Support & Education Protocol, not panic Send this to your finance team

“I recognized
the voice”
proves less than it did.

For your whole life, recognizing someone has been proof it was them. Their face on a call, their voice on the phone, their way of phrasing a request. That was never written down as a security control, because it never had to be.

It has stopped working. Not gradually: in about two years, and for a price that rounds to nothing. This page is not an argument that you should be afraid. It is the replacement procedure, short enough to adopt this afternoon.

Go straight to the protocol ↓
The whole page in one line:
Money and access move on a callback to a number you already had, never on a voice, a face, or a number the request gave you.

What actually
broke.

↳ two documented cases, and why they worked

The material that makes an impersonation convincing was never stolen from you. Most of it was published: your posts, your interviews, your voice on a recorded webinar, your executives on a conference panel. Combined with an ordinary leaked staff list, that is enough to place a persuasive, personalized call to whoever moves your money.

The same collapse in cost that made attacking infrastructure cheap made impersonating your people cheap. Below are the two clearest public records of it.

February 2024 · Hong Kong

The video call that wasn’t

Hong Kong Police later summarized a 2024 prerecorded-video-conference deepfake fraud causing approximately HK$240 million in losses. That summary is the primary record, and it is deliberately spare.

Secondary reporting identified the victim as the engineering firm Arup and reported fifteen transfers involving apparent colleagues, including its chief financial officer, with the synthetic participants said to have been built from publicly available footage. The case was disclosed in February 2024 and Arup confirmed it was the victim that May. We keep the two layers apart on purpose: the loss figure comes from the police summary, the employer and transfer detail from reporting.

⚠ police summary confirms the fraud and the loss; the rest is reporting
December 3, 2024 · FBI

The bureau said the quiet part

The FBI’s Internet Crime Complaint Center issued a public service announcement on criminals using generative AI to commit financial fraud at scale. Among the described techniques: generating short audio clips of a loved one’s voice to impersonate a relative in a crisis and demand money, and generating video for real-time chats posing as company executives or authority figures.

The PSA’s framing is worth repeating plainly: AI does not invent these scams. It reduces the effort, the language errors and some of the tells that used to expose these scams.

⚠ alert I-120324-PSA
↳ read the Arup case again, slowly:

Arup said its own systems were not compromised. Public reporting attributes the loss to synthetic impersonation, though it does not establish that no credential or technical compromise occurred anywhere in the preparation chain. What is clear is that the employee did what a careful person does: he was suspicious of the first email, so he asked for a video call to confirm it. The attackers turned a familiar verification step into part of the attack.

That is why this page is about protocol rather than technology. Technical detection alone should not be treated as sufficient here. The rule that would likely have interrupted this attack is procedural: money does not move on a call, however convincing. It moves after a callback to a previously verified number, and that materially reduces the risk even though no control eliminates it.

The verification
protocol.

↳ screenshot this bit and send it round

Six low-cost rules. They add modest friction to legitimate requests and materially reduce this class of risk. Write them into your payment process so they are policy rather than instinct: instinct is exactly what gets targeted.

One distinction worth making before the list, because the Spanish scams page covers the family version of the same problem: a family code word is an additional check that a cloned voice does not resolve on its own. A callback to a number you already had is the stronger control, because it does not depend on a secret staying secret. Use both, and lean on the callback.

Money & access · verification protocol

Before anything moves.

Applies to every payment, every change of bank details, every credential reset, every urgent access request, regardless of who appears to be asking.

  1. Call back on a number you already had.Not the number in the email. Not the number the caller reads out. Not the number on the invoice. The one already in your contacts, your HR file, or the signed vendor contract. This single rule is the spine of the protocol. It assumes the contact record itself is trustworthy, so check that assumption periodically: a compromised directory defeats a callback.
  2. Change the channel.If the request arrived by video call, confirm by phone. If it arrived by phone, confirm on your internal chat. A second independently chosen channel is harder to compromise, though account takeovers, SIM swaps and altered contact records can span more than one.
  3. Two people above a threshold.Pick the number tonight, whatever amount would genuinely hurt. Above it, a second named person confirms independently. Not approves in a system; confirms, out loud, having done their own callback.
  4. Bank-detail changes restart the clock.A changed account number is treated as a brand-new vendor relationship: full verification, no exceptions, no matter how long you have worked together or how routine the invoice looks.
  5. Nobody is exempt, and seniority is not a password.The protocol applies hardest to requests that appear to come from the top, because those are the ones worth imitating. Say so publicly, so the junior person who follows the rule is protected rather than embarrassed.
  6. Delay is always allowed.Any employee may pause any transaction to verify and will never be penalized for it, even if it turns out to be genuine, even if it costs a discount. Put that sentence in writing, signed by whoever runs the place.
↳ the only rule that matters: verify on a channel the request did not choose.
why rule six is the one people skip:

Every other rule is procedural and easy to agree to. Rule six is cultural, and it decides whether the protocol survives contact with a real Tuesday. If pausing a payment to check makes someone look slow, distrustful or junior, they will stop pausing, and the protocol is now decorative.

The organizations that get this right make the pause the default and say out loud that following it can never be the wrong call. Say it before you need it, not in the post-mortem.

Two code words
worth agreeing on.

