The Cheapest Defence Against a Deepfake Is a Question It Cannot Answer
As voice and video cloning reach finance teams, the most reliable check is not technology but something only the real person would know.

Sign up for my Substack daily AI newsletter here.
See my AI Training course portfolio for corporate Business Leaders here.
Follow me on LinkedIn: https://www.linkedin.com/in/johanosteyn/
In July 2024, an executive at Ferrari began receiving urgent WhatsApp messages, and then a phone call, from a voice that sounded exactly like the company’s chief executive, down to his southern Italian accent. The caller pressed for help with a confidential deal. Growing suspicious, the executive asked one question: the title of a book the chief executive had recently recommended to him, Decalogue of Complexity by Alberto Felice De Toni. The impersonator could not answer, and the call ended. Ferrari lost nothing. A few months earlier, a finance worker at the engineering firm Arup had faced almost the same attack and was not so fortunate.
CONTEXT AND BACKGROUND
At Arup’s Hong Kong office, an employee joined a video call with people who looked and sounded like the firm’s chief financial officer and several colleagues. Every one of them was an AI-generated deepfake. Reassured by the familiar faces, the employee made fifteen transfers totalling about 25 million US dollars, and realised the fraud only when he later checked with head office.
The two cases bracket the same threat. Deepfakes of executives are now cheap to produce, built from the audio and video anyone can gather from earnings calls, conference talks and online meetings, and Deloitte projects that generative-AI-enabled fraud losses in the United States could reach 40 billion dollars by 2027, warning that attacks like the one on Arup will proliferate. The uncomfortable part is that you cannot reliably spot the fake. As one security analysis of the Arup case put it, defending against deepfakes is as much a human challenge as a technological one, because the technology is designed to leave nothing for the eye or ear to catch.
INSIGHT AND ANALYSIS
This is why Ferrari’s escape matters, and why it is instructive rather than lucky. The executive did not detect the deepfake; he defeated it. He moved the test off the call and onto ground the impersonator could not occupy, a shared piece of knowledge that existed only between two real people and that no scraped audio could reproduce. That is the shift every finance team needs to internalise. When you cannot tell a real voice from a synthetic one, the answer is not to listen harder but to verify through a channel and a fact the fake cannot reach. The United States financial-crime authorities give the same advice in plainer form: confirm an unexpected request by hanging up and calling back on a number you already hold, not one supplied in the message.
IMPLICATIONS
For a finance function, the practical response is to build verification that does not depend on recognising a voice. Payments above a threshold should require a second, named approver, and the person who initiates a transfer should not be the person who releases it. Any urgent or confidential instruction, and any change to banking details, should trigger a callback on a number the company already holds, never the one the request arrived on, which is easily spoofed. Teams can agree on simple, unscripted checks for high-value exceptions, of the kind that defeated the Ferrari attack. Above all, urgency should be treated as a reason to slow down rather than speed up, because manufactured time pressure is the weapon these frauds rely on. That discipline holds only if it is company policy, so that an employee who pauses a payment to verify is seen to be doing their job rather than questioning a superior. In South Africa, SABRIC has warned that criminals may increasingly use deepfake audio and video to impersonate executives and bank officials, so local finance teams are in scope, not on the margins.
CLOSING TAKEAWAY
The reassuring lesson of these two calls is that the defence is neither expensive nor technical. Ferrari was saved not by a detector but by a question. As synthetic voices and faces become ordinary, the organisations that keep their money will be the ones that build the humble discipline of verifying, in a way no clone can pass, before the money moves. Against a perfect fake, the strongest defence is an imperfect, human question the machine cannot answer.
Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net




Comments