AI Voice Cloning Scams: 5 Tips to Prevent Them

Sol Narosky

AI


Your accounts payable clerk picks up the phone. The voice sounds exactly like someone from your leadership team, urgent and rushed, asking for a wire transfer before a deal closes. That voice was never actually on the line. 

AI voice cloning tools can fool close colleagues convincingly. Before acting on any high-risk request, a money transfer, a credential reset, or an exception to your process, confirm it with a callback to a number you already trust. 

How accessible have AI voice cloning tools become for businesses?   

“Unfortunately,voice cloning technology has become very accessible,” says Dave Hatter, a cybersecurity and compliance consultant, speaker, and co-author of 12 books on technology.   

In a conversation with IPFone, he states that anyone with an internet connection can access AI-powered voice cloning tools: “A voice can be cloned in less than an hour using freely available online tools, and in some cases a voicemail greeting provides enough audio to create a convincing impersonation.” 

For small and mid-sized businesses (SMBs), a phone call, voicemail, or even a familiar voice can no longer be assumed authentic. Hatter warns that attackers can use cloned voices to impersonate executives, business owners, vendors, IT staff, or trusted partners in an attempt to:   

  • Authorize fraudulent wire transfers   
  • Change payment instructions  
  • Obtain sensitive information  
  • Reset passwords or MFA credentials  
  • Convince employees to bypass security procedures  

Because SMBs often have leaner staffs and less formal verification processes than large enterprises, they can be particularly vulnerable to social engineering attacks like this one. The good news is that awareness and simple verification procedures can dramatically reduce the risk.

What are 5 practical tips to prevent AI voice cloning scams?  

Hatter recommends five concrete steps.

1. Verify high-risk requests through a second channel, also known as going out-of-band  

Never rely solely on a phone call, voicemail, or voice message for requests involving money, credentials, sensitive information, or changes to established processes.    

If someone from your leadership team calls requesting an urgent wire transfer, hang up and call them back using a trusted number from your company directory. This “out-of-band” verification is one of the most effective defenses.   

2. Establish a shared secret or verification phrase

Create a pre-arranged code word, phrase, or challenge-response question known only to trusted employees and/or family members. Ferrari reportedly thwarted a suspected deepfake attack using a similar approach.¹ 

3. Train employees to be skeptical of urgency

Create a culture of security where it’s not only acceptable to slow down and to question things, it’s actually encouraged. Voice cloning scams are a dangerous new threat and almost always involve urgency, secrecy, or pressure.

Employees should be trained to recognize phrases such as:   

  • “I need this done immediately.”   
  • “Don’t tell anyone.”   
  • “We’re in a crisis.”   
  • “Just bypass the normal process this one time.”

The more emotional or urgent the request, the more important it is to verify independently. 

4. Reduce public exposure of executive voices

Podcasts, webinars, social media videos, interviews, and voicemail greetings can all provide audio samples for attackers.

While businesses can’t eliminate public exposure entirely, they should be mindful of how much executive audio is publicly available and avoid unnecessarily lengthy voice recordings to the extent possible. Pay special attention to people who are in the public eye extensively. 

5. Never use voice alone as an authentication factor

If a bank, vendor, or internal system allows voice-based authentication, treat it as insufficient on its own. Organizations should require multi-factor authentication (MFA), strong identity verification, and documented approval processes for sensitive actions. A familiar voice is no longer proof of identity, and out-of-band verification is essential.

A verification policy only works when it’s built into how calls actually get handled. IPFone helps SMB teams add that verification step to their call flow. Request a quote to talk through your setup.

Sources 

  1. “How Ferrari Hit the Brakes on a Deepfake CEO,” (2025). https://sloanreview.mit.edu/article/how-ferrari-hit-the-brakes-on-a-deepfake-ceo/

Sol Narosky is a journalist and content marketing specialist with over six years of experience covering technology, innovation, and emerging digital trends.