The attack becomes much harder to challenge in real time. A fake email can be reinforced by a convincing voice or video message, which increases social pressure and reduces the chance that an employee pauses to verify the request. This cross-platform approach is designed to make fraudulent transfers feel routine, urgent, and personally endorsed by a trusted executive.
Why BEC Becomes Harder to Interrupt When Voice or Video Is Added
Once a business email compromise message is reinforced with a believable voice note, phone call, or video clip, the attacker is no longer relying on email alone. The added channel reduces friction, because the target hears a trusted-sounding executive, sees a familiar face, or experiences a tighter sense of urgency. That makes a request feel more legitimate, especially when the ask is framed as routine finance work.
deepfake audio and video also compress the decision window. A suspicious email can be debated, but a live-sounding voice message or short video tends to push employees toward immediate action, particularly when the request is high consequence and time sensitive. The practical effect is that the attack borrows credibility from multiple communication layers at once, making challenge and verification harder in the moment.
What the Combined Attack Is Trying to Exploit
The core objective is social pressure, not technical novelty. Attackers are trying to override normal caution by pairing a familiar BEC pretext with a sensory cue that feels personal and authoritative. That combination can defeat a person’s instinct to verify through a second channel, because the fake message now appears to come from both the inbox and the executive presence behind it.
This matters because many organisations still treat email as the primary fraud vector and voice or video as separate trust domains. Cross-platform impersonation exploits that assumption. If the employee is already conditioned to respond quickly to payment, gift card, payroll, vendor banking, or urgent wire instructions, the deepfake layer can make the request feel routine enough to bypass hesitation.
For practical defence, the most important issue is whether the request can be confirmed through an independent path that the attacker is unlikely to control. That usually means an out-of-band check through a known number, a callback procedure, or a pre-approved approval workflow, not a reply to the same thread or a phone number supplied in the message.
Risk and Threat Considerations
Combined BEC and deepfake attacks raise the success rate of impersonation because they attack human verification habits from more than one direction. The risk is not only fraudulent transfer, but also speed, since the attacker wants the target to act before they compare channels or escalate the request.
Failure mechanism: The email supplies the business context, while the synthetic voice or video supplies emotional and social confirmation, which can defeat normal scepticism and weaken the chance of a pause for validation.
Impact: Organisations face higher exposure to payment fraud, approval bypass, executive impersonation, and incident response delay, especially where staff are trained to trust urgency but not given a strong independent verification process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1656 — Impersonation | Combining BEC with deepfake media is an impersonation tactic to gain trust and drive action. |
| Recommendation — Map suspected impersonation attempts to T1656 and verify requests through an independent channel. | ||
| CIS Controls v8 | 14 — Security Awareness and Skills Training | Users need scenario-based training for executive impersonation and payment fraud cues. |
| Recommendation — Train staff to challenge urgent transfer requests and follow a verified callback process. | ||
| NIST CSF 2.0 | PR.AT — Awareness and Training | Awareness controls reduce susceptibility to social engineering and synthetic-media fraud. |
| Recommendation — Build training for BEC and deepfake pretexts into role-specific awareness programmes. | ||
| NIST AI RMF | GOV-4 — Map, Measure, and Manage AI Risks | Synthetic audio and video are AI-enabled fraud risks that require governance and escalation rules. |
| MAP-1 — Contextualise AI Risks | Deepfake-enabled BEC depends on understanding where synthetic media can influence trust decisions. | |
| Recommendation — Document AI fraud scenarios and define escalation steps for suspicious synthetic-media requests. Assess where synthetic media could affect approvals, payments, and executive communications. | ||
Practitioner Guidance
What to verify: Treat any finance-related request that arrives by email and is reinforced by voice or video as untrusted until it is confirmed through a channel the requester did not provide. The key judgement is whether the verifier is using a known directory, known callback path, or documented approval step.
Decision rule: If the request involves a transfer, credential reset, bank detail change, or other irreversible action, require a second-person confirmation and a separate callback before execution. If the message is time pressured, that is a reason to slow the process, not speed it up.
Practitioner takeaway: The control objective is to make impersonation expensive for the attacker by separating business convenience from approval authority; if the same message can influence both, the organisation has already collapsed two trust checks into one.
Related resources from NHI Mgmt Group
- What happens when attackers can combine a limited file write with stored XSS in a management server?
- What happens after attackers use fraudulent emails to trigger a data breach in a finance environment?
- What happens when attackers use compromised credentials to combine exfiltration with encryption in a breach?
- What happens when attackers combine credential harvesting with lateral movement and data exfiltration?