AI voice, email and social impersonation being verified and contained by a security team
Verify → Contain → Preserve → Warn → ReportIn the first hour, coordinated action matters more than proving exactly which AI tool was used.

A familiar voice is no longer reliable proof of identity. AI can improve phishing emails, imitate an executive’s voice, produce a convincing video call or rapidly create fake business profiles. The surrounding request still reveals risk: urgency, secrecy, payment changes and pressure to bypass normal approval.

The response should focus on business impact. Confirm whether accounts are compromised, stop financial or customer harm, preserve useful evidence and communicate through trusted channels.

Warning signs that matter more than perfect fake detection

  • A payment destination, bank account, QR code or wallet address changes unexpectedly.
  • The sender asks staff to keep the request confidential or bypass a second approver.
  • A senior person supposedly contacts you from a new number, email domain or social account.
  • The message creates artificial urgency around payroll, tax, suppliers, investment or an emergency.
  • A customer-support profile asks people to continue in private messages or send credentials.
  • A login or document link uses a lookalike domain, shortened URL or unfamiliar file-sharing service.

Do not debate whether a voice or image “sounds AI-generated.” Verify the request using a known number, a separate channel and the organisation’s normal approval process.

The first 60 minutes

Minutes 0–10: verify and pause harm

Stop the requested payment, password reset, disclosure or account change. Contact the real person through a previously known number or internal channel. Notify the security or incident owner without forwarding a malicious attachment to more people.

Minutes 10–20: contain exposed accounts

If an employee clicked, signed in or shared a code, reset the affected account from a trusted device, revoke active sessions, review MFA methods, remove malicious forwarding rules and check administrator changes. Contact the bank or payment provider immediately if money moved.

Minutes 20–40: preserve evidence

Capture full URLs, screenshots, account handles, timestamps, message headers, phone numbers, payment details and the original files. Record who received the message and what actions they took. Avoid altering the only copy of evidence.

Minutes 40–60: coordinate warning and reporting

Use the verified website, official social accounts and known customer channels to warn affected people when the risk is credible. Report fake profiles through the platform process, contact hosting or domain providers when appropriate, and prepare a formal cybercrime complaint.

Evidence checklist for takedown and investigation

ChannelPreserveImmediate control
EmailOriginal message, full headers, links, attachment hashes, sender and reply-toBlock sender/domain, reset affected accounts, review forwarding rules
Social profileProfile URL, username, screenshots, messages, creation clues, victim reportsPlatform report, verified public warning, monitor new copies
Voice or videoNumber/account, recording if lawfully available, call time, request detailsVerify through known contact, pause payment or data release
Fake websiteFull URL, screenshots, page source if available, payment detailsNotify registrar/host, protect customers, block internally

Reporting cybercrime in Nepal

Nepal Police Cyber Bureau publishes complaint guidance for fake or hacked identities, online financial fraud and other cybercrime. Its reporting page identifies supporting information such as URLs and screenshots; organisations should follow the current instructions and use official documentation where requested.

For financial fraud, contact the relevant bank, wallet or payment provider immediately as well. Platform reporting and police reporting serve different purposes and can proceed in parallel.

Reduce the chance of the next impersonation succeeding

  1. Require independent approval: payment, payroll and bank-detail changes should never rely on one message or voice call.
  2. Use strong MFA: prioritise phishing-resistant options for email, cloud, domain and social administrators.
  3. Protect email identity: configure SPF, DKIM and DMARC, then monitor reports and move toward an enforcement policy safely.
  4. Control public information: understand which executive voices, videos, org charts and supplier relationships can help an attacker create context.
  5. Monitor brand exposure: look for fake domains, profiles, advertisements, apps and customer-support accounts.
  6. Practice the scenario: run a short exercise involving finance, leadership, communications, IT and customer support.

A professional customer warning

Communicate only confirmed facts: which channel is fake, what customers should avoid, which official channels are valid and where to report contact. Do not speculate publicly about the attacker or technology. Update the message when facts change.

A useful warning answers four questions:

What happened? Which account, domain or message is fraudulent? What should recipients do now? Where can they verify future communication?

Frequently asked questions

How can we detect an AI voice?

Voice artefacts are not dependable. Treat unusual urgency, secrecy and process bypass as risk signals, then verify through a known number or separate trusted channel.

What evidence should we save?

Preserve URLs, screenshots, account handles, message headers, phone numbers, timestamps, payment details and a timeline of actions.

Where do we report a fake Facebook page or cyber fraud in Nepal?

Use the platform’s reporting process and review the current complaint instructions on the Nepal Police Cyber Bureau website. Contact financial providers immediately if money is at risk.

Protect the identity customers recognise

Find impersonation early and coordinate a credible response.

Innomerc Tech supports authorised brand monitoring, dark web monitoring, threat intelligence and response preparation for organisations in Nepal and internationally.

Brand Monitoring Dark Web Monitoring Discuss Your Exposure