Back to Blog
Cybersecurity8 min read

AI Voice Cloning and Deepfake Fraud: A Practical Defence Guide for Canadian SMBs

By Anton Kuznetsov

In February 2024, a finance employee at the Hong Kong office of global engineering firm Arup joined a video conference with what appeared to be the company's CFO and several colleagues. Everyone looked and sounded familiar. By the end of the call, the employee had authorized 15 wire transfers totalling $25.6 million USD. Every other participant on that call was a real-time AI deepfake. Hong Kong police confirmed the fraud in February 2024; the funds remain unrecovered.

The attackers did not compromise any systems or networks. They reconstructed convincing audio and video likenesses of Arup's executives from footage scraped off LinkedIn, YouTube, and publicly available earnings calls. That same methodology is now accessible as a service, available to criminal groups targeting Canadian SMBs.


The Canadian Threat Landscape

Canadian businesses are already in the crosshairs. In 2025, the Canadian Anti-Fraud Centre (CAFC) recorded more than $704 million in reported fraud losses — Canada's worst year on record — with the CAFC and RCMP estimating the true figure is between $3.5 billion and $7 billion, since only 5 to 10 percent of fraud is ever reported.

Impersonation fraud grew 356% between 2023 and 2024. The CAFC, RCMP, and Competition Bureau designated it the focus of Fraud Prevention Month 2025 as one of the fastest-growing forms of fraud in Canada.

AI voice cloning is now a significant driver of that growth. CAFC data tracked by Canadian financial researchers shows that AI voice-cloning emergency scams alone cost Canadians $9.2 million in a single year. In those cases, callers cloned the voice of a family member to convince parents there was a kidnapping or legal emergency — and to wire funds immediately. The same technical infrastructure is being directed at finance teams, HR departments, and IT staff inside Canadian businesses.

In June 2025, the CCCS, CAFC, and RCMP issued a joint advisory warning that an active malicious campaign was using AI-generated voices to impersonate senior Canadian officials and public figures, and that identical tactics were being deployed against Canadian organizations. In June 2026, the Canadian Centre for Cyber Security issued a formal statement on frontier AI models specifically flagging the capability uplift these tools provide to threat actors conducting social engineering at scale.

This is not a future risk being monitored from a distance. It is an active threat with confirmed Canadian victims.


How the Attack Actually Works

Modern deepfake voice fraud requires three to five minutes of audio — easily sourced from a LinkedIn video, a company podcast episode, a YouTube investor presentation, or a recorded webinar. That input is enough for commercially available voice-cloning tools to produce a real-time synthetic voice that human ears cannot reliably distinguish from the original. Researchers have found that people perform barely better than chance when asked to identify sophisticated deepfake audio without technological assistance.

The attack sequence follows a consistent pattern:

1. Reconnaissance. Attackers map the target organization's executive names, titles, and reporting relationships — all available from LinkedIn and company websites. They collect audio and video samples from public sources. Senior executives who regularly appear on webinars, podcast interviews, or investor calls provide the richest training material.

2. Initial contact. An email arrives from a spoofed or newly registered lookalike domain, creating urgency around a pending deal, acquisition, compliance deadline, or CRA payment.

3. The call. The target receives a voice or video call from what sounds and appears to be their CEO, CFO, or a known colleague. The caller references specific internal details gathered during reconnaissance to establish credibility. For more sophisticated attacks — as in the Arup case — the call is a real-time deepfake video conference with multiple synthetic participants.

4. The request. The fraudster creates a time-pressured situation: a wire transfer must complete today, vendor banking details have changed, a payroll adjustment is needed urgently. The request is framed to bypass normal approval chains because it appears to come from the top of the organization.

5. Exfiltration. Wire transfers move to accounts that are rapidly drained across multiple jurisdictions. Recovery rates are very low; law enforcement crossing international boundaries compounds the difficulty.

The FBI's 2025 Internet Crime Report introduced AI as a formal crime category for the first time, logging over 22,000 complaints and approximately $893 million in losses attributable to AI-enabled fraud. Business Email Compromise overall — the broader category that now incorporates voice and video deepfake variants — drove $3.046 billion in losses in 2025, with an average loss per incident exceeding $122,000.


Why Canadian SMBs Are a High-Value Target

Enterprise organizations typically have treasury controls, dedicated fraud operations teams, and callback verification procedures embedded in their financial workflows. Canadian SMBs generally do not.

