
AI phishing: voice deepfakes and the "CEO" on a video call
2026 brings vishing with convincing voice clones. Controls that work when the attacker sounds exactly like your boss.
Schneier and Krebs have warned AI lowers the bar for sophisticated fraud — it does not replace weak process, it exploits it faster. Global cases of voice deepfake video calls authorizing transfers already made headlines; LatAm will follow — native Spanish plus local context is abundant dataset for malicious actors.
Defense in depth remains process: verbal codes for large transfers, callback to known number (not caller ID — spoofable), training showing voice clone demos. Technically, DMARC and anti-spoofing help on email; voice requires verification culture.
Emerging detection: some enterprise banks offer out-of-band confirmation; SMBs must require the same internally. Document policy: no payment instructions by Teams/WhatsApp alone without second channel.
AI red team: simulate internal vishing (with consent) using commercial cloning tools — educational impact beats slides. CISA awareness materials update; review quarterly.
Do not paralyze business with fear — formalize what should already exist: healthy skepticism toward financial urgency, no matter how real the "president's" voice sounds. AI changes the surface; it does not change that your Puerto Rico SMB needed disciplined payment controls yesterday.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


