Read the full written lesson (~8 min)
Level 0: attackers use AI even if you never do
Think of AI use in an organization as a ladder, from Level 0 (the firm uses no AI at all) up to Level 4 (autonomous AI agents making decisions on their own). This module sits at the very bottom of that ladder, Level 0 — and that is exactly the point. You do not climb onto this ladder to become a target. You are already on it, because the attacker climbed it for you.
Criminals now have access to the same AI tools everyone else does — tools that clone a voice from a short recording, generate a realistic face on a live video call, or write a flawless, personalized scam email. None of that requires your organization to have adopted anything. It only requires the attacker to have a target with money, data, or access — which describes almost every organization that exists.
The goal of this module is not to turn you into a technical fake-detector. Modern fakes are good enough that trying to spot them by eye or ear is a losing game, even for careful, experienced people. The goal is to give you one habit that makes the quality of the fake irrelevant.
Real case: the voice-clone 'boss' who wanted a wire transfer
Here is an anonymized, representative case built from patterns seen repeatedly in real incidents of this kind.
An accounts clerk at a small facilities-management firm received a phone call. The caller ID showed an unfamiliar mobile number, but the voice on the line was unmistakable: the firm's managing director, tone and phrasing exactly right, sounding slightly stressed and rushed. "I'm stuck in a supplier negotiation and can't talk long — I need you to send €18,400 to a new account today, it's for the equipment deal we discussed last week. I'll send the account details by text right after this call. Please don't loop in anyone else, I want to close this myself before the price changes."
The clerk hesitated for a moment — the request was unusual, and no equipment deal had actually been discussed — but the voice was completely convincing, matched the director's real speech patterns, and the urgency and secrecy felt plausible for a time-sensitive deal. The account details arrived by text moments later, from a different, unfamiliar number. The transfer was made.
The voice had been cloned from a few seconds of the real director's audio, taken from a public conference talk posted online months earlier. The director was not stuck in any negotiation — he was in a meeting elsewhere entirely and had never called. By the time the firm realized what had happened, later that same afternoon, the money had already moved through several accounts and could not be recovered.
Nothing about this case required the firm to be using any AI tool. It required only that the attacker had a few seconds of public audio and a phone.
Spot the risk: what made this attack work
Look back at the case above and notice the ingredients — because the same combination shows up in almost every version of this scam, whether the message arrives by phone, video call, email, or text.
- A voice or face you already trust. The cloned voice used real speech patterns pulled from public audio — a conference talk, a webinar recording, even a voicemail greeting or a video posted on social media. A few seconds is often enough.
- Urgency. "Right now," "before the price changes," "I can't talk long." Urgency exists to stop you from pausing to check.
- A reason not to verify normally. "Don't loop in anyone else," "keep this confidential," "I'm too busy to explain more." This is designed to stop you from doing the one thing that would catch it.
- A request involving money, access, or sensitive data. A payment, a password, a file, a change to bank details — something with real value to take.
- A new or different channel for the payment details. The instructions to actually send the money often arrive by a different route (a text from an unfamiliar number, a new account number) than the voice or video that built the trust.
Individually, none of these is proof of a scam — real deals sometimes are urgent, real bosses sometimes are brief. Together, and especially involving money or sensitive data, they are the exact pattern this module trains you to catch — not by spotting a flaw in the voice, but by noticing the pattern and stopping to verify.
The verify-before-you-act routine
This is the one habit that defeats this entire risk category, regardless of how convincing the fake becomes. It is deliberately simple enough to use under pressure, by anyone, with no technical knowledge required.
Rule: never approve an urgent request involving money, passwords, or sensitive data based on how it looks or sounds alone. Always verify it two ways before acting — on a channel you already trust, and with a second person's sign-off.
In practice, that means two checks, and either one alone helps — but using both is strongest:
- Call back on a known number. Hang up, and call the person back using a phone number you already had saved for them before this request arrived — never a number given to you in the message itself, and never by simply calling back the number that just rang you. If it is genuinely them, they will not mind a callback. If they push back on being verified, that is itself a warning sign.
- Get a second person to check before any payment or data goes out. Agree, as a standing team rule, that no one acts alone on a request to move money, change payment details, or share sensitive data — a second colleague always confirms it independently first, even if the first person is completely sure.
Treat pressure to skip either of these steps — "there's no time," "don't tell anyone," "just this once" — as a warning sign in itself. Genuine emergencies almost never require skipping verification, and attackers manufacture urgency specifically to make you skip it.
Making it a standing team rule, not a one-off lesson
Knowing this rule is not the same as using it in the moment, especially when a voice sounds exactly like your boss's and the ask feels time-sensitive. Two small, practical steps make it easy to apply without having to think hard under pressure:
- Agree the rule now, as a team, while nothing is urgent. Decide together — including with the owner or director — that any request to move money, change bank details, or share passwords always gets a callback on a known number and a second person's sign-off, no exceptions, regardless of who is asking or how urgent it feels. Agreeing this calmly in advance removes the awkwardness of "checking on the boss" mid-crisis.
- Keep a simple list of trusted contact numbers — for the owner, key colleagues, your bank, and main suppliers — saved somewhere everyone in the firm can find it, so a verification channel is always ready and never comes from the suspicious message itself.
This costs nothing, needs no technical skill, and works whether the attacker used a cheap script or the most advanced voice clone available today.