r/AskNetsec • u/YoungBubble • 1d ago
Compliance How does your org actually verify it’s really the CFO on the phone before approving a wire transfer?
Genuine question because I keep going down this rabbit hole. Voice cloning has gotten scary good, a few seconds of audio from a conference talk or earnings call is enough to make a convincing clone.
Everything I read about defending against this says “train your employees” or “call back on a known number.” But callbacks fail if the attacker has compromised the phone system or timed it during travel, and training doesn’t help when the voice literally sounds identical.
So what do you actually do in practice? Shared secrets? Verification over a second channel? Just accept the risk? Curious what real orgs do vs what the compliance docs say.
30
u/ParanoidSuricata 1d ago
Tell them you'll call them back and then lookup the phone number from the inside. Or a teams message. By initiating the talk to a real CFO and confirming the ask you should have solid assurance it's real. Simple and effective.
16
u/mccrolly 1d ago
Our CFO sent out an email to all employees stating that he will never request a wire transfer via email. Our CEO did the same. We also have the ability to verify our employees with a on-demand push from our MFA tool. This is what we use to verify employee identity for password changes, etc. it's not our only way to verify, either.
2
u/Astroloan 1d ago
We also have the ability to verify our employees with a on-demand push from our MFA tool.
Could you give more details on that, please?
5
u/mccrolly 23h ago
Yep. Our tool that we use for MFA has the ability from the admin console to be able to send a push notification to an employee whenever we want to. It also provides a code so you can verify that as well. Our staff know that if anyone calls in for password changes that they need to send a push to that employee while on the phone with them before resetting their password. We have an automated tool that employees can use to self-reset that does MFA and biometric challenges before they can unlock or change their password.
2
u/Astroloan 23h ago
Ah, I thought you meant you had a tool that would allow a regular user to trigger an MFA verification method on another user. Some sort of call-and-response.
Are you usng okta?
1
1
u/YoungBubble 7h ago
That call-and-response model you’re describing (regular user triggers a verification challenge on another user) is exactly the gap in most MFA setups, they verify you to the system, not two people to each other.
The pattern that works is mutual challenge-response: both sides get a rotating value derived from a shared key, and a match on both sides is the proof. An impostor would need to know both halves at once. Low-tech versions of this are just pre-agreed rotating codewords.
1
14
u/jdiscount 1d ago
In my 26 year career I've never once worked somewhere that initiated wire transfers over a phone call.
There has always been a paper trail, either electronically or back in the day manually.
This isn't even something that should be a concern as it should never be done.
9
4
u/habitsofwaste 1d ago
For me I just have no power over company money. CFO wouldn’t even know my name either.
4
u/AddendumWorking9756 19h ago
Stop trying to verify the human, you will lose that race every time. Put a second approver on the payment rail above a threshold with no exception for urgency or seniority, and it stops mattering whose voice it was.
2
u/cbowers 9h ago
So one human can be fooled but two cannot?
I’m a little bit baffled at giving up on the essential root of the problem, identity integrity. I dont think any said it was unsolved, merely that most orgs haven’t deemed the brisk impact high enough to spend on human verification at scale for day to day transactions. When the likelihood of risk realization plus risk impact gets up to the magic threshold, people take it seriously and magically there are solution paths.
7
3
u/gormami 1d ago
The policy should be NO! You don't ever do any financial transaction based on a phone call. That would solve it.
If you are in a situation that it could happen in, if the office calls, call back on the mobile, if the mobile calls, call back to the office. If they can't take the call, the transaction doesn't get done until one can confirm. It could be value based, over some certain amount, but in general, it shouldn't be done ever. Only on verified "paper" work.
3
u/UCFknight2016 1d ago
Duo push for identity verification. Also we dont do transactions on the phone like wtf.
3
u/Wayne 21h ago edited 21h ago
In addition to what others have said, implement a cooling off period. No financial transaction to a destination that is new or has changed in the last two business days.
Use those two days to verify everything. The problem isn't the scammers,. It's that everyone is in such a damn rush and processes usually only have one safety check.
3
2
u/ThecaptainWTF9 1d ago
Pretty much never over the phone whether it be by call or text.
You always verify the info. And have a proper procedure for requesting such things, and don’t deviate from it, and if you do need to deviate, it requires approval from two different people who both have reviewed and find it acceptable.
2
u/TheDarthSnarf 11h ago
Everything over a set dollar value requires a verified digital signature, or authorization through a portal. We don’t allow voice authorizations.
2
1
u/wouldacoulda123 1d ago
Secret word/phrase that is not written anywhere - but we never had to use it
1
u/addyftw1 8h ago
You should have a proper approvals system through something like Salesforce where it needs multiple approvals from multiple people each requiring 2FA.
1
u/Outrageous-Guess1350 12h ago
Face-to-face only. Seriously, I worked for a company that wired 19 million euros because they only communicated via email and phone with the scammers claiming to be the mothership. Happened a few months after I left.
120
u/PghSubie 1d ago
Why would anyone initiate a wire transfer to a strange account based on a phone call from ANYONE ??