The threat to your organization’s money has changed more in the last two years than in the twenty before it. AI has made a cloned voice, a fake video call, and an email in your CEO’s exact writing style cheap and easy, which means the old defense of training people to spot something off no longer holds up on its own.
In this session, Heide Olson, Founder and CEO of All In One Accounting, walks through what has changed, the specific controls that still work, and the nine things a leader can do this week. She also shares what All In One Accounting’s own alert system has caught for clients in the past year.
Recorded live on August 4, 2026. Runtime 53 minutes. Free to watch, no registration required.
Jump to a section
- 1:09 How the threat evolved from 2004 to today
- 4:29 The numbers behind the risk
- 6:42 Tightening your accounts payable process
- 7:55 Live verbal approval before money moves
- 10:25 Positive pay, and why only 35% of businesses use it
- 11:47 Why paper checks are still the number one target
- 13:47 MFA, authenticator apps, and locking your SIM card
- 16:52 Freezing your credit, and the account opened in Heide’s name
- 19:40 The cyber insurance coverage that actually matters
- 20:53 Setting a corporate and family code word
- 22:50 AI deepfakes and the $25 million video call
- 27:22 Our Code Red system and $1.5 million protected
- 32:18 The action worksheet
- 37:06 Live Q&A with attendees
How the threat changed
When Heide started All In One Accounting in 2004, the risk sat inside the building. Post-Enron, the concern was the trusted insider: a bookkeeper or controller running fake vendors, padded invoices, or billing schemes. A fraudster needed a badge and a login, and the defense was internal controls.
By the late 2000s money went digital. Online banking, card payments, and the first large data breaches meant a criminal no longer had to be inside your company. They just needed credentials.
The 2010s established the outside threat. Business email compromise exploded, along with urgent wire requests from the “CEO” and hacked vendors asking you to update their bank details. Those attempts were still catchable, because the grammar was bad, the tone was wrong, and the details were off.
That last safety net is gone. Remote work widened the attack surface, and AI now produces flawless phishing, cloned audio in your CEO’s voice, and synthetic executives on live video calls. The threat is now anyone with an internet connection.
“Fraud doesn’t steal a line on a page. It steals a life’s work.”
Heide Olson, Founder & CEO
The numbers behind the risk
The scale here is not theoretical, and it is not shrinking.
- $20.9 billion in cybercrime losses were reported to the FBI in 2025, up 26 percent from $16.6 billion the year before.
- Over $3 billion of that came from business email compromise alone.
- More than 22,000 AI-related complaints were logged in 2025, with close to $900 million in associated losses.
- 40 percent of business email compromise messages are now written with AI.
- Roughly 85 percent of losses come from schemes that exploit people rather than technology.
- 682,000 reports involving check fraud were filed by banks last year, which is why paper checks remain the number one target.
- Only 35 percent of businesses use positive pay, one of the cheapest protections a bank offers.
Figures cited in the session come from the FBI’s 2025 Internet Crime Report and related industry reporting. The consequence is what matters to a leader: nearly one in five businesses face bankruptcy after a major attack, and 40 percent say a single six-figure loss would end them.
Nine things to do this week
This is Heide’s action worksheet from the session. None of it requires new software, and most items take minutes.
- Turn on multifactor authentication everywhere it is offered. Email, banking, credit cards, retirement accounts, every application. Use an authenticator app rather than text messages, because texts can be intercepted.
- Lock down your SIM card with your phone carrier. Criminals call your carrier, impersonate you, and unlock your SIM to take over your phone and receive your verification codes. Most carriers let you lock it online in a few minutes.
- Freeze your credit at all three bureaus. It is free, it takes about five minutes, and you thaw it only when you need it. Do it for yourself, your key executives, and your family.
- Call your bank today about positive pay. The bank matches every check and ACH against a list you preapprove and holds anything that does not match for your review before it clears.
- Add identity and credit monitoring. A freeze stops someone from opening credit in your name. Monitoring tells you they tried, and alerts you if your information surfaces on the dark web.
- Use a password manager. Post-it notes, a spreadsheet, and one base password with the year on the end all fail the same way. One strong password protects the rest.
- Confirm your cyber insurance covers social engineering and funds transfer fraud, not only data breaches. Strong controls also tend to lower the premium.
- Eliminate paper checks. A check hands a stranger your account number, routing number, and signature, then travels through the mail. The FBI and the Postal Service have both warned that criminals are recruiting postal employees to steal them.
- Set a corporate code word, and a family one. Any urgent wire, gift card, or credential request has to include it. Share it in person, never online, and update it about once a year.
The one control most companies are missing
At All In One Accounting, nothing gets paid without a live verbal approval. The accountant calls the client, gets verbal confirmation, follows up in writing, and the whole thing is backed by a documented policy.
