5 min read
The Voice on the Phone Sounded Exactly Like Your Supplier. It Was Not.
A solo owner gets a call. The voice is unmistakably her main supplier, same accent, same warmth, asking her to rush a payment to a new account because of a banking issue. She almost does it. The only reason she does not is that something feels slightly off, so she hangs up and calls the supplier back on his real number. He never called. In 2026 that near miss is becoming ordinary, and small businesses are being targeted precisely because they run on trust and quick informal approvals rather than layers of verification. The good news is that defending yourself does not require a security team or a big budget. It requires a few simple habits. Here is what the threat looks like and how a business of one can stay ahead of it.
Why the Smallest Businesses Are the Biggest Targets
The uncomfortable truth is that solo owners are attractive marks. An attacker needs only a few seconds of your voice from a webinar, a podcast, or a social clip to clone it convincingly, and a single public photo to build a passable video call. According to a 2026 fraud trends report from Sumsub, deepfake video impersonation, AI voice cloning, and AI powered business email compromise now sit among the highest risks organizations face, and smaller operations get hit harder because they lack formal verification steps.
The financial scale is not small. Industry reporting puts deepfake video call fraud losses above 200 million dollars in a single quarter of 2025, with the average corporate incident costing well over half a million dollars. The broader category of imposter fraud cost Americans about 3.5 billion dollars across 2025. For a one person business, you do not need to be a target of a huge scam. A single successful one can be catastrophic. As a guide to deepfake brand protection from Doppel points out, criminals also impersonate your brand outward, using your name and likeness to scam your own customers, which damages the reputation you spent years building.
The Two Faces of the Threat
It helps to split this into two distinct problems, because the defenses differ.
- Someone impersonates others to fool you. A cloned voice of a supplier, a fake video call from a “client,” or an email that perfectly mimics a partner, all designed to get you to move money or hand over access.
- Someone impersonates you to fool your customers. Fake ads using your logo, a cloned version of your voice in a scam, or a lookalike social account pushing fraudulent offers to people who trust your name.
Most solo owners think only about the first. The second is just as damaging, because the victims are your audience, and the fallout lands on your brand even though you did nothing wrong.
Simple Defenses That Actually Stop This
Here is the reassuring part. The single most effective defense costs nothing and takes seconds. Security agencies including the NSA, FBI, and CISA point to out of band verification as the most reliable protection against synthetic media impersonation, meaning you confirm any sensitive request through a second, separate channel. If someone calls asking for a payment, you hang up and reach them on a number you already have. A deepfake cannot follow you to a different channel it does not control.
Build these habits into how you operate:
- Set a code word. Agree on a simple verbal password with key suppliers, contractors, or your bank for any money related conversation. If the caller cannot say it, the call ends. This one step stops real time voice deepfakes cold.
- Slow down money. Adopt a personal rule that no payment or account change happens on the strength of a single call or email. Urgency is the scammer’s favorite weapon, so a built in pause is your best shield.
- Verify through a channel you chose. Always call back on a saved number, never the one provided in the suspicious message.
- Watch your own brand. Periodically search your business name and set up alerts so you catch fake accounts or ads using your identity before your customers get burned.
These habits sit naturally alongside the wider security mindset we have covered before. If you have not tightened how you handle sensitive information generally, our guide on staying safe while you hand work to AI is a good companion, as is our case for keeping your data on your own machine.
Your Anti Impersonation Checklist
- Today: pick a code word and share it with your bank and your two most important suppliers for any payment related call.
- This week: write down a simple rule that no money moves on a single unverified request, and stick it where you will see it.
- This week: set up a search alert for your business name so you are notified if it appears in places you did not create.
- This month: do a quick audit of how much of your voice and face is publicly available, and decide whether you are comfortable with it.
- Ongoing: when anything feels rushed or slightly off, treat that instinct as a signal to verify, not ignore.
Trust, Rebuilt on Purpose
Deepfakes work by hijacking the very thing that makes small business human: the willingness to trust a familiar voice and act fast to help. You do not fight that by becoming paranoid. You fight it by adding one deliberate pause, one second channel, one shared code word, so trust is verified rather than assumed. Those habits cost nothing and protect everything. The technology behind these scams will keep improving, which is exactly why the human habit of double checking matters more each year. What is one verification step you could put in place before the end of today? For more plain English guidance on navigating AI’s risks and rewards as a solo owner, SoloAITool is here to help you stay a step ahead.



