← All terms

Voice Cloning

Voice cloning uses AI to replicate a person's voice from a short audio sample, letting attackers impersonate executives and colleagues over the phone.

Voice cloning is the use of AI speech-synthesis models to replicate a specific person's voice — tone, accent, pacing, and mannerisms — from a sample of recorded audio. What once required hours of studio-quality material now needs only seconds: McAfee's research found that some tools can produce a convincing match from as little as three seconds of audio. Since executives leave abundant voice samples in earnings calls, webinars, conference talks, and social media videos, nearly every senior leader is cloneable today.

How it works

The attacker gathers source audio from public appearances or even a recorded pretext call, feeds it to a commercial or open-source voice model, and can then generate arbitrary speech in the target's voice — either as pre-rendered clips or, increasingly, in real time during a live call. The clone is deployed where voice equals trust: a "CEO" phoning an accountant to authorize an urgent transfer, a "colleague" leaving a voicemail asking for credentials, or a caller verifying themselves to a help desk in the voice of the employee they are impersonating. Voice cloning supercharges vishing and CEO fraud because it removes the strongest authenticity signal a phone call ever had. In the 2024 Arup case, a finance employee was walked through 15 transfers totaling about $25.6 million after a video call with deepfaked colleagues.

How to defend against it

  • Never treat voice as authentication. Policy should state that no payment, credential reset, or data release is approved on the strength of a familiar voice alone — regardless of apparent urgency.
  • Verify out of band. Call the person back on a known number, or confirm through a separate channel. The FBI recommends agreeing on a shared secret word for high-risk verifications.
  • Train the scenario. Include cloned-voice pretexts in awareness exercises so employees rehearse polite refusal; our guide to deepfake voice attacks on finance teams covers the playbook in depth.
  • Protect the callback chain. Ensure help desks and finance teams have documented verification procedures that a stressed employee can follow without improvising.

Related terms

DeepfakeA deepfake is AI-generated synthetic media — audio, video, or images — used in social engineering to impersonate trusted individuals convincingly.VishingVishing (voice phishing) is a social engineering attack conducted over phone calls to manipulate victims into revealing sensitive information or taking harmful actions.CEO FraudCEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo