Primeworks Security Brief #001 graphic advising employees to stop, verify and call back when faced with a suspicious instruction.

Primeworks Security Brief #001

Imagine receiving a WhatsApp voice note from a director. A supplier must be paid urgently, the banking details have changed, and the matter is confidential. The voice sounds right. A follow-up email looks convincing. You may even receive a video call that appears to confirm the instruction.

Would you know whether it was real?

Modern artificial intelligence can help criminals create convincing text, images, voices and video. Rather than looking for a strange expression, unnatural pause or badly written email, use a verification process that still works when the impersonation looks and sounds genuine.

The threat

A deepfake is synthetic or manipulated media that can make it appear that a real person said or did something that never happened. AI can also help criminals write polished messages and combine publicly available or stolen information into a believable story.

The FBI has documented criminal use of AI-generated text, images, audio and video in fraud schemes, including vocal cloning and real-time video chats involving alleged company executives. In South Africa, SABRIC’s 2025 crime report noted increasing use of AI-generated messages and impersonation techniques, as well as isolated cases involving cloned voices.

Not every unusual request involves an advanced deepfake. Ordinary account compromise and social engineering remain common. Either way, a familiar voice, face, writing style or caller ID is not sufficient proof of identity.

How an attack could work

Consider this hypothetical business scenario:

  1. A criminal gathers information about a company, its directors, suppliers and finance staff.
  2. An accounts employee receives an urgent, confidential payment request that appears to come from a director.
  3. A convincing voice note or call reinforces the request.
  4. The employee is told to use a new beneficiary, bypass normal approval or approve an unexpected authentication prompt.

The technology makes the story more convincing, but the attack still depends on a person being pressured into abandoning a trusted process.

Why it matters

A successful attack could cause an unauthorised EFT, supplier or payroll fraud, disclosure of confidential information or compromise of a Microsoft 365 account. Once money or access has been handed over, the window for intervention may be short.

SABRIC reports that much South African digital banking crime is driven by social engineering: criminals manipulate customers or employees into authorising actions rather than directly defeating banking systems.

Warning signs

Pause when a request involves one or more of the following:

  • Unusual urgency, secrecy or emotional pressure
  • A request to bypass normal approval procedures
  • New or changed supplier banking details
  • A new beneficiary or unusual EFT
  • An unexpected payroll or payment instruction
  • A request for passwords, one-time PINs or confidential information
  • An unexpected multi-factor authentication (MFA) or sign-in approval prompt
  • Resistance when you say you need to verify the request
  • Instructions to continue using only the channel on which you were contacted

These are behavioural warning signs. They matter even when the voice, email address, profile picture or video appears genuine.

What you should do

Stop

Do not make the payment, share the information, change the banking details or approve the authentication request while you are under pressure.

Verify

Contact the person or organisation through a trusted method you already have, such as an internal directory, verified supplier record or official website. Do not use contact details supplied in the suspicious message.

Call back

If the request came by telephone or voice note, end the interaction and call back on a number already known to you. Retain the normal approval process and required secondary authorisation for sensitive financial instructions.

Never approve an unexpected MFA prompt. Deny it, report it where the option is available, and notify your IT support team promptly. An unexpected prompt may mean that someone already has your password and is trying to complete a sign-in.

If money, credentials or confidential information may have been exposed, contact your bank and IT support provider immediately and preserve the suspicious communications as evidence.

How Primeworks helps

Primeworks can help organisations review practical verification procedures, strengthen Microsoft 365 identity and email protections, improve monitoring and give employees clear security-awareness guidance. If an incident occurs, early reporting gives your IT team the best opportunity to investigate and contain it.

Key takeaway

You do not need to prove that a voice or video is fake before taking precautions.

Stop. Verify. Call back.

Trust the process, not the person.

If you would like help reviewing your organisation’s security controls or staff verification procedures, email [email protected] or use the Primeworks contact form.

Sources and further reading

Enquire Now
close slider