Abstract image representing AI voice cloning and deepfake impersonation risks for family offices.

A family office that has worked on payment fraud holds a rule for instructions that move money, and it holds it for good reason. What it usually does not hold is a rule for the request that moves no money at all: the principal’s voice on a Sunday evening asking an assistant to forward the trust documents, a familiar face on a video call asking for the new custodian contact, a daughter’s number calling a grandparent from an airport in distress. Those requests never reach the payment control, and the person making them is someone the office knows, so the instinct to verify does not fire.

The control that works is a phrase agreed in advance between the people who need it, used on a channel chosen before anybody was frightened, and while writing it down takes an afternoon, making it usable is the whole of the work, because the obstacle is social rather than technical.

What the advisories establish

The FBI’s Internet Crime Complaint Center published an advisory in December 2024 on criminal use of generative AI in financial fraud, and its list of observed techniques is the useful part. Under audio it records the cloning of family members’ voices in crisis scenarios and impersonation of individuals to obtain access to bank accounts. Under video it records deepfakes of executives or authority figures for live chats. The advisory’s recommendation is to “Create a secret word or phrase with your family to verify their identity.”

A second IC3 advisory, from May 2025, describes the same capability aimed higher. Malicious actors had sent text messages and AI-generated voice messages impersonating senior officials, working to “establish rapport before gaining access to personal accounts.” Its guidance distinguishes vishing, the targeting of individuals using voice memos and increasingly using “AI-generated audio to impersonate well-known, public figures”, from smishing (phishing by text message). The operational instruction in it is one most offices have never turned into a rule: verify new contact information through a platform on which you have already confirmed the person, rather than through the channel that delivered it.

The United States Treasury’s Financial Crimes Enforcement Network issued an alert in November 2024 on fraud schemes using generative AI to circumvent identity verification, authentication and customer due diligence controls at financial institutions, having observed a rise in suspicious activity reports describing suspected deepfake media since 2023. That alert is addressed to banks rather than to families, and it is worth a family office’s attention for one reason: the institutions holding the family’s money are contending with synthetic identity documents and synthetic faces at their own onboarding and verification gates. The assumption that the custodian will catch an impersonation of the principal is thinner than it was.

Two sources outside the United States describe the same mechanism in the same terms, which is what makes it a control question rather than a national one. Canada’s Cyber Centre records that deepfakes are “becoming an increasingly common tactic used by cyber threat actors” and that the technology “is evolving rapidly and deepfakes are getting easier to make and harder to detect.” Australia’s consumer regulator is blunter about the effort involved: “Scammers can use a few seconds of a voice recording to create AI clones”, and “They can use these clones and call you pretending to be friends or family members in distress.” A few seconds is less than any principal who has given an interview, recorded a message or spoken at an event has already published.

In September 2023 the United States National Security Agency, FBI and CISA published a joint information sheet, Contextualizing Deepfake Threats to Organizations, urging organizations to review it for steps to “prepare, identify, defend against, and respond to deepfake threats.” The regulators differ on what they will report and where a victim should turn, and each family should know the equivalent body in its own jurisdiction. On the mechanism itself, and on the remedy, four countries agree and none of them is describing a future condition.

Video is where this breaks

Voice has been unreliable for long enough that most offices have absorbed it, at least as a fact if not as a control. Video has not, because seeing somebody is the proof people trust most and the one they are least willing to doubt out loud. A face on a screen, on the expected platform, at the scheduled time, with the right background and the right mannerisms, defeats a verification instinct that was never conscious in the first place.

Treat the presence of a face as evidence of nothing. That is a hard instruction to follow and an easy one to state, and it is the reason the agreed phrase has to exist: it gives a person something to do in a moment when their own judgement is being used against them.

Where callback runs out

The office’s existing rule, that an instruction is confirmed by ending the contact and calling back on a number the office holds in its own records, is the right rule and it does not reach this case twice over. It is scoped to instructions that move money, which is where we set it out in wire transfer authorization controls, and a request for a document, an introduction, a password reset or a travel itinerary never triggers it. And where the caller is a stranger claiming the standing of a police force, a tax authority or a bank’s fraud desk, the office holds no number to call back at all, which is a separate problem with a separate answer.

