Category: Verification Intelligence

Evidence-led investigations, verification methods and practical risk intelligence from The Verification Desk.

  • Screenshots Are Not Proof: Building a Defensible Evidence Trail

    Screenshots Are Not Proof: Building a Defensible Evidence Trail

    A screenshot shows pixels. It does not automatically prove the event behind them.

    CLAIM

    A screenshot is self-authenticating evidence because it appears to reproduce a message, payment or webpage.

    EVIDENCE

    Screenshots are useful but incomplete. They can omit surrounding conversation, source addresses, headers, URLs, timestamps and platform identifiers. They can also be cropped, annotated, recomposed or generated. None of this means a screenshot is false; it means the image must be assessed in context.

    TEST

    Ask what the screenshot actually establishes. Does it show that particular words appeared on a particular screen? Can the underlying message, account, transaction or webpage be obtained independently? Is the time, source and method of capture recorded?

    VERDICT

    A screenshot is usually a lead or supporting exhibit—not the entire evidence trail.

    ACTION — STRENGTHEN THE RECORD

    1. Retain the original source. Keep the email, message thread, account record or transaction entry where possible.
    2. Capture context. Include the account identifier, date, time, full address or URL and surrounding exchange.
    3. Record acquisition. Note who took the screenshot, when, from which device or account and why.
    4. Avoid destructive editing. Keep an untouched copy. Work from duplicates for redaction or annotation.
    5. Export where possible. Platform exports, original emails and bank statements often contain more testable information.
    6. Corroborate. Match the image to transaction records, server data, independent correspondence or other contemporaneous evidence.

    EVIDENCE GRADING

    • V1 — Unsupported: screenshot with no source or context.
    • V2 — Attributed: source claimed and capture circumstances described.
    • V3 — Corroborated: independently matching records exist.
    • V4 — Strongly verified: original source and reliable provenance retained.
    • V5 — Determinative: multiple independent records resolve the material point, subject to competent assessment.

    The grade applies to the proposition being tested, not to the visual quality of the image.

    A PRACTICAL EXAMPLE

    A cropped image saying “payment received” may show that those words appeared on a screen. It does not necessarily prove that funds settled, who controlled the account or whether the image relates to the disputed transaction. A bank record, transaction identifier and matching chronology materially strengthen the position.

    LIMITATIONS

    Evidence requirements depend on purpose. A customer-service complaint, internal inquiry, regulatory submission and court proceeding may require different handling. Obtain appropriate advice where formal admissibility or forensic preservation matters.

    Primary source


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • Verify Before You Pay: Five Independent Checks

    Verify Before You Pay: Five Independent Checks

    The safest time to verify a payment is before the money moves.

    CLAIM

    A convincing invoice, message or telephone call is enough to justify payment.

    EVIDENCE

    Scam communications increasingly reproduce genuine brands, names and business language. The NCSC warns that attackers use pressure and trust to make people act quickly. Surface quality is therefore a weak test: a polished document can still contain a false destination.

    TEST

    A proposed payment should survive checks that do not depend on the instruction itself.

    VERDICT

    Verify the transaction, the recipient and the route independently. One matching detail is not enough.

    ACTION — FIVE CHECKS BEFORE PAYMENT

    1. Authority

    Does the person requesting payment have the authority to do so? Verify through the normal approval route. A senior name in an email header does not establish authority.

    2. Obligation

    What is the payment for? Match the request to a contract, purchase order, verified invoice or other underlying obligation. Check quantity, amount, date and supplier identity.

    3. Destination

    Are the bank details already verified? Any change requires independent confirmation using pre-existing contact information.

    4. Identity

    Confirm the counterparty through a reliable source independent of the message. Check the complete domain and telephone number, not merely the display name or logo.

    5. Context

    Does the transaction make sense? Look for unusual urgency, secrecy, payment method, timing, value, beneficiary country or departure from established practice.

    THE TWO-CHANNEL RULE

    When risk is material, verify through a second channel that the requester did not provide in the same communication. If the request arrives by email, use a known telephone number or internal workflow. If it arrives by telephone, verify through a trusted written route.

    STOP CONDITIONS

    • The requester resists verification.
    • The payment destination has changed unexpectedly.
    • The instruction demands secrecy.
    • The request sits outside the normal commercial relationship.
    • The evidence cannot be reconciled to existing records.

