How to Verify a CEO's Identity During an Urgent Request
How to verify a CEO's identity when an urgent request arrives: which channel to call back on, what to ask, when to escalate, and what you should never treat as proof.
The call comes in late on a Thursday. It’s the CEO, and the voice is right down to the accent. An acquisition is closing, a payment has to clear before end of day, and nobody else can be told yet. You have about ten minutes to decide.
You will not win this by listening harder. Voice and video can be synthesized from material an executive has already published, and the artifacts that used to give a fake away are getting harder to catch. Your team still controls everything around the request: which channel you answer on, which number you dial next, who else you bring in, and how long you take. Verify the request through those controls instead of trusting the performance.
What You’ll Learn
- The signal that tells you a request needs verification, which has nothing to do with how the caller sounds
- How to run a callback an attacker can’t redirect, starting with where the number comes from
- What separates a challenge question that works from one an attacker can answer off a LinkedIn profile
- Why a familiar voice, a video call, and a liveness check each prove nothing on their own
- How to move the decision to a second approver without accusing anyone of anything
Why a Familiar Voice or Face Is No Longer Proof
Recognizing someone by voice or face is a shortcut that has worked your entire life, and it fails precisely where it matters most here. Cloning a voice takes a short audio clip, and executives supply that material routinely through earnings calls, conference talks, podcasts, and voicemail greetings.
The technology hasn’t solved this from the other direction either. When the Federal Trade Commission assessed interventions against AI-enabled voice cloning, it found problems at every stage: watermarks can be stripped or distorted, false positives in authentication settings cause real harm, and detection is an arms race in which synthesis keeps improving. Its conclusion was that no single approach is sufficient.
Because perception is unreliable, verification must rest on procedure. An attacker controls how convincing they sound and can’t control whether you hang up and dial a number they’ve never seen. If you’re designing the wider defense rather than executing it, our CISO playbook for deepfake social engineering covers the program layer around this procedure.
The Request Patterns That Should Trigger Verification
The trigger is the shape of the request. Any of these should stop the process regardless of who appears to be asking:
- Contact on a channel the executive doesn’t normally use, such as a personal mobile, WhatsApp, or a new messaging profile
- A deadline you didn’t set and can’t negotiate
- An instruction to keep the matter confidential, especially from finance, legal, or a named colleague
- A payment, a change to account or payment details, a credential reset, or a request for sensitive data
- Contact outside working hours, or timed when the people who would normally be consulted are unavailable
- A first-time counterparty, or new banking details for an existing one
- Any suggestion that a normal control should be skipped this once
A request to bypass a control is the signature of the attack, and it’s the item people most often rationalize away, because it sounds like ordinary executive impatience.
When attackers targeted LastPass in April 2024 with audio deepfakes of CEO Karim Toubba delivered through WhatsApp calls, texts, and voicemail, the employee reported it because the contact arrived outside normal channels with manufactured urgency. The attempted attacks on Ferrari and WPP that year were caught through similar circumstantial signals, not audio analysis.
Step 1: Call Back on a Channel You Control
End the current contact first. You cannot verify a request inside the channel that delivered it, because that channel belongs to whoever initiated it.
Then find the number yourself. It has to come from a source you already held before this request existed: your internal directory, your HR or identity system, or a contact saved from earlier legitimate communication. The FTC gives consumers facing cloned-voice scams the same advice, and it transfers cleanly to the workplace. Call the person on a number you know is theirs.
What doesn’t count as a source:
- Caller ID or the displayed number, both trivially spoofed
- The signature block of the message that carried the request
- A number written in the request itself, however official it looks
- A calendar invite or meeting link that arrived with it
- A number you found by searching the web during the call
- An offer to transfer you to someone who can confirm
A transfer offer keeps you inside a session the attacker controls, so whoever answers is whoever they want answering. Decline it and dial out yourself.
If the executive doesn’t pick up, you haven’t verified, and the request stays unactioned. A legitimate urgent request survives a twenty-minute delay, which is the difference between a real deadline and a manufactured one.
