A Callback Beats a Deepfake: How NYC Law and Accounting Firms Stop a BEC Wire
The invoice looks right. The matter number is real. The partner’s name is spelled the way it is on the letterhead. Someone in a 15-person Staten Island or midtown practice hits send on a wire because the email asked them to, and because the voice on a follow-up call sounded like the person they already know.
That is business email compromise. It is not a new Microsoft CVE, and it is not an MFA gap you close with one Conditional Access policy. It is a payment-control failure. The control that still works is boring: before any vendor or client bank-detail change, someone calls a number that was already on file — not the number in the email, and not the number that just rang in.
We already wrote about email and identity as the breach path. This post is the next question that post does not answer: what do you do when the message is good enough that the bookkeeper believes it.
What IC3 actually counted
The FBI’s Internet Crime Complaint Center 2025 Annual Report is the primary source. We opened the PDF.
In 2025 IC3 recorded 24,768 business-email-compromise complaints and $3,046,598,558 in reported BEC losses. That is the second-largest loss category in the report. Investment fraud was first, at $8,648,617,756. BEC in 2024 was 21,442 complaints and $2,770,151,146. In 2023 it was 21,489 complaints and $2,946,830,270.
Those are complaints people filed. They are not a census of every redirected closing or vendor ACH in New York.
New York State ranked fourth in the same report for all IC3 crime, not for BEC: 45,255 complaints and $1,226,307,877 in reported losses. That $1.23 billion is every crime type IC3 tabulated for the state. It is not a New York BEC total. Anyone who quotes it as “NYC law firms lost $1.2 billion to BEC” is misreading the table.
IC3 also counted AI-related complaints: more than 22,000 in 2025, with adjusted losses over $893 million. Inside that set, BEC scams that involved AI accounted for $30,256,592. The report is explicit that there are multiple BEC tactics and that not all of them are AI-enabled. Chat generators can write official-sounding mail that looks like a CEO or a partner and that tells someone to click a link or send a wire. Voice cloning can be used to request the same payment. The $30 million is the AI-tagged slice. The $3.05 billion is the whole BEC category.
We are not going to invent a Brooklyn closing, a Queens tax-season ACH, or a MicroSky client loss to fill the gap between those two numbers.
What changed is the follow-up call
On December 3, 2024, IC3 published a public service announcement on criminals using generative AI for financial fraud. The examples are specific: AI-written text that no longer carries the old spelling tells, cloned audio of a person you think you know, and generated video that can include a live-looking chat with an alleged company executive.
Steve Weisman’s August 8, 2026 Forbes column walks the same path and restates the IC3 2025 BEC total. His defense list is the one a 15-user firm can actually run: independent verification of wires, a callback to a number you already trust, dual authorization, training that names deepfakes and voice cloning, and a code word for executive payment requests.
A video conference does not replace the callback. The IC3 PSA describes real-time video chats with alleged executives as one of the things generative video is used for. If the only confirmation is a face on a screen that was not on last quarter’s Zoom, you have not confirmed the bank account.
Why a 15-user NYC firm is the target, not the exception
A small law or accounting shop in the city moves money the same week it files, closes, or remits payroll taxes. The bookkeeper is also the person who answers the partner. The vendor who “updated banking” is often a real landlord, a real court reporter, or a real software publisher. The change request arrives on a Thursday afternoon because that is when wires still clear.
Attackers do not need to encrypt the tenant. They need one person who can release funds, one plausible email, and enough time pressure that “I’ll call them tomorrow” feels expensive.
SHIELD still applies. New York’s statute asks for reasonable safeguards. A written callback rule for payment-detail changes is a safeguard you can name. We already laid out the SHIELD checklist. This post is the payment step that checklist does not write for you.
If the mailbox itself is later wiped, that is a different recovery problem. Retention is not a backup. Do not confuse a recalled wire with a restored mailbox.
Seven things a 15-user shop can finish this week
- Write the rule in one sentence. “We do not change vendor, client, or partner bank details, and we do not release a new payee, until two people have called a phone number that was already in the file.” Put it where the bookkeeper actually works. If the sentence is only in a handbook nobody opens, you do not have a rule.
- Build the number file before the email arrives. For every payee you have wired in the last year, record a voice number that did not come from this week’s email: the number on last year’s W-9, the engagement letter, the invoice footer from a paid job, or a listing you already used. A cellphone the partner texted you last night does not count.
- Callback means you place the call. Hang up. Dial the number on file. Do not call back the inbound caller-ID. Do not use a number that arrived in the same thread as the new routing number. IC3’s own tip is hang up, look up the organization, and call a number you found yourself.
- Dual authorization on any new payee or any changed account. One person prepares. A second person, who did not receive the email, releases. A partner who is “in a cab and can’t talk” is not the second person.
- A spoken code for executive payment asks. Agree on a word or a short phrase that is not on the website and not in the email signature. Use it on the callback. Forbes lists this for a reason. If the voice on the phone cannot give it, you do not send the wire. We already covered deepfake scams aimed at NYC small businesses; the code is how a 15-user firm makes that article operational.
- Treat “updated banking” mail as hostile until the callback clears. That includes a PDF that looks like your vendor’s invoice, a shared-mailbox thread that already had real traffic, and a voicemail that names the right matter. Look-alike domains and inbox-rule hiding are old BEC tactics. AI did not invent them. It made the prose cheaper.
- If money already moved, call the originating bank first and file IC3 second. Ask for a recall. Then file at ic3.gov with the dates, amounts, account numbers, and the receiving institution. Do not wait for a blog post to tell you the recovery rate. IC3 does not publish a number we are willing to invent.
Identity hardening still matters. Phishing-resistant MFA and a clean Microsoft 365 tenant reduce the odds that the attacker is sitting in the partner’s mailbox while they write the request. That work lives in the email-and-identity post. This post is what you do after the message is already on screen.
How MicroSky helps — on this payment, not a generic stack
We will tell you, in writing:
- Which payees you have actually wired in the last year, and which of them have a phone number on file that did not come from a recent email.
- Whether a callback-before-change rule exists, who the second approver is, and whether the spoken code is in use.
- Whether shared mailboxes used for AP or closings have mailbox-audit and forwarding rules you can explain.
- What to take to the bank and to ic3.gov if a wire already left.
We will not replace a callback with a slide about AI.
Call MicroSky at (718) 672-2177 or visit microskyms.com for a free, no-obligation look at how your firm releases money. We serve NYC, Staten Island, New Jersey, and the tri-state.
Ask who can change a vendor’s bank details, which number they would dial, and who the second approver is. If nobody can answer in one minute, that is the finding.