    IF UNCERTAIN

    Do not allow a deadline manufactured by the requester to replace your control process. Escalate internally or contact the relevant financial institution using trusted details.

    Official guidance


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • Can a Deepfake Detector Prove a Recording Is Fake?

    Can a Deepfake Detector Prove a Recording Is Fake?

    A detector can produce a score. A score is not a verdict.

    CLAIM

    Uploading a recording or image to an automated deepfake detector can establish whether it is genuine.

    EVIDENCE

    NIST treats synthetic-content detection as one part of a wider authenticity problem. Its guidance also identifies provenance information—such as authenticated content credentials—and contextual evidence as relevant. Operational performance can deteriorate when detectors encounter unfamiliar generators, compression, editing or material outside their test conditions.

    A detector may therefore contribute evidence, but both false positives and false negatives remain possible.

    TEST

    Before accepting a detector result, ask:

    • What media type and manipulation was the system trained to detect?
    • Has the file been compressed, edited or re-recorded?
    • Is the result reproducible?
    • Does the provider disclose validation data and error rates?
    • Is the submitted material retained or used for training?
    • What independent evidence supports or contradicts the result?

    VERDICT

    A deepfake detector cannot, by itself, prove authenticity or fabrication. It can support an assessment when its scope, reliability and limitations are understood.

    ACTION — A BETTER AUTHENTICITY TEST

    1. Preserve the original. Do not begin with a social-media download if a higher-quality source exists.
    2. Trace provenance. Identify the earliest available source, acquisition route and any content credentials or metadata.
    3. Check context. Does the claimed event appear in reliable independent reporting, official records or other contemporaneous material?
    4. Verify the person independently. For a live payment or instruction, contact the supposed sender through an established channel.
    5. Use technical tools cautiously. Record the tool, version, settings, result and file tested.
    6. Seek specialist examination where stakes are high. A consumer web detector is not a substitute for a competent forensic process.

    WHAT A DETECTOR RESULT CAN SAY

    At most: “This system assessed this submitted file, under these conditions, and returned this result.” It cannot automatically establish the identity of the creator, intent, chain of custody or the truth of the underlying event.

    Primary sources


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • Fraud First Aid: What to Do in the First 30 Minutes

    Fraud First Aid: What to Do in the First 30 Minutes

    You think you have been defrauded. The next thirty minutes matter—but panic is not a plan.

    The objective is not to solve the entire case immediately. It is to stop additional loss, protect access, preserve evidence and create a reliable record.

    CLAIM

    A short, ordered response can reduce avoidable damage and make the later account easier for a bank, reporting body or investigator to understand.

    EVIDENCE

    The National Cyber Security Centre advises anyone who has lost money following a suspicious message to tell their bank and report the matter as a crime. Its wider phishing guidance emphasises breaking contact, avoiding suspicious links and using recognised reporting routes.

    The Payment Systems Regulator’s authorised push payment reimbursement framework also makes prompt reporting and a coherent account practically important. It does not guarantee reimbursement in every case, but it establishes protections for many in-scope UK payments.

    TEST

    Use the sequence below. Do not spend the first half-hour arguing with the suspected fraudster, investigating social-media profiles or producing a polished narrative. Secure the position first.

    VERDICT

    The best immediate response is disciplined rather than dramatic: stop, secure, preserve, report and record.

    ACTION — THE FIRST 30 MINUTES

    Minutes 0–5: stop the movement

    • Do not send further money, codes, documents or credentials.
    • Break contact. Do not announce that you are collecting evidence.
    • If a payment has been made, contact the bank or payment provider through its official app or a trusted number.
    • Ask whether the payment can be stopped, recalled or flagged.

    Minutes 5–15: secure access

    • Change affected passwords from a trusted device.
    • Start with the email account controlling password resets.
    • Enable multi-factor authentication where available.
    • Check for changed recovery details, forwarding rules and unfamiliar sessions.
    • Tell the bank immediately if card, account or security information was disclosed.

    Minutes 15–25: preserve the evidence

    • Keep original messages and emails. Do not rely only on cropped screenshots.
    • Record telephone numbers, usernames, account details, URLs and transaction references.
    • Save confirmation emails and bank notifications.
    • Write down what was said while the memory is fresh, clearly labelling it as your recollection.

