On a Friday at month-end, Sophie B., managing partner of a Swiss accountancy firm, takes a call from one of her partners, who is travelling. The voice is right, the tone is suitably urgent: a deposit to pay today to secure a client file, quietly, before closing. Everything rings true — except her partner never made that call.
This is no longer the stuff of movies. Cloning a convincing voice now takes only a few dozen seconds of recording: a voicemail greeting, an interview, a short clip posted online is enough. For a Swiss SME, where decision chains are short and trust is immediate, the attack is all the more effective.
Why voice phishing targets SMEs
A deepfake is audio or video fabricated by artificial intelligence to imitate a real person — their voice, face and intonation. The word blends “deep learning” (machine learning) and “fake”. What used to be a research problem now fits inside consumer tools: from content already online, a fraudster reconstructs a voice, sometimes a face animated in real time.
Voice phishing — “vishing”, meaning phishing over the phone — is transformed by it. It used to take a gifted impersonator; today a few audio samples and an off-the-shelf tool are enough. And the mechanics are the same as good old CEO fraud (or “BEC”, business email compromise: an email or call that impersonates an executive to trigger a payment). AI doesn’t change the script — it simply makes it far more convincing.
The case that made the headlines involved a large international engineering firm, which acknowledged it publicly: in early 2024, an employee in Hong Kong made a series of transfers worth about 25 million dollars after a video call featuring his chief financial officer and several colleagues. Every one of them was a deepfake. The chilling part is that the employee did exactly what we recommend — asked for a video call to verify. The verification itself was faked.
You might reassure yourself: “A small accountancy firm — who would target us?” That reasoning is precisely what exposes you. The tools have become cheap: attackers no longer need whales to make their scheme pay, so they cast a wide net. An SME often has less formal payment procedures than a large group — an urgent transfer “requested by the boss” sometimes goes through without a second look. And a loss of 50,000 or 100,000 francs, merely embarrassing for a multinational, can lastingly weaken a family business with no legal department and no crisis unit. For an accounting firm, there is an added risk: its clients entrust it with their most sensitive data.
In plain terms, from Camille. You don’t need to understand how AI clones a voice to protect yourself. Just remember one thing: the voice, the face and the number on your screen no longer prove anyone’s identity. From now on, the proof is the one you ask for.
What to keep in mind
First, default trust — “that’s my partner’s voice, so it’s him” — is no longer tenable for a sensitive request. This isn’t paranoia; it’s professional hygiene, no different from checking an IBAN.
Second, the defence is human before it is technical. The companies that have foiled these frauds didn’t do so with detection software, but with a simple reflex: taking back control of the verification. In an attempt targeting a large carmaker, one executive was enough to make the fraudster hang up — by asking a personal question only the real leader could answer.
Third, urgency and secrecy are the two levers of every one of these scams. As soon as a request combines “it’s urgent” and “don’t tell anyone”, the right reflex is not to speed up, but to slow down. These signals matter more than the so-called “technical tells” of a deepfake: the micro-glitches in voice or image, quite real two years ago, fade as the tools improve. You can no longer rely on your ear — only on your procedure.
And if the transfer has already gone out? Every hour counts. Two immediate steps, before anything else: call your bank to attempt a recall of the funds (sometimes possible in the very first hours), and file a report with the cantonal police. If personal data leaked in the process, a notification to the Swiss data protection authority (FDPIC) may also be required. The detailed playbook — who to call, in what order, with what message — belongs to a response plan you prepare cold, not in a panic.
The reflexes to install this week
1. A verbal password for payment requests
Agree out loud, off any digital channel, on a word or question that only signatories know — a detail found nowhere online. Any unusual transfer request requires that word. A cloned voice cannot answer what it never learned. It’s rudimentary, and that is exactly why it works.
2. A systematic call-back to a known number
No financial request received by phone, message or video is validated on the incoming channel. You hang up and call the person back on the number saved in your contacts — never the one displayed, nor one given during the call. Thirty seconds of checking weighs little against the time spent cleaning up a fraud.
3. Dual approval above a threshold
Set an amount above which two people approve every payment, on two different channels. A request that came by email is confirmed by voice; a spoken request is confirmed in writing. It’s the least technological measure on the list, and the most effective: it turns a lonely, rushed decision into a four-eyes control.
Where do you really stand?
Faced with voice phishing, the real question isn’t “would I spot a deepfake?” but “do my payment procedures survive a perfectly credible request?”. These reflexes fall under payment governance and staff awareness — two areas expected of any business handling sensitive data under the nFADP (Switzerland’s new Federal Act on Data Protection, in force since September 2023), and on which the National Cyber Security Centre (NCSC) regularly issues guidance. The legal framework itself lags behind: in Europe, the AI Act has, since August 2026, required certain AI-generated content to be labelled, but no law protects you in place of your own procedures.
Cyber Passport certifies nothing: the self-assessment shows you, question by question, where your organisation is solid and where it still rests on interpersonal trust alone. And to work through the full procedure — approval thresholds, call-back circuit, verification script, an awareness outline and a response plan for when the fraud succeeds — the “CEO fraud” blueprint gives you ready-to-use templates to adapt to your SME.



