Back to The BriefSecurity

Trust Your CFO. Hang Up Anyway.

August 10, 2026 · 7 min read · Inglorious Editorial

The attack does not start with a suspicious link or a malware payload. It starts with a phone call. Someone who sounds credible, knows enough about your business to be convincing, and needs your finance director to act quickly on something urgent. By the time anyone realises what happened, the access has been granted or the transfer has gone.

Google's threat research team published findings this month confirming that dozens of financial services firms have been targeted in recent months by coordinated vishing campaigns. Voice phishing. Old method, sharply upgraded execution. The researchers are explicit: this is not opportunistic. These are targeted operations against firms where someone has done the reconnaissance first.

If you run an iGaming operation, a crypto exchange, a payment processor, or any other high-risk financial services business, you need to understand why you are not just a potential target but a preferred one.

Why High-Risk Operators Are Getting Targeted First

Vishing works best when a few conditions are met. The target has access to funds or sensitive accounts. The target is accustomed to handling urgent, non-standard requests. The target operates in an environment where not every relationship is fully documented and where moving quickly is normal.

High-risk operators tick every one of those boxes.

Your finance team is regularly dealing with payment processors, banking partners, and compliance contacts they may have spoken to only a handful of times. Relationships rotate. PSPs change. The person who set up the original account is often not the person handling it now. When someone calls claiming to be from your acquiring bank or your compliance provider and asks for verification details or requests an urgent action on an account, the instinct to cooperate is real.

Add to this the public footprint most operators carry. Licensing databases, corporate registries, LinkedIn profiles of your senior staff, press coverage of funding rounds or market entries. A competent attacker can build a convincing picture of your business before they dial anyone.

What AI Has Actually Changed Here

Vishing is not new. What has changed is the production quality and the scale at which it can be run.

Voice cloning tools that were experimental two years ago are now accessible and cheap. An attacker who can find a recording of your CFO, your legal counsel, or a counterpart at your bank can generate a synthetic version of that voice with enough fidelity to pass a casual check. The calls sound right. The cadence, the accent, the name-dropping of internal references that came from a LinkedIn scrape or a leaked data set.

The other change is speed of targeting. AI tooling now allows attackers to process large amounts of publicly available information and identify which firms have specific characteristics: recent funding, new market entries, banking transitions, licensing activity. High-risk operators doing anything newsworthy are flagging themselves.

This is not about AI making phishing emails slightly better. This is about a qualitative shift in how convincing a voice attack can be when it is properly resourced.

The Specific Scenarios Your Team Needs to Recognise

The attacks targeting financial services firms in this campaign follow recognisable patterns. Your team should know what these look like before they encounter them.

The urgent account action. A caller identifies themselves as being from your bank or PSP. There is a compliance hold, a suspicious transaction flag, or an account verification requirement that needs to be resolved within the hour or the account will be suspended. They need your team member to confirm account details, authorise access, or approve a transfer to a safe account.

The internal escalation. The caller impersonates a senior person inside your business. A director who is travelling, a founder who is in a meeting. They need something done quickly and do not want it going through normal channels because of time pressure or sensitivity.

The third-party intermediary. The caller claims to be from a legal firm, a regulator, or a licencing body. They are following up on something your business filed or applied for. They need to verify information, and they have just enough real detail to sound legitimate.

The common thread is urgency combined with just enough specific detail to bypass scepticism. Your team is not stupid. They are being presented with a scenario that is designed to feel legitimate.

What Your Controls Actually Need to Cover

Most high-risk operators have invested in technical controls: endpoint protection, email filtering, access controls, multi-factor authentication. These matter. They also do nothing to stop a phone call.

The controls that address vishing are procedural, and most organisations have let them atrophy because they feel low-tech.

Callback verification as a hard rule. Any request that arrives by phone and involves account access, fund movement, or credential sharing must be verified by calling back on a number sourced independently. Not the number provided by the caller. The number from your own records or from the official website of the organisation they claim to represent. This is not optional for high-value actions.

Out-of-band confirmation for internal requests. If someone calls claiming to be a colleague and asks for something sensitive, the response is to confirm via a separate channel, a pre-established internal system, a direct message to a known account, before any action is taken. A voice call alone, even a convincing one, is not sufficient authorisation.

Defined escalation paths for unusual requests. Your team needs to know who to call when something feels off. Right now, many of them will comply rather than escalate because they do not want to be wrong or cause a delay. That instinct is the vulnerability. Build a culture where pausing and checking is the expected response, not an overreaction.

Limit the public footprint of operational staff. You cannot scrub everything. You can be deliberate about which staff appear in press releases, on the corporate website, and in industry databases. Finance and operations personnel should not be the public face of the business.

The Regulatory Angle Nobody Is Talking About

If a vishing attack results in a breach of customer data, an unauthorised fund transfer, or a failure of your financial crime controls, you are not just dealing with a financial loss. You are dealing with a reporting obligation.

Under UK GDPR, a personal data breach needs to be reported to the ICO within 72 hours if it is likely to result in risk to individuals. Under FCA rules, firms are expected to have operational resilience frameworks that account for social engineering as a threat vector, not just technical attacks. For iGaming operators, the UKGC expects licensees to maintain adequate controls across all aspects of their operation, and a successful attack that compromised player data or funds would attract scrutiny.

The point is that vishing is not just a finance problem. It is a compliance exposure. A successful attack followed by slow, inadequate response will cost more than the attack itself.

What You Should Do This Week

Get your finance, compliance, and operations teams in a room and walk through the specific scenarios above. Not a generic cybersecurity briefing. A specific conversation about what a convincing call sounds like, what the right response is, and who has authority to override the usual process if someone genuinely believes they are being targeted.

Then document it. Write the callback verification rule into your operating procedures so it is a policy, not a suggestion. Make sure your banking and PSP contacts have a way to verify urgent requests that does not rely on phone calls alone.

The attackers doing this work are not making random calls. They have researched your business, identified who handles money, and prepared a scenario calibrated to get compliance. The only thing that stops it is a team that knows to pause, verify, and check before acting. That knowledge does not appear on its own. You have to install it deliberately, and you need to do it before the call comes in rather than after.

Newsletter

Stay ahead in high-risk finance

Insights on banking, payments, crypto regulation, and licensing.

Weekly. No spam. Unsubscribe anytime.

Ready to act on what you just read?

Get a free assessment from our team within 24 hours. No obligation, completely confidential.

Contact Us