TechnologySeptember 16, 2026

Vishing with cloned voices: why recognizing who's calling proves nothing anymore

Three seconds of audio are enough to clone a voice. That turned vishing into one of the main entry vectors, and made the 'be wary if the voice sounds off' advice obsolete.

By id3a Team
Vishing with cloned voices: why recognizing who's calling proves nothing anymore

Vishing — phishing over the phone — had spent years being the least sophisticated version of fraud: someone impersonated your bank and trusted nerves to do the rest. The classic advice was to listen carefully, because the impostor didn't sound like who they claimed to be.

That advice doesn't hold anymore. Generative audio models need around three seconds of voice to reproduce it with high fidelity, and the tools have dropped in price down to free. Recognizing the voice of whoever's calling stopped being evidence of anything.

This is a fundamental shift, not a matter of degree

Vishing used to fail when the victim paid attention. Now paying attention doesn't help: the voice is right, the name is right, and so is the context, because it's pulled straight from your social media.

How far this has gone

In 2024, a multinational lost 25 million dollars after a video call in which several of the supposed participants were synthetic recreations of its executives. It wasn't a shady call someone picked up in a hurry: it was a meeting that looked normal.

In August 2026, Bloomberg reported coordinated intrusion attempts against major Wall Street asset managers using calls with cloned voices, aimed at getting credentials and access to internal systems.

And the vector grew enough to partially displace email as the initial access mechanism. That's what should catch a company's attention the most: the phone became an entry door again.

Where the audio comes from

You don't need to be recorded. Material that's already public is enough:

  • A social media story where you talk
  • A corporate video or a recorded talk
  • A podcast, a webinar, an interview
  • Your voicemail greeting
  • A short call in which the scammer only needs you to say "hello" a couple of times

The more exposed a person's voice is, the easier it is to clone — which puts managers, partners and spokespeople at the top of the list, precisely because they're the ones who authorize things.

The three scripts that work

1. The family emergency

A call with the voice of a child, a sibling or a parent urgently asking for money. It works because urgency shuts down verification, and because the voice removes the doubt that would normally slow things down.

2. The CEO fraud

A call or video call from an executive instructing a transfer outside the usual procedure, almost always with a reason that justifies skipping the process: a confidential deal, a closing that can't wait, a vendor that has to be paid today.

3. Tech support or the bank

The classic version, but now with the voice of the actual rep who helps you, and with real data about you obtained from an earlier breach.

What actually works

Everything that helps has one thing in common: it doesn't depend on recognizing the voice.

A shared codeword. Agree on a phrase with your family and your team that only you know and that isn't published anywhere. If the call is urgent and asks for money or access, ask for the phrase. It's the simplest countermeasure and the most effective one, because a model can clone the voice but doesn't know what was never written down.

Hang up and call back. Not the number that called: the number you already had saved. A scammer controls the channel they opened, not the one you open yourself.

A payment procedure that can't be skipped over the phone. If a transfer above a certain amount requires two approvals through a channel other than the phone, CEO fraud stops working — and that rule doesn't get negotiated no matter how urgent the call sounds. It's worth writing down before you need it, precisely because the attack arrives designed to make breaking it seem reasonable.

Verify through another channel. A message to the known number, an internal voice note, a question whose answer isn't on the internet.

For a company, specifically

Three things you can put in place this week:

  • Define who can authorize what, and through which channel. If it isn't written down, every urgent call becomes an improvised decision.
  • Tell the team the policy exists. The defense fails when whoever takes the call doesn't know they're allowed to say "I'll call you back."
  • Treat voice as public data. If someone in your organization has their voice recorded online — and almost everyone does — assume it's cloneable and design processes so that doesn't matter.

In short

Vishing stopped being an attack on attention and became an attack on trust. The defense is no longer listening more carefully: it's having procedures that don't depend on who seems to be talking.


This article was originally published in March 2024 and rewritten in September 2026, because voice cloning changed the attack enough that the earlier text was giving advice that no longer protects anyone.

Let's talk about your process security

Enjoyed this article?

Find out how we can help you bring these solutions into your business.