    Minutes 25–30: report and open a chronology

    • Use the appropriate official reporting route for your location and incident.
    • Record the date, time, organisation, contact method, reference number and advice received.
    • Begin a single chronology. Add later events; do not rewrite the earlier entry.

    DO NOT

    • Delete accounts or conversations before preserving what is needed.
    • Use contact details supplied by the suspected fraudster to “verify” the story.
    • Pay a recovery agent who makes an unsolicited approach or guarantees success.
    • Send identity documents to anyone claiming they need them to release recovered funds.

    Official sources


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • The Bank-Detail Change Verification Test

    The Bank-Detail Change Verification Test

    A request to change supplier bank details may be genuine. The email containing it proves almost nothing.

    CLAIM

    A bank-detail change should be treated as a change to a control, not an ordinary administrative instruction.

    EVIDENCE

    Compromised email accounts and convincing impersonation can place a fraudulent instruction inside a genuine conversation. Familiar wording, a correct signature block and knowledge of an invoice do not establish that the payment destination is legitimate.

    TEST

    The decisive test is independent confirmation through a channel already trusted before the change request arrived.

    VERDICT

    No independent confirmation, no change. Urgency is a reason to slow the process down, not bypass it.

    ACTION — THE BANK-DETAIL CHANGE TEST

    1. Freeze the change. Do not amend the supplier record or release payment.
    2. Use a pre-existing contact. Call a known contact using a number from the existing contract, verified supplier master record or official website—not the message requesting the change.
    3. Ask open questions. Confirm the change, effective date, reason and account name without reading every detail from the request.
    4. Require dual approval. One person verifies; another approves the amendment.
    5. Record the verification. Date, time, person contacted, number used, questions asked and outcome.
    6. Notify the known contact. Send confirmation to the previously established address as well as any new address.
    7. Control the first payment. For material changes, consider an independently approved test payment or enhanced review under the organisation’s policy.

    RED FLAGS

    • Pressure to act before a deadline
    • A request to avoid the usual contact
    • A new domain, subtle spelling variation or reply-to address
    • An explanation involving an audit, frozen account or confidential transaction
    • A simultaneous change to contact and bank details
    • Resistance to established verification controls

    IF PAYMENT HAS ALREADY BEEN MADE

    Contact the bank immediately through a trusted channel. Preserve the request, full email headers, invoice, payment approval, supplier record and every verification attempt. Contact the genuine supplier using established details.

    CONTROL TEMPLATE

    Change requested: ______
    Existing trusted contact: ______
    Independent number/source: ______
    Confirmed by: ______
    Verified by: ______
    Approved by: ______
    Date/time: ______
    First-payment control: ______

    Official guidance


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • Preserve the Evidence: A Fraud Incident Checklist

    Preserve the Evidence: A Fraud Incident Checklist

    An incident report is only as strong as the material behind it.

    After a fraud, people often collect too much of the wrong thing: hundreds of screenshots, repeated downloads and unlabelled files. The result looks substantial but becomes difficult to test.

    CLAIM

    Preserving evidence means retaining context, origin and sequence—not merely accumulating images.

    EVIDENCE

    Digital material changes easily. Messages can be edited or deleted, websites can disappear and account details can be replaced. A screenshot may capture what was visible at one moment, but it does not automatically establish who created the content, whether anything was omitted or whether the displayed account was genuine.

    TEST

    For every item, ask five questions: What is it? Where did it come from? When was it obtained? Is the original retained? What claim does it support?

    VERDICT

    A smaller, structured evidence pack is usually more useful than a large, unexplained folder.

    ACTION — BUILD THE PACK

    1. Preserve originals

    • Keep original emails in the mailbox where possible.
    • Export or download conversations using the platform’s own function if available.
    • Retain original photographs, audio and documents rather than repeatedly re-saving them.
    • Do not annotate the only copy.

    2. Record identifiers

    • Email addresses and full headers where available.
    • Telephone numbers, usernames and profile URLs.
    • Bank details, payment references and transaction identifiers.
    • Website addresses, including the complete URL.
    • Device and account names relevant to the event.

