{"id":30971,"date":"2026-08-21T12:56:42","date_gmt":"2026-08-21T09:56:42","guid":{"rendered":"https:\/\/safetech.ro\/vishing-bec-and-cloned-voice-how-to-prevent-ai-amplified-financial-fraud\/"},"modified":"2026-08-21T14:04:32","modified_gmt":"2026-08-21T11:04:32","slug":"vishing-bec-cloned-voice-how-to-prevent-ai-amplified-financial-fraud","status":"publish","type":"post","link":"https:\/\/safetech.ro\/en\/vishing-bec-cloned-voice-how-to-prevent-ai-amplified-financial-fraud\/","title":{"rendered":"Vishing, BEC, and Cloned Voice: How to Prevent AI-Amplified Financial Fraud"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30971\" class=\"elementor elementor-30971 elementor-30958\">\n\t\t\t\t<main class=\"elementor-element elementor-element-1b74bef e-flex e-con-boxed e-con e-parent\" data-id=\"1b74bef\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-92eb681 elementor-widget elementor-widget-ld_breadcrumb\" data-id=\"92eb681\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"ld_breadcrumb.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"lqd-breadcrumb-wrapper\"><nav role=\"navigation\" aria-label=\"Breadcrumbs\" class=\"breadcrumbs\"><ol class=\"breadcrumb reset-ul inline-nav inline-ul comma-sep-li\"><li class=\"breadcrumb-item active\"><a href=\"https:\/\/safetech.ro\/en\/\" rel=\"home\"><span>Home<\/span><\/a><\/li><\/ol><\/nav><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0cc6a1d elementor-widget elementor-widget-table-of-contents\" data-id=\"0cc6a1d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"table-of-contents.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t \t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f34bf2f elementor-widget elementor-widget-text-editor\" data-id=\"f34bf2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3>Vishing, BEC, and Cloned Voice: How to Prevent AI-Amplified Financial Fraud<\/h3><p>Finance and operations departments are facing a new reality: cybercrime has become a sophisticated industry, based on &#8220;Fraud-as-a-Service&#8221; and artificial intelligence (AI) technologies that erode the last barriers of trust in remote communication. In recent years, compromising IT infrastructure has become an intermediate goal in attackers targeting an organization&#8217;s financial fraud.<\/p><p>A recent example, documented in the <strong><a href=\"https:\/\/www.dnsc.ro\/vezi\/document\/dnsc-raport-anual-2025\" target=\"_blank\" rel=\"noopener\">2025 Annual Report of the Romanian National Directorate of Cyber Security<\/a><\/strong> , illustrates this vulnerability: Tohan SA of the ROMARM group was the victim of a Business Email Compromise (BEC) attack. Attackers took control of critical email addresses (office@ and achizi\u021bii@) and set up automatic redirects, facilitating Man-In-The-Middle (MitM) attacks. By discreetly modifying documents in legitimate conversations, hackers hijacked commercial payments, causing more than \u20ac20,000 in damage. The Tohan SA case is not an isolated incident, but a demonstration of how standard procedures can be circumvented by systematically manipulating the flow of information.<\/p><h3>Reality on the ground: BEC and Vishing in numbers<\/h3><p>According to the reports <strong><a href=\"https:\/\/www.enisa.europa.eu\/sites\/default\/files\/2026-01\/ENISA Threat Landscape 2025_v1.2.pdf\" target=\"_blank\" rel=\"noopener\">ENISA Threat Landscape 2025<\/a><\/strong> and <strong><a href=\"https:\/\/www.europol.europa.eu\/cms\/sites\/default\/files\/documents\/IOCTA-2026.pdf\" target=\"_blank\" rel=\"noopener\">IOCTA 2026<\/a><\/strong> of Europol, online fraud is the fastest growing area of organised crime. Phishing and vishing (voice phishing) make up about 60% of the initial attack vectors. Artificial intelligence amplifies the threat by:<\/p><ul><li>Eliminating grammatical and stylistic mistakes \u2013 messages are clearly more convincing.<\/li><li>Voice cloning: A synthetic voice can faithfully reproduce a director&#8217;s timbre, rhythm, and vocal tics.<\/li><li>Generating deepfake video content that reinforces the impression of legitimacy.<\/li><li>Real-time translation and automation of massive contact with victims.<\/li><\/ul><p>In Romania, DNSC data constantly highlights a dangerous rise in vishing attacks, based on phone spoofing and social engineering. The attackers impersonate the executive leadership, banks, authorities. The target: the financial and operational departments where a single decision can mobilize tens or hundreds of thousands of Euro, as shown in the aforementioned case.<\/p><h3>The Anatomy of a Hybrid Attack: The Process Behind the Losses<\/h3><p>The experience gained by Safetech Innovations shows that a modern attack is not a spontaneous event, but a layered, carefully orchestrated process:<\/p><ol><li><strong>Reconnaissance (OSINT)<\/strong>: Collecting public information from company websites, LinkedIn, and business registers. Identifying the management structure, suppliers, current projects, and vacation periods of decision-makers. Extracting voice samples from interviews or public webinars to create the &#8220;voiceprint&#8221; needed for deepfake.