Callback verification is a control that no longer controls anything.
Ringing someone back to confirm a payment has anchored treasury and vendor-management security for decades. It rested on one assumption — that a familiar voice is hard to fake — and generative AI made that assumption false for anyone with a browser. The control is still in every policy document. Almost nobody has updated it.
- audio needed to clone
- ~3 s
- cost of the ai model
- $0
- time to clone
- minutes
- controls triggered
- none
Every control shows green while the money leaves.
This is not a sophisticated attack. It is a cheap AI attack against an expensive assumption, and it works precisely because the control it defeats is the one everyone trusts most.
Nothing in this sequence is a failure of process. The team followed policy exactly. Dual authorisation happened. The callback happened, to a number on file. The control performed as designed — and the design was built for a world where voices could not be manufactured on demand by a model.
Four controls, none of which are looking at the voice.
Most organisations assume something in the stack would notice. Walk through what each control actually inspects, and the gap becomes obvious.
Email security
Headers, domains, links, attachments
The mailbox is genuine and compromised. There is nothing anomalous to score.
Payment screening
Sanctions, velocity, beneficiary history
A first payment to a new supplier account is a normal business event.
Dual authorisation
Two approvers, separation of duties
Both approvers rely on the same callback that the attacker just passed.
Voice biometrics
Does this sound like the enrolled speaker
A generative AI clone is optimised to pass exactly this test. It was trained to.
Keep the callback. Add the one check it was always missing.
You do not need to rip out a control that your policies, auditors and staff already understand. You need to stop that control depending on human hearing, and let AI answer the one question a person no longer can.
Proveniro scores the live callback with a multimodal AI ensemble while it is happening. The question it answers is not ‘does this sound like the CFO’ — a clone passes that — but ‘was this audio produced by a human being, on a real line, right now’.
The verdict lands where the decision is made: a badge in the approver's queue, a hold on the payment file, an escalation to a second channel. Everything else about the process stays as it is, including the paperwork.
- codec_fingerprint—
- prosody_continuity—
- spectral_artefacts—
- replay_liveness—
- registry_match—
- 01
Callback initiated
Unchanged. Same policy, same number on file, same approver.
policy intact
- 02
Media forked
The call leg is mirrored to Proveniro. The caller notices nothing.
passive
- 03
Verdict returned
Human, synthetic, or authorised AI agent — with model reason codes, inside the conversation.
< 400 ms
- 04
Decision enforced
Release, hold or step up to a second channel — and it is all on the record.
sealed
What we hear from treasury and fraud teams.
Shared secrets fail the same way they always have: they leak, they get written down, and a caller who has compromised a mailbox has often already seen the last three emails containing the phrase. They also do not scale past a handful of relationships. Use one if you like — but do not let it be the only thing standing behind the payment.
Update the control before the incident writes the business case.
We will run a shadow evaluation against your own callback traffic and show you, on your data, what the control is currently missing.
soc 2 type ii in progress · eu & uk data residency · no ai training on your data