CyberPlay

Deepfake voice fraud training: verify the request before money or access

Build a callback routine for AI voice scams, executive impersonation and helpdesk requests. Connect CyberPlay Courses with practical game scenarios.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

A staged video meeting in CyberPlay’s voice-deepfake lesson shows a payment request and secrecy pressure.

Expand image · Course video frame · English interface

Actual frame from A copied voice, a copied face, with English on-screen text. The participants are drawings in a fictional training scenario.

Deepfake voice fraud training should teach one repeatable decision: pause a request for money or account access, end the incoming conversation and verify through an established contact route. Recognising a voice or face is not enough to authorise a payment, reset an account or share a code. The useful skill is knowing how to check when the person sounds entirely convincing.

CyberPlay Courses introduces that decision through short video lessons with answer checkpoints. This guide connects the voice, phone-scam and payment lessons with The Social Engineer, then adds a workplace exercise. Course narration is available in English and Romanian; the platform and this game support all nine site languages.

What you’ll take away

  • A familiar voice can support a story without proving who controls the call.
  • A callback uses contact details established before the suspicious request.
  • Confirming identity does not replace payment approval or account-recovery checks.
  • Courses explain the decision; game practice and a new scenario reveal what needs discussion.

1. Why this belongs in the current training programme

A voice deepfake uses generated or manipulated audio to imitate a person. Vishing is the wider category of deception through voice communication; it does not require AI. In its December 2025 update, the FBI described impersonation using AI-generated voice messages, followed by requests involving authentication codes, documents or money. It also warned that generated content can be difficult to identify.

A separate Microsoft report from September 2026 described executive impersonation supported by fabricated invoices and conversations, with indicators consistent with AI-assisted writing. That report concerned email, not a proven voice-cloning campaign. Together, these examples make a useful teaching point: convincing presentation can appear across channels, while the decision to release money or access still needs an independent check.

Section sources: Senior U.S. Officials Continue to be Impersonated in Malicious Messaging Campaign · Protecting organizations from AI-assisted executive impersonation and invoice fraud

2. Start with what the caller wants you to change

Use the fictional prompts below to build a role-specific discussion. Ask learners to name the requested action before debating whether the voice sounds artificial. A person may have a reasonable explanation for poor audio or an unfamiliar number. That explanation does not settle whether the requested action is authorised.

2. Start with what the caller wants you to change
Fictional requestDecision at riskSafe next step
Your director asks for a confidential transfer before a meeting.Payment and approval controls.Hold the request and contact the director through the established directory.
A colleague says a lost phone requires an urgent MFA reset.Account recovery and enrolment of a new factor.Apply the approved identity-verification and recovery procedure.
A support caller asks for a code to stop an attack.Authentication or device access.Do not disclose the code; contact the known service desk.
A familiar supplier voice confirms new payment details.A change to the payee record.Use the existing supplier contact and the payment-change process.

3. Rehearse an independent callback

The FTC's voice-cloning guidance recommends contacting the person using a number already known to be theirs. Apply that principle at work with the approved directory or an established supplier record. Redialling the incoming number, following a new chat invitation or using a number supplied in the request keeps the check inside the caller's story.

Practise a short response: “I will check through our normal contact route and follow the approval process.” Then end the call. For this exercise, ask the learner to point to where they would obtain the trusted contact. If that route is unavailable, identify the designated escalation contact and keep the requested action on hold. A deadline is a reason to escalate the delay, not to invent a substitute verification method.

Nova pauses a staged familiar-voice call and instructs the learner to call an already saved number.

Expand image · Course video frame · English interface

  1. Leave the incoming call

    End the conversation before verifying through a number already saved for the person.

  2. Verify the request, not the voice

    Urgent money and secrecy are reasons to use the established process, even when the voice sounds familiar.

Actual frame from A copied voice, a copied face, with English on-screen text. The call is fictional; independent verification is the decision being taught.

Section sources: Scammers use AI to enhance their family emergency schemes

4. Keep payment approval separate from recognising the person

A successful identity check answers who you reached. The organisation's payment process answers whether the transfer, recipient and amount are approved. In a training discussion, keep those questions separate. Even an authentic manager can ask for something outside their approval authority or overlook a changed supplier record.

Give the finance team a fictional request with a correct project name, a realistic invoice and a familiar voice message. Ask them to locate the approved payee record, explain the required independent verification and identify who must authorise the payment. The aim is a usable sequence, including what happens when an approver is absent. IC3 recommends a secondary channel for account-information changes; your team must map that advice to its actual controls.