    3. Create a chronology

    Use one row per event:

    • Date and time
    • What happened
    • Who or what account was involved
    • Evidence filename
    • Action taken
    • Reference number

    4. Separate fact from recollection

    “The message was received at 14:06” may be supported by the original message. “The caller sounded nervous” is a recollection. Both may matter, but they are not the same kind of evidence.

    5. Keep a working copy

    Retain originals securely and use copies for highlighting, redaction or submission. Record what was provided, to whom and when.

    MINIMUM INCIDENT INDEX

    1. One-page summary
    2. Chronology
    3. Transaction schedule
    4. Communications
    5. Account and website identifiers
    6. Reports and reference numbers
    7. Actions and outstanding deadlines

    LIMITATIONS

    This process organises material; it does not certify authenticity or determine admissibility. Requirements differ between banks, investigators, regulators and courts. Follow any instructions issued by the body handling the matter.

    Official guidance


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

  • The 30-Minute Subscription Audit

    The 30-Minute Subscription Audit

    £4.99.

    £8.99.

    £12.99.

    On their own, none of these look like much. That is part of what makes them easy to overlook: individually, each payment can appear relatively small.

    Add them up, and the picture changes. A £12.99 monthly subscription is £155.88 a year. Multiply that across the streaming service you forgot to cancel after the free trial, the app you downloaded once, and the fitness plan you haven’t opened since January, and a household can be carrying a genuinely meaningful annual cost without ever having made a conscious decision to keep paying it.

    This isn’t a guess. It’s a documented, measured problem — and it’s one a short, structured audit can meaningfully help with.

    CLAIM

    Do you actually know what recurring services you’re paying for right now — and are they all still worth it?

    If you cannot list every recurring payment immediately, you are far from alone: official and consumer research shows that unwanted and forgotten subscriptions are a material UK problem.

    EVIDENCE

    The scale of this is well established. Government analysis estimates that UK consumers spend around £1.6 billion a year on subscriptions they do not want. Citizens Advice, working from independent national polling, put the cost of completely unused subscriptions at £688 million in a single year, and found that 26% of UK adults — more than 13 million people — had accidentally taken out a subscription in the preceding 12 months, often because a free trial rolled over or a contract auto-renewed without warning.

    Within the wider unwanted-spending total, government analysis breaks the picture down further: an estimated £573 million a year goes on subscriptions people have simply forgotten about, and £602 million comes from introductory trials or discounts that rolled over into a full-price contract without the customer meaning to continue.

    None of this means every subscription is wasteful — most people hold subscriptions deliberately, and use most of them. But it does mean the unwanted slice is large enough, and common enough, to justify checking what you are still paying for periodically.

    TEST

    We wanted to know whether a simple, structured household audit could realistically help — and whether it could realistically be done in about half an hour.

    The short answer: the finding and triage stages are designed to fit inside a 30-minute session. We have not independently tested that timing across a representative group of users. The cancelling part sometimes doesn’t, because some cancellation processes involve substantially more friction than sign-up. So we built the audit as two stages: a fast discovery-and-decision sprint, and a follow-up queue for anything that needs more time.

    VERDICT

    A structured audit doesn’t need to produce a wave of cancellations to be worth doing. It should sort everything into one of three categories:

    • KEEP — clearly used, clearly worth what it costs.
    • REVIEW — occasional use, an upcoming renewal, a recent price rise, or something you’re just not sure about yet.
    • CANCEL — genuinely unwanted, forgotten, or no longer used — once you’ve checked the contract terms.

    Government estimates suggest that cancelling an unwanted subscription saves an average of around £14 a month — approximately £168 a year — for each service eliminated. That figure is a useful yardstick, not a promise: what any individual household actually saves depends entirely on what they were paying for and how many CANCEL decisions they end up making.

    ACTION — THE 30-MINUTE AUDIT AND TRIAGE SPRINT

    This works best with your phone and a notes app, spreadsheet, or the worksheet at the end of this piece open in front of you.

    1. Find (roughly 8 minutes) Check where recurring payments actually live:

    • Your banking app — Direct Debits and the last two months of card transactions
    • Apple: Settings > [your name] > Subscriptions
    • Android: Google Play > Profile > Payments & subscriptions
    • PayPal: Account Settings > Payments > Automatic payments
    • Any other payment accounts you use regularly

    2. List (roughly 5 minutes) Put everything you find in one place.

    3. Annualise (roughly 4 minutes) Convert every monthly or weekly cost into a yearly figure. £12.99 a month becomes £155.88 a year. This single step tends to do more than anything else to make the real cost visible.

