Digital security

Invoice Fraud and AI Voice Cloning: 5 Moments You Can Still Stop It

Your supplier calls about a bank detail. The voice sounds exactly right — which is exactly the problem. Five moments in that one call, and what you can still do at each of them.

In this article
  1. What actually changed
  2. The callback protocol
  3. How risky is this call?
  4. If it already happened
  5. To set up this week
  6. The point

It's a Tuesday afternoon. Your regular meat supplier calls — you recognise the voice instantly, the same man you've worked with for three years. He sounds rushed: the restaurant's bank has switched systems, and today's payment needs to go to a different account number. He sends it straight over on WhatsApp. Can you send it now, he's between two deliveries?

The voice isn't fake. It sounds exactly like him. And that's exactly what's changed: a voice sounding right is no longer proof you're talking to the person it belongs to.

What actually changed

Invoice fraud is as old as invoices — a forged letter, a spoofed email from a domain with one letter off, a signature that doesn't quite match. Restaurants have largely learned to spot that kind: an email from "your bookkeeper" with an extra space in the address gets a second look.

What's new is the voice. Research from security firm McAfee found that roughly three seconds of audio is enough to clone a voice with around 85% accuracy — enough to convince a trained ear, let alone a busy one. Those three seconds are everywhere: a voicemail greeting, a reply on a Google review your supplier recorded themselves, a clip from a podcast episode. Nobody has to do anything unusual to make that audio public; it's often already sitting there.

The exact scale of this for independent restaurants isn't easy to pin down — most incidents are never reported, out of embarrassment or because the amount felt too small to bother. What is documented: for larger businesses, the average loss per incident of this kind (tracked in the US by the FBI under the label "Business Email Compromise") runs into the tens or hundreds of thousands of euros, and the number of cases keeps climbing year over year. The mechanism that works there is exactly the mechanism that works on a small kitchen — only the amount differs.

The reason an independent business is especially exposed isn't technical, it's organisational. In a larger company, one person sets a payment up and a different person approves it. In a restaurant, that's often the same person — the owner, or whoever happens to be at the desk between two services. A request that sounds like it comes from someone you already trust is designed precisely to skip the second pair of eyes a bigger business would apply.

The anatomy of one call

Five moments, each with a tell and a stop

Moment 1 · The trigger

A message or call that's urgent, slightly outside the usual channel (WhatsApp instead of email) or at a slightly odd time — usually with an excuse ("the bank switched systems", "our accounts changed").

A genuine supplier or bookkeeper is never in a hurry about a bank detail. Waiting costs them nothing; it costs you everything if you pay now.

Moment 2 · The call itself

The voice sounds right — but there's pressure to act today, and not to check with anyone else first. "Let's keep this simple", or "I didn't want to bother you with the details".

A real business partner understands you want to double-check. Anyone who waves that off is giving you the clearest signal of all five.

Moment 3 · The isolation

You're asked not to mention it to your partner, your bookkeeper or whoever else is normally involved — "to keep it simple" — or told the usual contact person is unreachable right now.

This is the sharpest tell of the five. A real supplier never asks you to keep something from your own bookkeeper.

Moment 4 · The actual ask

A changed bank detail on an existing or upcoming invoice — sometimes a small difference from the number you've used for years, sometimes a completely different one, "just this once".

Call the number you already had, from before this conversation started — never a number that arrives in the same message asking for the change.

Moment 5 · The transfer

Once the money leaves through an ordinary bank transfer, it's essentially gone almost immediately — unlike a card payment, there's no automatic chargeback.

This is the last moment, which is exactly why every moment before it is the real line of defence. Once you're here, everything depends on how fast you call the bank (see below).

At any of these five moments, one habit is enough to stop it: call back on a number you already had, never one from the message asking for the change.

None of these five moments takes technical knowledge to spot. They just take knowing what to look for — and having one habit already in place before the call ever comes.

The callback protocol

There's one habit that works at every moment above, and it costs almost nothing: always verify a changed payment detail using contact information you already had — never a number, email address or link that arrives in the same message asking for the change. Call the number saved in your phone, or the one on last month's invoice. Not the number that just called you.