Four-step practice sequence: pause the requested action, leave the incoming call, independently verify and apply approvals, then escalate or report unresolved concerns.

Expand image

Original CyberPlay training framework. Adapt the contact and approval steps to your organisation's procedure.

Section sources: Business Email Compromise: The $55 Billion Scam

5. Include the service desk in the same lesson

The July 2025 joint Scattered Spider advisory describes criminals impersonating employees to persuade helpdesks to reset passwords or transfer MFA to attacker-controlled devices. It also describes callers pretending to be support staff. The advisory does not establish that every such call uses a deepfake; ordinary persuasive conversation is enough to make recovery procedures worth rehearsing.

Run the scenario from both sides. An employee must know where to report an unexpected support call. A helpdesk worker must know the approved identity check, when to escalate and how to handle a caller who cannot use their usual factor. Do not turn knowledge of a job title, manager or current project into an improvised identity test. Record any missing recovery route as a process gap for its owner.

Section sources: Scattered Spider: joint cybersecurity advisory, July 2025 update

6. Use three Courses to build the decision in stages

Begin with A copied voice, a copied face for the problem of trusting familiar audio or video. Follow with Vishing: convincing phone scams to practise ending a call and using a contact you independently locate. Add Call before you pay for finance staff, managers and anyone handling payment requests. These are three different angles on the same verification habit.

Each CyberPlay course has five checkpoints where the video stops for an answer before the explanation. Ask learners to explain a missed decision in their own words. A correct checkpoint answer is evidence about that exercise; it does not establish that a real transfer would be stopped. The selected lessons offer English or Romanian narration. Their availability depends on the learner's account and plan.

The payment-diversion course compares trusted verification with requests to bypass approval.

Expand image · Course video frame · English interface

  1. Use a contact from before the request

    Find the number in a trusted existing record rather than in the message being checked.

  2. Keep the second approval

    A convincing call or video does not replace the separate approval required by your payment process.

Actual frame from Call before you pay, with English on-screen text. The lesson connects an independent callback to the organisation’s existing payment approvals.

7. Transfer the habit to The Social Engineer

The Social Engineer includes an incoming “IT Security” call that pressures the player to install a support tool. The player can contact the published helpdesk and report the attempt. Another scenario presents an urgent, confidential executive payment request and offers verification through a separate known channel. These are actual scripted decisions in the game, with fictional organisations and contacts.

Use the game after the relevant Courses and ask what changed when the request appeared in a busy working day. The game rehearses verification under pressure; it is not a detector test for synthetic voices or a live audit of your helpdesk. Review the decision and its debrief, then ask the learner to identify the equivalent contact route at work.

8. Try a fresh scenario without judging the voice

Read this invented case aloud or use ordinary text. No cloned colleague voice, real bank details or surprise call is needed. The exercise tests the response to a request, so a facilitator can vary the urgency while keeping the decision clear.

9. Make the next action easy to find

If money has already moved, notify the designated finance and security contacts immediately so the financial institution can be contacted about a recall. IC3 emphasises prompt contact with the financial institution; recovery is not guaranteed. If an account change, code disclosure or remote-access action occurred, tell the response team exactly what happened and when, then follow its instructions. Preserve the original messages through the approved reporting route.

End the session with a small deliverable: a verified contact route, an escalation owner and a clear payment or recovery procedure. Repeat a changed fictional scenario later and discuss the explanation, not just the score. If learners know the safe answer but cannot find the approved contact, the next improvement belongs in the workflow as well as the training.

Section sources: Business Email Compromise: The $55 Billion Scam

Practise the callback decision in English

Follow the voice and payment Courses with The Social Engineer. Rehearse a known-channel check, explain your decision and read the scenario debrief.

Play The Social Engineer

Sources and further reading

  1. Senior U.S. Officials Continue to be Impersonated in Malicious Messaging Campaign — FBI Internet Crime Complaint Center. Accessed 2026-10-03
  2. Protecting organizations from AI-assisted executive impersonation and invoice fraud — Microsoft Security. Accessed 2026-10-03
  3. Scammers use AI to enhance their family emergency schemes — Federal Trade Commission. Accessed 2026-10-03
  4. Scattered Spider: joint cybersecurity advisory, July 2025 update — FBI, CISA and international partner agencies. Accessed 2026-10-03
  5. Business Email Compromise: The $55 Billion Scam — FBI Internet Crime Complaint Center. Accessed 2026-10-03

Keep exploring

All articles

Contact · About