The Voice Was Your CEO’s. The Wire Transfer Was Real. The Caller Was AI.

The voice sounded right. The phrasing sounded right. The caller knew the deal, the deadline, and exactly who had authority to approve the payment.

So the employee sent the wire.

Then the real CEO called.

AI voice cloning has changed a familiar business scam. A fake invoice or hacked email can now arrive with a convincing call, voice message, or video meeting that appears to confirm the payment. Once the money moves, the urgent question is no longer whether the fraud looked obvious. It is who may bear the loss, whether the transfer can still be stopped, and what the business must do immediately.

The Quick Answer

A deepfake does not automatically make the bank responsible for the loss.

Florida’s funds-transfer law examines who issued the payment order, whether the person had authority, what security procedure the bank and customer agreed to use, whether that procedure was commercially reasonable, and whether the bank accepted the order in good faith and followed the agreed procedure.

If an employee with payment authority personally instructs the bank to send a wire after being deceived, calling the transfer “unauthorized” may not settle the legal question. The employee may have issued the actual banking instruction even though a criminal induced it.

The best opportunity to protect the money may come before the liability fight. Minutes matter.

This Is Not Just a Better-Written Phishing Email

The FBI’s 2025 Internet Crime Report recorded 24,768 business email compromise complaints and more than $3 billion in reported BEC losses. It also recorded more than 22,000 complaints containing AI-related information, with adjusted losses exceeding $893 million.

The report specifically warns that voice cloning can be used to request wire payments. Businesses reported more than $30 million in losses from BEC schemes involving AI in 2025.

The scam works because it combines familiar pressure points:

  • an executive’s apparent authority;

  • a confidential or time-sensitive deal;

  • information taken from email, social media, or a compromised account;

  • a sudden change in payment instructions; and

  • a voice or video that appears to eliminate doubt.

The call is not always the first step. It may be the final piece used to make a fraudulent email feel real.

Who May Bear the Loss?

There is no universal answer. Several relationships and documents may matter.

The Business and Its Bank

Florida Statutes section 670.202 addresses when a payment order is authorized or can become effective against a customer through an agreed security procedure. The analysis can include the customer’s normal transaction size and frequency, the alternatives the bank offered, the procedures used by similar customers, and whether the bank followed the agreed process in good faith.

If the order was neither authorized nor effective under those rules, section 670.204 may require the bank to refund the payment. Notice timing matters, and an account agreement may establish a reasonable reporting period.

That does not mean a business should treat the statutory outside period as time to spare. A legal refund claim and a successful recall are different things. The chance of freezing the actual funds can shrink rapidly.

The Business and the Intended Vendor

If a criminal intercepted a vendor’s email or substituted payment instructions, the parties may dispute whose systems, representations, or failures caused the loss. The contract may contain payment-instruction, notice, cybersecurity, indemnification, limitation-of-liability, or insurance provisions.

The history of prior payments also matters. A first-time account, an unexpected country, or a sudden change from established instructions should trigger verification.

The Recipient Bank

A beneficiary name that does not match the account holder may look like an obvious safety net. It may not be.

Florida’s Article 4A rules can permit a beneficiary’s bank to rely on the account number when it does not know that the name and number identify different people. That makes independent verification before sending the wire critical.

The Insurer

Cyber, crime, social-engineering, computer-fraud, and funds-transfer-fraud coverages are not interchangeable. Definitions, exclusions, sublimits, notice requirements, and the exact method used to induce the payment can affect coverage.

Notify the appropriate carrier or broker promptly without assuming the policy either covers or excludes the event.

The First-Hour Response

1. Contact the bank immediately. Use a verified number. Ask for the fraud department, an emergency recall, a freeze request, and escalation to the receiving institution. Obtain a case number and document every contact.

2. Report the transaction to IC3. Submit the full transaction information at IC3.gov. The FBI’s Recovery Asset Team works with financial institutions and law enforcement to help freeze funds in qualifying matters.

