Deepfake Calls and Tiny Test Charges: Two Payment Fraud Clues Small Businesses Should Not Ignore

Fraud does not always kick the front door in.

Sometimes it walks in wearing a familiar face.

Sometimes it starts with a charge so small you almost ignore it.

That is what makes today’s payment fraud so dangerous for small businesses. The clues are there, but they do not always look dramatic at first. A voice that sounds like the owner. A video call that appears to show a trusted vendor. A $1.07 charge on a company card. A tiny test transaction that everyone assumes is just noise.

But fraud investigators know better.

Small clues matter.

The old fraud question used to be: “Did this payment come from the right person?”

Now the better question is: “Can we prove this payment instruction is real before the money leaves?”

That is the shift small businesses need to understand. Fraud is moving faster. It is getting more convincing. And it is no longer enough to rely on instinct, familiarity, or the fact that someone “sounded right.”

The First Clue: The Voice Sounds Right, But Something Feels Off

Deepfake fraud is not science fiction anymore.

Criminals can use AI-generated audio or video to impersonate an owner, executive, vendor, client, or employee. They do not need to break into your accounting system. They do not need to hack your bank. They just need one person inside the business to believe what they are seeing or hearing.

That is the scary part.

A staff member gets a call that sounds like the owner.

The request is urgent.

The payment needs to go out today.

The caller says not to bother anyone else because it is sensitive.

And because small businesses are built on trust, the employee wants to help.

That is exactly what the fraudster is counting on.

Deepfake fraud works because it attacks the human side of the payment process. It uses familiarity as a weapon. The voice sounds right. The face looks right. The request seems to come from someone with authority.

But here is the hard truth: familiar is not the same as verified.

A familiar voice can be cloned.
A familiar face can be simulated.
A familiar email thread can be copied.
A familiar sense of urgency can be manufactured.

So what do you do?

You stop treating “I recognize them” as a control.

The Second Clue: The Charge Is Tiny, But It May Be a Test

Not all payment fraud comes with drama.

Sometimes the fraudster starts small.

A few dollars. Maybe less. A tiny card charge. A small online purchase. A quick transaction that looks too insignificant to chase down.

But to a fraudster, that tiny charge answers a very important question:

“Does this account work?”

If the charge goes through and no one catches it, the criminal has learned something valuable. The door may be open.

This is why small test transactions matter. They can be the first footprint before a bigger theft. The criminal may be testing stolen card data, login credentials, payment access, or account controls.

Now, does every small charge mean fraud?

No.

Small businesses have plenty of legitimate little charges. Subscriptions. Software trials. Vendor verifications. Employee purchases. Bank test deposits.

The point is not to panic over every tiny transaction.

The point is to notice patterns.

A small unfamiliar charge by itself may be nothing.

A small unfamiliar charge plus a new device login, a password reset, a vendor bank change, or a larger payment attempt?

Now we have a trail.

And trails are where fraud gets caught.

Payment Fraud Is No Longer Just an Email Problem

For years, businesses were told to watch for suspicious emails.

Bad grammar. Strange links. Fake invoices. Spoofed addresses.

That still matters.

But today’s fraud is not limited to email. A payment instruction may arrive through a phone call, a video meeting, a text message, a vendor portal, a copied email thread, or a compromised account.

The delivery method is changing.

The goal is not.

The fraudster wants money to move before anyone slows down long enough to ask the right question.

That is why small businesses need a verification layer.

Not more paranoia. Not more red tape. Just a simple, repeatable process for high-risk payment moments.

Because once the money leaves, the conversation gets a lot harder.

What Small Businesses Should Do Now

1. Verify unusual payment requests through a separate channel

If the request comes by email, verify it by phone using a number you already trust.

If the request comes by phone or video, verify it another way.

Do not use the phone number, link, or contact information provided in the request. That is like asking the suspect to confirm their own alibi.

Use the vendor record. Use the known contact. Use the number already on file.

And yes, it may take five extra minutes.

That five minutes could save the business thousands.

2. Create a high-risk payment checklist

Not every payment needs a full investigation. But certain payments should always slow down.

Put extra controls around:

New vendors
Changed bank account information
Urgent wires
International transfers
Large refunds
First-time ACH instructions
Payments requested outside the normal process
Anything involving secrecy or pressure

These are not routine payments. These are high-risk payment moments.

Treat them that way.

3. Give employees permission to pause

This is a big one.

Controls do not work if employees are afraid to use them.

If your staff believes they will get in trouble for slowing down a payment, they may push it through just to avoid looking difficult.

That is how fraud wins.

Make the rule clear: pausing a suspicious payment is not a problem. It is professionalism.

An employee who says, “I need to verify this before we send money,” is protecting the business.

That person deserves backup.

4. Watch small anomalies in context

A tiny charge may not mean much.

But a tiny charge plus another odd signal deserves attention.

Look for combinations like:

A small unfamiliar card charge and a later larger transaction
A failed login attempt and a new device alert
A password reset and a vendor bank change
A payment request outside normal timing
A new merchant charge no one recognizes
A caller who refuses independent verification

Fraud is often visible in pieces before it becomes obvious.

Your job is to connect the pieces before the money is gone.

5. Require two approvals for high-risk changes

No single email, phone call, video call, or text message should be enough to change payment information or approve a high-risk transfer.

Use dual approval for things like:

Bank detail changes
Large payments
Wires
New vendors
Refunds over a set amount
Emergency payment requests

This does not have to be complicated.

It can be as simple as one person entering the payment and another person approving it after verification is documented.

The key is this: one person should not be able to receive, approve, and release a risky payment instruction alone.

6. Keep a verification trail

When a sensitive payment is verified, write down what happened.

Who verified it?
What trusted channel was used?
Who approved it?
When was approval given?

This does two things.

First, it helps prevent confusion. Second, if something does go wrong, you have a record of the steps taken.

Good notes are not busywork.

They are evidence.

Red Flags To Put On The Wall

Here are the clues your team should know:

A voice or video call asking for urgent payment
A request for secrecy
A senior leader asking to bypass normal procedures
A vendor changing bank details right before payment
A small unfamiliar charge followed by a larger payment attempt
A payment request that skips the usual invoice or approval process
A caller who does not want you to call back independently
A message that says, “Just this once”
A request that makes the employee feel rushed, guilty, or afraid to ask questions

Fraudsters hate verification because it breaks the spell.

That is the point.

The pressure is part of the setup. The urgency is part of the script. The “just this once” is not a favor. It is a clue.

The Detect-A-Fraud Takeaway

Deepfake calls and tiny test charges may look like two different fraud stories.

They are not.

They are both reconnaissance.

One tests human trust.
The other tests payment systems.

A deepfake call asks, “Can we fool the person?”

A tiny test charge asks, “Can we get through the system?”

Either way, the fraudster is looking for a weak spot before making the bigger move.

Small businesses do not need a bank-sized fraud department to fight back. They need clear rules for the moments when money is about to move.

Verify through a known channel.
Use a second approval for risky payments.
Treat small oddities as clues when they show up with other strange activity.
Give employees permission to stop the process when something feels off.

Because the fraudster wants the payment to feel routine.

Your job is to notice when the routine has been quietly rewritten.