<\/li><li><strong>Initial access<\/strong>: Compromising an account through phishing, theft of session tokens (AiTM), or reused credentials. The attacker does not act immediately; He &#8220;lives&#8221; in the account, monitoring conversations, invoices, and speech style, setting up hidden forwarding rules to avoid detection.<\/li><li><strong>Impersonation Preparation<\/strong>: Generating a voice clone of the director or CFO and setting up a spoofed Caller ID. VoIP technology allows the victim&#8217;s legitimate company or directory number to appear on the victim&#8217;s screen.<\/li><li><strong>Pitching and Psychological Pressure<\/strong>: Injecting the fraudulent message into a real email flow. Invoking a confidential purchase or surprise audit. Time pressure (&#8220;it must be done urgently before the bank closes&#8221;) is the key element that blocks the employee&#8217;s critical thinking.<\/li><li><strong>Exfiltration and Trace Deletion<\/strong>: After confirming the payment, the attackers delete compromising messages and try to modify the logs to delay the discovery of the fraud until the funds are dispersed through intermediary accounts and cryptocurrencies.<\/li><\/ol><p>Frequent risk situations in the operational reality:<\/p><table><tbody><tr><td width=\"192\"><strong>Department<\/strong><\/td><td width=\"192\"><strong>Risk scenario<\/strong><\/td><td width=\"192\"><strong>Essential Control<\/strong><\/td><\/tr><tr><td width=\"192\"><strong>Finance<\/strong><\/td><td width=\"192\">Urgent payment &#8220;requested by the CEO<\/td><td width=\"192\">Mandatory independent callback and dual approval<\/td><\/tr><tr><td width=\"192\"><strong>Procurement<\/strong><\/td><td width=\"192\">Change of provider bank account<\/td><td width=\"192\">Validation via contact details pre-registered in ERP<\/td><\/tr><tr><td width=\"192\"><strong>HR<\/strong><\/td><td width=\"192\">Modificarea contului de salariu<\/td><td width=\"192\">Verificare direct\u0103 \u0219i eventual fizic\u0103 a identit\u0103\u021bii angajatului<\/td><\/tr><tr><td width=\"192\"><strong>Customer Service<\/strong><\/td><td width=\"192\">Refund or change of account<\/td><td width=\"192\">Exception logging and multi-channel validation<\/td><\/tr><\/tbody><\/table><h3>Technical, procedural and human controls. What works and what limits are there?<\/h3><p>Given both international statistics and the constant recommendations of the DNSC, organizations in Romania must understand that voice, image and email address are no longer sufficient evidence of identity. No isolated control can guarantee the complete blocking of an advanced BEC or vishing attack. A robust defense requires a layered architecture:<\/p><ul><li>Basic and advanced technical controls: Implementing DMARC policy in reject mode significantly reduces the risk of direct domain spoofing. Multi-factor authentication (MFA) must be resistant to phishing (based on FIDO2\/hardware keys), eliminating the classic vulnerabilities of OTP codes received via SMS or push notifications (vulnerable to MFA fatigue or AiTM attacks). Also, behavioral monitoring through EDR and XDR\/SIEM solutions is essential to detect logins from unusual locations or the sudden creation of email forwarding rules.<\/li><li>The limits of technology: Email filters and automatic deepfake detectors are not an absolute shield. A compromised legitimate account will pass SPF\/DKIM\/DMARC filters because the email leaves an authorized infrastructure. That is why the technology must be complemented by process controls.<\/li><li>Procedural and personnel measures:<ul><li>Independent callback: No request for urgent payment or change of IBAN is honored without the employee closing the call and calling the person on a pre-existing and validated number from the internal address book (never on the number indicated in the suspicious message).<\/li><li>Dual approval without exceptions: Strict separation of roles (the one who enters the data is not the one who approves the payment) and the imposition of clear value thresholds. No executive authority should be able to override this flow by verbal provisions.<\/li><\/ul><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-90fb21e elementor-widget elementor-widget-image\" data-id=\"90fb21e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"780\" height=\"439\" src=\"https:\/\/safetech.ro\/wp-content\/uploads\/2026\/08\/Vishing-BEC-fraud-prevention-1024x576.webp\" class=\"attachment-large size-large wp-image-30966\" alt=\"\" srcset=\"https:\/\/safetech.ro\/wp-content\/uploads\/2026\/08\/Vishing-BEC-fraud-prevention-1024x576.webp 1024w, https:\/\/safetech.ro\/wp-content\/uploads\/2026\/08\/Vishing-BEC-fraud-prevention-300x169.webp 300w, https:\/\/safetech.ro\/wp-content\/uploads\/2026\/08\/Vishing-BEC-fraud-prevention-1536x864.webp 1536w, https:\/\/safetech.ro\/wp-content\/uploads\/2026\/08\/Vishing-BEC-fraud-prevention.webp 1672w\" sizes=\"(max-width: 780px) 100vw, 780px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e900971 elementor-widget elementor-widget-text-editor\" data-id=\"e900971\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3>How does Safetech Innovations help?