Skip to main content
← Back to blog

A Familiar Voice Is Not Payment Authorization

How to design payment controls that survive executive impersonation, compromised email, and synthetic audio.

By Alex Castrillo3 min readFact-checked August 28, 2026
A Familiar Voice Is Not Payment Authorization

A voice note, video call, or urgent executive message can be persuasive without being authentic. Payment control should rely on a known process that remains valid when the message itself cannot be trusted.

What the evidence supports

The FBI documents business email compromise schemes that impersonate executives and vendors. It has also described fraudsters using still images and deepfake audio in virtual meetings to direct wire transfers. The FBI recommends verifying requests through a separate communication channel.

Why it matters to a Connecticut operator

The risk is highest when urgency can bypass normal approval. A written payment-change process protects finance staff by making verification mandatory rather than discretionary.

Operator checklist

  • Require two approvals for high-risk payments and all bank-detail changes.
  • Verify requests using a known number or in-person channel independent of the message.
  • Create a pause-and-escalate rule for secrecy, urgency, or pressure to bypass process.
  • If fraud occurs, contact the financial institution immediately and report to the FBI’s IC3.
Scope note: This briefing separates documented facts from practical recommendations. It is cybersecurity guidance, not legal advice or a statement that every recommended control is expressly required by Connecticut cannabis regulations.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.