By Anat Goldstein and Farook Sattar
A finance worker at a multinational firm received what appeared to be a legitimate call from someone claiming to be the company’s CFO. The person receiving the call ended up transferring $25 million. The reality: The CFO’s voice was AI generated. The CFO never made that call.
That incident is no longer an outlier. Voice fraud in banking increased by roughly 30 percent in 2025, with AI-powered synthetic voices capable of fooling even experienced professionals. Synthetic voice attacks against financial institutions rose sharply in 2024, increasing by a factor of approximately 20 compared to the prior year, as data from the same period indicated that roughly one in 750 banking calls was flagged as potentially fraudulent.
Commercial AI voice-cloning tools have significantly reduced the barrier to entry for attackers. As synthetic voice technology becomes…
CLICK HERE to read the FULL The voice fraud threat to banking | ABA Banking Journal article.
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
