Your Ears Are Not a Security Control
For your entire life, recognizing someone’s voice has been good enough. That stopped being true recently, and almost nobody has updated the procedures they built on top of it.
What actually changed, and what didn’t
There is a version of the AI-security conversation that is mostly adrenaline. Attackers have AI now, everything is different, the old rules are gone, please buy something.
The data does not support the drama, and the real finding is more useful than the panic.
The 2026 Verizon Data Breach Investigations Report — the largest annual study of actual breaches, not surveys — concludes that AI is “primarily accelerating and scaling known attack methods rather than inventing entirely new ones,” with the median malicious actor using AI across roughly fifteen documented attack techniques. Not fifteen new techniques. Fifteen familiar ones, executed faster and cheaper.
That is genuinely good news, and it deserves to be said clearly: the controls that worked last year still work. MFA still works. Least privilege still works. Out-of-band verification still works. Nobody needs to throw out their security program because attackers started using a language model.
What changed is the economics. Things that used to require skill, time, or fluent English now require a prompt. The attacker who previously sent a thousand clumsy emails can now send a thousand good ones, each referencing your actual vendor, your actual project, in your actual house style. Volume went up and quality went up at the same time, which historically almost never happens.
But there is one exception to “nothing is really new,” and it is the reason I wanted to write this instead of the version the LinkedIn post implied. One thing genuinely did change categories.
The thing that actually broke
Voice and video are no longer proof of identity.
That is not a faster version of an old attack. It retires a heuristic that every person reading this has relied on since childhood, and that a great many business processes quietly depend on without ever writing it down.
The case everyone should know: in early 2024, the UK engineering firm Arup lost roughly US$25 million from its Hong Kong office. An employee received a message purporting to come from the company’s CFO about a confidential transaction. Suspicious, the employee did the responsible-seeming thing and joined a video call — where the CFO and several other colleagues appeared and spoke. They were all synthetic. The employee made a series of transfers to five different Hong Kong bank accounts, and the fraud only surfaced on a later follow-up to headquarters. Arup confirmed to the Financial Times that “false voices and images were used.”
Sit with the shape of that for a second. The employee escalated. They didn’t act on a text message; they asked to see and hear the people involved. Under every piece of security training written before about 2023, they did the right thing — and the verification step itself was the attack surface.
That is why this one is different. It didn’t make an old attack cheaper. It turned a control into a vulnerability.
About that “AI phishing beats humans” statistic
You will see a headline claiming AI-generated phishing now outperforms elite human red teams. It comes from research by Hoxhunt, run across more than two and a half million users on their platform with roughly seventy thousand AI-generated simulations. The finding: AI-written phishing went from 44.8% worse than expert human attackers in 2023 to 23.3% better by March 2025.
That sounds like the sky falling. Then you look at the numbers those percentages are computed from.
A 2.78% failure rate for the AI-written messages versus 2.25% for the human-written ones. The real-world difference is about half a percentage point.
Two things are true at once, and most coverage only reports the first. The trend line is real and pointing the wrong way — machine-generated social engineering is closing a gap it used to lose badly. And the present-day delta is small enough that it should not be the thing restructuring your security budget. Quoting the relative figure without the absolute one is how a modest finding becomes a sales tool.
Worth saying plainly: Hoxhunt sells security-awareness training. This is a vendor measuring a problem it is in the business of solving, using its own platform’s data. That does not make it wrong — it is one of the few actual controlled measurements anyone has published on this question, and I am citing it because of that. It does mean you should read it with the same eyebrow you would raise at any vendor’s benchmark, and the company is transparent that its own 2023 baseline isn’t an apples-to-apples comparison.
The practical read: don’t rebuild your program around half a percentage point. Do fix the thing that broke outright.
The fix is a process control, not a product
Here is where I will admit a bias. A good chunk of my career has run along the seam between IT and finance — ERP implementations, custom job-cost and management reporting, a QuickBooks integration I built from scratch, and enough SOX and IT general controls work to have spent real time on approval workflows and segregation of duties.
So when I look at the Arup case, I don’t primarily see an AI problem. I see a payment authorization control failure that AI happened to walk through. And the fix is one that auditors have been asking about for twenty years.
Out-of-band verification. Any payment instruction, banking-detail change, or urgent financial request gets confirmed on a different channel than the one it arrived on, using a number or address you already had — never one supplied in the request. If the ask came by email, you call. If it came by phone or video, you use a channel with an independent identity, and you call the number in your own directory. This is the entire ballgame, and it costs nothing.
A dollar threshold with a second human. Pick a number the business can absorb losing. Above it, two people approve, and the second one is not in the reporting line of the first. This is textbook segregation of duties, and it is the control that would have stopped Arup regardless of how convincing the video call was — because the synthetic CFO can be persuasive, but he cannot also be the second approver in your system.
Banking-detail changes as a privileged transaction. Vendor bank-account changes should be the most controlled routine action in your organization. Callback to a known number, on file, documented. Most business email compromise losses trace back to exactly this step.
Explicit permission to slow down. Urgency and confidentiality are the two levers in every one of these attacks. If your culture punishes the person who made the CFO wait ten minutes for a callback, you have already lost — the control exists on paper and not in practice. Leadership has to say out loud that verifying is never the wrong call, and then not be annoyed when it happens to them.
That fourth one is the hardest and the cheapest, and it is the one I would spend a meeting on this quarter.
What to actually change in awareness training
The old advice — watch for bad grammar, look for weird phrasing — is dead. It was always a weak signal and it is now an actively harmful one, because it teaches people that a well-written message is safe.
Replace the tells with structural questions, which don’t degrade as the writing improves:
- Is this asking me to move money, change where money goes, or hand over credentials? That category gets verified every time, regardless of who it appears to come from or how normal it looks.
