Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Incident Response

Deepfake Voice Cloning Fraud: The Incident Response Playbook Financial Institutions Are Missing

When a deepfake call beats your fraud controls and a wire goes out, you have hours — not days — to act. This playbook covers the challenge protocol before a wire clears, wire recall procedures, SAR filing for deepfake fraud, evidence preservation, and what FinCEN and the FBI expect you to have documented.

By Rebecca Leung · June 20, 2026 ·
Table of Contents

TL;DR

  • Deepfake-enabled vishing attacks rose more than 1,600% in Q1 2025 versus Q4 2024; the FBI’s 2025 Internet Crime Report logged 22,000+ AI-related fraud complaints totaling $893 million in losses
  • FinCEN issued Alert FIN-2024-Alert004 in November 2024 specifically warning financial institutions about deepfake fraud — that alert created a documented obligation to implement responsive controls
  • The wire recall window is tight: the FBI’s Recovery Asset Team (RAT) has the best chance of freezing funds if you contact ic3.gov within hours, not days
  • When filing a SAR, use the keyword “DEEPFAKE MEDIA” in the subject line — FinCEN specifically flagged this for pattern analysis

In early 2024, a finance employee at Arup — the global engineering firm — wired $25.6 million across 15 transfers to five Hong Kong accounts. He’d been suspicious at first. Then he joined a video call.

The CFO was there. So were other senior executives. Convincing faces, correct voices, right context. Every single participant was a deepfake. The fraud wasn’t discovered until the employee followed up with corporate headquarters and realized no one had scheduled the meeting.

That case set the attack template. Deepfake-enabled vishing attacks surged more than 1,600% in Q1 2025 compared to Q4 2024 in the US alone. The FBI’s 2025 Internet Crime Report logged more than 22,000 AI-related fraud complaints with losses exceeding $893 million. A voice can be cloned from as little as three seconds of publicly available audio — and every earnings call, conference keynote, and investor presentation your executives have ever recorded is sitting on the open internet as potential training data.

Most incident response playbooks weren’t written for this. Wire fraud checklists assume the control failure was a compromised email account. Deepfake attacks bypass email controls entirely — they exploit identity verification at the voice and video layer, targeting the person on the other end of the call who is authorized to initiate the transfer.

Here’s what the response actually looks like.

Why Deepfake Wire Fraud Is Different from Standard Wire Fraud

The money moves the same way. The response mechanics look similar on the surface. But the differences matter for how you respond and what you need to document.

The control that failed is identity, not channel. Standard wire fraud involves account compromise, email hijacking, or spoofed instructions. Deepfake attacks fail your identity verification — the voice biometric, the face match, the basic human judgment that this is the person they say they are. The transaction may have cleared every standard check because the person authorizing it genuinely believed they were complying with a legitimate instruction from a known executive.

Evidence is different. In a BEC wire fraud case, your evidence is email headers, IP logs, and message content. In a deepfake case, the primary evidence is the audio or video of the interaction itself — which exists only if it was recorded, and which attackers may take steps to prevent. Preserving that evidence requires immediate action, not routine log retention.

The SAR requires a specific narrative. FinCEN’s Alert FIN-2024-Alert004 explicitly instructed institutions to include “DEEPFAKE MEDIA” in SAR narratives for pattern analysis. Examiners expect the narrative to explain why controls didn’t flag the transaction — which requires describing the deepfake mechanism, not just the transaction.

Regulatory expectations are specific. If a deepfake attack occurs after November 2024 — when FIN-2024-Alert004 was issued — examiners will ask what your institution did in response to the alert. The alert made the threat a known, documented risk. Failure to implement documented controls after that date is harder to defend.

The Challenge Protocol: Before the Wire Goes Out

The most effective incident response happens before the money leaves your institution. That requires a documented, practiced challenge protocol — a set of verification steps that must occur before any payment instruction delivered by phone, video call, or instant message is authorized.

An effective challenge protocol for high-value wire instructions includes:

Out-of-Band Verification (OOBV). Always confirm payment instructions through a separate, trusted channel — not a reply through the same medium. Received a wire instruction by video call? Call back on the executive’s number from your address book. Received it by phone? Follow up by email to the known corporate address. The separate channel must be truly independent — not a call-back in the same meeting, not a message reply in the same thread.

Pre-established code words. Organizations with significant wire volumes should maintain a rotating code word system between executives and the finance team. A pre-established phrase included in any large payment instruction that changes on a schedule. A deepfake attacker who doesn’t know this week’s code word cannot complete the verification.

Threshold-triggered mandatory holds. For transfers above a defined dollar threshold, implement a mandatory hold — even for instructions that appear to come from known executives — until out-of-band verification is complete. This threshold should be documented, board-approved, and enforced at the wire processing system level, not left to discretion.

No same-session confirmation. Deepfake attackers control the call or video session. Any verification request made within that session — asking for a callback in the meeting, requesting email confirmation that arrives during the call — is confirmable within the attacker’s environment. The verification channel must be entirely separate.

