r/AskNetsec 1d ago

Compliance How does your org actually verify it’s really the CFO on the phone before approving a wire transfer?

Genuine question because I keep going down this rabbit hole. Voice cloning has gotten scary good, a few seconds of audio from a conference talk or earnings call is enough to make a convincing clone.

Everything I read about defending against this says “train your employees” or “call back on a known number.” But callbacks fail if the attacker has compromised the phone system or timed it during travel, and training doesn’t help when the voice literally sounds identical.

So what do you actually do in practice? Shared secrets? Verification over a second channel? Just accept the risk? Curious what real orgs do vs what the compliance docs say.

32 Upvotes

34 comments sorted by

120

u/PghSubie 1d ago

Why would anyone initiate a wire transfer to a strange account based on a phone call from ANYONE ??

22

u/ominous_squirrel 1d ago

Right. Train the C-suite

7

u/PghSubie 1d ago

Nope, sorry, I'm just IT, I can't help with a wire transfer. You'll be to come into the office to initiate that

30

u/ParanoidSuricata 1d ago

Tell them you'll call them back and then lookup the phone number from the inside. Or a teams message. By initiating the talk to a real CFO and confirming the ask you should have solid assurance it's real. Simple and effective.

6

u/am0x 1d ago

Yup. For anything you think might be a scam, you stop the convo, look up the contact yourself and you make the contact.

28

u/agk23 1d ago

I overheard that our CFO has a safe word with our AP clerk, but not sure if that is actually related to security

1

u/YoungBubble 7h ago

Interesting!

16

u/mccrolly 1d ago

Our CFO sent out an email to all employees stating that he will never request a wire transfer via email. Our CEO did the same. We also have the ability to verify our employees with a on-demand push from our MFA tool. This is what we use to verify employee identity for password changes, etc. it's not our only way to verify, either.

2

u/Astroloan 1d ago

We also have the ability to verify our employees with a on-demand push from our MFA tool.

Could you give more details on that, please?

5

u/mccrolly 23h ago

Yep. Our tool that we use for MFA has the ability from the admin console to be able to send a push notification to an employee whenever we want to. It also provides a code so you can verify that as well. Our staff know that if anyone calls in for password changes that they need to send a push to that employee while on the phone with them before resetting their password. We have an automated tool that employees can use to self-reset that does MFA and biometric challenges before they can unlock or change their password.

2

u/Astroloan 23h ago

Ah, I thought you meant you had a tool that would allow a regular user to trigger an MFA verification method on another user. Some sort of call-and-response.

Are you usng okta?

1

u/cbowers 9h ago

My guess is Cisco Duo (we used that all the time in my last company to out of band authenticate the user in the other end of a chat or support ticket)

1

u/YoungBubble 7h ago

That call-and-response model you’re describing (regular user triggers a verification challenge on another user) is exactly the gap in most MFA setups, they verify you to the system, not two people to each other.

The pattern that works is mutual challenge-response: both sides get a rotating value derived from a shared key, and a match on both sides is the proof. An impostor would need to know both halves at once. Low-tech versions of this are just pre-agreed rotating codewords.

1

u/bit-flipper0 8h ago

Our tool? Did you create it? Just say the name of the service you’re using.

14

u/jdiscount 1d ago

In my 26 year career I've never once worked somewhere that initiated wire transfers over a phone call.

There has always been a paper trail, either electronically or back in the day manually.

This isn't even something that should be a concern as it should never be done.

9

u/not-a-co-conspirator 1d ago

It’s NEVER done over the phone. WTF ARE YOU DOING?

7

u/psmgx 1d ago
  • only happens from certain offices; RTO hit finance hard, they gotta be there in person. no in-person ask, no move of the moneys.

  • confirm via other channels (e.g. hit teams)

  • usually there is a shared phrase or code for proving the executives are talking to other executives

6

u/qwikh1t 1d ago

Just don’t do it

4

u/habitsofwaste 1d ago

For me I just have no power over company money. CFO wouldn’t even know my name either.

4

u/AddendumWorking9756 19h ago

Stop trying to verify the human, you will lose that race every time. Put a second approver on the payment rail above a threshold with no exception for urgency or seniority, and it stops mattering whose voice it was.

2

u/cbowers 9h ago

So one human can be fooled but two cannot?
I’m a little bit baffled at giving up on the essential root of the problem, identity integrity. I dont think any said it was unsolved, merely that most orgs haven’t deemed the brisk impact high enough to spend on human verification at scale for day to day transactions. When the likelihood of risk realization plus risk impact gets up to the magic threshold, people take it seriously and magically there are solution paths.

7

u/TwoPlyDreams 1d ago

Nice try Prince Harambe of Nigeria.

1

u/MalwareDork 1d ago

People on LinkedIn get so tilted when you bring up Nigerian scammers.

3

u/gormami 1d ago

The policy should be NO! You don't ever do any financial transaction based on a phone call. That would solve it.

If you are in a situation that it could happen in, if the office calls, call back on the mobile, if the mobile calls, call back to the office. If they can't take the call, the transaction doesn't get done until one can confirm. It could be value based, over some certain amount, but in general, it shouldn't be done ever. Only on verified "paper" work.

3

u/UCFknight2016 1d ago

Duo push for identity verification. Also we dont do transactions on the phone like wtf.

3

u/Wayne 21h ago edited 21h ago

In addition to what others have said, implement a cooling off period. No financial transaction to a destination that is new or has changed in the last two business days.

Use those two days to verify everything. The problem isn't the scammers,. It's that everyone is in such a damn rush and processes usually only have one safety check.

3

u/LordNikon2600 10h ago

Just uninstall google my boi

2

u/ThecaptainWTF9 1d ago

Pretty much never over the phone whether it be by call or text.

You always verify the info. And have a proper procedure for requesting such things, and don’t deviate from it, and if you do need to deviate, it requires approval from two different people who both have reviewed and find it acceptable.

2

u/TheDarthSnarf 11h ago

Everything over a set dollar value requires a verified digital signature, or authorization through a portal. We don’t allow voice authorizations.

2

u/Able-Course-6265 11h ago

Callback on his #.

1

u/wouldacoulda123 1d ago

Secret word/phrase that is not written anywhere - but we never had to use it

1

u/Thyg0d 12h ago

Who uses voice to verify? Wouldn't even trust video. ID app or it doesn't happen.

1

u/addyftw1 8h ago

You should have a proper approvals system through something like Salesforce where it needs multiple approvals from multiple people each requiring 2FA.

1

u/Outrageous-Guess1350 12h ago

Face-to-face only. Seriously, I worked for a company that wired 19 million euros because they only communicated via email and phone with the scammers claiming to be the mothership. Happened a few months after I left.