO.” A UK energy company CEO was cloned by voice alone and authorized a $243,000 transfer. Entrust’s research shows deepfake fraud attempts are up roughly 3,000% since 2022, with a documented attempt every five minutes somewhere on the internet.

The point isn’t that video calls are dangerous. The point is that the human signals we’ve relied on to verify identity (a familiar face, a familiar voice, a familiar writing style) are now reproducible.

What “MFA enabled” actually means

Here’s the other thing keeping security professionals up at night. In incident after incident, the breached organization had multi-factor authentication turned on. Kroll’s breach investigations found that 90% of compromised organizations had MFA deployed at the time of unauthorized access. Cisco Talos reported that authentication abuse showed up in 65% of their Q2 2026 incident response engagements, up from 35% the previous quarter.

How does that happen? Three patterns account for most of it.

The first is push fatigue, also called prompt bombing. An attacker who already has your password sends your phone dozens of push notifications in the middle of the night until you tap “Approve” just to make it stop. The second is the adversary-in-the-middle proxy. You think you’re logging into Microsoft 365. You’re actually logging into a lookalike page run by the attacker, who relays your password and your one-time code to the real Microsoft in real time. The third is session token theft. Once you’re authenticated, the attacker steals the browser cookie that proves you’re logged in and replays it from their own machine. MFA didn’t fail — the attacker never had to defeat it, because they stole the result of having passed it.

The platforms selling these as services are mature. Tycoon 2FA ran as a turnkey MFA bypass kit specializing in Microsoft 365 and Google Workspace accounts; before law enforcement took it down in March 2026, it accounted for roughly 62% of Microsoft’s blocked phishing volume. The operators adapted within weeks. The replacement kits are out there now.

What actually helps

I’m going to skip the generic “raise awareness” advice and tell you what I’d do if I ran a 40-person company this week.

Move off SMS and push-based MFA. SMS is interceptable through SIM swaps, and push prompts are fatigue-attackable. Phishing-resistant MFA means FIDO2 / WebAuthn keys: physical security keys (YubiKey is the common brand), or the passkey feature built into iOS, Android, and modern browsers. The protocol is designed so the credential can’t be phished, replayed, or proxied, because the authentication only works against the legitimate domain. Microsoft, Google, and the U.S. federal government have all moved to this. If your business is still relying on a six-digit code texted to a phone, you’re using 2015 defenses against 2026 attacks.

Write down a verification rule for money. Pick any dollar threshold that matters to your business — $5,000, $10,000, whatever. For any wire or ACH above that, require an out-of-band confirmation using a number already on file, not one provided in the request. Not the number the email gave you. Not the number the caller ID showed. The number on the back of the contract or in the original vendor setup email from six months ago. Add a second approver. Make the rule annoying enough that attackers can’t route around it.

Test your employees with synthetic attacks. Most phishing simulation services now offer voice-cloning and deepfake video scenarios alongside the standard “click the bad link” test. Run one against your finance team this quarter. The point isn’t to punish anyone who fails. The point is to find out whether your verification procedure survives contact with a real attempt.

Lock down the obvious stuff. Microsoft reports that simply blocking legacy authentication protocols (the old “basic auth” pathways that skip MFA entirely) stops the majority of automated account takeover attempts. Enable that. Require MFA on every admin account, not just user accounts. Audit who has password reset permissions.

Make backups boring. The actual outcome most ransomware victims care about is recovery time. The current median downtime after a ransomware hit is 24 days. Three weeks where you can’t invoice customers, can’t access accounting, can’t serve the people depending on you. Immutable, offline-tested backups are the difference between a bad week and a closed business. If you haven’t restored from backup in the last six months, you don’t have backups — you have hopes.

The uncomfortable truth

I keep coming back to one statistic. CrowdStrike’s 2025 SMB cybersecurity survey found that 44% of small businesses that suffered an attack believed they wouldn’t be hit again, and 26% considered themselves safe because they were “too small to target.” Both groups were wrong in the same direction.

Attackers aren’t targeting you because you’re interesting. They’re targeting you because your CFO’s face is on YouTube and your finance person hasn’t been told that face can be copied. The fix isn’t exotic. It’s a phishing-resistant second factor, a verification rule that holds even when the voice on the phone sounds exactly right, and the discipline to test both.

You don’t need a million-dollar security program. You need to assume the next request that looks and sounds legitimate is the one to verify hardest. That posture is the actual product now.

When the CFO on the Video Call Isn’t Your CFO
~/other/posts

Keep Reading

Your Vendor Just Became Your Biggest HIPAA Risk. Here’s What To Do Before They Breach.
Aug 31, 2026 Identity Access

Your Vendor Just Became Your Biggest HIPAA Risk. Here’s What To Do Before They Breach.

Your Vendor Just Became Your Biggest HIPAA Risk. Here’s What To Do Before They Breach. On July 20, 2026, Craneware, the company that runs revenue-cycle software for hundreds of U.S. hospitals, disclosed a cyberattack to the London Stock Exchange. Two weeks later, healthcare-tech vendor CareCloud confirmed a breach affecting 3.75 million patients. In between, NYC […]

Your Own Antivirus Just Became an Attacker’s Toolkit
Aug 24, 2026 Identity Access

Your Own Antivirus Just Became an Attacker’s Toolkit

Your Own Antivirus Just Became an Attacker's Toolkit Last week we wrote about the friendly voice on the phone convincing an accountant to wire $25 million to the wrong bank. This week the threat is quieter, uglier, and closer to home: the security software sitting on every Windows machine in your office. On August 21, […]

The Phone Call That Wires Your Money to the Wrong Bank
Aug 17, 2026 Identity Access

The Phone Call That Wires Your Money to the Wrong Bank

On July 31, an accountant at a mid-sized U.S. private equity firm picked up the phone. The caller introduced herself as the firm’s outside counsel, ran through details about an upcoming acquisition, and walked the accountant through a routine wire transfer. The voice was right. The professional shorthand was right. The wire went out. By […]

The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means
Aug 10, 2026 Identity Access

The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means

Last year, 63% of small businesses watched their cyber insurance premiums jump 200% or more. This year, the carriers are not just charging more. They are sending applications with a checklist that looks a lot like a security audit. For a lot of small business owners, that checklist is the first time anyone has told […]