    4. Triage (roughly 5 minutes) Go down the list and mark each one KEEP, REVIEW, or CANCEL. Be honest rather than strict — there’s no need for a rigid rule like “unused for exactly 60 days.” If you’re not sure, REVIEW is the right answer, not CANCEL.

    5. Check before acting (roughly 4 minutes) Before you cancel anything, check:

    • Is it a fixed-term contract, or rolling monthly?
    • Is there a notice period or an early-termination charge?
    • Is it bundled with something else you still want?
    • Is it shared with anyone else in your household?
    • Do you need to export any photos, files, or data first?
    • Are you on a legacy or discounted rate you’d lose permanently?

    6. Act Cancel the straightforward ones properly, through the merchant or platform itself. Anything with a phone queue, a multi-step retention flow, or a “call us to cancel” process goes onto an escalation queue to deal with later — it doesn’t need to hold up the rest of the audit.

    7. Record Keep the confirmation email, the cancellation reference, and a screenshot if one’s offered. This matters more than it sounds like it should — see the warning below.

    8. Repeat Set a reminder to do this again in three to six months. Subscriptions creep back.

    THE PART MOST PEOPLE GET WRONG: PAYMENT VS. CONTRACT

    This is worth being precise about, because getting it wrong can cost you money.

    Stopping a card payment and cancelling a contract are not the same thing.

    FCA guidance confirms that you can ask your card issuer to stop a recurring card payment, and the card issuer cannot insist that you contact the business first.

    But stopping the payment does not, by itself, end the underlying contract. If you simply block the card, you may still legally owe the business money under the agreement you signed. That debt doesn’t disappear because the payment stopped landing.

    So the safer order of operations is:

    1. Understand what you actually agreed to.
    2. Cancel properly with the merchant, through their own cancellation process, wherever that’s possible.
    3. Keep the evidence — confirmation, reference number, date.
    4. Use your bank or card issuer to stop the payment as a safeguard — particularly if a business ignores a lawful cancellation and keeps charging you.

    LIMITATIONS

    A few things this audit doesn’t do, and shouldn’t be expected to do:

    • It won’t tell you your exact savings in advance. £168 a year is an average across cancelled unwanted contracts, not a promise about any individual household.
    • The 30-minute format is designed for discovery and triage; we have not independently tested a representative sample to establish a typical completion time.
    • It isn’t a reason to cancel things you rely on. Infrequently used insurance, breakdown cover, or emergency services aren’t “waste” just because you haven’t needed them recently — that’s what they’re for.
    • It doesn’t replace checking your own contract terms. Fixed-term agreements can carry real exit costs.

    A NOTE ON THE RULES CHANGING

    The law here is moving, but hasn’t moved yet. The Digital Markets, Competition and Consumers Act 2024 includes a dedicated subscription-contracts regime — covering clearer upfront information, renewal reminders, and easier online cancellation — but that regime is not yet in force. The UK Government announced on 9 August 2026 that it is bringing this forward, with commencement now expected in January 2027.

    Until then, your current rights sit under the Consumer Contracts Regulations 2013 (covering cancellation rights on many distance contracts) and the unfair-commercial-practices protections that have applied since 6 April 2025 under the Digital Markets, Competition and Consumers Act 2024. Your right to ask your card issuer to stop a recurring card payment, discussed above, is already in force under FCA rules.

    THE TAKEAWAY

    You don’t need to distrust every subscription you hold. Most people use most of what they pay for. The value here is narrower and more useful than that: thirty minutes, once every few months, to actually see what’s leaving your account — and to make a deliberate decision about each one, rather than a decision by default.

    Did the audit identify something you no longer wanted to pay for?

    And would you use a quarterly Verification Desk household audit covering subscriptions, digital accounts and recurring costs?

    Reply and tell us what you found. Your response will help determine whether we develop this into a regular Verification Desk feature.

    Evidence before certainty.


    The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. Findings are based on the evidence available at the date of publication and may be updated if material new evidence emerges. Nothing published should be taken as legal, financial or regulatory advice.