Three rules make that protocol workable in a kitchen where nobody has time for a compliance department:

  • Every changed bank detail deserves a second pair of eyes — even in a two-person business. That's your partner, your bookkeeper, or whoever isn't the same person who took the call AND sends the payment. One person doing both is exactly the situation fraud is looking for.
  • A first-time change on a large invoice deserves a short pause — a day, or just until you've reached the supplier on the old number. A genuine change survives that pause easily; a fraudulent one usually doesn't, because the pressure to act now was the whole point.
  • Agree with your team that nobody gets laughed at for a verification call. The biggest reason this protocol fails isn't ignorance — it's someone feeling awkward calling the supplier back "to check it was really them". Make that the norm, not the exception.

No callback versus a callback

The same request, two paths

No callback check

Message arrives with a changed bank detail

Payment is sent right away

Money is gone — no chargeback possible

With a callback check

Message arrives with a changed bank detail

Callback on the number you already had (< 2 minutes)

Fraud caught — nothing lost

The defence costs under two minutes. The mistake it prevents costs whatever was on the invoice.

How risky is this call?

None of the flags below prove fraud on its own — but the more of them are present, the stronger the reason to call back before you pay. Tick what applies to a call you just had, or are on right now.

Risk check for this call

Tick what applies — the verdict updates as you go

Verdict

Low risk

Few flags present. Still no harm in calling back on the known number before you confirm — it costs you two minutes.

0 / 7 flags ticked

This list doesn't replace judgement — a call with zero flags can still be fraud, and one flag alone proves nothing. It's a memory aid for the moment you feel rushed and want to check whether that rush is normal.

If it already happened

If you only realise something was wrong after the transfer went out, every minute counts. Do this, in this order:

  1. Call your bank's fraud line immediately — not general customer service. Banks can sometimes recall a transfer while the money hasn't fully cleared into the receiving account, but that window is usually a matter of minutes to a few hours, not days.
  2. File a police report. Even if the amount feels small: a report is needed for any insurance claim, and it helps police spot the pattern if the same fraudster is targeting other businesses.
  3. Tell your real supplier or bookkeeper. They can warn other customers who might get the same call — and it's just as unpleasant for them that their name and voice are being used for this.
  4. Don't be embarrassed to report it inside your team. This happens to businesses of every size: in 2024, the UK subsidiary of a German energy firm reportedly transferred €220,000 after its head received a call that sounded exactly like the German parent company's CEO, using a cloned voice, requesting an urgent payment to close a deal. If it can happen there, it isn't a personal failure that it happened to you.

To set up this week

Four things you can put in place this week, no system or budget needed:

  • Write the callback protocol down, literally — one line on a sheet by the till or the desk: "Changed bank detail: call the old number back, never the new one."
  • Tell everyone who touches payments — including whoever pays an invoice on your day off.
  • Agree a codeword or check question with your regular suppliers and bookkeeper for phone-based changes — something a cloned voice wouldn't simply know.
  • Put a second pair of eyes on every payment above an amount you consider significant — even if that means your partner or bookkeeper gets a text before you hit send.

The point

A cloned voice is convincing because it's exactly what it claims to be: a voice that sounds right. What doesn't sound right is the urgency, the request to keep it quiet, and the changed number — and all three are recognisable without a shred of technical knowledge. One habit, calling back on a number you already had, stops nearly every version of this story before any money leaves.

Frequently asked questions

Can my bank reverse a transfer once it's sent?

Sometimes, and only if you act fast. As long as the money hasn't fully cleared into the receiving account, a bank can often still recall a transfer — but that window is usually minutes to a few hours. Call your bank's fraud line immediately, not general customer service.

Is this covered by my restaurant insurance?

It varies a lot by policy and insurer — some business policies cover cyber fraud or invoice fraud specifically, others don't at all. Ask your insurer directly rather than assuming it's included.

How do I bring this up with my supplier without insulting them?

Most suppliers actually appreciate a callback to confirm — it protects them too, since their name and voice might be misused by someone else. A simple "just calling back to confirm, standard procedure on our end" is enough, and any serious business partner sees that as completely normal.

What if it's not a voice clone, just a spoofed email?

The same callback protocol works just as well there: a changed bank detail always deserves confirmation through a channel and contact details you already had, whether the request arrived by phone, WhatsApp or email.

Can I tell by ear if a voice is cloned?

Not reliably anymore. Research shows modern voice clones are barely distinguishable from the real voice to the human ear. Don't rely on your hearing — rely on the protocol: verify through a channel the fraudster doesn't control.