3. Preserve the evidence. Save the email in its original format, full headers, voice messages, call logs, meeting invitations, payment approvals, bank confirmations, access logs, and internal chats. Do not delete the fake message or reset systems before relevant evidence is preserved.

4. Verify through known channels. Contact the real executive, vendor, and financial institution using previously confirmed contact information. Do not use a number, link, or reply address contained in the suspicious communication.

5. Notify counsel and the insurer. Counsel can help coordinate preservation, notices, contractual analysis, communications, and potential claims while avoiding inconsistent statements made during the initial scramble.

6. Contain the compromise. Determine whether an email account, device, password, or payment platform was accessed. Involve qualified cybersecurity professionals as appropriate and change credentials through a controlled process.

The Procedure Every Business Should Adopt Now

A convincing voice should never be the final approval for moving money.

For new recipients, changed banking instructions, or payments above a defined threshold, require:

  • an independent callback to a previously verified number;

  • two-person approval;

  • confirmation of the beneficiary and account information;

  • a waiting period when instructions suddenly change;

  • written documentation of the verification; and

  • a clear rule that urgency or confidentiality does not override the process.

Executives should follow the rule too. A control that senior leadership routinely bypasses is not a reliable control.

Businesses should also review bank agreements, employee authority, vendor contracts, insurance coverage, and incident-response procedures before a fraud occurs. The goal is not merely to spot an artificial voice. As the technology improves, that may become harder. The goal is to make one convincing communication insufficient to move the company’s money.

The Bottom Line

In an AI-assisted wire fraud, the voice may be fake while the financial and legal consequences are completely real.

The immediate priority is recovery: contact the bank, request a recall, report the event, preserve the evidence, and contain any compromise. The next priority is determining how Florida’s funds-transfer rules, the bank agreement, vendor contract, insurance policy, and parties’ conduct allocate the loss.

MB Law Group represents Florida businesses in commercial disputes involving payment fraud, contracts, financial losses, and failed business transactions. If a fraudulent instruction has moved company funds, act before the trail gets colder.

This is for informational purposes only and does not constitute legal advice or create an attorney-client relationship. Attorney Advertising.

FAQ SECTION

Is a bank automatically responsible for an AI voice scam?

No. The result can depend on who issued the payment order, the employee’s authority, the bank’s security procedure, whether it was commercially reasonable, whether the bank acted in good faith, and whether it followed the agreed process.

Is a wire unauthorized if an employee was tricked into sending it?

Not necessarily. An employee with authority may have personally issued the payment order even though fraud induced the decision. The facts, agency rules, bank agreement, and Florida funds-transfer law require careful review.

Can a fraudulent business wire transfer be reversed?

Sometimes, but speed is critical. The business should immediately contact its financial institution, request a recall and freeze, and submit complete transaction information to IC3.gov. Recovery is not guaranteed.

What evidence should the business preserve?

Preserve original emails and headers, voice messages, call logs, meeting information, bank records, payment approvals, access logs, internal communications, vendor records, and the devices or accounts potentially involved.

Does a mismatched beneficiary name stop a wire transfer?

Not always. Florida law may permit a beneficiary’s bank to rely on the account number if it does not know that the beneficiary name and account number identify different people.

Does cyber insurance cover AI wire fraud?

Coverage varies. Cyber, crime, social-engineering, computer-fraud, and funds-transfer-fraud provisions may contain different definitions, exclusions, notice requirements, and sublimits.

How can a business prevent deepfake payment fraud?

Require independent callbacks to verified numbers, two-person approval, beneficiary confirmation, documented verification, and additional scrutiny for new accounts or changed payment instructions. Do not allow urgency or an executive’s apparent voice to bypass the process.

Previous
Previous

Deepfake Divorce: When the Evidence Looks Real but Isn’t

Next
Next

The Tariff Hit. Who Pays? What Florida Businesses Should Check Before Eating the Cost