The only exception is an online bill pay system where the owner or CEO logs in to approve, and only when that login has multifactor authentication and the CEO uses a password manager. The same rule covers every bank detail change and every urgent wire, including payroll change requests from employees. If your bank contacts you, call the number on their website rather than the number in the email or text.
As Heide put it in the session, training people to spot a deepfake is a losing game, because the technology only gets better. Process is what holds.
“Process does not get fooled. Process is so much smarter than us at protecting our assets than the human is.”
Heide Olson, Founder & CEO
What our Code Red system caught in one year
About a year ago, a nonprofit client lost roughly $800,000 to wire fraud. Criminals deepfaked the executive director’s voice and called the bank on a Friday afternoon. Our accountant noticed something odd, but the controller on that account was traveling, and by Monday morning the money was gone. The client did eventually recover all of it.
By the end of that week, All In One Accounting built the Code Red alert system. Any of our team members who sees anything suspicious on a client account, a strange email, an unusual request from a CEO, something off in the bank, has fifteen minutes to call in and get help.
Code Reds
Called in by our team in one year
Client Assets Protected
Across those alerts
Lost
On the top exposures we caught
A few of the specific catches:
- $475,000 vendor impersonation through a hacked email, stopped immediately.
- $280,000 payment diversion, caught by verbal verification.
- $102,000 compromised bill pay. The CEO had no multifactor authentication, his credentials were stolen, and the payments were redirected before he logged in to approve them. Our accountant caught it.
- $80,000 in fraudulent account transactions, caught by positive pay review.
In the seven days before this session, the team fielded nine Code Reds. That is roughly one every other day.
Questions from the session
Is text message multifactor authentication good enough?
No. Text-based multifactor authentication is better than nothing, but it is now the weakest version. Criminals call your mobile carrier, impersonate you, and get your SIM unlocked so they can receive your codes on their device. Use an authenticator app instead, lock your SIM card with your carrier, and consider geofencing, which restricts logins to the regions where your team actually works and requires a heads-up before anyone travels.
Does cyber insurance cover wire fraud and deepfake scams?
Not automatically. Many policies cover data breaches but exclude the scenarios that actually drain operating accounts. Ask your agent two specific questions: does this policy cover social engineering, and does it cover funds transfer fraud. Confirm both in writing. Having multifactor authentication, positive pay, and a verification process in place also tends to reduce what you pay, because insurers price on those behaviors.
Are gift card scams still working?
Yes, and they still succeed because they target people who are new or off balance. Heide shared two examples in the session: an accountant standing in a checkout line buying gift cards because of an email she believed came from Heide, and her own daughter, on the first day of an internship in London, receiving a text from her “boss” asking her to buy gift cards. Criminals look for new hires, role changes, travel, and Friday afternoons, because that is when process is weakest.
What should companies with international accounts do differently?
Apply all of the same controls and be stricter about them. Lean on your IT partner for geofencing so systems cannot be accessed from outside the regions where your people work, and notify them before anyone travels. A login attempt from a country where nobody on your team is working should be treated as a red flag rather than an inconvenience. For a multinational cash pooling structure, the same fundamentals apply, with a three-way match so you always know when money goes in and when it comes out.
Was the $800,000 wire fraud a fake voice from the bank or the vendor?
Neither. Criminals built a deepfake of the nonprofit’s own executive director and used it to call the bank. That is what makes this category different from older schemes: the fraudulent voice belonged to someone the bank already trusted. The organization recovered the funds in this case, but only because the attempt was eventually caught. Speed matters, because fraudsters start with one amount and keep going until someone stops them.
Where your accounting team fits
Every control in this session lives inside the accounting function, which is why the conversation belongs with whoever runs your books. Segregation of duties, reconciliation, and audit trails do two jobs at once. They give you numbers you can act on, and they stop wire fraud, CEO impersonation, and deepfake requests from succeeding.
That is what protecting your assets looks like in practice, and it is one of the three outcomes we build into every engagement through our Accounting Clarity® process. For companies running on EOS®, it is also a Process component issue rather than a technology one.
Worth asking your team this week: what is our process when something looks wrong, and how fast can we act on it?
Your host
Heide started All In One Accounting out of her basement 22 years ago with a mission to make the lives of entrepreneurs and nonprofit leaders better through strategic accounting that supports profitable growth, protects assets, and amplifies impact.
She leads a team of accountants, controllers, and CFOs serving entrepreneurs and nonprofits nationwide, and she is the Visionary of an EOS® run company.
Who is watching your accounts right now?
If you are not sure what happens when something looks wrong, that is worth an hour. Our fractional accounting teams build these controls into how they work and escalate anything unusual within fifteen minutes. Bring one question from the webinar and we will start there.