↳ one for work, one for the people you love

A shared secret is the cheapest out-of-band channel there is. It costs one conversation, and a secret kept out of searchable systems is far less exposed than anything you have published. It can still be overheard, recorded, phished, or stored somewhere later compromised, so rotate it if that happens.

For the finance team

Agree a phrase that any employee can ask for when a request involves money or access, and that anyone genuine will know. It is not a password to be typed anywhere. It is a question with an answer, used live, on a call.

Rotate it when someone leaves. Keep it out of email, out of shared drives, and out of the document where you keep everything else.

“Before I move this, what’s the phrase this quarter?”

For your family

This is the one people skip and later wish they had not. The FBI’s public warning describes criminals generating short audio clips containing a loved one’s voice to impersonate a close relative in a crisis situation, asking for immediate financial assistance or demanding a ransom.

Agree a word with your parents, your kids, your partner. Something ordinary and memorable that would never appear in a post. Then teach the rule that goes with it: if the word is missing, hang up and call back on the number you have.

“Say the word first.”
↳ teach the shape of it, not just the word:

The crisis-call script is consistent: a familiar voice, an accident or an arrest or a stranded traveler, a demand for money now, and a reason you must not call anyone else. The instruction not to hang up is the mechanism. Urgency should never override independent verification, so agree in advance what your family does in a genuine emergency, and make a callback part of it.

Say that to an older relative once and it stays. It is more durable than any technical control you could install on their phone.

Urgency is
the tell.

↳ stop looking at the face; look at the shape of the ask

People try to spot fakes by looking harder: blinking, lip sync, odd lighting. Give that up. Those artifacts get fixed on somebody else’s development schedule, and a bad connection explains all of them anyway. The reliable signals are in the request, and they have not changed in twenty years of fraud.

01

It has to happen now

A deadline that collapses your ability to check is the point of the deadline. Define an escalation path in advance so that genuine urgency has a route that is not “skip the check”.

02

It must stay secret

Confidentiality that stops you consulting a colleague is not confidentiality. A pending acquisition is not a reason to skip your own controls.

03

The channel changed

A vendor who always emailed is suddenly calling. An executive who never texts is texting. The switch is often the whole attack.

04

The destination is new

New account, new bank, new country, new payee. Nearly every successful invoice fraud ends here, whatever it looked like at the start.

the sentence to train into everyone:

“I believe you, and I’m still going to call you back.” It is polite, it is not an accusation, and it is unanswerable. If the response is pressure, treat that as a reason to keep verifying rather than as proof of fraud: genuine people under stress can react badly too.

And what the law
here gives you.

↳ two Puerto Rico statutes worth knowing

Most of this page is prevention, because recovery is unreliable. But Puerto Rico did move on this recently, and both statutes are new enough that few people locally know they exist.

If your likeness is used

Ley 163-2026

As of 2 August 2026, Ley 139-2011’s protection of a person’s image expressly covers AI-generated, cloned, simulated or altered likeness, voice, movement and gestures. The liability attaches to unauthorized commercial, mercantile or advertising use of an identifiable person’s likeness, subject to consent and the statutory exceptions. A consented, documented use is not automatically a violation, in either direction.

Damages come from the parent statute rather than the amendment: statutory damages of $750 to $20,000 per violation, up to $100,000 where the conduct is intentional or grossly negligent, plus attorney’s fees, with a one-year statute of limitations. It reaches unauthorized commercial use within Puerto Rico regardless of where the person depicted lives. Carve-outs exist for news, political expression, non-commercial satire, and people incidentally in the background.

$750–$20,000 per violation · 1-year clock
If the material is intimate

Ley 135-2026

Enacted 15 July 2026, it amends Ley 21-2021 on non-consensual intimate imagery to cover material altered or generated using digital technology, and makes threatening to disclose such material a separate felony. This one binds any person, criminally.

Federally, the TAKE IT DOWN Act (signed 19 May 2025) criminalizes publishing non-consensual intimate imagery including AI “digital forgeries,” and requires covered platforms to remove reported material, and known identical copies, within 48 hours of a valid request. The FTC enforces it and the platform compliance deadline has passed, so that takedown right is live.

Criminal · 48-hour platform takedown
↳ and the gap, stated plainly:

As of 15 August 2026, we found no general cross-sector Puerto Rico statute imposing AI-specific disclosure, risk-assessment, bias-audit or deployer duties on a private company merely because it uses AI. The AI-specific enactments highlighted here cover four principal areas: elections, government, criminal deepfakes, and likeness. The PR AI statutes cited here do not create a general duty for a toolmaker to warn you, or a guarantee that your bank will reimburse an authorized payment. Other law, your contracts and network rules may still apply.

Which is the honest reason this page is mostly protocol and only a little law. The statutes give you a claim afterwards. The callback rule is what reduces the chance the money leaves at all.

to be clear ↳

This is education, not legal advice. We are a technology studio, not a law firm, and nothing here creates a lawyer-client relationship or accounts for your particular facts. The two statutes above are weeks old. If you are dealing with an actual impersonation, talk to your counsel, and if money has already moved, call your bank and the police before you call anyone else.

↳ the protocol is free; the hard part is everything under it

Who verifies the verifier?

A callback rule works until the contact list it depends on is the thing that was compromised. If you want the systems underneath to deserve that trust, that is our day job.