Deepfakes and CEO fraud in Mexico: how to protect your local operation from cloned voice and video scams
On September 14, 2026, a video of Luisito Comunica, the most watched YouTuber in Mexico, praising the federal government went around. He never recorded it. As Xataka México reported, it was AI: voice, gestures and tone cloned with tools anyone can download.
If that works on a public figure, it works on your CFO. And the scammer does not care about fame. They care about the accountant in your Querétaro plant approving a wire before head office wakes up.
What CEO fraud looks like when the boss sits abroad
CEO fraud is simple: someone impersonates a director, the accountant or a supplier so finance pays or hands over access. A deepfake is AI-generated audio or video that imitates a real person. Put together, they hit subsidiaries especially hard. The local team rarely meets the executives in person, so a voice on the phone is all they have to go on.
Cloning a voice takes a few seconds of audio. An earnings call, a LinkedIn video, a voice note forwarded on WhatsApp. Most executives already have plenty of material out there.
The backdrop does not help. Diario21 reported a rise in phishing cases in Mexico this same week, and according to DPL News ransomware grew 25% across Latin America, with Mexico taking 18% of the attacks. The same groups that encrypt servers also ask for wires.
How they operate: the call, the email and the CLABE
In our experience, almost every attempt follows one of three scripts.
| Script | What it looks like | What they want |
|---|---|---|
| The urgent call | The “CFO” calls or joins a short video call: in a meeting, cannot talk, this has to go out today | A fast wire transfer |
| The email from the boss | Arrives from a domain almost identical to yours, real signature copied | Finance pays or shares passwords |
| The CLABE change | A “supplier” says they changed banks and sends the new account | Divert legitimate payments for months |
The CLABE is the 18-digit number that identifies a bank account in Mexico, used for every transfer. Changing a supplier CLABE from an email, with nobody calling anyone, is the easiest way to lose money without noticing until the real supplier complains.
Warning signs that almost never fail
- Urgency plus secrecy: “keep this between us, I will explain later”.
- A new channel: the CFO always writes on Teams and today calls from an unknown number.
- Bank details changed without a prior call.
- Someone who cannot answer a simple question about the office.
- A request timed for when head office is offline: Friday afternoon in Mexico, late evening in Madrid.
A verification protocol with three locks
- Second channel. If the request comes by email, hang up and call the number already in your directory. Never reply through the same channel or to the number they gave you.
- Code word. Head office finance and the Mexico team agree on a word that is asked on any request for money or access. It changes every quarter and never appears in an email.
- Dual approval. Nothing out of the ordinary goes out with a single approval, ideally one in Mexico and one at head office, and every CLABE change is confirmed by voice with the supplier at the usual number.
Locks on email so the fake boss never gets in
Many of these frauds start with a compromised mailbox. Four things are worth checking. Two-step verification for everyone, with no exceptions for executives. The SPF, DKIM and DMARC records, which tell other mail servers which messages really came from your domain. Alerts when someone creates a hidden forwarding rule, which is the first place we look when a case comes in. And blocking of lookalike domains.
If you want to go deeper, we already covered how to protect Microsoft 365 email from passkey phishing and how to spot fake IT support asking for remote access. It is the same family of tricks.
At ProcessBi, anti-fraud training in Spanish for your Mexico team and email hardening are part of the IT support plan, and we run phishing simulations with a report in English for head office.
What about your Mexico operation?
Ask your Mexico finance team today what they would do if the CFO called asking for an urgent wire. If the answer is “pay it”, you know where to start.
We can review your email setup, build the protocol with you and run the first simulation at no cost.
Book your free assessment — we reply the same business day.
Your path
Running IT in Mexico from abroad
10 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →