top of page

That Voice on the Phone Might Not Be Real: Deepfake Scams Come for Small Business

Imagine your bookkeeper gets a call. It is your voice, unmistakably. You sound rushed, maybe a little stressed, and you need a payment sent before end of day to close something out. You will explain later. The bookkeeper, being helpful, sends it.


Except it was never you. Security researchers report that only a few seconds of recorded audio, McAfee's research puts it at as little as three seconds for an 85 percent accurate match, is enough for AI tools to produce a convincing clone of someone's voice. And the audio is not hard to find: a video on your website, a social media clip, a voicemail greeting, or simply a recording of you answering a spam call.


This is not a big-company problem. The scam works best exactly where a familiar voice replaces process, and that describes most small businesses.


How the scam actually works


Voice deepfake scams are a new coat of paint on an old con: impersonate someone trusted, create urgency, and get money or access moving before anyone thinks to check. The AI part solves the one weakness the old con had, which is that the impostor used to have to sound like a stranger.


The common plays we expect to see, and in some cases already see nationally:


  • The owner or manager calls an employee who handles money, asking for an urgent wire, payment, or gift card purchase. The voice is right, the caller ID may even be spoofed to match, and the request comes with a reason to keep it quiet.

  • A known vendor calls about a past-due invoice and new payment details, matching a real relationship your business actually has.

  • Fake IT support calls an employee, sounds professional and calm, and walks them into sharing a password or approving a multi-factor sign-in prompt.

  • The scale is real: AI-enabled fraud grew over 1,200 percent in 2025 by some industry measures, and large companies now field hundreds of AI-generated scam calls a day. Small businesses are next down the food chain, with fewer defenses.


The uncomfortable takeaway from the research: people can no longer reliably tell cloned voices from real ones. If your protection against a fraudulent payment is "we would recognize the voice," you no longer have protection.


Why small businesses are especially exposed


In a ten-person company, a call from the owner is not a transaction, it is a relationship. Nobody wants to say "prove it" to their boss. Payments often live with one trusted person, approvals happen verbally, and speed is considered a virtue. Attackers know all of this. The informality that makes small businesses pleasant to work in is exactly the gap this scam drives through.


Western North Carolina businesses are not too small or too far from anywhere to be targets. These calls are cheap to make, automated to scale, and aimed wherever the process is weakest.


The defenses are refreshingly low-tech


Here is the good news: because the attack fakes a voice, not a process, process beats it. You do not need special software to defuse voice cloning. You need a few habits that hold even when the voice on the phone sounds exactly right.


Verify by calling back on a number you already have


Any request involving money, payment changes, gift cards, or credentials gets one response: hang up and call the person back on the number already in your contacts. Not the number that just called you. This one habit defeats nearly every version of the scam.


Use a verification word for money requests


Agree on a simple code word or question within your team for out-of-the-ordinary money requests. A cloned voice can say anything, but it does not know what you agreed on at last month's staff meeting.


Require two people for meaningful payments


Set a threshold above which any payment, wire, or banking change needs a second person's sign-off. Dual approval turns a perfect voice clone into only half of an attack.


Never approve a sign-in you did not start


If IT, real or fake, calls and asks you to read back a code or approve a prompt on your phone, stop. Legitimate support does not need you to approve a multi-factor prompt they triggered.


Talk about it before it happens


Five minutes at a staff meeting is the whole training. The message is simple: an urgent voice on the phone is no longer proof of anything, and nobody will ever be in trouble here for taking sixty seconds to verify.


Where this fits in the bigger picture


Voice cloning usually arrives alongside the email attacks we have written about before: a compromised or lookalike email thread sets the stage, and the phone call closes the deal. That is why the defense is layered: secured email, monitoring, MFA, and verification habits that treat every channel, voice included, as spoofable.


Final thoughts


Technology created this problem, but honestly, technology is not the main fix. A sixty-second callback habit and a two-person rule beat the most convincing voice clone ever generated. The businesses that get hurt will not be the ones with the smallest budgets. They will be the ones that never talked about it.


If you want help putting the technical layers around these habits, from email security and MFA to monitoring that spots the account takeovers these calls often start with, we would be glad to help. Asheville Computer Company works with small businesses across Asheville, Arden, Fletcher, Hendersonville, and Western North Carolina to make practical security part of how the business runs, without slowing it down.


bottom of page