The call was fake.
The wire was real.

$3.04 billion left US organizations last year on payment instructions that looked legitimate. Almost none of it came back.

For organizations where one instruction can move six figures.

Today, 9:03 AM · Teams video call
$185,000.00
BeneficiaryABC Holdings LLC
Account•••• 4821
Requested byThe CEO, on camera
Reason givenBoarding a flight, needs it today
He looked right. He sounded right. He knew what the CEO knows. Finance sent it in four minutes.
What last year actually cost

Impersonation is now the second most expensive crime in America.

$3.04BReported business email compromise losses in 2025
24,768BEC complaints filed, widely believed to be a fraction of real incidents
$893MLosses in the 22,000+ complaints that referenced AI
~$50KMedian size of a single BEC transaction
Why it stopped working

The advice was always to call and confirm. That is the part AI broke.

For twenty years the control for a suspicious payment instruction was a phone call to a voice you recognize. It assumed a voice was hard to fake and a face was harder. Neither assumption survived.

The check you were taught
What defeats it now
The check you were taughtCall back on a number you already have on file.
What defeats it nowA voice cloned from a short clip of public audio — a conference talk, a voicemail greeting, a podcast — good enough to hold a live conversation and answer your questions.
The check you were taughtAsk them to turn their camera on.
What defeats it nowLive face replacement that runs on ordinary hardware and holds up through a video call on Teams or Zoom.
The check you were taughtTrust the thread. You recognize the names, the history, the way they write.
What defeats it nowWeeks of quiet mailbox access before anything is sent. Real thread, real names, real deal stage, and they know when the principal is actually travelling.

The FBI logged more than 22,000 complaints referencing AI in 2025, with $893 million in associated losses. Detection is not the way out of this, because it is a bet that your filter keeps beating a model that improves every month. Authenary does not try to tell you whether the call was real. It asks the person.

After the money leaves

The FBI is good at this. It is still mostly too late.

The Bureau's Recovery Asset Team can ask receiving banks to freeze an account through the Financial Fraud Kill Chain. It works, when it is reached in time. The clock is the problem.

0 – 24 hours
Best chance of a freeze, if you have already filed with complete wire details.
24 – 72 hours
Narrowing fast. Funds are usually being moved to second-hop accounts.
After 72 hours
Rarely recoverable. Investigation and litigation run for months or years, mostly without the money.
3,900Incidents the Recovery Asset Team acted on in 2025, against 24,768 BEC complaints.
$679MFrozen in attempted theft, against $3.04 billion reported lost. Roughly 22 cents on the dollar.
58%Success rate on the cases it could act on at all. Frozen is not the same as returned to you.
And the policy you bought for this

Cyber insurance pays less than the headline limit. Sometimes nothing.

Three pieces of standard policy language decide what you actually collect after a fraudulent wire, and most buyers do not read them until the claim is filed.

The sublimit

Your $1M policy is not a $1M policy

Social engineering and funds transfer fraud are commonly capped between $25,000 and $250,000, inside a policy with a far larger headline limit. A $300,000 wire against a $100,000 sublimit leaves most of the loss with you.

Voluntary parting

You sent it, so you chose to send it

Many crime and cyber policies exclude losses arising from the voluntary parting of funds. Your employee initiated the transfer. Carriers and courts do not treat deception consistently as an override.

Failure to verify

Coverage assumes you called them back

Many endorsements condition payment on verification before the transfer: a callback to a number already on file, dual authorization above a threshold, independent confirmation of any banking change. No verification, no claim.

A Mississippi manufacturer wired more than $1 million on new payment instructions from what appeared to be a known supplier. A federal court held the loss capped at the policy's social engineering sublimit rather than its full limit. Separately, several carriers narrowed or excluded AI-generated content at 2026 renewals, so policies renewed this year may not cover deepfake-driven fraud at all. Read your definitions and exclusions before you need them.

What Authenary does

Keep the policy. Prove the control.

We still recommend cyber insurance. But your policy already asks you to verify a request out of band before the money moves, and it asks you to show that you did. Authenary is that verification, and it produces the proof.

  • Verification happens on a device the approver enrolled in advance. Not on the channel the request arrived on.
  • Face ID signs the exact amount, beneficiary and account. A signature that covers these details, not just a presence check.
  • Every decision leaves a receipt anyone can check independently. Your underwriter, your auditor, your client's counsel.
  • The audit log cannot be edited or deleted. By anyone, including your administrators and us.
Authenary verified
Denied — the CEO never asked
ActionWire transfer
Amount$185,000.00
BeneficiaryABC Holdings LLC
Asked ofDaniel Hart, CEO
Signed oniPhone, Face ID
DecisionDenied, 47 seconds
ReceiptAUT-7F3K-92QD
SignatureECDSA P-256 · valid
Four steps, no new habits

Your staff keep working. The money waits for a real person.

You set the policy

Wires over $25,000. Any change to vendor banking details. Sensitive document releases. Executive password resets. Your thresholds, your approvers.

Staff submit the request

Whoever received the instruction enters the exact action: amount, beneficiary, account, and how the request reached them.

The real person decides

The approver named by your policy gets it on their enrolled phone, sees exactly what is being authorized, and approves or denies with Face ID.

You keep the receipt

A signed, tamper-evident record of who approved what and when. Verifiable by anyone you hand it to, without giving them access to anything else.

Where we see this most often

Single and multi-family offices Wealth managers and RIAs Title, escrow and real estate closings Law firms Accounting and outsourced CFO practices Private equity and venture firms Construction and contractor payments Manufacturers paying suppliers Healthcare systems Nonprofits and foundations Executive offices
Pricing

You pay for approvers. Everyone else is free.

Priced per approver per month, billed annually. Two approver minimum. Unlimited staff submitting requests, unlimited verifications, no per-transaction fee.

ApproversEssentialAdvanced
1 – 5$149$249
6 – 15$119$199
16 – 50$89$149
More than 50Talk to usTalk to us

Essential includes

  • Microsoft 365 and Google Workspace sign-in
  • Device enrollment with administrator approval
  • Policy engine and approval routing
  • Signed receipts and independent verification
  • Tamper-evident audit log

Advanced adds

  • Multi-approver policies and escalation tiers
  • API and webhooks for treasury and ERP workflows
  • Audit export for underwriters and examiners
  • Directory provisioning and custom policy packs
  • Priority support and onboarding

One prevented wire pays for a decade of this.

Twenty minutes, your real approval thresholds, and a live verification on your own phone.

Or write to us directly

hello@authenary.com