Voice and deepfake

Vishing vs voice cloning: what is the difference?

Vishing is the attack: a fraudulent phone call intended to extract credentials, access or a payment. Voice cloning is a tool that can be used inside it. Most vishing involves no cloning at all, just a confident human with good research.

Conflating the two leads to the wrong defence. If staff believe vishing means synthetic audio, they will trust a live caller who simply sounds normal, which is how the largest breaches in this library actually happened.

Documented cases

  • No cloning needed: MGM Resorts was breached by a ten-minute call from a real person to the help desk.
  • Also no cloning: Clorox and Cognizant show the same help-desk pretext pattern.
  • Cloning used: a UK energy firm lost about EUR 220,000 to a synthesised executive voice.

The control that breaks it

  • Train on the request, not the voice. An unusual ask is the signal, whoever appears to be making it.
  • Harden the help desk: no credential or MFA reset on a call alone.
  • Use callbacks on stored numbers, which defeat both variants identically.

Related: how to prevent vishing · deepfake vs voice cloning · Vishing