- Is there urgency plus secrecy? “Don’t discuss this with the team yet” is the single most reliable indicator in the entire genre, and no amount of AI polish removes it — the attacker needs isolation to work.
- Did this arrive through a channel I can independently verify? Not “does it look real.”
- Am I being asked to break a normal process because of who is asking?
And add one thing most training still doesn’t cover: a familiar voice is not authentication. People need to hear that stated directly, because it contradicts a lifetime of lived experience and will not be inferred.
The help desk needs its own version of this. Attackers increasingly target the reset path rather than the account — calling support, sounding like an employee, and asking for an MFA reset. Support is where an organization’s helpfulness is load-bearing, which is exactly what makes it the softest target. Identity-verification steps for resets should be written down and non-negotiable, and the people staffing that queue need explicit cover to refuse a plausible, friendly, urgent request.
Phishing-resistant authentication matters more now
If AI makes the bait better, the durable answer is to reduce how much a successful lure is worth.
Standard MFA still helps enormously and you should have it everywhere. But push-approval and one-time codes can be relayed by a convincing attacker in real time — and “convincing” is precisely the part that got cheaper. Phishing-resistant factors — passkeys, FIDO2 security keys — break that, because the credential is cryptographically bound to the real site and simply will not produce anything usable on a lookalike domain. No amount of persuasion moves that.
Start with the accounts where a compromise is catastrophic: email administrators, domain admins, the finance team, anyone who can move money or change where it goes. That is the same prioritization logic I argued for in getting privileged access under control — fix the accounts that matter most first, rather than attempting everything and finishing nothing.
Email authentication is the other half. DMARC at enforcement stops attackers sending as your domain, which removes the most convincing pretext available to them. And it is worth knowing that some legitimate paths into your own tenant bypass authentication entirely — a Microsoft 365 feature that accepts internal-looking mail with no credentials at all is a live example. AI-written bait delivered through a channel your users have been taught to trust is the combination to worry about.
Why Q4 is when this gets tested
The seasonal argument is not marketing. It is operational.
Year-end is when unusual financial activity stops looking unusual. Budget flushes, accelerated invoices, vendor onboarding before a fiscal close, renewals, bonus runs. A wire request that would raise an eyebrow in April reads as ordinary in December.
It is also when coverage thins. People take leave, approvals get delegated to someone less familiar with the process, and “just handle it, I’m out until the 3rd” becomes a normal sentence. Attackers don’t need to guess at any of this — the holiday calendar is public and the pattern is well known.
So the window to fix the approval process is now, while it is boring. A control written in September gets followed in December. A control written in December gets skipped in December.
The federal and contractor angle
For contractors, the AI threat conversation tends to get pointed at the wrong end of the problem.
- The requirements you have are still the requirements. There is no AI control family in NIST SP 800-171. What applies is what already applied: access control, identification and authentication, awareness and training, incident response. AI changes the volume and quality of attempts against those controls, not the controls themselves. This is the same pattern I described in the post-quantum piece — a loud industry deadline that turns out not to be yours, sitting on top of a plain requirement that is.
- Awareness training is an assessed requirement, and yours is probably out of date. If your material still teaches grammar tells, it is teaching something false. That is a cheap, high-value refresh, and it is the kind of thing an assessor can see.
- The bigger CUI exposure is your own staff’s AI use, not the attacker’s. Employees pasting contract language, drawings, or customer data into public AI tools is a spillage path that requires no adversary at all. That deserves a written policy and a sanctioned alternative — because the reason people use the unsanctioned tool is almost always that the approved one doesn’t exist.
- Rehearse the money scenario specifically. A deepfaked payment instruction is an incident, and the first hour decides how much you recover. Wire recalls are extremely time-sensitive; knowing which bank to call, and who is authorized to make that call at 7 p.m., is the difference between a partial recovery and a total loss.
And for anyone tempted to treat this as purely a defensive story — AI cuts both ways. Detection, log triage, and anomaly spotting all got meaningfully better on the defender’s side too. Small organizations benefit disproportionately from that, because the tooling arrives inside products they already pay for. This is not a losing position. It is a changing one.
Where this usually goes wrong
- Treating a familiar voice as authentication. The single most important sentence in this article.
- Teaching grammar tells. Worse than useless — it certifies well-written attacks as safe.
- Verification on the same channel as the request. Replying to the email, or calling the number in the signature, verifies nothing.
- An approval threshold with no second human. One person authorized to move large amounts alone is the whole vulnerability.
- Punishing the callback. If verifying an executive is socially costly, the control is decorative.
- Buying a detection product instead of fixing the process. Deepfake detection is immature and adversarial; approval controls are mature and deterministic.
- Forgetting the help desk. The reset path is a credential path.
- Assuming this is a big-company problem. Small organizations have shorter approval chains and fewer people who would notice. That is the target profile, not protection from it.
The meeting to have this month
Get whoever can authorize a payment in a room, and answer three questions out loud.
What is the largest amount one person can move alone? How does someone verify an unusual request from an executive — specifically, which number do they call? Does everyone in this room agree that making the CEO wait for that callback is the correct behavior?
If the third answer is anything other than an immediate yes, that is the finding, and it is a culture fix rather than a technology purchase.
None of this requires believing anything in particular about how fast AI is advancing. It only requires accepting that a convincing voice is now cheap — and building the one process that never depended on the voice being real.
Veteran Forge Strategies is an SBA-Certified Service-Disabled Veteran-Owned Small Business providing IT infrastructure, operations, and cybersecurity support to small businesses and federal clients from Northern Virginia. If nobody at your organization can say what the payment-verification callback procedure is, that is the engagement — get in touch. You can also read about how a fractional IT engagement works, or browse the rest of the Deck Log.