The call comes in on a Tuesday afternoon.
It sounds exactly like your business partner. Or your CFO. Or the vendor you have worked with for six years. The voice has the same cadence, the same phrasing, the same slight accent you have always recognized. Maybe there is a video call and the face matches too.
There is an urgent wire transfer. A confidential acquisition. A vendor payment that needs to go out before end of business. The request is unusual but the person making it is someone you know, someone you trust, someone you would wire money for without a second thought.
Except it is not them. It is a synthetic voice and a synthetic face generated by AI software that can be run from a laptop using audio scraped from a podcast, a YouTube video, a LinkedIn post, or a voicemail greeting. The entire interaction is fabricated. And the money, once it goes, does not come back.
This is not a hypothetical. This is the fastest-growing category of business fraud in the United States right now, and small businesses are the primary target.
The Numbers Are Not Theoretical Anymore
Deepfake-related fraud losses reached $1.1 billion globally in 2025, nearly tripling from the year before. In the United States alone, the FBI logged approximately $893 million in AI-enabled fraud losses in 2025, the first year it tracked AI as its own category. Surfshark research estimates that deepfake scams accrued $96 million in losses in just the first four months of 2026.
Deloitte’s Center for Financial Services projects that generative AI fraud losses in the United States could reach $40 billion annually by 2027, up from $12.3 billion in 2023. That is a compound annual growth rate of 32 percent in a category that barely existed five years ago.
The average loss per deepfake incident in 2024 was nearly $500,000 for businesses. The mean loss exceeded $280,000 per incident according to a 2025 IRONSCALES report. Sixty-one percent of organizations that lost money in a deepfake attack reported losses over $100,000. Nearly 19 percent reported losses of $500,000 or more.
CEO fraud now targets at least 400 companies per day. The FBI’s IC3 2025 annual report logged a 312 percent year-on-year increase in business email compromise losses that had confirmed deepfake audio or video components.
And here is the number that should concern every small business owner specifically: small and mid-sized businesses accounted for 70.5 percent of all data breaches in 2025. The reason is straightforward. Large corporations have dedicated security teams. Small businesses do not. Attackers know this and price their risk accordingly.
What the Attacks Actually Look Like
The playbook that fraudsters are using against businesses has evolved significantly. In 2023 and early 2024, most deepfake fraud was relatively crude: a cloned voice on a phone call, a manipulated audio message, a fake email with an AI-generated text. Those attacks still happen and they still work. But the sophistication has advanced dramatically.
The most prominently documented case illustrates where this technology now sits. In January 2024, attackers targeted Arup, a multinational engineering firm, through a video call in which every participant, including the apparent CFO and multiple senior colleagues, was an AI-generated deepfake. A finance employee in Hong Kong received what appeared to be a phishing email, grew suspicious, and then joined a video call that appeared to confirm the legitimacy of the request. The facial movements were synchronized. The voices matched. The executives said everything a legitimate executive would say in that context. The employee authorized 15 separate wire transfers totaling $25.6 million in a single day. The fraud was discovered only through later internal verification. The funds remain unrecovered.
In March 2025, a finance director at a multinational firm authorized a $499,000 transfer after joining a Zoom call with multiple executives, each of whom was a deepfake. The attackers had studied previous cases and knew that finance professionals were beginning to verify unusual requests. So they proactively suggested a video call to create false confidence. The willingness to go on video, which should have been a reassuring sign, was itself part of the attack.
These are enterprise-level cases with enterprise-level losses. But the technology that produced them is now available on consumer hardware. A voice can be cloned from as little as three seconds of publicly available audio. Every voicemail greeting, every podcast appearance, every YouTube video, every earnings call your executives have ever recorded is available as training data. The barrier to entry for this category of fraud has essentially collapsed.
Why Small Businesses Are the Target Now
The shift toward small business targeting is deliberate and strategic on the part of the people running these operations.
Large enterprises have begun investing in deepfake detection tools, enhanced verification protocols, and dedicated fraud response teams. The fraud protection budgets of Fortune 500 companies have grown substantially in response to high-profile incidents. Attackers respond to friction by moving toward softer targets.
Small businesses are softer targets for several specific reasons.
They have fewer verification layers. A small business owner who receives a call from someone who sounds like their bank, their accountant, or a key vendor is likely to act on that call without a multi-step verification process because they have never built one. Large businesses have call-back protocols, dual authorization requirements, and out-of-band verification for wire transfers. Most small businesses do not.
Their principals are identifiable and their audio is available. A small business owner who has appeared on a podcast, given a local chamber talk, made a video for their website, or posted on LinkedIn has given attackers everything they need to clone their voice. The more public-facing your business is, the more material exists for creating a convincing impersonation.
They use consumer-grade communication tools. WhatsApp, Zoom, FaceTime, and standard phone calls are the primary communication channels for most small businesses. These are also the channels where deepfake attacks are most commonly deployed. Business email compromise has expanded into business communication compromise, and the platforms small businesses rely on are the attack surface.
They make faster decisions under less oversight. A small business owner with a time-sensitive request and no finance committee to run it by is more likely to act quickly. Speed is what attackers engineer for. The urgency in the call, the confidentiality of the deal, the end-of-business deadline, all of these are manufactured pressure designed to compress the time between the request and the transfer.
The Three Attack Types Targeting Small Businesses Right Now
Voice cloning fraud. An attacker clones the voice of someone the business owner trusts, typically the owner’s accountant, a bank contact, a key supplier, or a business partner, and calls requesting a wire transfer, payment information, or login credentials. The technology to do this requires only a few seconds of audio and is available through tools that cost nothing or next to nothing. Vishing attacks, voice phishing using cloned voices, surged over 1,300 percent in 2024 according to Pindrop and continued accelerating in 2025.
Synthetic executive impersonation. Attackers impersonate the business owner or a senior employee to deceive the business’s own staff. A bookkeeper receives a voice message from what sounds like the owner asking for an urgent payment. A manager gets a text followed by a voice note from someone who sounds exactly like the CEO. The employee processes the request because they trust the voice. This attack works particularly well when the impersonated person is traveling or otherwise unreachable for immediate callback.
Vendor and client impersonation. Attackers impersonate a known vendor, supplier, or client to redirect payments. They send updated banking information for an existing vendor relationship, sometimes following up with a phone call using a cloned voice to confirm the request. The business pays what it believes is a legitimate invoice to accounts that the attacker controls. Business email compromise in this form, often enhanced now with voice or video deepfakes, accounted for $2.77 billion in losses in the 2024 Internet Crime Report.
What Illinois Law Says About Deepfake Fraud
Illinois has been ahead of many states on deepfake legislation. The Preventing Deepfakes of Intimate Images Act has been on the books since 2019. In 2023, Illinois amended the law to expand its scope. In May 2025, the federal TAKE IT DOWN Act became law, adding federal protections against nonconsensual intimate deepfakes.
For business fraud specifically, the legal framework draws on existing statutes. Wire fraud under federal law carries penalties of up to 20 years per count. The Computer Fraud and Abuse Act applies when attackers access systems or communications without authorization. Illinois state fraud statutes apply to deceptive practices that cause financial harm.
The harder legal question for businesses is recovery. When a business is defrauded through a deepfake attack, the civil recovery options are limited in practice. The money goes to accounts that are rapidly drained and closed. The attackers are frequently overseas. Law enforcement involvement is critical but recovery rates for wire fraud are very low. The FBI’s advice, and the advice of every attorney who handles these matters, is consistent: prevention is significantly more achievable than recovery.
That means the legal and operational work that matters most happens before the attack, not after.
