Keep a fraudulent transfer from clearing
Verify the people and the payment instructions on the call where money moves, and catch the pressure that pushes a wire through before anyone verifies it.
- UnconfirmedCaller identityVoice not matched to approver on record
- SyntheticSynthetic mediaCloned-voice artifacts detected
- ChangedPayment instructionsBeneficiary differs from account of record
- Out of policyApproval pathSecond approver skipped under deadline
From signals to one action your team can take.
- UnconfirmedIdentityVoice on the call does not match the approver on record
- New accountPaymentBeneficiary has never received a payment from you
- Urgency risingConversationAuthority claim plus a closing deadline plus a push to stay off-channel
- Out of policyPolicyDual approval and callback to the number of record both skipped
Hold the wire. Route to a second approver before funds move.
A redirected wire is not one event
The attack moves across channels, and each layer looks acceptable on its own. Here is what happens at each one, and what Diopter does about it. The last layer is the one that costs the most, because it does not stop at a single payment.
The vendor email thread
AttackerOwns a real thread for weeks, learns the cadence, then changes a single banking detail.
DiopterRead as context for the call, so a fresh domain or an unfamiliar contact is already known before anyone picks up.
The approval call
AttackerPuts a cloned voice or a deepfaked face on the call to authorize the change personally.
DiopterScored continuously for synthetic video and voice, and for the authority, urgency, and isolation pattern.
The payment instructions
AttackerSupplies a beneficiary account that has never received a payment from you.
DiopterValidated against the account of record before the transfer is released.
The approval path
AttackerCompresses the deadline until dual approval and the callback both get skipped.
DiopterChecked against your own wire thresholds and dual-approval rules, so a shortcut is what raises the hold.
The vendor record
AttackerGets the banking details changed on the vendor master, so every future payment is redirected instead of one.
DiopterThe call that authorizes a standing-record change is scored the same way as a transfer, and the new account is checked against the vendor's payment history before the record is updated.
What Diopter looks for
Identity and payment verification
Confirm who is on the call and validate wire instructions, flagging fraud signals like a brand-new email domain or a SIM-swapped number.
Pressure and policy checks
Detect the urgency and out-of-policy framing that accompanies a redirect, and catch asks that skip your controls.
Impersonation detection
Score the call for synthetic voice and video used to authorize the transfer.
Approval-path verification
Check whether the transfer followed your normal multi-approver, callback-to-a-known-number process, so a shortcut around that path is what raises the hold.
Where wire fraud happens
- 01
Redirected closing and treasury wires
Bank, treasury, and closing wires redirected through impersonation and last-minute instruction changes.
- 02
Vendor and invoice changes
Banking detail changes pushed under urgency on accounts-payable and vendor onboarding calls.
- 03
Capital calls and fund transfers
Requests that arrive in the right format with the right balances, against an account that was never yours.
- 04
Changes to the vendor record itself
The worst case is not one transfer. A spoofed supplier that gets its banking details changed on your vendor master redirects every payment that follows, quietly, until someone reconciles.
How a wire fraud attack unfolds
These attacks move through a recognizable sequence. Diopter scores that sequence while the call is still in progress.
An impersonated authority
A cloned CFO, a title agent, or a known vendor establishes a believable reason to move money.
The deal closes today
Time pressure compresses the verification that would normally catch a redirect.
The channel narrows
Instructions arrive off the usual path, a new email domain, a private call, a different contact.
The transfers stack
One approved wire normalizes the next, the way fifteen transfers cleared on the Arup call.
The wire clears
Funds leave for an account that does not come back once the transfer settles.
Most tools cover one layer. The attack uses all of them.
A redirected wire is never just a call. It is a vendor thread owned for weeks, then a convincing approver on video or voice, then a beneficiary that has never been paid, then an approval path compressed until the second signature gets skipped. A tool that checks one of those four passes the other three. Diopter scores the call and reads it against the payment instructions, the account of record, and your own approval policy, so the verdict reflects the whole attack instead of one frame of it.
A clone can imitate your CFO. It cannot reproduce a real approval: the right people, the right channel, and instructions that match your controls.
Where single-layer tools stop.
Each category below covers one part of the attack and is blind to the rest. The last column is the only one that correlates them into a single verdict.
Detects synthetic voice on a live call
- Awareness training
- Single-frame deepfake
- Identity / reputation
- Live-call detection
- Diopter Arc
Detects deepfake video frames
- Awareness training
- Single-frame deepfake
- Identity / reputation
- Live-call detection
- Diopter Arc
Verifies caller identity (reputation/biometric)
- Awareness training
- Single-frame deepfake
- Identity / reputation
- Live-call detection
- Diopter Arc
Models the conversation arc (pressure → ask)
- Awareness training
- Single-frame deepfake
- Identity / reputation
- Live-call detection
- Diopter Arc
Correlates identity, media, and conversation signals on live calls
- Awareness training
- Single-frame deepfake
- Identity / reputation
- Live-call detection
- Diopter Arc
Forensic evidence chain for incident review
- Awareness training
- Single-frame deepfake
- Identity / reputation
- Live-call detection
- Diopter Arc
| Capability | Awareness training | Single-frame deepfake | Identity / reputation | Live-call detection | Diopter Arc |
|---|---|---|---|---|---|
| Detects synthetic voice on a live call | |||||
| Detects deepfake video frames | |||||
| Verifies caller identity (reputation/biometric) | |||||
| Models the conversation arc (pressure → ask) | |||||
| Correlates identity, media, and conversation signals on live calls | |||||
| Forensic evidence chain for incident review |
Light to deploy, clear about what runs where.
Pilot in days, roll wider through MDM, and keep sensitive call media inside your perimeter.
- On-prem and hybrid deployments supported
- No caller-side install
- Bot or bot-free capture
- Configurable retention, including ZDR
- MDM rollout (Intune, Jamf)
- SOC 2 Type II in progress
Walk an attack arc with Diopter.
We will replay a real incident, show the signals Diopter scored, and map the verdict your team would act on. We will sign your NDA first if you want one.