According to the 2026 IBM Cost of a Data Breach Report, Canadian organizations took an average of 205 days to detect and contain a breach — a 6% increase over the prior year — and paid an average of $7.11 million per incident. The same report found that 1 in 6 breaches now involved AI-enabled attack methods, with deepfake impersonation accounting for 35% of those AI-assisted events.

The Verizon 2026 Data Breach Investigations Report found that pretexting — building a fabricated scenario to manipulate a target — now accounts for more than 50% of all social engineering incidents. CrowdStrike measured vishing (fraudulent voice calls) growing 442% between the first and second half of 2024 alone. By the time a Canadian SMB owner starts reading about this threat category, the attack volume targeting businesses is already substantial.

The profile of a high-risk Canadian SMB looks like this: publicly listed executives with accessible audio or video, a finance team that handles wire transfers or vendor payments, fewer than 50 employees (meaning fewer approval layers between a request and execution), and a perception that the organization is too small to be worth targeting. Attackers actively select for this profile because conversion rates are higher than for large enterprises with mature controls.


Six Practical Defences That Do Not Require a Security Team

None of the following controls require specialized security staff or significant budget. They require deliberate process design and consistent enforcement.

Establish a pre-agreed verification phrase for any out-of-cycle payment request. Create a secret phrase known only to the authorized signatories for financial transactions. Any request for an unscheduled wire transfer, vendor banking change, or payroll adjustment must include this phrase before it is acted upon — regardless of who appears to be asking and regardless of the urgency framing. CISA, the FBI, and NSA jointly recommend this as the single most effective procedural defence against executive impersonation fraud.

Require out-of-band callback verification for all changed payment instructions. When vendor banking details change — even by a single digit — call the vendor at their established phone number before processing the first payment to the new account. Never use a number provided in the email requesting the change. This one control defeats a significant fraction of deepfake-assisted payment fraud because it breaks the attacker's control over the communication channel.

Set a dual-approval threshold for wire transfers. No single individual should be able to authorize a wire transfer without a second approver confirming through a separate channel. A threshold of C$5,000 is a reasonable starting point for most Canadian SMBs. Make the second approval mandatory, not advisory.

Limit the public audio and video footprint of executives who have signing authority. Every public recording of an executive's voice or video is raw material for voice cloning. This does not mean going dark. It means being deliberate: review what is publicly posted on the company website, LinkedIn, YouTube, and podcast platforms, and consider whether that material needs to remain publicly accessible.

Treat urgency as a red flag, not a reason to accelerate. The core social engineering mechanism in deepfake fraud is time pressure. A standing policy stating that no financial instruction received under unusual time pressure is processed without a cooling-off callback gives employees clear authority to push back — and shifts the burden back to the attacker.

Update security awareness training to cover voice and video fraud explicitly. Most Canadian SMB security training still focuses on email phishing. Employees need to know that a caller sounding exactly like the CEO is not proof of identity, that a video call showing a familiar face is not proof of identity, and that requesting a callback to a known number from a legitimate executive is always appropriate when an unusual financial request arrives by phone.


Monitoring for Impersonation Infrastructure

Attackers typically register lookalike domains weeks before an attack campaign begins. Services such as Microsoft Defender for Office 365 and dedicated domain monitoring tools flag newly registered domains that resemble your company's domain — giving advance warning before the first call arrives.

The CCCS National Cyber Threat Assessment 2025-2026 explicitly identifies AI-generated audio and visual deepfakes as an active threat vector used by cybercriminals and state-sponsored actors alike, noting that "generative AI tools enable cyber threat actors to create realistic audio and visual content impersonating trusted individuals." The CCCS recommends that organizations train staff specifically on how to handle vishing attempts and implement internal protocols for verifying identity over the phone when sensitive information or financial transactions are involved.

The fraud infrastructure is built. The attack playbooks are proven. The countermeasures are straightforward. Canadian SMBs that implement them now are significantly harder to victimize than those waiting for a closer call.


Sources


Cloud Forces helps Canadian SMBs implement the process controls, staff training, and monitoring that make AI voice cloning and deepfake fraud significantly harder to execute successfully. If your organization does not yet have dual-approval wire transfer controls, out-of-band callback verification policies, or security awareness training that covers AI-enhanced social engineering, we can help you put them in place. Explore our Cybersecurity services or contact us to book a no-cost security assessment.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation