A voice-cloned executive just cost an Indian SaaS company €3 million

A finance team at an overseas subsidiary of a Bengaluru-based SaaS company heard what sounded like senior leadership authorizing an urgent transfer. The voice was familiar. The paperwork looked right. By the time anyone questioned it, roughly €3 million had moved to accounts the company didn't control.

The incident, involving Capillary Technologies' overseas subsidiary, is one of the clearest examples yet of how voice cloning is being combined with old-fashioned social engineering to defeat corporate treasury controls — and how ordinary that combination has become.

What happened at Capillary's subsidiary

Attackers cloned the voices of company leadership and paired the cloned audio with forged signatures to authorize transfers to unauthorized accounts. Capillary disclosed the incident through a mandatory stock exchange filing and notified its cyber and crime insurer. The company has recovered roughly €450,000 so far and is working with banks and cybercrime authorities to trace the remainder.

The incident snapshot, at a glance:

  • Category: Fraud / impersonation
  • Type: Attack
  • Modality: Audio
  • Attack vector: Cloned executive voices paired with forged signatures to authorize fraudulent transfers
  • Trend: Voice-cloned executive impersonation remains the most financially damaging deepfake attack vector against corporate treasury functions
  • Policy / regulatory response: Disclosed via mandatory stock exchange filing; insurer notified

The layered playbook that beat finance-team defenses

What stands out about this case isn't the voice cloning itself — that threat has been known for years. It's the layering. Voice cloning alone gets flagged more often now, as finance teams have been trained to be suspicious of unexpected calls requesting transfers. So attackers are stacking multiple weak signals on top of each other, and each one covers for the others' gaps.

Why the layering works

A cloned voice with no supporting documentation raises suspicion on its own — most finance staff know to ask for written confirmation. But pair that voice with a forged signature and a plausible reason for urgency, and the combination passes the informal verification most finance teams still rely on. Each element does a job:

  • The cloned voice creates a sense of direct, personal authorization from someone senior
  • The forged signature supplies the paper trail that a purely verbal request would lack
  • The social engineering — urgency, confidentiality, seniority — discourages the target from pausing to double-check

None of these tactics is new individually. Combined, they exploit the fact that most organizations still verify high-value transfers through a patchwork of informal checks — a familiar voice, a signed document, a trusted job title — rather than a single, technical point of verification that can't be faked.

What corporate treasury teams should do now

Cases like Capillary's are pushing finance and security leaders toward a simple conclusion: if a request can be authorized by voice, that voice needs to be verifiable as real, not just familiar. In practice, that means:

  • Requiring out-of-band confirmation — a callback to a known number, not the number provided in the request — for any high-value transfer
  • Screening executive-authorization calls and voicemails for signs of synthetic or manipulated audio before treasury acts on them
  • Treating "urgent, confidential, senior-authorized" requests as a red flag pattern in themselves, regardless of how convincing the supporting details seem
  • Building incident response and insurance notification steps into the fraud playbook now, rather than after a loss

Voice used to be one of the more trustworthy ways to confirm someone's identity in a hurry. Deepfake audio has quietly erased that assumption, and layered attacks like the one at Capillary's subsidiary show how quickly that gap gets exploited. Corsound AI's real-time deepfake detection helps finance and security teams verify whether the voice on the line is genuine before a transfer goes out. Learn more about Deepfake Detect from Corsound AI.

Photo: Yan Krukau / Pexels

See Corsound AI Voice Intelligence In Action
Thank you.
Your submission has been received.
Oops! Something went wrong while submitting the form.