My boss is an AI, part two

Part one covered voice cloning and what it does to defences built on human vigilance. Part two follows the other channel: access to an executive’s mailbox, and the imitation of their writing style.
How an attacker reaches an executive’s mailbox
Through phishing, most of the time. An email that appears to come from a legitimate source leads the recipient to hand over a password. Once inside, the attacker holds something other than a mailbox: a corpus of text written by one specific person, over years.
That corpus trains a model
A language model learns to reproduce a way of writing from the text it is given. Turns of phrase, sentence length, opening and closing formulas, the degree of familiarity with each correspondent: all of it sits in the archived email.
The attacker then produces messages that read as though the executive wrote them. Criminals even have purpose-built tools, such as WormGPT, presented in the summer of 2023 as a model without guardrails, aimed among other things at wire fraud.
Why standard recommendations fall short
Security agencies recommend checking the sender’s address and treating unusual attachments with suspicion. That advice still holds, but it targeted an attacker who left traces in the text.
A message produced by a model trained on the executive’s own email carries no mistake, no awkwardness, no phrase foreign to their habits. It arrives from a legitimate address, since the mailbox is compromised. Looking for the anomaly means looking for precisely what the tool has learned not to produce.
Verify the person rather than the message
One element stays outside the attacker’s control: the requester themselves. Sealfie prompts the real decision-maker on their own phone at the moment of the request, cross-checks independent sources, and seals the result into a timestamped log.
The friction added is small, and it often replaces heavy procedures that are followed unevenly, particularly over holidays or under time pressure.
Measure your exposure
The BEC risk calculator estimates your company’s annual incident probability and expected loss in six questions. Published methodology, sourced coefficients, and no data leaves your browser.