It's Friday afternoon. The controller at a 180-person company gets a call. It's the CEO. His voice is exactly right. Same cadence, same accent, same slight throat clear before he gets to the point. He needs a wire moved before end of day for a supplier renegotiation that has to close before Monday. He's in back-to-back meetings, can't be reached, and asks her to just handle it. The number is significant but not outrageous. Everything about the call feels normal.
It isn't him.
This is not a hypothetical. It's a documented pattern, and it's coming for companies smaller than the ones you've read about in the news.
The Advice Most Companies Still Give Is Broken
For twenty years, phishing awareness training taught employees to look for the same handful of tells. Spelling mistakes. Awkward grammar. Generic greetings. Suspicious formatting. That checklist worked when phishing was written by non-native speakers using free tools, and it built an entire industry around teaching people to spot the seams.
The seams are gone.
Large language models now write flawless, context-aware messages. They reference real projects, real clients, real internal terminology pulled from LinkedIn, press releases, and public filings. Voice cloning tools can produce a convincing impersonation from roughly three seconds of source audio. Every earnings call, conference panel, and podcast appearance is training data.
The signals employees were taught to look for have been erased. The training has not moved.
What We're Seeing
Two cases already on the record are worth knowing by name.
At the engineering firm Arup, a finance employee in the Hong Kong office was pulled into a video call to discuss a confidential transaction. Every other participant on the call, including the CFO and several colleagues, was an AI-generated deepfake. He initiated fifteen transfers before anyone realized. Total loss was about $25.6 million. The CIO's public comment was blunt. No systems were compromised. It was technology-enhanced social engineering.
At Ferrari, an executive received a voice call from "the CEO" with the correct southern-Italian accent, asking for a confidential currency-hedge transaction. The executive was suspicious but not certain. He asked a single question only the real CEO could answer, the title of a book he had recently recommended. The caller hung up.
The Ferrari case is the point. What stopped the fraud was not the executive's ear. It was a verification pattern.
Why SMBs Are Becoming the Target, Not Just Collateral Damage
There is a comfortable assumption that this is a Fortune 500 problem. The evidence points the other way.
The scale advantage of AI cuts against small and mid-sized businesses in a specific way. It costs the attacker nothing to try, and one success pays for a lot of failures.
The Fix Is Procedure, Not Perception
The most important shift is mental. Fraud detection is no longer a perception problem. It is a procedure problem.
Peer-reviewed research from University College London tested this directly. Even with training, humans could not reliably tell synthetic voices from real ones. That is the ceiling on any strategy built around "listen carefully."
What actually works is boring, and boring is the point.
None of these depend on someone catching the tell. They work when the caller is perfect, because they do not ask the employee to detect anything. They ask the employee to follow a routine.
How InsITe Approaches This
When we work with clients on fraud resilience, we spend less time training people to detect and more time building the routine that catches attempts regardless of how convincing they sound. The verification callback becomes muscle memory, not a suggestion. Dual approval is enforced by policy and workflow, not by hope. The result is a business that stays safe on the day someone's voice sounds exactly right.
Protocol Beats Perception
The old phishing tells are gone. AI has erased them, and the awareness training built around them is no longer a control. What remains is procedure. The callback. The second signature. The question only the real person can answer.
If a call came in tomorrow that sounded exactly like your CEO asking for an urgent wire, what would happen? Would policy catch it, or would the answer depend on how alert someone happened to be that Friday afternoon?
The voice on the phone can be perfect. The grammar and details in an email will be spot-on. The verification routine still catches it.