A finance officer takes a call at ten past four on a Thursday. It is the chairman. The voice is right — the clipped delivery, the habit of starting sentences with "listen", the faint irritation of a man between meetings. He is closing something sensitive, the lawyers need a deposit before the banks shut, and he will explain properly tomorrow. The officer moves the money because the officer recognises the voice. That recognition is the entire attack.

What actually changed

Voice cloning stopped being a laboratory exercise and became a product. McAfee's research found that three seconds of audio is enough to produce a voice match of roughly eighty-five per cent — close enough that the people who speak to you daily will not question it over a phone line. More audio makes it better. A twenty-minute recording of you at a chamber of commerce event produces something close to indistinguishable.

The raw material is not stolen. It is published. Conference panels on YouTube, a television interview, a podcast appearance, an Eid message posted to the company Facebook page, the voicemail greeting on your own mobile, a voice note you sent to a WhatsApp group of forty people. Anyone building a clone of a Bangladeshi business figure does not need to breach anything — they need an afternoon and a search engine.

The scale is no longer speculative either. Pindrop's 2025 Voice Intelligence and Security Report measured a surge of around 1,300 per cent in deepfake fraud attempts reaching contact centres, moving from roughly one a month to several a day. In May 2025 the FBI's IC3 issued a public warning that criminals were impersonating senior US officials with AI-generated voice messages to reach their contacts. The reference case for corporate loss remains the engineering consultancy Arup, which publicly confirmed in May 2024 that a synthetic-media video call had cost it around twenty-five million US dollars.

Act on this: search your own name on YouTube and Facebook this week and count the minutes of your recorded voice that are publicly available. That number is your exposure. You will not get it to zero, and you should not try — the point is to stop assuming an attacker has nothing to work with.

Voice was never a credential

Most Bangladeshi companies have never written down how a payment gets authorised, because everyone knows how it works — the boss says so. Voice recognition became the control by accident. Nobody chose it, nobody documented it, and nobody tested whether it could be forged.

It can. And unlike a password, you cannot change your voice after it leaks. This is the fundamental problem with any biometric used as a shared secret — it is permanently public, permanently attached to you, and now permanently reproducible. A voice on a phone line is evidence of nothing except that someone had a recording.

The same applies to the things that usually accompany the voice. Caller ID is trivially spoofed. A WhatsApp account with your photograph and a number one digit off yours will pass inspection on a busy Thursday. A video call is no longer a defence either — the Arup case involved a call with multiple synthetic participants, and the one real person on it was the victim.

Act on this: write one sentence and circulate it to everyone who can move money — "no payment or credential change is ever authorised by a voice call, a video call, or a WhatsApp message, regardless of who appears to be asking." Get it signed off by the chairman personally, because the whole control depends on staff believing they will not be punished for doubting him.

The callback protocol

The fix is unglamorous and it works. Verification must move to a channel the attacker does not control, initiated by the person receiving the request. Not the person making it.

  • Hang up and call back on a stored number. The number in your phone's contacts, saved before today, or in HR records. Never a number offered during the call, never the number that appears on the display, never a number in the email signature of the message that prompted the call.
  • Change the medium. If the request arrived by voice, verify by a channel with an audit trail — a message inside the corporate email system, or an internal chat account protected by multi-factor authentication. Two suspicious phone calls do not verify each other.
  • Set a threshold and a second pair of eyes. Pick an amount that would genuinely hurt — for many family businesses this is far lower than the accounting team assumes — and require two named people to approve above it. The attacker's script depends on isolating one person under time pressure.
  • Impose a cooling-off period on new beneficiaries. Any first payment to an account that has never received money from you before waits twenty-four hours, no exceptions. Almost every one of these frauds requires a new beneficiary. The delay costs a legitimate deal nothing and breaks the fraudulent one entirely.
Urgency is not a reason to skip verification. Urgency is the reason verification exists.

Act on this: the protocol only works if it survives contact with a genuinely angry executive. Tell your finance team, in writing, that a callback is mandatory even when the caller objects — and especially then. A real chairman will wait ninety seconds. An impersonator cannot afford to.

The version that targets your family

Executives protect the company and leave the household open. The domestic variant of this fraud does not ask for a corporate transfer — it is a distressed call from a son stranded abroad, a daughter in an accident, a driver claiming detention, sometimes accompanied by an implication of kidnapping. The voice is cloned from whatever the child has posted online, which for anyone under thirty is a great deal.

The countermeasure is a safe word. A short phrase, agreed in person, never written in any chat and never stored on a phone. Anyone claiming distress on a call must produce it. If they cannot, you hang up and reach them on their own number.

Teach it to everyone in the house, including staff and drivers, and pick something unguessable — not the name of a pet or a school that appears on somebody's Facebook profile. Two unrelated words work best. Then rehearse it once, so that the person under real stress remembers there is a procedure at all.

Act on this: agree a family safe word at dinner tonight, and set every family member's social media accounts to private in the same sitting. Voice notes in large WhatsApp groups are the single richest source of clean audio for a household.

What to do while the call is happening

You will not reliably detect a clone by ear, and you should not build a defence around trying. Peer-reviewed work now places synthetic speech past the point where listeners can consistently distinguish it. But live-generated audio still struggles under conditions the script did not anticipate.

  • Ask something only the real person could answer that is not recoverable online — what you discussed at the end of last Sunday's meeting, not their date of birth or their mother's name.
  • Interrupt. Change subject abruptly. Cloned audio driven by an operator working from a script degrades when it has to improvise.
  • Listen for what is missing rather than what is wrong — no background noise at all, no breath, unnatural evenness of pace, a slight lag before each reply.
  • Say you will call back. Note the reaction. Pressure, anger, or a reason why callback is impossible is the strongest single indicator you will get.

Act on this: treat every one of these as a supporting signal, never as the decision. The decision is always the callback.

If it has already happened

Speed determines recovery. Money moving through mule accounts is typically dispersed within hours, and once it leaves the country it is effectively gone.

  • Telephone your bank's fraud desk immediately and follow with written instruction to recall the transfer. Do not wait for the morning and do not begin with email alone.
  • File with the police and, for a cyber-enabled offence, with the Cyber Crime unit — the criminal complaint is what lets banks act on the receiving account rather than merely noting your call.
  • Preserve the evidence before anyone tidies up. Call logs, the recording if your system captured one, the WhatsApp thread, the transfer instruction. Screenshots are not enough — export the chat and keep the original files.
  • Assume the mailbox that carried the request is compromised until proven otherwise, and check for forwarding rules and unfamiliar sessions. Voice fraud is frequently the second stage of an email intrusion, not a standalone event.
  • Tell your staff what happened. Silence is what allows the same script to work on the next person in the building.

Act on this: put the fraud desk number of every bank you hold an account with into the phones of your finance team today, saved under a name they can find in a panic. The hour you spend finding it afterwards is the hour the money leaves.

The honest position

There is no technology you can buy that reliably tells you whether a voice on a Bangladeshi mobile network is real. Detection tools exist, they are improving, and they are not a control you should place a payment behind. What works is procedural — verification on a channel the caller cannot control, a threshold requiring two people, a delay on new beneficiaries, and a workforce that has been told plainly it will never be penalised for checking.

Those four things cost nothing but a morning of somebody's attention. Companies that lose money to this fraud almost never lack the technology. They lack the sentence that says a voice is not an authorisation.