    Sources

    • Department for Business and Trade / BEIS — Implementation of the New Subscription Contracts Regime: Government Response to Consultation (April 2026) and Enhancing Consumer Rights: Policy Summary Brief (July 2023)
    • Citizens Advice — Consumers Spend £688 Million on Unused Subscriptions in the Last Year (March 2024)
    • Citizens Advice — Half a billion pounds spent on subscriptions that rolled over without people realising (December 2022)
    • Financial Conduct Authority — Recurring card payments: know your rights
    • Prime Minister’s Office / UK Government — “PM starts roll out of ‘everyday fixes’ on the cost of living – ending rip-off discounts and subscription traps” (9 August 2026)

    Free Subscription Audit Worksheet

    Copy this entry once for each subscription you find. There is no expected number — work through what you actually discover in the Find step.

    SUBSCRIPTION #____

    Service: ____________________________
    Category: ____________________________
    Cost: ____________________________
    Billing frequency: ____________________________
    Annualised cost: ____________________________
    Payment method: ____________________________
    Renewal / contract date: ____________________________
    Last used: ____________________________

    Decision: ☐ KEEP   ☐ REVIEW   ☐ CANCEL

    Bundle / shared account? ☐ Yes   ☐ No   ☐ Not sure
    Data or files to export first? ☐ Yes   ☐ No   ☐ Not sure

    Cancellation action: ____________________________
    Cancellation proof / reference: ____________________________
    Estimated annual amount removed: ____________________________
    Next review date: ____________________________
    Notes: ____________________________

    QUICK REFERENCE

    Weekly cost × 52 = annual cost
    Monthly cost × 12 = annual cost
    Quarterly cost × 4 = annual cost

    KEEP — clearly used and worth the cost.
    REVIEW — occasional use, upcoming renewal, recent price rise, or you are unsure.
    CANCEL — genuinely unwanted, forgotten or unused — after checking the contract first.

    BEFORE CANCELLING, CHECK:

    • Fixed term?
    • Notice period?
    • Early-termination charge?
    • Bundled with another service?
    • Shared with another household member?
    • Files, photos or data to export?
    • Legacy or discounted rate you would lose?
  • Can You Trust This Voice Note?

    Can You Trust This Voice Note?

    What a business can and cannot prove from executive audio

    A voice message arrives from a senior executive.

    It sounds right.

    The cadence is familiar. The accent is right. The phrasing feels plausible.

    The instruction is urgent: process a payment, change a bank detail, send credentials, call a new number.

    The natural reaction is to ask:

    Does this sound like them?

    That is now the wrong question.

    The better question is:

    What independent evidence proves that this message actually came from them?

    That distinction matters because synthetic voice technology has moved the problem from “spot the fake” to verify the identity.

    The FBI now explicitly warns that AI-generated voice messages are being used to impersonate trusted people, including senior officials, and says recipients should not assume a message is authentic simply because the voice appears familiar.

    The FTC gives similar advice to consumers: if a caller sounds like someone you know but asks for urgent money, do not trust the voice alone. Independently contact the person using a number you already know.

    This investigation asks a narrower professional question:

    Can a business reliably authenticate an executive voice note from the audio itself?

    CLAIM

    The claim under examination is simple:

    “This voice message was recorded by the executive whose voice it resembles.”

    That claim may feel persuasive.

    But resemblance is not authentication.

    A convincing recording tells us that the audio sounds like a person. It does not, by itself, establish who created it, when it was created, whether it was manipulated, or whether the message was sent by the person being imitated.

    EVIDENCE

    A typical suspicious voice message may provide several forms of evidence:

    • the audio itself;
    • the phone number or messaging account that delivered it;
    • file metadata;
    • the wording of the request;
    • timing and context;
    • previous communications;
    • the recipient’s familiarity with the speaker;
    • any related emails, invoices or approval messages.

    The mistake is to treat all of these as equal.

    They are not.

    The strongest evidence is usually independent provenance: a known communications channel, independently confirmed sender identity, authenticated account history, or a separate confirmation from the purported speaker.

    The weakest evidence is often the thing people instinctively trust most: the sound of the voice.

    That is no longer enough.

    TEST 1 — “It sounds exactly like them”

    The FBI says AI-generated content has advanced to the point that it can be difficult to identify and that cloned voices can sound nearly identical to the real person.

