Skip to main content

We use Google Analytics on Knowledge Center pages to understand aggregate readership. No account, session, or security-tool data is included. See our Privacy Policy.

CyberBlink AIEvidence. Clarity. Confidence.
Verified Incident

Deepfake Voice Scam

The voice on the phone sounded exactly like the boss — because it was built to. One of the earliest documented AI voice-cloning frauds shows how convincing this attack already is.

The voice on the phone sounded exactly like his boss — same tone, same accent, same natural authority. Then came the instruction: move roughly €220,000 to a supplier's account, and do it now. Nothing about the call would have flagged it as fraudulent, because the voice on the line was not a live recording of a real person speaking in that moment — it was an AI-generated clone, built from a small sample of real audio, and criminals have already used this exact capability to carry out real financial fraud.

EVIDENCEThe Wall Street Journal reported, citing Rüdiger Kirsch, a fraud expert at the German parent company's insurer, Euler Hermes Group SA, that in March 2019 criminals used AI-generated voice-cloning technology to impersonate the chief executive of the German parent company in a phone call to the CEO of its UK-based subsidiary. Believing he was speaking with his own superior, the UK executive followed an urgent instruction to transfer roughly €220,000 (about $243,000) to what he was told was a Hungarian supplier's account. The funds were moved on again within hours and were never recovered. Neither company was ever publicly named. The case is widely described as one of the first publicly documented instances of AI voice-cloning used to carry out financial fraud — not confirmed as the very first, but among the earliest on record.
Illustrative reconstruction — the voice was real, the person on the other end was not
01The Investigation

The attackers reportedly used recordings of the real executive's voice, likely gathered from public appearances, interviews, or internal recordings, to train a voice-cloning system capable of producing new speech in that same voice — speech the real executive never said. The cloned voice was convincing enough, combined with the pressure of an urgent, executive-level instruction, that the UK-based CEO carried out the transfer without the kind of hesitation a written email might have prompted.

What made this attack effective was not technical sophistication in the transfer itself — it was the combination of a highly convincing voice and a classic urgency-based social engineering script, the same pattern behind many far simpler scams, now made harder to doubt because it arrived in a familiar voice, live, on the phone.

Illustrative reconstruction — tone, accent, and speech pattern, all recreated from a short sample
02The Evidence

Voice has long been treated as a reliable, almost instinctive way to verify identity, precisely because it used to be extremely hard to fake convincingly. That assumption is now outdated, and the tools required to clone a voice have become significantly more accessible since 2019, not less. A short public recording — a conference talk, a company video, a voicemail greeting, a social media clip — can be enough source material for a convincing clone.

This matters most in exactly the scenario the 2019 case illustrates: a request involving money, urgency, and a senior figure's authority, delivered live rather than in writing. Those three ingredients together are specifically designed to short-circuit the kind of careful verification that would normally catch a scam.

Since 2019, security researchers and law enforcement agencies have continued to report similar voice-cloning attempts, targeting both businesses and individual families, as the tools needed to clone a voice have become cheaper, faster, and easier to access than they were at the time of the original case. The core method has stayed the same — a short sample of real speech, a cloning tool, and a phone call built around urgency — even as the technology producing the voice itself has kept improving.

Illustrative reconstruction — verified through a separate, trusted channel, not the same call
03The Protection

Do not rely on recognizing a cloned voice by ear alone. The real defense has everything to do with changing how urgent financial requests are verified, regardless of how convincing the voice sounds.

  • Treat any urgent, unusual request for a money transfer as requiring independent verification, no matter how convincing or familiar the voice sounds.
  • Verify through a separate channel you control — call back on a known number, or confirm in person — rather than continuing on the same call or thread that made the request.
  • Establish a pre-agreed verification step for high-value transfers, such as a callback procedure or a second approver, so a single convincing phone call is never enough on its own.

Voice-cloning tools have only become more capable and more available since 2019, which is part of why this case is still cited as a baseline rather than an outlier. The German-UK call worked with 2019-era technology — nothing about the method requires anything more advanced than what is freely available now.

A practical reminder

The 2019 case succeeded because the target trusted the voice enough to skip a verification step he would likely have used for an unfamiliar request. The lesson is not to distrust every call — it is to verify every urgent transfer request the same way, regardless of who it appears to be from.

Protection

The Takeaways

  1. Agree on a family or company code word in advance for any request involving money — one nobody could guess from public information.

  2. Hang up and call back on a number you already have saved, never one given to you during the same call.

  3. Slow down on purpose when a request feels urgent and involves money — the urgency is the actual attack, not the voice.

Companion Video

If you would like a visual explanation, continue with the accompanying CyberBlink video.

An incoming call screen labeled Managing Director beside a pinned transcript fragment requesting an urgent transfer

Deepfake Voice Scam: How AI Phone Calls Trick Families

How AI voice cloning enabled one of the earliest documented deepfake financial frauds, and the verification habit that would have stopped it.

Now availableWatch on YouTube