
The Swiss Federal Office for Cybersecurity counted 971 reported cases of CEO fraud for 2025, up from 719 the year before. That makes it one of the most frequently reported types of fraud in Switzerland. The pattern behind it is old: someone poses as the boss, it is urgent, it is confidential, and at the end there is a payment.
What is new is the soundtrack.
In August 2026 the BACS wrote down how little a deepfake fraud attempt requires. Cloning a voice currently takes an audio file of around ten seconds. The reason attackers bother at all is uncomfortably plain: a voice is trusted more than an email.
Most companies respond by asking how to spot a cloned voice. That is the question whose answer gets worse every year. Another one lasts longer: what does a payment release actually depend on in your company?
What AI changed about CEO fraud
The sequence the BACS describes needs no technical magic. The attackers research LinkedIn and your website to work out who reports to whom and who triggers payments. Then an email arrives from the supposed superior, often from a domain with one letter swapped. Urgent and discreet, with pressure.
What AI adds are layers of credibility. First the writing style: criminals use AI tools to imitate the way the real superior expresses himself. Then the voice, in the form of deepfake audio calls and voice messages. And by now the image as well. The BACS notes that AI can quickly generate video from static pictures. A portrait photo from your team page is enough raw material.
In economic terms this is not a new type of attack. It is a price cut. What used to require talent, time and language skills now costs a subscription. The kind of attacks stays the same. Their hit rate goes up.
That also shifts the calculation of when an attempt pays off. Anyone who had to invest half a week of preparation concentrated on targets with large amounts. Anyone who needs ten seconds of audio and a photo can run the same scam against a company with eighty people and still work profitably. That is why deepfake fraud is arriving at Swiss SMEs right now.
Why detection does not protect you against deepfake fraud
The reflex after reports like these is awareness training. We have looked at the uses and limits of security awareness training elsewhere, and with deepfakes that limit is particularly visible.
Training works with signals. The clumsy sentence, the wrong form of address, the sender that does not hold up on a second look. Generative AI clears those signals away. You are training a marker that the attacker fixes first.
On top of that comes a timing problem. The decision whether a voice on the phone is real is made within seconds, under pressure, facing a person with authority to give instructions. That is not a situation in which knowledge reliably wins.
We are not saying this against training. It is useful for what it can do: giving people permission to be unsure and put the phone down anyway. As a last line of defence it does not work. We made the same argument about phishing prevention, where the click belongs in the plan from the start.
In our experience the employees who stopped one of these cases almost never spotted the fake. They had a rule.
Where the money leaves the building
A deepfake call aims at one of a small number of doors with money or access behind them. Those doors can be counted, and that makes the problem workable.
The first is a payment release outside the usual path. Friday afternoon, the accountant is alone in the office, a voice message from the managing director: an acquisition, strictly confidential, the lawyer will be in touch shortly, the down payment has to go out today. The voice is right. The urgency explains why the usual path does not work this time. The confidentiality explains why she should not ask anyone. The technology only supplies the voice here. What opens the way to the money is an exception rule that existed before.
The second door gets overlooked more often: the master data change. An existing supplier reports new bank details. No time pressure, no drama, just one field in the accounting system. The next three invoices run entirely normally, into someone else's account. It can only become visible when the real supplier sends a reminder. The BACS recommends the same four eyes principle for payments and for master data changes.
The third door is the internal help desk. A call in a familiar voice, a reset password, a newly registered second factor. After that nobody needs a forged voice any more, because the account is real. Closing this door needs no product: a reset is confirmed over a channel that is not part of the call itself, for example through the line manager or through the already registered device. If your help desk is external, that rule belongs in the contract rather than in the culture.
All three routes run through processes you already have. The only question is whether they are written down or whether they live in the heads of two people.
The myth of the silent call
One piece of advice circulating on this topic costs more attention than it delivers: do not take unknown calls, say nothing, or your voice will be cloned.
The BACS addressed this explicitly in August 2026. That a simple "hello" or saying your own name is enough for a complete voice clone is unlikely. A targeted attempt needs a longer conversation.
An authority damping down the excitement around its own topic is a rare thing. Take it. In practical terms it is a relief, because the voice of your managing director is not a secret. It sits in the podcast interview, the webinar recording, the video message on the home page, the phone announcement. Ten seconds of it are publicly available, and no behavioural tip changes that.
A defence that relies on the boss's voice staying secret is therefore finished before it starts. What remains is the defence that works without the voice.
What you do not have to buy against deepfake fraud
There is software meant to detect deepfakes, and it is being sold right now. We have no solid basis for telling you how well that kind of detection works in the daily life of an SME. That is the objection. You would have to entrust it with a decision whose quality you cannot measure, in a field where the other side improves every few months.
The callback rule you can measure. It was followed or it was not, and that shows up in the record. Security you can verify is worth more than security you have to believe in. On this topic it is also the cheaper option.
The rule that does not need to know whether the voice was real
The BACS names verification over a second channel as the measure: call the caller back on the known number. That sounds like very little. It is the whole point.
A callback to the number stored in your system works regardless of how good the fake was. The rule does not check the voice, it checks the channel. That is why it does not age with the technology.
The number comes from your system, never from the message. A callback number printed in the same email as the payment request checks nothing.
The threshold is set in advance and written down. Above which amount is a second person mandatory, and who is that second person when she is on holiday? Without an answer to the deputy question, the rule gets bypassed at the first bottleneck and then only exists on paper.
And the rule applies to everyone. That is where it fails most often in practice. A release rule that management exempts itself from is a recommendation for subordinates. Whoever releases payments has to be able to contradict a call from their own boss without having to justify it later. That permission can only come from the top, and it has to be said out loud. Which puts the topic where cybersecurity as a question of oversight and liability belongs anyway.
For the same reason we do not treat AI risk and the safe adoption of AI separately from the rest of the security work. The tools your people use and the tools used against them belong in the same risk picture. If you are already working out which AI is circulating in your company, take the release question along with it.
The next three payments
The check takes less than an hour. Take the last three payments above your threshold and follow them up. Who triggered them, who released them, and over which channel was that confirmed. Then do the same for the most recently changed supplier bank details.
If the answer anywhere is "by email" or "the boss told me", you have found your gap. It is organisational, it costs nothing but a decision, and it closes faster than any tool can be procured.
If you want to know how your release paths would hold up against a targeted attempt, we will go through it with you in a structured way. A first conversation is without obligation.
One question stays open for us, and we have no solid figures on it: how many of these cases in Swiss SMEs get reported at all, when the person who released the payment would be the one answering for it?
Frequently asked questions
How do you protect a company against deepfake fraud?
Through the release path, not through detection. The BACS recommends verification over a second channel: call the caller back on the number stored in your system, never on the number from the message. Add a second person above a defined amount and the same four eyes principle for changes to supplier bank details.
How much audio does it take to clone a voice?
In August 2026 the BACS noted that cloning a voice currently takes an audio file of around ten seconds. For most executives those ten seconds are publicly available, for example in a podcast, a webinar recording or a video message on the company website.
Can my voice be cloned if I answer an unknown call?
The BACS considers it unlikely that a simple hello or saying your own name is enough for a complete voice clone. A targeted attempt needs a longer conversation. Not answering calls is therefore not an effective protective measure, while a callback rule for payments is.