What is left is the case where callback would work perfectly and nobody thinks to use it, because the request came from someone known, on a channel the office uses every day, and asked for something that felt administrative.

The real obstacle is that nobody wants to challenge the principal

Every control in this area rests on one person asking another to prove who they are, and the requests that matter most come from the people hardest to challenge. An executive assistant asked by the principal’s voice for a document, at speed, with a note of impatience, is being asked to choose between a security procedure and their read of the relationship. Household staff are in a worse position again, because their employment is personal and the cost of being wrong feels personal too.

Our recommendation is to fix this by instruction rather than by training. The principal, in their own voice, tells the assistant, the estate manager and the family that the phrase will be used on them, that using it is expected rather than permitted, and that no explanation is owed afterwards. A control that a junior person has to find the courage to invoke is a control the office does not have. A control the principal has personally mandated costs nobody anything to use.

Extend the same convention to the family, where the mechanism arrives as a distressed call from a child, a sibling or a grandchild, and where the pressure is engineered to prevent exactly the pause that would defeat it. The advice from regulators reduces to the same instruction, which is to call the person back on a number you already hold rather than to respond to the one that reached you, and the secret-phrase recommendation exists because a frightened parent will not always do that. A family office is well placed to be the party that gets both agreed, because it is usually the only party that talks to everybody, including the relatives in other countries whom nobody has briefed.

Detection is not the control

Advisories offer signs to look for: imperfections in images, lag between audio and video, unnatural movement, an off note in tone or word choice. Those are worth knowing and they are not a control, because they depend on the quality of a particular forgery and on the attention of someone who is being hurried. A procedure that asks people to be perceptive fails whenever the forgery is good, and the forgeries are improving on a schedule nobody controls. A procedure that asks a question only the real person can answer fails only if the answer has leaked.

What to build

  • Agree one phrase for the family and one for the office. Not a password, and nothing derivable from anything published about the family. It is spoken, never typed into anything that syncs, and never stored in the systems it exists to protect.
  • Name the second channel before you need it. For each person who might be impersonated, decide now which route counts as confirmation, and make it one the office already uses with that person rather than one invented during the call.
  • Extend the rule past money. Documents, credentials, introductions, access requests, changes of contact detail and information about where the family will be all deserve the same pause as a transfer.
  • Give the principal the script. The instruction to challenge has to come from the person who will be challenged, and it has to reach staff who are not employees.
  • Treat any request for secrecy or speed as the trigger, not the context. Urgency and confidentiality are what the technique needs in order to work, and their appearance together is the most reliable signal available.
  • Rehearse it once. Have somebody call the assistant in the principal’s voice and ask for something ordinary. What the exercise finds is not whether the phrase is remembered, but whether the assistant felt able to use it.
  • Refresh the phrase when the group changes, after a staff departure, and after anything that put the family’s voice into public circulation at length.

What to ask this week

If the principal called an assistant tonight and asked for something sensitive, what would the assistant do? Does anybody in this family have a phrase, and would a frightened parent remember it? Which of our people has been told, by name and by the principal, that challenging is expected? What would a member of household staff do with a video call from someone they recognize? And has anybody here ever been given permission to say no to the family?

Where this sits

The payment case, where the instruction moves money, is covered in wire transfer authorization controls. What to do once something has gone wrong is in the first 24 hours of a cyber incident, and the public material that makes a convincing voice or face possible in the first place is the subject of reducing the family’s public exposure.

Agreeing the conventions, briefing the household and running the rehearsal is work we handle through cybersecurity program development, and keeping it current as the family and its staff change is what ongoing advisory is for.

Sources

FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Alert I-120324-PSA, 3 December 2024

FBI Internet Crime Complaint Center, Senior US Officials Impersonated in Malicious Messaging Campaign, Alert I-051525-PSA, 15 May 2025

Financial Crimes Enforcement Network, United States Department of the Treasury, Fraud Schemes Involving Deepfake Media Targeting Financial Institutions, FIN-2024-Alert004, 13 November 2024

National Security Agency, FBI and CISA (United States), Contextualizing Deepfake Threats to Organizations, 12 September 2023

Canadian Centre for Cyber Security, How to identify misinformation, disinformation, and malinformation, ITSAP.00.300, May 2024

Scamwatch, Australian Competition and Consumer Commission, How scammers use technology and AI