Someone in accounts receives a call. The voice on the other end sounds exactly like the business owner: same accent, same way of speaking, same slight urgency in the sentence. A transfer needs to go out today, before the end of business. Whoever picks up that call has no reason to doubt it for a second. That's exactly the problem.
What's going on
Classic CEO fraud — a scammer posing as the boss by email and demanding an urgent payment — has been around for years. What's new is that criminals can now recreate that voice using artificial intelligence (AI, software that recognises and imitates patterns — in this case, a voice). With just a few seconds of audio, taken from a LinkedIn video or an interview, they can clone a voice that sounds unsettlingly real.
The Centre for Cybersecurity Belgium (CCB) is registering a clear rise in “vishing” — phone-based phishing. In the fourth quarter of 2025 alone, 226 reports came in; in January 2026, 106 more. According to the CCB, reports arrive in waves with a peak during the winter months, and the underlying trend is structurally upward. Scammers call from foreign numbers, use automated robocalls, and are increasingly using AI-generated voices with a local accent to sound more convincing.
78% of Belgian and Dutch companies experienced a fraud attempt in the past two years — source: Allianz Trade.
This isn't limited to individuals being tricked into thinking their bank is calling. Belgian employers' federation VBO warns that fraudsters are increasingly using AI to “convincingly mimic the voice or face of the boss” in attacks against businesses. A recent example: in early 2026, a Swiss entrepreneur lost several million euros over a two-week period after fraudsters cloned the voice of a business partner.
Why this affects SMEs
Large companies often have a dedicated finance department with standing dual-approval rules. At a smaller business, the decision on an urgent payment often rests with just one or two people — the owner, a bookkeeper, an office manager. There's less time, less backup, and more reliance on “I recognise that voice.” That trust is exactly what scammers exploit. On top of that, SMEs tend to share a lot about themselves publicly: interviews, company videos, the owner's LinkedIn posts. That's exactly the audio material needed to clone a voice.
What to actually do about it
- Set a fixed amount above which a second approval is required. No matter how urgent the call sounds, above that threshold a payment never goes through without a second sign-off via a separate channel.
- Call back on a known number. Not the number the caller provides, but the number already on file before the call happened. A scammer can fake a voice, but not an existing phone number.
- Agree on a code word within the team for urgent financial requests — something never shared publicly, asked every time an unusual request comes in.
- Build in a short delay for unusual or urgent transfers, even when the request says “today.” That handful of hours is usually enough to unmask a scam.
- Train the team to spot the pattern: time pressure, secrecy (“don't mention this to anyone yet”), and an unusual channel are three signals that, together, almost always point to fraud.
How NetGuard helps
This kind of fraud isn't caused by a gap in the IT setup — it's caused by missing agreements and a team that doesn't know how to respond. With CISO-as-a-Service, an SME gets a tested payment and verification policy — plus training that teaches the team to spot the one call that doesn't look like the rest — without hiring a full-time security lead. A no-obligation introduction can be arranged by e-mail.
Related articles
Your website still works fine. That says nothing about how secure it is.
Since 17 July, WordPress has been patching a flaw that lets an attacker take over a website without logging in. The update exists — the question is whether it's on every site the business owns.
What is External Attack Surface Management, and why does your SME need it?
Attackers scan the internet continuously for vulnerable systems. EASM makes it possible to know what they see — before they strike.
The NIS2 directive: what does it mean in practice for your SME?
The NIS2 directive is in force. Is your organisation affected? What needs to happen now? A practical explanation for business owners and IT managers.