Cybercriminals have found a new way to bypass the security awareness that email phishing training has built over the past decade: they’re picking up the phone.
In August 2026, attackers used AI-generated voice cloning to impersonate trusted colleagues at several major investment firms, including Point72, Citadel, and Millennium Management, convincing staff to grant system access before anyone realized the voice wasn’t real, according to Bloomberg’s reporting. One firm, Two Sigma, caught the attempt before it caused damage.
This tactic, known as vishing, or voice phishing, is no longer confined to Wall Street. Accounting and CPA firms hold exactly the kind of data that makes them an attractive target: client Social Security numbers, bank account details, and tax records. Understanding how vishing works, and how to help clients recognize it, is becoming a necessary part of practice management.
Recommended Articles
What Is Vishing?
Vishing is a form of social engineering carried out by phone rather than email or text. A caller may pose as a bank representative, a vendor, a colleague, or even a firm’s own IT support, using urgency or authority to convince the person on the other end to share credentials, approve a transaction, or grant remote access. AI voice cloning has made these calls significantly more convincing, since attackers can now mimic a real person’s tone and speech patterns rather than relying on a generic script.
Why This Matters for the Accounting Profession
The data supports the concern. Verizon’s 2026 Data Breach Investigations Report found that phone-based social engineering succeeds roughly 40% more often per attempt than email phishing, largely because people are inclined to trust a human voice over written text. Separate research from Gartner found that 35% of organizations have already experienced at least one deepfake-related incident, yet only 10% of security leaders are training staff specifically to recognize a cloned voice, compared to 73% who focus training on email phishing alone.
The financial consequences of a successful attack can be significant. In 2023, a single vishing call to an IT help desk was the starting point for a breach that cost MGM Resorts an estimated $100 million. For an accounting firm, a comparable incident carries the added weight of client financial data exposure and, for many practices, obligations under the FTC Safeguards Rule to maintain a written information security plan.
Practical Steps for Firms and Their Clients
Accounting firms are well positioned to model good practice for clients who face the same exposure. Several steps are worth building into a firm’s procedures and sharing with clients:
- Require independent callback verification before acting on any phone request involving a wire transfer, credential reset, or release of financial data. The callback should go to a number already on file, never one provided by the caller.
- Build a firm culture, and encourage a client culture, where pausing to verify an urgent request is expected rather than discouraged.
- Incorporate vishing awareness into existing compliance and security training rather than treating it as a separate initiative.
- Work with IT staff or a managed provider to enforce multi-factor authentication across financial software, email, and remote access tools, with no exceptions granted over the phone.
- Ensure help desk and password reset procedures require verified identity before any changes are made.
- Schedule simulated vishing exercises ahead of high-pressure periods, such as tax season, when staff are busiest and most susceptible to urgency-based scams.
Questions Clients Are Likely to Ask
Firms that get ahead of these questions will be better positioned to reassure clients and reduce their own exposure:
How do I know if a call about my account is legitimate? A firm should never ask for full account credentials over the phone. Clients should be encouraged to hang up and call the firm’s main line directly if anything feels off.
Could someone use a fake voice to redirect my funds? It’s a growing and documented risk industry-wide, which is why independent verification on every fund transfer, with no exceptions, is becoming standard practice.
What should I do if I receive a suspicious call claiming to be from my accountant? Clients should avoid sharing any information and call the firm directly using a number from their website or a prior invoice, not the number the caller provides.
Looking Ahead
As AI voice tools continue to lower the cost and effort required to run a convincing vishing attack, the professions handling the most sensitive financial data, including accounting, will remain a preferred target. Firms that build verification into everyday procedures, and that take the time to walk clients through the same habits, are in a stronger position to prevent a single phone call from becoming a costly breach.
Scott Carr, owner of Farmhouse Networking in Grants Pass, Oregon, is a veteran Network & Computer Systems Architect with over 30 years of IT experience. For over a decade, he’s led his team in delivering proactive, secure, and fully managed IT services to more than 80 businesses—including accounting and finance firms that rely on data security, compliance, and efficiency. Scott’s hands-on, jargon-free approach ensures every client understands their technology and gains confidence in their systems. His firm is known for fast, responsive support—most issues are resolved within 15 minutes—and deep expertise in cybersecurity, network design, and IT compliance. Learn more about how Farmhouse Networking supports the accounting industry at https://www.farmhousenetworking.com/finance-it-support/.
Sign in to get access to this free resource, and all of our whitepapers and reports.
Download this content today!
Register Now Already registered? Click here to Log In
Tags: data security, Firm Management, hackers, phishing, scams, Technology, vishing