When a Familiar Face Isn’t Enough

The accounts, relationships, and messages were all real. The face and voice appeared convincing. Even the lag and audio problems were part of the setup. What looked like a technical issue was designed to make the malicious download seem reasonable.

Sep 30, 2026

In a recent post on the Mesh blog, the company shared a deepfake social-engineering incident involving one of its sales reps. The employee received a Telegram message from a contact he had worked with for months, asking him to join a quick Teams call.

The meeting appeared legitimate. The contact was on camera. The face and voice were familiar. Other attendees were already present. When the rep could not be heard, someone in the meeting shared a link to download an “updated” version of Teams. The file was malicious. 

The accounts, relationships, and messages were all real. The face and voice appeared convincing. Even the lag and audio problems were part of the setup. What looked like a technical issue was designed to make the malicious download seem reasonable.

For finance and operations teams, this matters because the same type of impersonation can be used to request a vendor banking change, redirect a payment, or pressure someone into sending an urgent wire.

A familiar email address, inbound voice call, video meeting, or message thread is no longer enough to authorize a high-risk action. Compromised accounts and AI-generated impersonation can make fraudulent requests look entirely credible. The most effective defense is not expecting employees to spot every fake.

That means embedding technical controls into payment workflows that automatically flag changes to payment instructions, detect suspicious indicators for any type of verification, route unusual or urgent payments through the appropriate approval paths and prevent even seemingly legitimate executive or vendor requests from bypassing established safeguards. 

The goal is not to slow every interaction down. It is to create the right amount of risk-based friction when money, account details, or sensitive information are at risk.

At Conduit Security, we help finance teams make payment verification a consistent, documented part of the workflow, not something that depends on an employee’s memory, judgment, or willingness to slow down a request. Conduit gives teams an easy and structured way to validate high-risk payment changes, route requests through the appropriate approvals, record and ensure proper verification steps, and maintain an auditable trail before funds are released. That helps organizations move quickly on legitimate business while reducing the chance that a convincing email, phone call, or video request turns into a fraudulent payment.

‍

Contact Us