Deepfake Voice Scam
The voice on the phone sounded exactly like the boss — because it was built to. One of the earliest documented AI voice-cloning frauds shows how convincing this attack already is.
The voice on the phone sounded exactly like his boss — same tone, same accent, same natural authority. Then came the instruction: move roughly €220,000 to a supplier's account, and do it now. Nothing about the call would have flagged it as fraudulent, because the voice on the line was not a live recording of a real person speaking in that moment — it was an AI-generated clone, built from a small sample of real audio, and criminals have already used this exact capability to carry out real financial fraud.
The attackers reportedly used recordings of the real executive's voice, likely gathered from public appearances, interviews, or internal recordings, to train a voice-cloning system capable of producing new speech in that same voice — speech the real executive never said. The cloned voice was convincing enough, combined with the pressure of an urgent, executive-level instruction, that the UK-based CEO carried out the transfer without the kind of hesitation a written email might have prompted.
What made this attack effective was not technical sophistication in the transfer itself — it was the combination of a highly convincing voice and a classic urgency-based social engineering script, the same pattern behind many far simpler scams, now made harder to doubt because it arrived in a familiar voice, live, on the phone.
Voice has long been treated as a reliable, almost instinctive way to verify identity, precisely because it used to be extremely hard to fake convincingly. That assumption is now outdated, and the tools required to clone a voice have become significantly more accessible since 2019, not less. A short public recording — a conference talk, a company video, a voicemail greeting, a social media clip — can be enough source material for a convincing clone.
This matters most in exactly the scenario the 2019 case illustrates: a request involving money, urgency, and a senior figure's authority, delivered live rather than in writing. Those three ingredients together are specifically designed to short-circuit the kind of careful verification that would normally catch a scam.
Since 2019, security researchers and law enforcement agencies have continued to report similar voice-cloning attempts, targeting both businesses and individual families, as the tools needed to clone a voice have become cheaper, faster, and easier to access than they were at the time of the original case. The core method has stayed the same — a short sample of real speech, a cloning tool, and a phone call built around urgency — even as the technology producing the voice itself has kept improving.
Do not rely on recognizing a cloned voice by ear alone. The real defense has everything to do with changing how urgent financial requests are verified, regardless of how convincing the voice sounds.
- Treat any urgent, unusual request for a money transfer as requiring independent verification, no matter how convincing or familiar the voice sounds.
- Verify through a separate channel you control — call back on a known number, or confirm in person — rather than continuing on the same call or thread that made the request.
- Establish a pre-agreed verification step for high-value transfers, such as a callback procedure or a second approver, so a single convincing phone call is never enough on its own.
Voice-cloning tools have only become more capable and more available since 2019, which is part of why this case is still cited as a baseline rather than an outlier. The German-UK call worked with 2019-era technology — nothing about the method requires anything more advanced than what is freely available now.
A practical reminder
The 2019 case succeeded because the target trusted the voice enough to skip a verification step he would likely have used for an unfamiliar request. The lesson is not to distrust every call — it is to verify every urgent transfer request the same way, regardless of who it appears to be from.
The Takeaways
Agree on a family or company code word in advance for any request involving money — one nobody could guess from public information.
Hang up and call back on a number you already have saved, never one given to you during the same call.
Slow down on purpose when a request feels urgent and involves money — the urgency is the actual attack, not the voice.
If you would like a visual explanation, continue with the accompanying CyberBlink video.
Deepfake Voice Scam: How AI Phone Calls Trick Families
How AI voice cloning enabled one of the earliest documented deepfake financial frauds, and the verification habit that would have stopped it.