Cybercriminals are evolving their tactics to sidestep the defenses against email phishing that have become more widespread over the last decade. Their latest strategy? Picking up the phone.
In August 2026, sophisticated attackers employed AI-driven voice cloning technology to impersonate employees from prominent investment firms including Point72, Citadel, and Millennium Management. Staff members were misled into granting system access before realizing they were deceived, a report from Bloomberg revealed. Fortunately, Two Sigma successfully thwarted a similar attempt before any harm was done.
This emerging form of manipulation, referred to as vishing or voice phishing, now extends beyond Wall Street, making its way into the accounting sector. With sensitive data such as Social Security numbers, bank account details, and tax records at stake, accounting firms are particularly appealing targets for this kind of attack. It's crucial for these firms to understand the mechanics of vishing and to equip their clients with the knowledge to recognize and counteract it.
Understanding Vishing
Vishing involves social engineering conducted via phone calls rather than through emails or texts. A fraudster might masquerade as a bank employee, a vendor, a coworker, or even IT support within the firm, using urgency or authority to manipulate the recipient into divulging sensitive information or allowing transaction approvals. The use of AI-generated voice cloning technology enhances the realism of these calls, making the deception more convincing as attackers can replicate specific individuals’ tone and speech patterns instead of relying solely on generic scripts.
The Implications for Accounting Professionals
The data reflects a growing concern. According to Verizon’s 2026 Data Breach Investigations Report, attacks via phone-driven social engineering are roughly 40% more successful than email phishing attempts due to the inherent trust people place in a human voice over text. Additionally, Gartner's research indicates that 35% of organizations have dealt with a deepfake-related incident, but alarmingly, only 10% of security leaders are training their teams to identify cloned voices, while a hefty 73% concentrate only on email phishing.
The financial impact of a successful vishing attack can be staggering. Just last year, MGM Resorts faced a breach stemming from a single vishing call to their IT help desk, costing them an estimated $100 million. For accounting firms, the stakes are even higher given their responsibility to safeguard client financial data and adherence to the FTC Safeguards Rule, which mandates the implementation of a comprehensive information security plan.
Steps Forward for Firms and Clients
Accounting firms should take the lead in establishing best practices that clients can mirror as they face similar threats. Here are several measures that can enhance security:
- Institute a policy requiring independent callback verification for any phone requests related to wire transfers, credential resets, or the disclosure of financial information. Callbacks should be made to verified numbers already on file rather than those provided by the caller.
- Encourage a firm culture where taking a moment to verify urgent requests is the norm, not an inconvenience.
- Integrate vishing awareness into existing compliance and security training regimes instead of treating it as a standalone item.
- Collaborate with IT personnel or a service provider to mandate multi-factor authentication for all financial software, email, and remote access tools, with no exceptions allowed via phone.
- Ensure procedures for help desk operations and password resets require verified identities prior to any changes being made.
- Conduct simulated vishing exercises in advance of high-demand periods, such as tax season when staff are particularly vulnerable to these fast-paced schemes.
Anticipating Client Concerns
Firms proactive in addressing these queries will better reassure clients and mitigate their own risks:
How can I verify a call about my account is legitimate? No firm should request complete account details over the phone. Clients should be urged to disconnect and call back using the firm’s main line if something feels suspicious.
Could someone misdirect my funds using a fabricated voice? This is a documented risk and is becoming a standard concern across industries, which is why independent verification for all fund transfers is gaining traction.
What should I do if I receive a dubious call claiming to be from my accountant? Clients should refrain from sharing any personal information and should contact the firm directly using numbers from the website or invoices rather than following any contact information provided by the caller.
Looking to the Future
As AI voice technologies continue to evolve, making vishing attacks easier and more realistic, firms handling sensitive financial data, especially in accounting, will remain prime targets for these threats. Establishing verification procedures as ingrained habits and guiding clients to adopt the same practices will significantly enhance defenses against the destruction of a single fraudulent call.
Scott Carr, owner of Farmhouse Networking in Grants Pass, Oregon, has over 30 years of experience as a Network & Computer Systems Architect. Over the last decade, he and his team have successfully managed IT services for more than 80 businesses, particularly in the accounting and finance sectors. Scott’s straightforward approach educates clients about technology and helps them feel secure in their systems. Fast support is a hallmark of his firm, with most issues resolved in under 15 minutes, and they excel in cybersecurity, network design, and compliance. Find out how Farmhouse Networking can assist your accounting practice at https://www.farmhousenetworking.com/finance-it-support/.

Discussion
Sign in to join the discussion.