Skip to main content
Solution

Keep a fraudulent transfer from clearing

Verify the people and the payment instructions on the call where money moves, and catch the pressure that pushes a wire through before anyone verifies it.

30 minutes with a founder. We will sign your NDA first if you want one.
~$200M
redirected on closing wires in one quarter
Source · Q1 2025
$35M
moved on a single cloned-voice call
Source · Reported, 2024
$2.9B+
business email compromise losses reported in a single year
Source · FBI IC3 · 2023
The verdict

From signals to one action your team can take.

What drove this verdict
  • Identity
    Voice on the call does not match the approver on record
    Unconfirmed
  • Payment
    Beneficiary has never received a payment from you
    New account
  • Conversation
    Authority claim plus a closing deadline plus a push to stay off-channel
    Urgency rising
  • Policy
    Dual approval and callback to the number of record both skipped
    Out of policy

Hold the wire. Route to a second approver before funds move.

The whole attack

A redirected wire is not one event

The attack moves across channels, and each layer looks acceptable on its own. Here is what happens at each one, and what Diopter does about it. The last layer is the one that costs the most, because it does not stop at a single payment.

The vendor email thread

Context

AttackerOwns a real thread for weeks, learns the cadence, then changes a single banking detail.

DiopterRead as context for the call, so a fresh domain or an unfamiliar contact is already known before anyone picks up.

The approval call

Scored live

AttackerPuts a cloned voice or a deepfaked face on the call to authorize the change personally.

DiopterScored continuously for synthetic video and voice, and for the authority, urgency, and isolation pattern.

The payment instructions

Scored live

AttackerSupplies a beneficiary account that has never received a payment from you.

DiopterValidated against the account of record before the transfer is released.

The approval path

Scored live

AttackerCompresses the deadline until dual approval and the callback both get skipped.

DiopterChecked against your own wire thresholds and dual-approval rules, so a shortcut is what raises the hold.

The vendor record

Scored live

AttackerGets the banking details changed on the vendor master, so every future payment is redirected instead of one.

DiopterThe call that authorizes a standing-record change is scored the same way as a transfer, and the new account is checked against the vendor's payment history before the record is updated.

How Diopter helps

What Diopter looks for

01

Identity and payment verification

Confirm who is on the call and validate wire instructions, flagging fraud signals like a brand-new email domain or a SIM-swapped number.

02

Pressure and policy checks

Detect the urgency and out-of-policy framing that accompanies a redirect, and catch asks that skip your controls.

03

Impersonation detection

Score the call for synthetic voice and video used to authorize the transfer.

04

Approval-path verification

Check whether the transfer followed your normal multi-approver, callback-to-a-known-number process, so a shortcut around that path is what raises the hold.

The risk

Where wire fraud happens

  • 01

    Redirected closing and treasury wires

    Bank, treasury, and closing wires redirected through impersonation and last-minute instruction changes.

  • 02

    Vendor and invoice changes

    Banking detail changes pushed under urgency on accounts-payable and vendor onboarding calls.

  • 03

    Capital calls and fund transfers

    Requests that arrive in the right format with the right balances, against an account that was never yours.

  • 04

    Changes to the vendor record itself

    The worst case is not one transfer. A spoofed supplier that gets its banking details changed on your vendor master redirects every payment that follows, quietly, until someone reconciles.

The attack playbook

How a wire fraud attack unfolds

These attacks move through a recognizable sequence. Diopter scores that sequence while the call is still in progress.

01
Authority

An impersonated authority

A cloned CFO, a title agent, or a known vendor establishes a believable reason to move money.

02
Urgency

The deal closes today

Time pressure compresses the verification that would normally catch a redirect.

03
Isolation

The channel narrows

Instructions arrive off the usual path, a new email domain, a private call, a different contact.

04
Escalation

The transfers stack

One approved wire normalizes the next, the way fifteen transfers cleared on the Arup call.

05
The ask

The wire clears

Funds leave for an account that does not come back once the transfer settles.

See this run against your own approval flow.
30 minutes with a founder. We will replay a real incident end to end.
Book a walkthrough
Why Diopter

Most tools cover one layer. The attack uses all of them.

A redirected wire is never just a call. It is a vendor thread owned for weeks, then a convincing approver on video or voice, then a beneficiary that has never been paid, then an approval path compressed until the second signature gets skipped. A tool that checks one of those four passes the other three. Diopter scores the call and reads it against the payment instructions, the account of record, and your own approval policy, so the verdict reflects the whole attack instead of one frame of it.

A clone can imitate your CFO. It cannot reproduce a real approval: the right people, the right channel, and instructions that match your controls.

Side by side

Where single-layer tools stop.

Each category below covers one part of the attack and is blind to the rest. The last column is the only one that correlates them into a single verdict.

Detects synthetic voice on a live call

Awareness training
Single-frame deepfake
Identity / reputation
Live-call detection
Diopter Arc

Detects deepfake video frames

Awareness training
Single-frame deepfake
Identity / reputation
Live-call detection
Diopter Arc

Verifies caller identity (reputation/biometric)

Awareness training
Single-frame deepfake
Identity / reputation
Live-call detection
Diopter Arc

Models the conversation arc (pressure → ask)

Awareness training
Single-frame deepfake
Identity / reputation
Live-call detection
Diopter Arc

Correlates identity, media, and conversation signals on live calls

Awareness training
Single-frame deepfake
Identity / reputation
Live-call detection
Diopter Arc

Forensic evidence chain for incident review

Awareness training
Single-frame deepfake
Identity / reputation
Live-call detection
Diopter Arc
Supported Partial Not supported
Deployment & trust

Light to deploy, clear about what runs where.

Pilot in days, roll wider through MDM, and keep sensitive call media inside your perimeter.

Deployment & trust
  • On-prem and hybrid deployments supported
  • No caller-side install
  • Bot or bot-free capture
  • Configurable retention, including ZDR
  • MDM rollout (Intune, Jamf)
  • SOC 2 Type II in progress
Walkthrough · 30 min

Walk an attack arc with Diopter.

We will replay a real incident, show the signals Diopter scored, and map the verdict your team would act on. We will sign your NDA first if you want one.

Common questions

What security and fraud teams ask first.