AI Voice Cloning Scams: What St. Louis Small Businesses Need to Know Before the Next Phone Call

Let me ask you something: if your business owner called you from an unfamiliar number, would you recognize the voice?

Most likely, yes. A familiar voice on the phone feels like a familiar face at your front door. You know the person. You trust the person. You open the door.

But what if someone learned to copy that face?

That is the danger behind AI voice cloning scams. Criminals can now create a convincing copy of a person’s voice from only a few seconds of audio scraped from a voicemail greeting, webinar, YouTube video, or social media post.

And they are using that copied voice to target small businesses with urgent wire transfers, payroll changes, gift card requests, and fake executive instructions.

AI fraud is no longer a far-off concern

The FBI’s Internet Crime Complaint Center tracked AI-enabled fraud as its own category for the first time in its 2025 annual report.

The numbers are hard to ignore: 22,364 complaints and roughly $893 million in reported losses.

That total is likely an undercount. Why? Many victims never realize artificial intelligence was involved. They may report a fraudulent wire transfer or business email compromise without knowing that the “CFO” on the phone was an AI-generated voice.

The technology is improving quickly.

AI-generated phishing emails can sound polished and personal. Deepfake video can make a fake executive appear on a video call. A cloned voice can “confirm” the payment request that just arrived by email.

Here’s where it gets scary: each piece of the attack reinforces the others.

You receive an email that appears to come from your owner. A few minutes later, the owner calls you. The voice sounds right. Then a video call request appears from the same person.

You open it without thinking twice.

And just like that, the scam feels legitimate.

Why Q4 creates extra risk for St. Louis businesses

October 1 marks the beginning of Cybersecurity Awareness Month 2026, with this year’s theme, “Securing the Next 250.” It is also the start of the fourth quarter, when many businesses become busier with payroll changes, bonuses, vendor settlements, annual purchases, and year-end financial activity.

That makes October a natural time for attackers to increase pressure.

Think about your own business in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, or the Metro East. Who handles payments when your team is busy? Who can approve a wire? Who updates direct-deposit information? Who knows the owner is traveling or unavailable?

Criminals look for those details.

Business email compromise remains one of the highest-loss crime categories affecting small businesses. AI does not replace the old scam. It makes the old scam more believable.

The most common AI voice cloning attack

Here’s a typical scenario.

You work in finance. At 2:15 p.m., you receive an email from your CFO asking you to send a wire transfer to a new account. The message explains that the payment is confidential and time-sensitive.

You notice the email domain looks almost right. Maybe one letter is different. Maybe the attacker used a lookalike domain that is difficult to spot on a phone.

Before you can respond, your phone rings.

The voice on the other end sounds exactly like your CFO.

“Did you see my email? I need this handled before the bank closes.”

The caller may know your name, your role, the vendor involved, and the amount in the email. That information can come from previous breaches, public websites, social media, or compromised inboxes.

Sometimes the attacker adds a fake video call. Sometimes the request involves gift cards instead of a wire. Sometimes the target is a payroll change that redirects an employee’s paycheck.

The details change.

The pressure stays the same.

Never trust a voice alone

It makes sense that you would trust a familiar voice. That is how normal business communication works.

But a voice is no longer proof of identity.

The same rule applies to video. Seeing someone on a screen does not guarantee the person is real, especially when deepfake technology can imitate facial movements, backgrounds, and speech patterns.

So, what can you do?

Create a verification rule that applies even when the request appears to come from the owner, CFO, controller, or a trusted vendor.

Use a verification code and a call-back rule

Start by agreeing on a simple internal process before an emergency happens.

For example, your finance team can require:

  • A private verification code for urgent payment requests.
  • A call-back to a known number already stored in your company records.
  • A second approval for wires, payroll changes, and new vendor banking details.
  • A face-to-face or separate-channel confirmation for unusual requests.
  • A short waiting period when someone demands secrecy or immediate action.

Do not use the phone number included in the suspicious email or provided by the caller. Look up the known number independently.

And do not let the caller choose the verification method.

If your CFO says, “Call me back on this number,” you should still use the number in your approved contact directory.

Give your finance team a script

People often recognize a scam but freeze when the person on the phone sounds like their boss.

A short script removes that pressure.

