At 7:43 AM on a Monday, Orbital's payroll specialist received a voicemail from the CEO asking for an urgent $840K transfer. The CEO was in his office. He had not made the call.
Background
Orbital's CEO was known for early-morning calls when deals were closing. The payroll specialist had taken several over the past two years — always brief, always urgent, always resolved without incident. She knew his cadence, his phrasing, the slight hurry in his voice when time was short.
What Happened
The voicemail lasted 47 seconds. "Sarah, it's David. I'm boarding in 20 minutes and I need you to process an off-cycle transfer for a deal I'm closing — $840,000 to the account details in the brief I just emailed. Don't run it through the usual approval chain, I need it done before my flight." There were airport announcements audible in the background.
Sarah was 90% ready to act. She had the payroll tool open. What stopped her was a two-week-old company policy requiring all voicemails requesting transfers to be forwarded to Phoenix's analysis endpoint before action.
Timeline
| 7:43 AM | Voicemail received from spoofed CEO number. Airport ambience included in background. |
| 7:44 AM | Sarah forwards voicemail to Phoenix analysis endpoint per two-week-old policy |
| 7:44:11 AM | Phoenix voice-clone detector scores audio 0.87 synthetic confidence. Payroll tool auto-paused for new beneficiaries. |
| 7:46 AM | Phoenix investigator calls Sarah and explains the hold. She is shaken. |
| 7:48 AM | Real David — in his office, never near an airport — confirms via pre-shared challenge phrase. He is equally shaken. |
| 7:52 AM | Incident escalated internally. Voice sample preserved for evidence. |
| 9:15 AM | Sample shared with FBI IC3 and financial industry ISAC. Challenge-phrase program expanded company-wide. |
How We Responded
- Real-time voice synthesis detection. Phoenix's voice analysis pipeline scored the 47-second audio in 11 seconds — flagging prosody anomalies, spectral artifacts, and unnatural breath patterns consistent with current-generation voice cloning. The score of 0.87 (not 1.0) reflects genuine uncertainty; background noise added by the attacker partially masked some artifacts. That's honest.
- Automatic payment pause on new beneficiaries. Regardless of the voice analysis result, any payroll action targeting a new beneficiary account triggers a mandatory hold. This is a backstop that operates independently — even if the voice detection had scored 0.3, the transfer would have paused.
- Pre-shared challenge phrase verification. Orbital had enrolled in Phoenix's executive challenge-phrase program two weeks earlier. Each C-suite member has a phrase known only to them and a sealed HR record — something no attacker with only public voice samples could know. David's phrase was never spoken in the voicemail.
- Evidence preservation and industry sharing. The voice sample was preserved under chain-of-custody procedures before any remediation, making it usable for law enforcement. The underlying voice model was identified as consistent with a commercially available cloning service, and the finding was shared with industry partners within two hours.
What Almost Went Wrong
The new voicemail-forwarding policy had been in place for exactly 14 days. The CISO had pushed for it after reading an industry report; Sarah had rolled her eyes during the training. "I thought it was another box-ticking exercise," she told us later. If the policy had been introduced a week later, or if Sarah had been in a hurry that morning, the transfer would have gone.
Outcome
- Loss prevented: $840,000
- Detection time: 11 seconds
- Synthetic confidence score: 0.87 / 1.0
- Time from voicemail to hold: 68 seconds
Key Takeaways
- Voice cloning tools available to criminals today can replicate a voice from as little as 3 minutes of public audio — earnings calls, conference talks, LinkedIn video posts.
- Pre-shared challenge phrases are the most friction-free, highest-confidence verification method for executive impersonation. Roll them out before you need them.
- Detection scores below 1.0 are honest, not a weakness. Real-world deepfakes include noise and artifacts that shift the score. Act on high scores; don't wait for certainty.
- Policy timing matters. The 14-day-old policy saved $840K. Security controls need to be in place before the attack, not after.