By J. Mesa
Your phone rings. Your daughter is crying and says she caused a car accident. A man takes the phone and demands bail money. The voice was hers. The call was fake. Criminals now copy a voice from a short audio clip, and they aim the same trick at businesses: the “CEO” who calls accounting and orders an urgent wire.
What is AI voice cloning?
AI voice cloning uses software to copy a person’s voice from a recording. The criminal feeds a sample into a cloning tool, types a script, and the tool speaks the script in the copied voice. Some tools convert the criminal’s own speech in real time, so the fake voice can hold a conversation.
The tools cost little or nothing, and they need no technical skill.
How much audio does a scammer need?
A few seconds produces a rough copy. Thirty seconds to a minute produces a convincing one. Sources include:
- Videos on Facebook, Instagram, TikTok, and YouTube
- Podcast and webinar appearances
- Your voicemail greeting
- A recorded company video or radio advertisement
- A “wrong number” or survey call that keeps you talking
Business owners and executives leave the largest trail, because marketing puts their voices in public.
What is a deepfake?
A deepfake is audio, video, or an image that AI generated or altered to show a real person saying or doing something they did not say or do. Voice clones are audio deepfakes. Video deepfakes place a person’s face and voice on a live video call.
How do voice cloning scams work?
The family emergency scam. A caller in a loved one’s voice claims an accident, an arrest, or a kidnapping. A second voice, playing a lawyer or an officer, takes over and demands money by wire, gift card, crypto, or cash handed to a courier. The caller insists that you stay on the line and tell nobody.
The executive scam. An employee in finance receives a call or voicemail in the owner’s voice. The message cites a confidential deal and orders a wire today. Often an email arrives first, and the call “confirms” it. This is business email compromise with a voice added.
The vendor or bank scam. A caller who sounds like your account representative asks you to update payment details or read back a security code.
The help desk scam. A caller in an employee’s voice asks IT to reset a password or enroll a new phone for multi-factor authentication.
Has this happened to real companies?
Yes. In early 2024, a finance employee at the engineering firm Arup joined a video call with people who looked and sounded like the company’s chief financial officer and several colleagues. All of them were deepfakes. The employee sent about $25 million across multiple transfers. In 2019, criminals used a cloned voice of a parent company’s chief executive to talk a UK energy firm out of roughly $243,000.
Criminals have since moved down-market. A scheme that needed a specialist team in 2019 now needs a laptop, so small businesses and families receive the same calls.
How can I tell whether a voice is fake?
You often can’t, and that is the wrong test to rely on. Audio quality over a phone line hides the flaws, and the tools improve each month. Some clues still help:
- Flat emotion, odd pacing, or strange pauses before answers
- Background noise that cuts in and out
- Refusal to answer a personal question
- On video: unnatural blinking, lips out of step with the audio, blurring around the hairline, or a face that glitches when the person turns sideways or passes a hand in front of it
Judge the request, not the voice. Urgency, secrecy, and an unusual payment method mark a scam no matter who seems to be asking.
What is a family safe word?
A safe word is a word or phrase your family agrees on in person and uses to prove identity in an emergency. Pick something a stranger could not find online. Skip pet names, street names, and birthdays. Tell the children and the grandparents. When a frantic call arrives, ask for the word. A real family member knows it. A cloned voice does not.
No safe word yet? Ask a question only the real person can answer, or hang up and call the person’s own number.
How do I verify a caller at work?
Build verification into the process so no employee has to judge a voice.
- Call back on a known number. Hang up and dial the number already in your records. Never use a number the caller or the email supplies.
- Require two people. No single employee sends a wire, changes vendor bank details, or adds a payee alone.
- Use a second channel. Confirm a phone request through a different system, such as an internal chat message the requester must answer.
- Set a challenge phrase. Give the finance team and the owners a code phrase for payment requests, shared in person and changed on a schedule.
- Allow the delay. Tell staff in writing that nobody gets disciplined for pausing a payment to verify it, even when the request came from the owner.
- Lock down the help desk. Require a callback or a video check with a manager before resetting passwords or multi-factor devices.
Write these steps into a payment verification policy. A rule on paper protects the employee who has to say no to a voice that sounds like the boss.
How do I limit my exposure?
- Set personal social media accounts to private and trim old public videos.
- Replace a personal voicemail greeting with the carrier’s default.
- Let unknown calls go to voicemail. Answering and talking supplies a sample.
- Skip the “yes” trap. Do not answer questions from unknown callers.
- Review how much video and audio of owners and finance staff the company website needs.
You can’t remove every recording, and a business needs a public face. Verification protects you when exposure can’t be avoided.
What should I do if I get a suspicious call?
Hang up. Call the person back at the number you already have. If the caller claims a relative is under arrest or in a hospital, call the relative, then another family member. Do not send money, read codes, or share account details during the first call. A real emergency survives a five-minute check.
What if I already sent money?
- Call your bank at once and ask for a wire recall or a payment reversal.
- Report the gift card numbers to the card issuer.
- File a report at ic3.gov and ReportFraud.ftc.gov. For a business wire, mention the amount and the receiving bank, because the FBI can sometimes freeze funds reported within a few days.
- Tell your cyber insurance carrier.
- Tell your staff or your family what happened, so the next call fails.
Is voice cloning illegal?
Using a cloned voice to defraud someone is a crime under existing fraud laws. In February 2024, the Federal Communications Commission ruled that robocalls using AI-generated voices are illegal under the Telephone Consumer Protection Act. Laws slow nobody who operates from overseas, so your own verification steps matter more than the statute.
Should I train my staff on deepfakes?
Yes. Play examples of cloned voices during security awareness training, so staff hear how convincing they sound. Then run a drill: have someone call accounting with an urgent payment request and see whether the callback step happens. Praise the employee who refuses.
Your next step
Choose a family safe word tonight. Tomorrow, write a one-page rule that requires a callback and a second approver for payments and bank detail changes. Cerberus Cybersecurity writes these policies and trains teams to follow them. See our services or contact us.