    The FTC has also warned that voice cloning can be created from short audio samples obtained from public material and used in fraud against families and small businesses.

    Voice similarity is an indicator of resemblance, not proof of identity.

    A familiar voice may increase plausibility.

    It does not independently authenticate the sender.

    Verification finding
    Verification grade: V4 — Inconclusive

    TEST 2 — Listen for glitches

    Public guidance often suggests listening for:

    • unnatural pauses;
    • odd rhythm;
    • robotic delivery;
    • pronunciation errors;
    • strange breathing;
    • latency;
    • unusual word choice.

    Those indicators may still be useful.

    But they are weak negative evidence.

    An obvious defect can increase suspicion.

    The absence of a defect does not establish authenticity.

    The FBI itself cautions that cloned voices may sound almost indistinguishable from legitimate speech.

    Detecting an artefact may help identify a suspicious recording. Failing to detect one does not prove the recording is genuine.

    Verification finding
    Verification grade: V3 — Indicative only

    TEST 3 — Check the phone number or messaging account

    This is stronger than listening to the voice, but still not decisive.

    Ask:

    • Is this the executive’s normal number?
    • Is the message from their established account?
    • Has the number changed recently?
    • Did the conversation begin through an unexpected channel?
    • Does the account history look normal?
    • Is there a sudden move from email to WhatsApp, Signal or another service?

    The FBI specifically recommends independently researching the originating number and then contacting the purported sender through a separately established channel.

    Even a familiar number is not absolute proof. Accounts can be compromised and caller identity can be spoofed.

    A recognised channel increases confidence but should not override unusual payment or access instructions.

    Verification finding
    Verification grade: V2–V3 depending on corroboration

    TEST 4 — Examine context

    Context is often more useful than audio analysis.

    Questions include:

    • Is the request normal for this executive?
    • Is the amount unusual?
    • Is there pressure to act immediately?
    • Is normal approval being bypassed?
    • Has confidentiality suddenly been requested?
    • Are bank details changing?
    • Is the sender discouraging independent confirmation?
    • Does the request fall outside normal hours or normal process?

    Fraudsters regularly use urgency, authority and secrecy because these reduce the chance that a recipient will independently verify the request.

    FTC guidance repeatedly highlights urgency and secrecy as warning signs in impersonation fraud.

    Context can materially increase or reduce risk, but still does not independently establish authorship.

    Verification finding
    Verification grade: V3 — Indicative

    TEST 5 — Independently contact the executive

    This is the decisive control.

    Do not reply using contact information supplied in the suspicious message.

    Do not call a number introduced in the same conversation.

    Instead:

    1. use a known internal directory;
    2. call an established number;
    3. contact an executive assistant;
    4. use an authenticated corporate messaging account;
    5. require a second authorised approver where money or sensitive access is involved.

    This is essentially the verification method recommended by both the FBI and FTC.

    Independent confirmation through a known channel can move the assessment from suspicion to reliable authentication.

    Verification finding
    Verification grade: V1 — Verified, if the confirmation process itself is robust.

    VERDICT

    Can you trust a voice note?

    Not on the basis of the voice alone.

    The audio may be genuine.

    It may be synthetic.

    It may be edited.

    It may be genuine audio delivered through a compromised account.

    Without independent corroboration, the recording should be treated as unverified.

    Our conclusion is therefore:

    A voice that sounds authentic should be treated as an identity claim, not as identity proof.

    That principle matters because the scale of AI-enabled fraud is no longer theoretical.

    The FBI’s 2025 Internet Crime Report recorded 22,364 complaints involving AI-related information and more than $893 million in adjusted losses. It specifically identified voice cloning as a tool used in business email compromise and distress scams.

    The FTC separately reported $3.5 billion in losses to impersonation scams in 2025, with business and government impersonation among the largest categories.

    Not all of those losses involved cloned audio.

    But they show why identity verification cannot depend on familiarity alone.