If the Wire Went Out: The First 60 Minutes

If a wire transfer completes before the fraud is identified, the clock starts immediately. Every additional hop through the banking system reduces the chance of recovery.

Minutes 1-30: Contact wire operations and your correspondent bank Request an immediate hold or recall. For SWIFT gpi-enabled payments, initiate a gpi Recall through your SWIFT service bureau or correspondent. Have the UETR (Unique End-to-End Transaction Reference) from the wire record ready — this is the identifier the receiving institution needs to locate and hold the payment. If the wire is within the Fedwire system, contact your Federal Reserve account servicer.

Minutes 30-60: File with IC3 and request RAT assistance File a complaint at ic3.gov and explicitly request assistance from the Recovery Asset Team (RAT) in your submission. The FBI’s RAT coordinates directly with financial institutions to place holds on fraudulent wire transfers — they have established channels with banks that move faster than standard inter-institution contact. Include the SWIFT UETR or Fedwire IMAD in your complaint. The RAT is most effective within the first 24-48 hours.

Minutes 30-60: Place a legal hold on all relevant records Issue an immediate legal hold that stops routine log deletion for all systems involved in the transaction. This covers voice recordings, video recordings, authentication logs, wire processing records, any digital communications related to the fraudulent instruction, and any deepfake detection tool alerts that did or didn’t fire.

Time WindowActionOwner
0-30 minInitiate wire recall (SWIFT gpi Recall or Fedwire)Wire Operations / Treasury
0-60 minFile IC3 complaint, request RATBSA Officer / Compliance
0-60 minNotify General CounselGeneral Counsel
0-60 minLegal hold on all records from the incidentIT Security / Legal
1-4 hoursNotify senior leadership and document initial timelineCISO / Risk Management
24-48 hoursComplete internal incident reportCompliance / Risk
30 daysFile SARBSA Officer

SAR Filing: What FinCEN Is Looking For

FinCEN’s Alert FIN-2024-Alert004 was specific about SAR documentation: institutions should include “DEEPFAKE MEDIA” in the SAR subject line when deepfake fraud is suspected. This is FinCEN’s mechanism for building national pattern data. Don’t miss it.

Your SAR narrative for a deepfake wire fraud incident should address:

  1. How the fraud was identified — discovered before the wire, after, during reconciliation, or through law enforcement contact
  2. The deepfake mechanism — voice call, video conference, synthesized audio, manipulated documents
  3. Who was impersonated — role and title (not necessarily name unless required), and how the attacker likely obtained training data (public earnings calls, conference videos, media appearances)
  4. Transaction details — exact amount, beneficiary name and bank, receiving account number, SWIFT UETR or Fedwire IMAD, date and time of authorization
  5. Which controls were bypassed — what verification steps weren’t completed or were completed within the compromised channel
  6. Controls that were in place at the time — document what was implemented in response to FIN-2024-Alert004, specifically

Standard SAR timing: within 30 calendar days of detecting suspicious activity, or 60 days if no suspect has been identified. Given law enforcement’s interest in tracking deepfake fraud patterns, many institutions file within 10-15 days when the material facts are documentable.

Evidence Preservation Checklist

Deepfake fraud evidence is perishable. Many attackers use platforms designed to avoid leaving persistent artifacts.

☐ Legal hold on all call recordings from the incident timeframe (inbound and outbound)
☐ Preserve any video recording of the fraudulent meeting — screen record if native recording wasn’t enabled
☐ Authentication logs from the wire initiation and approval system
☐ All emails, messages, and communications referencing the fraudulent payment request
☐ Network logs and access records for systems involved in authorization
☐ Deepfake or fraud detection tool logs — alerts that fired or failed to fire
☐ The phone numbers, email addresses, or meeting links associated with the fraudulent contact
☐ Screenshots of any digital artifacts from the communication (caller ID, video platform details)
☐ Contemporaneous employee statements — document witness accounts within hours, not days
☐ The original wire instruction documentation and approval chain records

Post-Incident: What Control Gaps This Exposes

A deepfake wire fraud incident typically traces back to one or more specific control failures. The post-incident review should identify which applied:

No documented OOBV procedure. The most common gap. Payment instructions delivered by phone or video were not required to be confirmed through a separate trusted channel before authorization. Fix: write and publish the procedure, train on it, enforce it at the process level.

OOBV procedure existed but wasn’t followed. Training and monitoring gap. The procedure was written; it wasn’t practiced. This is an internal audit finding that requires remediation evidence — not just a refresher email.

Verification happened within the compromised channel. The employee asked for a callback or email confirmation during the call, which the attacker provided. Fix: the procedure must explicitly prohibit same-session confirmation. The verification channel must be physically separate and established before the incident.

No documented threshold for mandatory holds. Wire amounts above a given threshold weren’t subject to automatic holds pending independent verification. Fix: define the threshold, get board approval, build it into the wire processing workflow.