<\/h3>\n<p>Preventing BEC fraud, vishing, or impersonation-based attacks does not mean implementing a single product or control. Practical experience shows that each mechanism has its own limits: MFA can be bypassed by stealing a session, SPF\/DKIM\/DMARC cannot stop messages transmitted from a compromised legitimate account, and vishing and cloned voice can bypass email infrastructure altogether. That&#8217;s why organizations need a layered approach that combines identity and email protection with endpoint security, access control, suspicious behavior monitoring, and last but not least, independent verification of financial transactions.  <\/p>\n<p>Safetech can support organizations throughout this process, from assessing the security posture and identifying vulnerable points, to implementing and monitoring the controls necessary to detect an attack before it has a financial impact.<\/p>\n<p>Safetech&#8217;s monitoring and response services, including SOC as a Service, can correlate different events in the access and identity area, email, endpoint, and network. Safetch experts use multiple technologies such as SIEM, EDR, NDR and XDR and thus manage to correlate signals that, analyzed individually, seem insignificant. Thus, an unusual authentication, the creation of a forwarding rule, or suspicious activity on an endpoint can be investigated as part of a potential chain of compromise.  <\/p>\n<p>At the same time, as a preventive approach, Safetech can support the assessment of the security posture, vulnerability management and the implementation of detection and protection controls.<\/p>\n<p>Safetech&#8217;s experience in critical incidents leads to a better understanding of risks and the creation of a security architecture tailored to the specifics of the organization and, therefore, with a higher level of resilience.<\/p>\n<p>For more information on preventing compromised business email fraud and impersonation-based attacks, contact us at email marketing @ safetech.ro or by phone +40 21 3160565 .<\/p>\n<h3>FAQ: What you need to know about vishing, BEC and cloned voice<\/h3>\n<p><strong>1. Why is the director&#8217;s &#8220;voice recognition&#8221; no longer secure? <\/strong><\/p>\n<p>AI voice cloning can faithfully replicate timbre, rhythm, and intonation. In a short, pressured call, the human brain tends to ignore discrepancies. Authentication must be done through the communication channel (process), not through the subjective impression left by the voice of the interlocutor.  <\/p>\n<p><strong>2. Which technical control prevents the most effective BEC? <\/strong><\/p>\n<p>MFA based on hardware keys (FIDO2) is the gold standard against credential theft. However, behavioral monitoring of accounts and automatic alerting in case of suspicious changes are what stop an attack that has already penetrated inside the organization. <\/p>\n<p><strong>3. How do we maintain the speed of payments without sacrificing security? <\/strong><\/p>\n<p>By automating approval flows in ERP systems and using strict registers of approved beneficiaries. Any change in bank data automatically triggers an additional validation protocol, without blocking the normal operational flow. <\/p>\n<p><strong>4. What proof of &#8220;training&#8221; can I present to the board?<\/strong><\/p>\n<p>Detailed reports on Tabletop practice exercises and multichannel simulations. They provide management with concrete metrics about the internal detection rate, the response times of the finance department and the level of compliance with anti-fraud procedures. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/main>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Safetech offers end-to-end support in assessing cybersecurity posture, implementing layered controls, and providing monitoring and response services to detect and prevent fraud before financial impact occurs.<\/p>\n","protected":false},"author":2,"featured_media":30960,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[101],"tags":[103,106,110,111],"class_list":["post-30971","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology-news","tag-cert-en","tag-monitoring-and-response","tag-risk-management","tag-security-testing"],"_links":{"self":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts\/30971","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/comments?post=30971"}],"version-history":[{"count":8,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts\/30971\/revisions"}],"predecessor-version":[{"id":30982,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts\/30971\/revisions\/30982"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/media\/30960"}],"wp:attachment":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/media?parent=30971"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/categories?post=30971"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/tags?post=30971"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}