Your finance team can say:

“I’m happy to help, but company policy requires me to verify payment changes through our approved callback process. I’ll call you back using the number in our directory.”

If the caller becomes angry, claims the policy does not apply, or demands secrecy, that is useful information.

A legitimate executive may be busy. They may even be frustrated by a delay. But they should not object to a reasonable security control designed to protect the business.

Here’s another helpful phrase:

“I cannot approve this request from a phone call alone. I need a second authorized approver.”

That sentence protects your employee from having to make a personal judgment about whether the voice sounds real.

Controls that reduce your exposure

AI voice scams are a people problem, but technology and process controls matter too.

Use this checklist to strengthen your defenses:

  • Require multi-factor authentication: Protect email, cloud services, remote access, payroll platforms, and financial accounts with MFA.
  • Verify payment changes by callback: Confirm new bank details and payroll instructions using a known, independent number.
  • Use dual approval for wires: Require two authorized people to approve high-value or unusual payments.
  • Set up SPF, DKIM, and DMARC: These email authentication controls make it harder for criminals to impersonate your domain.
  • Deploy endpoint protection: Protect laptops, desktops, and mobile devices from malware and account theft.
  • Train employees on AI scams: Include voice cloning, deepfake video, AI-generated phishing, urgency, and secrecy in security awareness training.
  • Create an incident response plan: Document who to call at your bank, payroll provider, cyber insurance carrier, IT provider, and law enforcement.
  • Limit public audio exposure: Review voicemail greetings, webinars, social posts, and public videos that contain long, clear samples of executive voices.
  • Monitor financial changes: Alert on unusual login locations, new payees, modified vendor accounts, and unexpected mailbox rules.

Finance manager pausing before approving a payment while a colleague recommends a verification call

No single control is perfect. Together, they add the right kind of friction.

That friction is not an inconvenience. It is a speed bump between a convincing impersonation and a completed payment.

Train your team without blaming them

Most people do not break security rules on purpose. They are trying to help a customer, support a manager, or finish an urgent task before the end of the day.

It is not about blame. It is about awareness.

Your training should help employees recognize warning signs such as:

  • Urgent requests that bypass normal procedures.
  • A demand for secrecy.
  • A new bank account or payroll destination.
  • A request to use gift cards, cryptocurrency, or personal accounts.
  • A caller who discourages a callback.
  • A voice or video that sounds slightly unnatural.
  • A message that creates fear, embarrassment, or pressure.

Practice the response.

Run a short exercise where an employee receives an urgent payment request and must follow the callback rule. That way, the process feels familiar when a real attack occurs.

Employees participating in a calm cybersecurity awareness discussion around a conference table

For a broader security foundation, review our guide to St. Louis cybersecurity for small business and the controls insurers now expect.

You can also see what proactive managed IT services in St. Louis should be doing for your business, including monitoring, endpoint protection, and security planning.

What to do if you suspect a scam

If someone may have acted on a fraudulent request, move quickly.

  • Stop further payments.
  • Contact your bank’s fraud department immediately.
  • Notify your IT provider and email administrator.
  • Preserve the emails, phone numbers, recordings, messages, and payment details.
  • Reset compromised passwords and revoke suspicious sessions.
  • Check for mailbox forwarding rules and unauthorized account access.
  • Contact law enforcement and report the incident to the FBI’s IC3.
  • Notify your cyber insurance carrier if applicable.

Speed matters, especially for wire fraud and payroll diversion.

If ransomware or another broader attack is involved, our guide on ransomware protection for St. Louis small businesses explains what to do before criminals demand payment.

The next phone call may sound exactly right

A familiar voice at your front door used to be a strong sign that the person was who they claimed to be.

Today, it is only one signal.

Your best defense is a repeatable process: verify the request, call back using a trusted number, require a second approval, and give employees permission to slow down.

Platinum Web Services helps small businesses across St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and Missouri build personalized cybersecurity, managed IT, endpoint protection, and incident response plans.

If you need help reviewing your controls before Q4 fraud activity increases, contact support@platinumwebservices.net. Platinum Web Services provides 24/7 support from 7827 Town Square Ave, 104-1184, O’Fallon, MO 63368.

The goal is simple: make sure the next urgent phone call does not become an expensive lesson.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *