Report Targeted Synthetic Media Impersonation Attack - Corporate Finance & Communications

1. Section 1: Target Executive & Reporting Employee Profile - Establishing the identities and context of the attack targets

This section captures critical information about the targeted executive and the employee reporting this incident. Accurate details are essential for forensic analysis and organizational response. All fields marked mandatory must be completed to ensure proper case documentation.

 

Targeted Executive's Full Name

Targeted Executive's Official Title/Role

Targeted Executive's Department/Division

Targeted Executive's Primary Office Location

Targeted Executive's Corporate Email Address

Targeted Executive's Official Corporate Phone Number

How many years has the targeted executive been with the organization?

What is the level of the targeted executive's public digital presence? (Select all that apply)

Is the executive's authentic voice publicly available through official channels (e.g., earnings calls, recorded presentations, podcasts)?

 

Specify where the authentic voice can be found (provide URLs or descriptions):

Does the executive regularly use voice or video calls for business communications?

 

Which platforms are routinely used? (Select all that apply)

Describe the executive's typical communication style or known phrases that colleagues would recognize:

 

Now please provide your details as the reporting employee:

 

Reporting Employee's Full Name

Reporting Employee's Official Title/Role

Reporting Employee's Department/Division

What is your professional relationship to the targeted executive?

Reporting Employee's Corporate Email Address

Reporting Employee's Official Employee ID Number

How many years have you been with the organization?

Have you completed the organization's security awareness training within the last 12 months?

 

Date of most recent training completion:

 

Explain why training was not completed:

How familiar are you with the targeted executive's authentic voice and communication patterns?

Your location (city/country) at the time of the incident:

2. Section 2: Incident Channel & Technical Transmission Details - Documenting the attack vector and technical characteristics

Preserve all technical evidence before completing this section. Do not delete any recordings, emails, or logs. This information is crucial for digital forensics and potential law enforcement involvement.

 

Exact date and time when the incident communication began

Exact date and time when the incident communication ended (if applicable)

Your timezone at the time of incident

Was the impersonation communication delivered live in real-time or as a recorded message?

What was the primary communication channel used for the attack?

 

What caller ID or phone number was displayed? (exactly as shown)

 

What mobile number was displayed? (exactly as shown)

 

Which video conferencing platform was used?

 

Which messaging app was used?

 

What was the sender's email address?

Did the displayed phone number, email address, or user ID appear to be the executive's authentic corporate contact information?

 

Explain why the spoofed credentials appeared authentic (e.g., matched internal directory, previous correspondence):

 

Describe the discrepancies you noticed (e.g., slight spelling difference, unknown number):

Do you suspect the communication was transmitted using caller ID spoofing, email spoofing, or similar identity falsification techniques?

Provide any technical identifiers available (IP addresses, email headers, message IDs, server logs, etc.):

Device used to receive the communication (your device)

Network environment when incident was received

Was the communication recorded by you or your organization?

 

Upload the recorded file (audio, video, or voicemail file):

Choose a file or drop it here
 

Upload screenshots of call logs, messaging interface, email headers, or any visual evidence:

Choose a file or drop it here

Duration of the communication in minutes (if applicable):

Rate the overall audio quality of the impersonation (1 star = very poor quality, 5 stars = excellent quality, indistinguishable)

Rate the technical quality of specific characteristics of the impersonation:

Very Poor

Poor

Neutral

Good

Excellent

Voice tone and pitch accuracy

Speech pattern and cadence

Accent or dialect replication

Background noise authenticity

Audio clarity and lack of artifacts

Video lip-sync accuracy (if video)

Did you notice any audio artifacts, robotic sounds, unnatural pauses, or other anomalies suggesting synthetic generation?

For video calls: Were there noticeable lip-sync issues, facial rendering anomalies, or unusual eye movements?

Did the attacker attempt to use screen sharing, file transfer, or other collaboration features?

3. Section 3: Impersonation Tactics & Fraudulent Instructions Analysis - Deconstructing the social engineering and fraudulent requests

Provide as much detail as possible about the conversation content, the attacker's requests, and any social engineering tactics employed. Your detailed recollection is vital for understanding the attack methodology.

 

Summarize the pretext or storyline the attacker used to justify the communication:

What specific fraudulent instruction(s) were you given? (Select all that apply)

 

Provide details of each wire transfer or payment request:

Requested Amount

Currency

Destination Account/Beneficiary

Bank Name or Payment System

Purported Reason

Marked as Urgent?

A
B
C
D
E
F
1
 
 
 
 
 
 
2
 
 
 
 
 
 
3
 
 
 
 
 
 
4
 
 
 
 
 
 
5
 
 
 
 
 
 
6
 
 
 
 
 
 
7
 
 
 
 
 
 
8
 
 
 
 
 
 
9
 
 
 
 
 
 
10
 
 
 
 
 
 

What type of confidential data was requested? (Select all that apply)

 

Describe what credentials or access was requested:

 

Which approval procedures were you instructed to bypass and how?

 

Describe the emergency meeting arrangement request (who, when, why):

Total financial amount requested across all instructions:

What social engineering tactics were employed to create urgency or pressure? (Select all that apply)

Did the attacker demonstrate specific knowledge of internal company processes, projects, or organizational structure?

 

Detail the specific insider knowledge revealed (e.g., names of real colleagues, current projects, internal systems):

Did the attacker reference specific names of real colleagues, assistants, or board members?

Was there any follow-up communication from the attacker after the initial contact?

Did the attacker explicitly instruct you to maintain secrecy or not verify the request through other channels?

 

What specific language was used to prevent verification?

List any suspicious phrases, unusual word choices, or language patterns that raised concerns:

Did the attacker claim the executive was in a situation where they were unavailable for normal verification (e.g., traveling, in secure meetings, device issues)?

Describe any background noises that seemed inconsistent with the claimed location (e.g., office sounds when claiming to be traveling):

What red flags or suspicious indicators did you notice during the interaction?

4. Section 4: Immediate Financial & Security Countermeasures Executed - Documenting response actions and containment measures

Detail all immediate actions taken from the moment of initial contact through to this report. Precise timeline information is critical for incident response and potential recovery efforts.

 

Were any financial transactions partially or fully executed before the impersonation was detected?

 

Provide transaction details:

Transaction Amount

Currency

Transaction Initiation Time

Transaction Status

Destination

Funds Recovered?

A
B
C
D
E
F
1
 
 
 
 
 
 
2
 
 
 
 
 
 
3
 
 
 
 
 
 
4
 
 
 
 
 
 
5
 
 
 
 
 
 
6
 
 
 
 
 
 
7
 
 
 
 
 
 
8
 
 
 
 
 
 
9
 
 
 
 
 
 
10
 
 
 
 
 
 

Was any sensitive corporate data or documents transmitted to the attacker?

 

Describe what data was shared and the potential sensitivity level:

Were any system credentials, or access tokens compromised or shared?

 

Specify what credentials were involved and immediate remediation taken:

What immediate IT security countermeasures were executed? (Select all that apply)

Which internal stakeholders were notified and when? (Select all that apply)

Which external parties were notified? (Select all that apply)

Has a formal incident response case number or ticket been created?

 

Provide the case number:

Timeline of key response actions (complete as precisely as possible):

Action Timestamp

Action Taken

Person/Team Responsible

Outcome/Status

A
B
C
D
1
 
 
 
 
2
 
 
 
 
3
 
 
 
 
4
 
 
 
 
5
 
 
 
 
6
 
 
 
 
7
 
 
 
 
8
 
 
 
 
9
 
 
 
 
10
 
 
 
 

Did you terminate or disconnect the communication with the attacker?

 

How many minutes elapsed from start of communication to disconnection?

Describe any additional preventive controls or monitoring implemented after the incident was detected:

Estimated total time in minutes from initial incident contact to this formal report submission:

5. Section 5: Enterprise Risk & Legal Counsel Authorization - Assessing organizational impact and authorizing investigative actions

This final section assesses the broader enterprise risk implications and establishes proper authorization for investigative activities. Information provided here may be subject to legal privilege and should be completed in consultation with legal counsel where appropriate.

 

Estimated maximum potential financial loss exposure from this incident (if transaction had succeeded):

Rate the potential reputational risk to the organization if this incident became public (1 = minimal impact, 10 = catastrophic reputational damage)

Which regulatory frameworks or compliance regimes could be implicated by this incident? (Select all that apply)

What is the highest data classification level of any information potentially compromised or requested?

Does this incident appear to be part of a coordinated campaign targeting multiple executives or organizations?

 

Provide reasoning and any evidence of broader campaign indicators:

Has internal or external legal counsel been formally engaged regarding this incident?

 

Name of legal counsel or firm engaged:

Could this incident trigger coverage under a cyber insurance, crime insurance, or professional liability policy?

 

Specify policy types and notification status:

Is regulatory notification to authorities required or being considered?

 

Specify which authorities and timeline requirements:

What is the required confidentiality level for handling this incident?

I authorize the organization's Information Security and Incident Response teams to investigate this incident, including forensic analysis of all related systems and communications.

I authorize engagement with external forensic investigation firms if deemed necessary by security leadership.

I authorize notification and cooperation with law enforcement agencies if deemed appropriate by legal counsel.

Preferred method for receiving incident updates and follow-up actions:

Additional comments, observations, or recommendations for enterprise-wide prevention:

Upload any additional supporting documents, threat intelligence, or evidence files not previously attached:

Choose a file or drop it here
 

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.