“CEO fraud”, also known as the president scam, is a classic form of economic crime. The principle: a fraudster poses as a company executive and orders an employee, often in the accounting department, to make an urgent and confidential transfer. Until now, the main weapon was the forged email. Today, artificial intelligence is changing the game.
The National Cyber Security Centre (NCSC, the federal authority responsible for cybersecurity) made this threat the subject of one of its weekly alerts in early 2026. The figures it reports deserve the attention of SME executives.
A sharply rising threat
According to the NCSC, CEO fraud is among the most frequently reported types of scam in Switzerland. The number of cases reported rose from 719 to 971 from one year to the next, an increase of roughly 35%. This growth reflects both an intensification of attacks and greater awareness of the phenomenon.
Above all, the method is evolving. Fraudsters no longer rely solely on fake emails: they increasingly turn to WhatsApp messaging or to the telephone, channels where verification is harder and psychological pressure stronger.
The turning point of voice cloning
The most worrying aspect concerns the use of artificial intelligence. A deepfake is content (image, video or voice) fabricated by artificial intelligence to imitate a real person in a highly realistic way. Applied to the voice, the technique can reproduce an executive’s tone and intonation from just a few recordings, for example an interview, an online conference or a simple voice message.
The NCSC cites a concrete case that occurred in the canton of Schwyz: a company there lost several million francs following faked calls and voice messages reproducing a manager’s voice. The employee who receives the call hears a voice they believe they recognise, in a context of urgency, and carries out the request without suspecting a thing.
In the summer of 2025, the NCSC had already warned about the use of AI to usurp the image and voice of public figures in scams circulated online. The same technology is now being used to target companies directly.
Why SMEs are particularly exposed
It is often assumed that this type of fraud targets large groups. That is a mistake. In an SME, decision-making channels are short and informal, the relationship with management is direct, and it is sometimes difficult for an employee to question an order coming “from above”. These are precisely the characteristics that fraudsters exploit: authority, urgency and confidentiality, three levers that short-circuit careful thought.
Moreover, an SME rarely has strict written procedures to validate an unusual payment. It is precisely the absence of a safeguard that makes the difference between a thwarted attempt and an outright loss.
What you can do right now
The good news is that the main defence costs nothing and rests on organisation, not on technology. The NCSC recommends the four-eyes principle (or two-person principle): any significant payment or any change to sensitive data, such as a change to a supplier’s bank details, must be validated jointly by two people.
To this are added a few simple rules. Always verify an urgent request through a known and different channel: call the executive back on their usual number, and never reply to the number provided in the suspicious message. Establish clearly, with your teams, that no security procedure may be bypassed, even on an order from management. Today, a voice no longer proves the identity of the person on the line.
In conclusion
CEO fraud through voice cloning shows that cybersecurity is no longer solely a matter of firewalls and antivirus software, but also of human processes. Putting in place the four-eyes principle and verification rules is within the reach of any SME, and it is an indispensable first line of defence. But every company has its own financial flows, its own contacts and its own habits. Defining procedures genuinely tailored to your organisation, training your teams in the right reflexes and testing how robust they are calls for bespoke support, because that is where the difference is made between a rule on paper and protection that truly works.