A callback is the strongest single control here, but it isn’t absolute. SIM swapping, recycled numbers, call forwarding, and social engineering aimed at a mobile carrier can all put an attacker on the other end of a number you looked up correctly. No single check should carry a payment alone. The money rarely comes back: the FBI’s Internet Crime Complaint Center recorded roughly $3 billion in business email compromise losses in 2025, the large majority moved by wire transfer or ACH.
Step 2: Ask Something an Impersonator Cannot Answer
In July 2024, a Ferrari executive received WhatsApp messages from a profile using CEO Benedetto Vigna’s photo on an unfamiliar number, followed by a live call. The cloned voice was convincing, southern Italian accent included, and the caller described a confidential deal requiring an unusual currency transaction. The executive said he needed to identify the caller, then asked for the title of a book Vigna had recommended to him days earlier. The call ended immediately, as Fortune reported at the time. It remains the clearest example of a low-tech question defeating a high-tech impersonation.
A question works when it meets four conditions. It’s recent, so an attacker researching for weeks would have missed it. It’s shared, drawn from something the two of you specifically did or discussed. It’s private. And it’s not inferable, so someone who knows the general facts of the executive’s life still can’t guess it.
The questions people reach for first fail all four. Birthdays, pet names, universities, hometowns, and first jobs belong to the security-question genre, and open-source research defeats that genre reliably.
With no shared history to draw on, ask something unrehearsed and mundane instead. A real person handles an off-script question the way people handle conversation, with a pause or a digression no script would produce. Someone driving a live voice clone under time pressure tends to freeze or produce an answer that sounds assembled.
You can do all of this without accusing anyone. Something close to what the Ferrari executive said works: “Before we go further, I need to confirm who I’m speaking with.” If the caller treats a routine identity check as an insult or an emergency, that reaction is information.
Step 3: Use a Pre-Agreed Code Word When There Is No Shared History
Challenge questions assume a relationship. A new accounts payable clerk who has never had a conversation with the CEO has nothing to draw on, and that clerk is exactly who these attacks target.
A pre-agreed phrase closes that gap. To be worth having, it needs a few properties:
- Distributed out of band, in person or through a channel unrelated to the ones it protects
- Never volunteered over the channel being verified, only requested
- Not derivable from public information about the company or its people
- Held by a defined, small group rather than circulated broadly
- Rotated on a schedule, and immediately after any suspected exposure
A code word said aloud on a channel an attacker controls is spent. If you use one during a call that turns out to be fraudulent, replace it that day.
A code word also changes what hesitation means. Once one exists and executives know about it, a caller thrown by the request has told you something, because a real CEO who has been briefed expects to be asked.
Step 4: Hand the Decision to a Second Approver
This attack runs on social pressure. The technical work only has to be good enough to put a junior employee somewhere that refusing feels like insubordination, on a deadline, with secrecy imposed so they can’t check with a colleague.
A second approver moves the decision to someone the request never reached, so the pressure doesn’t transfer with it. Make it structural: high-value payments, changes to payment details, and credential or access changes need two people, and the second person must be independently reachable rather than nominated by the requester. Dual approval is one piece of a wider control framework for impersonation fraud covering payment workflows, identity, and email security.
No executive should be able to waive this, including a real one. A genuine request survives the extra fifteen minutes, and a request that can’t survive it is what the control was built for.
Why a Video Call Is Not Verification
In January 2024, an employee at the engineering firm Arup received an email about a confidential transaction and was suspicious of it, which was the correct instinct. He then joined a video conference where the chief financial officer and several colleagues he recognized were all present and all AI-generated. He went on to make 15 transfers totaling HK$200 million, about $25.6 million, as the Financial Times reported.
The video call didn’t fail to catch a fraud. It reversed a suspicion the employee had already formed correctly, which is why adding one to a doubtful request can make the decision worse.
You’ve probably seen the liveness tricks recommended for these calls: ask the person to turn their head fully to one side, wave a hand across their face, or hold an object vertically down the middle of it. These exploit a real weakness, since face-swap models have historically been trained mostly on front-facing imagery and degrade at extreme angles or under occlusion. Treat them carefully, though. Newer models hold up better through motion and profile turns, and face-swap combined with camera injection already defeats some biometric liveness systems. Automated tooling has the same problem, as detection accuracy drops sharply outside the lab.
