Voice cloning and deepfakes: the new scam targeting Quebec SMBs
A call from your boss asking for an urgent wire transfer. The voice is perfect. Except it isn’t him. In 2026, voice cloning and deepfake scams are no longer science fiction, and they are aimed more and more at small businesses. In Trois-Rivières as anywhere else in Quebec, no company is too small to be targeted.
The good news is that you can protect yourself without being an expert. Here is what a deepfake actually is, why small businesses have become targets, and the simple habits that genuinely make a difference.
Quick answer: A deepfake is fake content (voice, video or image) generated by artificial intelligence to imitate a real person. Today, a voice can be cloned from as little as three to ten seconds of recording. To protect your small business, require verification through a second channel before any transfer or any sharing of sensitive information, and train your teams to recognize these scams.
1. What are deepfakes and voice cloning?
A deepfake is a forgery created by artificial intelligence, realistic enough to fool people. It can be an imitated voice, a doctored video or a fake image. Voice cloning is the form used most often against businesses, because it is fast and cheap to produce.
Here is the detail that worries us: three to ten seconds of clean audio is now enough to clone a voice convincingly. And those few seconds are easy to find. A video on social media, a conference talk, a webinar or a voicemail will do.

2. Why have small businesses become targets?
For a long time, small businesses believed they were out of reach. That is no longer the case. Artificial intelligence has made attacks cheap and automated, so they pay off even against small targets.
- Tailored bait: fraudsters use AI to write messages suited to your industry, built around believable themes such as an invoice or a call for tenders.
- Fewer warning signs: fraudulent emails now contain almost no spelling mistakes and do a much better job of imitating your suppliers.
- A very real impact: according to the World Economic Forum, close to three respondents out of four knew someone around them who had been hit by a digital fraud in 2025.
Phishing remains the number one way in for attackers, and AI simply makes it more convincing.
3. How do you recognize an AI-powered scam?
No technology replaces plain vigilance. A few reflexes will catch most of these frauds before it is too late.
- An unusual sense of urgency that pushes you to act fast and without thinking.
- A request for a transfer, a change of banking details or sensitive data.
- An unusual channel: a phone call or a text message instead of the usual email.
- A detail that feels off in the tone, the vocabulary or the procedure being followed.
OKTO tip: Adopt one simple rule in your company: every transfer request or banking change must be confirmed through a second known channel, for example a call to the person’s official number. That single reflex blocks the vast majority of voice cloning scams.

4. Six steps to protect your business
AI does not make good security practices obsolete. Quite the opposite: it makes the fundamentals more valuable than ever.
- Double validation: confirm every sensitive request through a second channel.
- Two-factor authentication: turn it on everywhere, especially on email and banking access.
- An internal safe word: agree on a secret word or question to confirm someone’s identity when in doubt.
- Team training: make your staff aware of deepfakes and voice cloning.
- Updates: keep your systems and your software current.
- Written procedures: document who can approve a payment, and how.
To turn on two-factor authentication in practice, follow our guide Turning on two-factor authentication in Microsoft 365.
5. What do you do if you become a victim?
If a fraud succeeds, speed limits the damage. Act right away and without embarrassment, because these scams catch even careful people.
- Call your financial institution immediately to try to stop the transfer.
- Change the passwords involved and review who has access.
- Report the incident to the Canadian Anti-Fraud Centre and to your IT provider.
Frequently asked questions
What is a deepfake?
A deepfake is fake content generated by artificial intelligence, such as a voice, a video or an image, designed to imitate a real person realistically. Fraudsters use it to pass themselves off as a boss, a supplier or a co-worker.
How long does it take to clone a voice?
Very little time. Current tools can produce a convincing clone from just three to ten seconds of clean audio. That is why a single public video or a voicemail can be enough for a fraudster.
How do you protect yourself against AI-powered scams?
The best protection is double validation: confirm every sensitive request through a different, known channel. Add two-factor authentication, written procedures and regular training for your teams.
Protect your small business with a local partner you can trust
Deepfake scams evolve quickly, but simple measures protect you effectively. To assess your risks and train your teams, take a look at our IT services or contact the OKTO Solutions team in Trois-Rivières for support that fits your reality.
An article sets out the principle. Putting it in place happens one workstation at a time: our managed cybersecurity service, backup and disaster recovery and our IT services in Montreal.