What Your Business Needs to Do Right Now
The businesses that are getting attacked and losing money have something in common: they had no process in place that required verification before funds moved. The businesses that caught attacks before they succeeded had exactly one thing working in their favor: a callback protocol that required a live, independently initiated call to a known number before any wire transfer was authorized.
That is the single most important protective measure for any business of any size. Before any wire transfer, any change to vendor banking information, or any unusual financial request, there must be a call back to a number you already have on file, not a number provided in the request. This one procedure, implemented consistently, stops the vast majority of deepfake fraud attempts because the attack depends on you not making that call.
Beyond the callback protocol, the measures that matter are:
A written policy requiring dual authorization for any wire transfer above a threshold you define. Two people need to approve and neither of them can be the person who received the original request. The duplication of authorization is what the attacker cannot replicate without compromising two people simultaneously.
Employee training that specifically covers deepfake fraud. Your accounts payable staff, your bookkeeper, your office manager, whoever handles financial transactions in your business, needs to know that voices and faces can be faked. They need to know what a deepfake attack looks like. And they need to know that feeling pressure to act quickly is the signal to slow down, not speed up.
Updated vendor agreements and payment protocols. Any agreement with a vendor that involves ACH transfers or wire payments should include a written provision specifying how banking information changes will be communicated and verified. A clause requiring out-of-band verification of any banking change, meaning verification through a channel other than the one that delivered the change request, is a meaningful contractual protection.
A cybersecurity policy that addresses communication tool risk. WhatsApp, Zoom, and standard phone calls are no longer inherently trustworthy channels for financial instructions. Your policy needs to reflect that and establish which channels are authorized for financial requests and what verification is required regardless of which channel is used.
Cyber liability insurance that specifically covers social engineering fraud. Standard business insurance does not cover wire fraud. Cyber liability policies vary significantly in what they cover, and social engineering fraud riders are not universal. Review your current coverage with your broker and understand specifically whether a deepfake-enabled wire fraud loss would be covered. Most small business owners have never had that conversation.
The Legal Framework for What Happens After
If your business is victimized by deepfake fraud, the immediate steps that preserve your legal options are as follows.
Report to the FBI’s Internet Crime Complaint Center immediately. Time matters. Law enforcement has tools to freeze accounts and attempt asset recovery that are most effective in the first hours after a fraudulent transfer. Every hour of delay reduces the probability of recovery.
Contact your bank immediately and request a wire recall. Banks have limited but real ability to recall recent transfers. This request needs to happen as quickly as possible after discovery.
Document everything. Every communication related to the fraud, every call, every email, every text, every voice message, needs to be preserved exactly as received. Do not delete anything. Do not try to clean up the record. The documentation is the foundation of any subsequent legal action and any insurance claim.
Notify your cyber liability insurer. If you have a policy with social engineering coverage, the notification requirements and deadlines are in the policy. Missing them can void the claim.
Engage legal counsel. Wire fraud investigations involve multiple agencies, potential civil litigation against financial institutions that failed to apply fraud controls, and in some cases actions against technology platforms. The legal landscape after a business fraud incident is complex and moving quickly with your own attorney matters.
The prospect of recovery is real but limited. What is more reliably achievable is building a business that is a harder target than the next one. Attackers make risk calculations. Every verification protocol you build, every employee you train, every policy you document, shifts your business toward the category of targets that are not worth the effort.
About George Bellas
George Bellas Partner, Bellas and Wachowski
George Bellas is a Chicago business attorney with decades of experience helping Illinois businesses navigate commercial disputes, fraud recovery, contract drafting, and the rapidly evolving legal landscape around technology and AI. Deepfake fraud is one of the fastest-growing categories of business crime, and the legal work that matters most is the work done before an attack occurs, not after.
If your business wants to review its vendor agreements, update its financial authorization policies, understand its insurance coverage for social engineering fraud, or simply understand what its legal options look like if it becomes a target, contact George Bellas for a consultation.
Call 800.825.9260 or visit bellas-wachowski.com.
Chicago Business Attorney Blog

