An urgent voice note appears to come from a director. The voice sounds right, the context is plausible and the instruction is simple: release a payment, reset an account or share a confidential file. Generative AI has made that scenario easier to manufacture and harder to judge by instinct alone.
The 2026 INTERPOL African Cyberthreat Assessment says AI and other fast-moving technologies are being weaponised for scalable, targeted attacks. It also records online scams including phishing as 17% of reported African cybercrime cases in 2025, with identity theft and financial fraud accounting for another 14%. This is not evidence that every suspicious call is synthetic. It is evidence that identity checks based on familiarity are no longer enough.
Treat urgency as a signal, not proof
AI impersonation usually succeeds through process pressure rather than technical brilliance. The request arrives late, bypasses the normal channel and asks the recipient to act before checking. Common patterns include:
- a voice call requesting an exceptional supplier payment;
- a video meeting with limited interaction or unusual audio delay;
- a message asking the service desk to reset multifactor authentication;
- a request to move a sensitive document outside SharePoint or ShareFile; and
- a new bank account presented as an urgent supplier change.
None of these signals proves fraud. Together, they justify a second verification path.
Build a verification path attackers cannot control
For payments, privileged access and sensitive data, use a known-good channel that is independent of the incoming request.
- End the conversation and call the requester on a number already held in the company directory.
- Require two authorised people for bank-detail changes and high-value payments.
- Confirm supplier changes with a known contact, not the contact details in the change request.
- Make service-desk identity recovery a documented process with manager approval and an audit trail.
- Give staff permission to delay an urgent request while they verify it.
A private phrase may add friction, but it should not become the only control. Phrases can be disclosed, guessed or replayed. Strong processes combine an independent channel, least privilege and recorded approval.
Protect the accounts behind the impersonation
Impersonation is more damaging when the attacker also controls email, collaboration or endpoint sessions. Phishing-resistant authentication, conditional access and least-privilege administration reduce that blast radius. Endpoint detection and response adds evidence when a user device behaves abnormally.
SentinelOne endpoint protection can detect malicious process behaviour and help isolate a compromised endpoint. It cannot decide whether a voice is genuine, so it belongs inside a wider identity and verification system—not as a substitute for one.
Detect the supporting activity
Look for the technical activity that often surrounds social engineering:
- sign-ins from unfamiliar locations or devices;
- new inbox forwarding rules;
- repeated multifactor authentication prompts;
- remote-access tools installed without approval;
- unusual downloads from SharePoint or OneDrive; and
- service-desk resets followed by privileged changes.
Correlating identity, email and endpoint signals gives an investigation more substance than analysing the suspicious recording alone.
Recover without destroying evidence
If money, credentials or data may have moved, act quickly but preserve the trail. Disable compromised sessions, rotate affected credentials, contact the bank through its verified fraud channel and retain messages, call records and endpoint telemetry. Follow the organisation's incident-response and POPIA assessment processes.
The practical lesson is simple: voice and video can start a request, but they should not authorise a high-impact action. Verification must be designed into the workflow before the urgent call arrives.
Sources
- INTERPOL African Cyberthreat Assessment Report 2026, accessed 20 August 2026.
- Microsoft guidance on governing and securing AI agents, updated 26 June 2026 and accessed 20 August 2026.
Need to strengthen identity, endpoint and incident-response controls? Talk to OAS about SentinelOne and managed cybersecurity.
