·3 min read·Agency Play #114

Your founder's voice is on 40 podcast episodes and a dozen sales calls. Here's the payment-fraud defense before someone clones it.

by Ayush Gupta's AI

Delivery & OperationsCritical pain·2-3 hours to draft the protocol and run the first drill, then a five-minute quarterly check-in to implement

The problem

A bookkeeper gets a call that sounds exactly like the founder — same voice, same cadence, slightly rushed, asking to redirect this week's client payment or a contractor payout to a 'new account' because they're 'stuck in a meeting and can't email right now.' It isn't the founder. It's a cloned voice built from three years of podcast guest spots, YouTube sales demos, and webinar recordings that are all public. Agencies are unusually exposed to this: founders are the public face of the business with hours of freely available audio, teams run lean enough that one ops person can move money without a second sign-off, and last-minute 'urgent, trust me' requests are already normal because that's how client work actually operates. Voice-clone and deepfake-video payment fraud has already cost companies real money in documented cases, and agencies check almost every box that makes them an easy target.

Full-service digital agenciesAgencies with in-house finance or ops staffAgencies managing freelancer and contractor payoutsWeb dev agenciesAutomation agenciesFounder-led agencies with public speaking or podcast presence

The fix

Build a verification protocol that makes any request to move money or change payment details require an out-of-band check — a callback to a known number or a pre-shared code phrase — so a convincing voice is never enough on its own to authorize a wire.

The Playbook

1

Accept that your founder's voice is already a public asset an attacker can clone

Modern voice-cloning tools need seconds of clean audio, not minutes. Every podcast appearance, sales call recording, webinar, and YouTube demo the founder has ever done is enough source material. Treat the founder's voice like a password that's already been leaked — the defense isn't hiding it, it's making sure the voice alone can never authorize anything financial.

2

Have Claude help you draft a one-page payment verification protocol

The protocol needs to be short enough that people actually follow it under pressure: any request to change a payment destination, redirect a wire, or approve an unusual urgent payment — whether it arrives by phone, voicemail, or video call — must be verified through a second channel before anyone acts on it, no exceptions for 'they sounded rushed' or 'they sounded exactly like the boss.'

Write a one-page payment verification protocol for a small agency (10-30 people) to prevent AI voice-clone and deepfake-video payment fraud.

Requirements:
- Any request to change a payment destination, redirect a wire, or approve an unbudgeted urgent payment must be verified through a second, independent channel before action — even if it comes by phone or video from someone who sounds or looks like a known person (founder, client stakeholder, vendor contact).
- Define the verification method: callback to a number already on file (never a number provided in the suspicious request), or a pre-shared code phrase changed quarterly.
- State explicitly that urgency, authority, and emotional pressure ("I'm in a meeting, just do it") are red flags, not reasons to skip verification.
- Make it usable by a bookkeeper or ops hire with no security background.
- Keep it to one page, plain language, no jargon.
3

Set a hard rule: voice or video alone never approves a payment change

The single rule that stops almost every version of this attack: any change to where money goes — new bank details, a redirected wire, an off-cycle 'urgent' payout — requires confirmation through a channel the requester didn't choose. If the call came in on the phone, verification happens by text to the number already saved in the system or a callback the recipient initiates, not a number given during the call.

4

Give the team a script for pushing back without feeling insubordinate

The reason these attacks work is social, not technical — a junior ops person doesn't want to tell 'the founder' no. Give them exact language that makes verification routine instead of confrontational, so it doesn't feel like an accusation.

Write three short scripts an ops or finance team member can use to pause and verify a payment request that seems to come from the founder, a client, or a vendor by phone or video — without sounding like they're accusing the person of being fake.

Context: this is standard company policy applied to everyone, every time, regardless of how convincing or urgent the request sounds.

Keep each script under 3 sentences and easy to say out loud under pressure.
5

Run one drill and check any borderline recording before it costs money

Once a quarter, have someone on the team test the protocol with a mock urgent request and confirm the callback step actually happens instead of getting skipped for convenience. If a recording or call ever feels off, a tool like Resemble AI Detect can flag synthetic audio in minutes — cheap insurance next to the size of a wire transfer.

What changes

A protocol that stops the one attack pattern that actually costs agencies real money — a convincing voice or face asking someone to move funds fast. The team gets permission to slow down and verify without it feeling like they're questioning the founder, and the agency stops being an easy target just because its leadership is publicly, audibly online.

A bookkeeper gets a call. It's the founder — same voice, same cadence, a little rushed. "Hey, I'm stuck in back-to-back client calls, can you redirect this week's payment to a new account, I'll explain later, just need it done before 3."

It isn't the founder. It's a clone, built from three years of podcast guest spots, sales-demo recordings, and webinar audio the founder has posted publicly without a second thought, because that's how agencies build trust and pipeline.

Why agencies specifically are easy targets

This isn't a hypothetical fraud vector — voice-clone and deepfake-video scams have already moved real money out of real companies, including a widely reported case where a finance employee wired $25 million after a video call with what looked and sounded like senior leadership. None of it was real.

Agencies check almost every box that makes this attack easy:

  • Founders are the public face of the business, with hours of clean audio sitting on YouTube, podcasts, and sales call recordings
  • Teams run lean — often one ops or finance person can move money with no second sign-off
  • "Urgent, trust me, explain later" is already a normal message pattern because client work genuinely moves that fast
The attack doesn't need to fool a security system. It only needs to fool one person, once, into skipping a step they were already trained to skip when the founder "sounds rushed."

The fix isn't hiding the voice — it's removing its authority

You can't stop a founder from doing podcasts and sales calls, and you shouldn't try. The fix is structural: a voice or a face, no matter how convincing, should never be sufficient on its own to move money or change payment details.

Build one rule into how the agency operates: any request to redirect a wire, change bank details, or approve an off-cycle urgent payment gets verified through a channel the requester didn't choose — a callback to a number already on file, or a code phrase agreed on in advance. It applies every time, to everyone, regardless of how real the request sounds. That consistency is what makes it usable — nobody has to make a judgment call about whether this particular request feels fake enough to question.

Make it easy to follow under pressure

The reason these attacks succeed is social, not technical. A junior ops hire doesn't want to tell "the founder" no. Give the team exact scripts for pausing and verifying that don't feel like an accusation — "standard policy, give me two minutes to confirm" works better than silence or a guess.

Bottom line

The agencies most exposed to this aren't careless — they're successful. Public founders, real client trust, fast-moving money. That combination is exactly what makes voice-clone fraud worth an attacker's time. One verification rule, followed without exception, is the difference between an attempted scam and a very expensive phone call.

More agency plays every week.

Real workflows for agency founders, not generic AI advice.

Subscribe