Deepfake or voice-clone payment fraud: incident response playbook
Use it when: Someone was asked to pay, change bank details or share access by a call, voice note or video that sounded or looked like a colleague, executive or supplier.
First 15 minutes
- If money was sent, call your bank's fraud line now and ask them to recall or freeze the payment.
- Call the real person on a number you already had, not one from the message.
- Keep the recording, voice note, video link, call log and any messages.
- Stop any other payment or bank-detail change linked to the same request.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (2 steps)
- Eradicate (1)
- Recover (1)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 11 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.
Other playbooks
- Phishing and business email compromise
- Ransomware
- Lost or stolen device
- Data sent to the wrong person or exposed
- Compromised account or cloud admin access
- Malware on a device
- Major outage or denial of service
- Supplier or third-party breach
- Data leaked to an AI tool
- Rogue or misbehaving AI agent
- Prompt injection against an AI assistant or agent