Their value runs in one direction only. If someone refuses or the image breaks, you’ve learned something and should stop. If they pass, you’ve learned nothing, because passing is exactly what an attacker with current tooling expects to do.
Treat a video call as a request that still needs step one. Leave the call and dial the number in your directory.
What Not to Treat as Proof
Everything on this list feels like evidence and none of it is:
- A familiar voice, including accent, cadence, and verbal habits.
- A face on video, and the profile photo on a messaging app.
- A thread that appears to continue a real conversation. Threads can be reconstructed, and mailboxes can be compromised.
- A meeting invite through your normal calendar. It proves someone had your address.
- Other people on the call. The Arup employee saw several colleagues he recognized.
- Knowledge of internal details. Org structure, project names, and live deals are researchable, and sometimes already stolen.
- An instruction to keep it quiet. Confidentiality is a tactic here far more often than a business need.
Why Employees Need Permission to Delay an Executive
Employees may know the procedure and still hesitate to tell the CEO to wait. Willingness to run the check under pressure is the harder problem.
Resolve that before the call happens. Leadership needs to state in writing that verifying an executive request is always acceptable, that nobody will be penalized for the resulting delay, and that this holds when the executive is genuinely in a hurry. Make verification an assigned step in the payment process rather than an act of individual bravery, so the employee is doing their job instead of making a judgment call about their boss. Repetition turns the written rule into a reflex, which is the argument for training staff against AI voice scams through realistic practice rather than annual modules.
Executive behavior determines whether the procedure holds. A leader who routinely asks people to skip controls for convenience has taught the organization that controls are optional, and an attacker only has to sound like that leader.
How Brightside Helps Teams Rehearse the Callback Reflex
A callback under pressure is a behavior that reading alone cannot establish. Brightside’s vishing simulations create that pressure in a controlled exercise. They run as live phone calls where the AI agent responds in real time rather than reading a script, so an employee who pushes back gets pushback in return. Exercises run voice-only or as hybrid attacks pairing a call with a tracked phishing email, mirroring the multi-channel sequencing in the Ferrari, WPP, and LastPass attempts. Security teams configure the pressure directly, choosing tactics such as authority impersonation, pretexting, and fear or threat, and setting urgency and conversational tone up to commanding.
For authorized audio-deepfake exercises, voice cloning is self-service: an admin uploads a one- to two-minute recording and the platform produces an executive voice replica for use in simulations. Video deepfake simulations follow a different model, scoped, produced, and run by the Brightside team as a managed service. Both vishing and audio deepfakes sit in the Pro tier or the standalone Voice add-on.
Brightside’s achievements reward progress only, with no punitive or “wall of shame” badges. Training that makes failure humiliating would undermine a procedure that depends on people feeling safe enough to stop a payment and escalate.
Frequently Asked Questions
What should I say if I think the person on the call is impersonating my CEO?
No accusation is needed. “Before we go further, I need to confirm who I’m speaking with, so I’m going to call you back on the number in our directory” is enough, and it’s defensible with a real executive. Then dial out yourself. How the caller reacts to a routine identity check is itself information.
What if I can’t reach the executive to verify the request?
The request stays unactioned. Not reaching someone is not a partial verification, and a closing deadline isn’t grounds to proceed. Escalate to a second approver, your manager, or the security team, and let the delay happen.
Can I trust a video call if the person looks and sounds right?
No. An Arup employee released about $25.6 million after a video conference in which the CFO and several recognizable colleagues were all AI-generated, despite having been suspicious of the original email. Treat a video call as another request that still requires a callback on a number you control.
Do liveness checks like asking someone to turn their head actually work?
Only in one direction. If someone refuses, or the image distorts at a profile angle or when a hand crosses their face, you’ve learned something and should stop. Passing tells you nothing, because newer synthetic-video models handle motion and profile turns far better than earlier ones. Never let a passed liveness check substitute for a callback.
How often should code words be changed?
Rotate on a defined schedule, and replace one immediately if it was spoken during any interaction that turned out to be suspicious. A phrase said aloud on a channel an attacker controlled is compromised, even if the attempt failed.