    ACTION

    The Verification Desk Executive Voice Protocol

    For any unexpected voice instruction involving money, credentials, bank details or sensitive information:

    1. Stop the transaction. Do not let urgency override verification.
    2. Preserve the message. Retain the original audio, sender details, timestamps and associated messages.
    3. Do not authenticate from voice similarity. “Sounds like them” is not sufficient.
    4. Examine the channel. Check whether the number or account is established and expected.
    5. Examine the request. Flag urgency, secrecy, unusual amounts, changed payment instructions or process bypass.
    6. Verify out-of-band. Contact the executive through an independently known corporate channel.
    7. Require dual approval for high-risk changes. Especially for bank-detail changes, new beneficiaries and high-value payments.
    8. Record the verification step. Document who confirmed, when, by which channel and what was confirmed.
    9. Escalate unresolved cases. If identity cannot be independently confirmed, the correct finding is: Inconclusive — do not act.

    Verification Desk finding

    Claim: The voice note came from the executive.
    Evidence: Voice similarity, sender channel and contextual indicators.
    Test: Provenance, channel history, contextual consistency and independent out-of-band confirmation.
    Verdict: V4 — Inconclusive until independently verified.
    Action: Do not authorise consequential action on voice evidence alone.


    Evidence before certainty

    The most important lesson is not that every suspicious recording is fake.

    It is that modern synthetic media has made familiarity a poor substitute for authentication.

    The correct professional response is not:

    “Can I hear anything wrong?”

    It is:

    “What evidence independently proves who sent this?”

    That is the standard The Verification Desk will apply.

  • Evidence Before Certainty

    Evidence Before Certainty

    We are entering a period in which seeing, hearing and reading something is no longer enough to establish that it is genuine.

    Synthetic voices can imitate executives. Deepfake video can simulate meetings. Fraudulent websites can reproduce brands convincingly. AI-generated documents can imitate internal approvals, invoices and correspondence. Public claims can spread faster than anyone verifies the evidence behind them.

    The Verification Desk exists to answer a simple question:

    What can actually be proved?

    We are not a scam-alert site.
    We are not a political fact-checker.
    We are not a cybersecurity news feed.

    We are an evidence-verification publication.

    Our work examines artefacts, claims, media, documents, websites and verification methods using a repeatable process:

    CLAIM → EVIDENCE → TEST → VERDICT → ACTION

    Claim — What exactly is being asserted?
    Evidence — What material actually supports that assertion?
    Test — What independent checks can be performed?
    Verdict — What does the evidence justify us concluding?
    Action — What should a professional or organisation do next?

    Just as importantly, we will say when the evidence does not permit a reliable conclusion.

    In verification work, “inconclusive” is not failure. It is often the most accurate finding available.

    The Verification Desk will grade conclusions according to evidential strength rather than tone or certainty:

    V1 — Verified
    Independently established from authoritative evidence.

    V2 — Strongly Supported
    Multiple reliable sources converge, with only limited uncertainty remaining.

    V3 — Indicative
    Credible indicators exist, but meaningful alternative explanations remain.

    V4 — Inconclusive
    The available evidence is insufficient to reach a reliable conclusion.

    V5 — Unsupported
    The claim lacks adequate supporting evidence.

    This distinction matters because confidence and evidence are not the same thing.

    A convincing voice is not proof of identity.
    A polished website is not proof of legitimacy.
    A screenshot is not proof of provenance.
    A widely repeated claim is not proof of accuracy.

    What we will investigate

    Our early work will focus on verification problems rather than alleged perpetrators.

    We will examine:

    • executive voice cloning and impersonation;
    • suspicious investment websites and online financial claims;
    • deepfake detection methods;
    • synthetic documents and manipulated media;
    • vendor and payment-verification controls;
    • digital-evidence provenance;
    • the limits of automated detection tools;
    • how organisations should make decisions when evidence is incomplete.

    The aim is not simply to publish interesting investigations.

    Each investigation should produce something useful: a checklist, protocol, scoring framework, verification workflow or evidence standard that professionals can apply themselves.

    Why The Verification Desk exists

    Fraud, synthetic media and digital deception are becoming easier to produce.

    Verification therefore has to become more disciplined.

    Our standard is straightforward:

    Show the evidence. Explain the test. State the uncertainty. Make the conclusion reproducible.

    That is the standard we intend to apply here.

    Our first investigation will ask:

    Can You Trust This Voice Note?

    We will test what businesses can—and cannot—reliably determine when faced with suspected AI-generated executive audio.

    Subscribe if you work in fraud, compliance, finance, law, investigation, risk, journalism—or simply believe that evidence should come before certainty.