Vishing is the attack: a fraudulent phone call intended to extract credentials, access or a payment. Voice cloning is a tool that can be used inside it. Most vishing involves no cloning at all, just a confident human with good research.
Conflating the two leads to the wrong defence. If staff believe vishing means synthetic audio, they will trust a live caller who simply sounds normal, which is how the largest breaches in this library actually happened.
Documented cases
- No cloning needed: MGM Resorts was breached by a ten-minute call from a real person to the help desk.
- Also no cloning: Clorox and Cognizant show the same help-desk pretext pattern.
- Cloning used: a UK energy firm lost about EUR 220,000 to a synthesised executive voice.
The control that breaks it
- Train on the request, not the voice. An unusual ask is the signal, whoever appears to be making it.
- Harden the help desk: no credential or MFA reset on a call alone.
- Use callbacks on stored numbers, which defeat both variants identically.
Related: how to prevent vishing · deepfake vs voice cloning · Vishing
Related