| John Bosman | 1,071 words
The FBI's Internet Crime Complaint Center logged $16.6 billion in reported losses in 2024 — up 33% from the year before — and deepfake-enabled fraud is one of the fastest-growing pieces of that number. A convincing fake voice or video of a CEO, vendor, or IT department doesn't need to fool a machine; it just needs to fool one person on a finance team for thirty seconds. This page covers the four ways deepfakes actually hit small and medium-sized businesses, what controls make the biggest difference, and where insurance coverage does — and doesn't — respond.
Short answer
Deepfakes hit SMBs mainly through payment fraud and executive impersonation, credential theft disguised as legitimate requests, reputation damage, and customer deception. Fewer approval layers and a culture of wanting to help make smaller businesses attractive targets. Coverage may respond through cyber, social engineering/funds transfer fraud endorsements, or business interruption — but only if the right procedures were followed and the right endorsements are in place.
Reader checkpoint
- Do you require callback verification (to a known, independently-confirmed number) before acting on any urgent wire transfer or vendor banking change request?
- Does your current cyber or crime policy include a social engineering or funds transfer fraud endorsement, or does it only cover unauthorized system access?
- If a deepfake voice or video impersonated your CEO or a vendor tomorrow, do you know which employees would be the first point of failure?
Quick answer
Deepfake-driven fraud most often targets a business through payment fraud (a fake executive or vendor voice requesting an urgent transfer), not through sophisticated technical breaches. The most effective defense is procedural — callback verification and two-person approval — since insurance coverage for these losses depends heavily on whether a social engineering or funds transfer fraud endorsement is actually in place.
At a glance
| Main Issue | Deepfake fraud succeeds by fooling a person, not a system — the FBI logged $16.6B in internet crime losses in 2024, and executive/vendor impersonation is a fast-growing share of it. |
|---|---|
| Common Blind Spot | Assuming standard cyber or crime coverage automatically includes social engineering or funds transfer fraud, when it's often a separate endorsement that has to be added. |
| Useful Document | Current cyber and crime policies (to check for a social engineering/funds transfer fraud endorsement), and your current wire transfer and vendor-change approval process. |
| Best Next Step | Add callback verification and two-person approval for urgent wire transfers and vendor banking changes, and confirm your policy actually includes social engineering coverage. |
Defined Q&A
How Deepfakes Are Impacting Small and Medium-Sized Businesses Today: common questions
Do we require callback verification before acting on urgent wire transfers or vendor banking changes?
Callback verification — calling a known, independently-confirmed number rather than one provided in the message — is the single most effective procedural control against deepfake payment fraud.
Does our cyber or crime policy actually include social engineering or funds transfer fraud coverage?
Social engineering and funds transfer fraud coverage is often a separate endorsement, not automatic. Check your policy declarations and endorsements specifically for these terms.
Do our employees know how to recognize and escalate a suspicious voice or video request?
Training doesn't need to be extensive — employees need to recognize a few key patterns: urgency plus secrecy, sudden payment instruction changes, and requests to bypass normal approval steps.
The FBI's Internet Crime Complaint Center reported $16.6B in internet crime losses in 2024. ic3.gov
The FBI has specifically warned about audio deepfakes being used in impersonation campaigns to manipulate targets into taking actions that benefit the attacker. arstechnica.com
Detection tools can help, but real-world detection is imperfect. Pair tools with verification procedures and clear approval steps. gao.gov
What deepfakes are and why they matter for small businesses
Deepfakes are AI-generated audio, video, or images designed to look and sound real, even when they aren’t. For small and mid-sized businesses, that matters because trust is operational. When an employee believes the “CEO” on a call is real, or a customer believes a fake video is authentic, the business can lose money, data, and credibility quickly.
This article explains how deepfake-enabled scams are showing up in business contexts, what the financial exposure looks like, and how to reduce risk without overcomplicating your operations.
How deepfake fraud is targeting businesses
CEO fraud and wire transfer scams
The most common business deepfake scenario involves impersonating an executive. An employee receives a call or video message that appears to be from the CEO or CFO, requesting an urgent wire transfer. The voice and face match. The request feels legitimate. By the time the fraud is discovered, the money is gone.
According to the FBI’s IC3, business email compromise and related fraud cost U.S. businesses over $2.9 billion in 2023 alone. Deepfake audio is increasingly used to make these attacks more convincing. ic3.gov
Vendor impersonation and invoice fraud
Deepfakes are also used to impersonate vendors, suppliers, or contractors. A business receives a call from a “vendor” with a familiar voice requesting a change to banking details. The change is made. The next payment goes to the fraudster.
Reputational attacks
Fake videos or audio clips can be used to damage a business’s reputation, impersonate customer service, or create false impressions about products or services. These attacks don’t require a wire transfer to cause real harm. arstechnica.com
Detection tools and their limits
Detection tools can help, but real-world detection is imperfect. Pair tools with verification procedures and clear approval steps. gao.gov
How to reduce deepfake risk in your business
Verification procedures
Establish a callback protocol for any wire transfer or banking change request, regardless of how the request arrives. Call back using a known number, not one provided in the request.
Employee awareness
Train employees to recognize the patterns: urgency, unusual requests, and requests that bypass normal approval steps. The goal isn’t to make employees paranoid—it’s to make verification a habit.
Insurance coverage
Cyber insurance and crime coverage can address some deepfake-related losses, but coverage depends on how the fraud was executed and what the policy covers. Review your current program with a focus on social engineering and funds transfer fraud coverage.
What to do next
Use the related tool or ask for a review before you make coverage changes.
Commercial Renewal Readiness Score | Start a Coverage Review | Cyber Liability Insurance