No employee training on deepfake fraud red flags. FinCEN Alert FIN-2024-Alert004 outlined specific red flags — urgency, unusual meeting platforms, instructions that bypass normal approval workflows. Training that covers these red flags is part of what examiners will ask about.

For the detection controls and prevention framing that should accompany this playbook, see Deepfake Detection and Controls for Financial Services. For the broader wire fraud response from a UCC Article 4A perspective, see Wire Transfer Fraud Incident Response. For an account takeover playbook covering the adjacent controls layer, see Account Takeover Incident Response.

What Examiners Are Starting to Ask

For institutions that experience deepfake wire fraud after November 2024, examiners will ask a specific question: what did you do in response to FinCEN Alert FIN-2024-Alert004?

The answers they’re looking for:

  • Updated or created a documented OOBV procedure for high-value wire instructions
  • Added deepfake-specific content to annual BSA/AML and fraud training
  • Defined a documented escalation path for suspected deepfake attacks
  • Reviewed SAR filing procedures to include the DEEPFAKE MEDIA keyword flag
  • Set a board-documented threshold for mandatory holds on large wire transfers

If the answer is “we were aware of the alert but hadn’t yet implemented responsive controls” — that’s the gap that turns a crime-victim scenario into an MRA. The regulatory expectation, documented since November 2024, is that known threats generate documented response.

So What?

The Arup attack cost $25.6 million in early 2024 — before deepfake-as-a-service platforms became commodity tools, before voice cloning from three seconds of audio became a consumer product, and before vishing attacks grew 1,600% in a single quarter.

That baseline doesn’t improve from here.

The incident response playbook is straightforward once it’s documented: challenge protocol before any wire authorization, wire recall and IC3 contact within the hour if one goes out, SAR with “DEEPFAKE MEDIA” in the subject, evidence hold from minute one, post-incident control review against the FinCEN alert.

The gap isn’t in knowing what to do. It’s in whether your institution has written it down, tested it in a tabletop, and built the mandatory hold into the authorization workflow before you need it.

That’s the prep that determines whether a deepfake attack becomes a recoverable incident or a regulatory finding on top of a financial loss.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

How is deepfake voice fraud different from a standard wire fraud incident?
The mechanics of wire fraud are the same, but the evidence and response steps differ. Deepfake attacks exploit your identity verification controls at the point of contact — the transaction may have passed all standard fraud checks because what appeared to be a legitimate voice or video of a known executive authorized it. Your SAR narrative needs to address why controls didn't flag it, what the deepfake indicators were, and which verification procedures were bypassed. Evidence preservation also differs — you need to capture the audio or video of the interaction itself, not just payment records.
What's the fastest way to attempt a wire recall after deepfake fraud?
Contact your correspondent bank or wire operations desk immediately and request a recall. For SWIFT payments, use the gpi Recall service — you'll need the UETR (Unique End-to-End Transaction Reference). Simultaneously, file a complaint at ic3.gov and request assistance from the FBI's Recovery Asset Team (RAT), which coordinates wire hold requests with financial institutions. Speed is critical — the window for successful recall narrows significantly after 24-48 hours as funds move through additional hops.
What should we include in a SAR narrative for deepfake fraud?
Your SAR narrative should include: (1) how the fraud was discovered; (2) description of the deepfake medium used — voice call, video call, synthesized audio; (3) who was impersonated and how the attacker likely obtained voice or likeness data; (4) transaction details — amount, beneficiary, receiving institution, SWIFT reference; (5) which internal controls were bypassed and how; (6) what verification steps were attempted and why they failed. Per FinCEN Alert FIN-2024-Alert004, use the keyword 'DEEPFAKE MEDIA' in the SAR subject line for pattern analysis.
How quickly do we need to file a SAR for deepfake wire fraud?
Standard BSA timelines apply: within 30 calendar days of detecting suspicious activity, or 60 days if the subject is still unidentified. In significant deepfake wire fraud cases, many institutions file within 10-15 days given law enforcement's interest in early notification. SAR filing obligations attach when you know or have reason to suspect suspicious activity — not when the investigation is complete.
Is deepfake fraud covered by cyber insurance?
It depends on your policy. Deepfake wire fraud typically falls under social engineering coverage and funds transfer fraud coverage — both of which carry sub-limits or exclusions in many legacy policies. Some policies require physical IT system compromise to trigger coverage, and a deepfake voice call may not qualify. The 2025-2026 renewal cycle saw underwriters adding explicit deepfake or AI-generated fraud riders or sublimits as separate line items. If your current policy doesn't have explicit deepfake coverage, that's a renewal conversation to have now.
What does FinCEN expect financial institutions to have as controls against deepfake fraud?
FinCEN Alert FIN-2024-Alert004 (November 2024) outlined expected controls: enhanced identity verification for high-value transactions, liveness detection for video-based verification, mandatory out-of-band verification (OOBV) for payment instructions received by phone or video, employee training on deepfake red flags, and documented transaction hold procedures. Institutions that cannot show they implemented controls responsive to that alert will face examiner questions if a deepfake fraud occurs — the alert made the threat a known, documented risk.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.