Attack Techniques

Voice cloning

A synthetic copy of a real voice, used to make a request sound authorised.

Voice cloning produces a synthetic copy of a real person’s speech from a short sample of their recorded audio. In fraud it is used to make an instruction sound as though it came from someone the victim knows, which removes the reassurance a phone call used to provide.

This library records 5 cases. The earliest is from 2019, and the technique has moved from novelty to routine within that period.

How the attack runs

  1. Sample collection. Public audio is usually sufficient: interviews, earnings calls, conference recordings, social video.
  2. Model training. Modern tools need only a short sample to produce convincing speech.
  3. A pretext is set up first, often by text or email, so the call confirms an existing story rather than introducing one.
  4. The call is made, typically short, with limited interaction to reduce the chance of a slip.
  5. The instruction is acted on because the voice was recognised.

Documented cases

  • Arup (2024, $25.6M): an employee joined a video call populated by a deepfaked finance chief and several deepfaked colleagues, then executed 15 transfers.
  • Retool (2023, about $15M): a text message followed by a call using a cloned colleague’s voice obtained MFA codes.
  • A deepfake Zoom call impersonating Singapore’s prime minister (2026) cost victims about S$4.9M.
  • A UK energy firm (2019): one of the first documented uses of a cloned executive voice to authorise a transfer.
  • WPP (2024): an attempt using a cloned chief executive on Teams that failed, which makes it the most instructive case here.

How it differs from related techniques

Deepfake and synthetic media is the parent category. Synthetic identity fabricates a person who does not exist, whereas cloning imitates someone real. Vishing is the delivery channel, and cloning is what now makes it credible.

The control that would have stopped it

  • A recognised voice is no longer proof of identity. This is the single most important change in practice.
  • Out-of-band callback on a known number for any financial instruction, regardless of how the request arrived.
  • A live challenge: an unexpected question, or a request to perform an action a prepared clone cannot handle. This is what protected WPP.
  • Watch for passivity. Hong Kong Police noted the fake Arup participants barely interacted, which is a practical detection cue on group calls.
  • Dual authorisation and per-transaction caps, so that a single convinced employee cannot complete the transfer alone.
Explore more

Related techniques and attack types

Parent attack type