AI Voice Cloning and Deepfake Scams: Protecting Yourself From the Newest Fraud Tactic

For years, the advice to spot a scam call included listening for things that didn’t sound quite right — a stranger’s voice, an unfamiliar accent, hesitation. AI voice cloning technology has started to remove that safety net, making it possible to convincingly recreate a familiar voice from a very small amount of audio.

What the UK’s cyber security authority says

The National Cyber Security Centre (NCSC), the UK’s official authority on cyber threats, has flagged this directly as an emerging risk: “it’s possible that over the next few years, attackers may also make increasing use of voice clones or ‘deep fakes’ to trick users to reveal sensitive information.” This is a notable warning from the body responsible for advising the UK public and organisations on cyber threats, and reflects a shift from a theoretical risk to one worth actively preparing for.

A real example of the scale of the risk

This isn’t a hypothetical, distant threat. Fraudsters have already used an artificial intelligence voice clone of a senior executive at a European energy company to scam a UK subsidiary’s chief executive out of €220,000, with the UK-based target genuinely believing he was speaking with the head of his company’s parent firm. Separately, research published by Starling Bank found that 28% of UK adults believed they had been targeted by an AI voice-cloning scam attempt over a recent 12-month period — suggesting this has moved well beyond a rare, isolated tactic.

How these scams typically play out

The scenario that comes up repeatedly involves a call, voice note or voicemail that sounds exactly like someone you know — a family member, a colleague, or in business contexts, a senior figure at your company — making an urgent request, usually involving money or sensitive information, and creating pressure to act immediately without checking. The voice itself being convincing is precisely why these scams can succeed even against people who would normally be cautious about unexpected requests.

The core defence: verify through a separate channel

Because the voice itself can no longer be relied on as proof of identity, the practical defence has to shift to independent verification. Take Five to Stop Fraud’s broader guidance on suspicious requests applies directly here: “go directly to the organisation’s official website or app using details you trust” rather than acting on the contact details or channel the request arrived through, and “verify the request using contact details you found yourself.”

Applied to a voice-cloning scenario, this means: if you get an urgent call, voice message or voicemail from someone claiming to be a known contact asking for money or sensitive information, hang up or don’t act on it immediately, and instead call that person back on a number you already have saved and trust — not a number given to you during the suspicious call itself.

Practical steps to protect yourself and your family

  • Agree a family or workplace verification method in advance — a pre-agreed question, phrase or code word that only the real person would know, used to confirm identity for any urgent request involving money.
  • Always call back on a known number. Never rely on a number provided during the suspicious call or message itself.
  • Treat urgency itself as a red flag. Take Five’s core principle applies well beyond voice scams: “ask yourself, could it be fake? It’s ok to reject, refuse or ignore any requests.”
  • Be mindful of what you post publicly. Voice clips posted on social media, in videos or voicemail greetings can potentially be used as source material, so it’s worth being aware of this when deciding what to share publicly, particularly in a business or public-facing role.
  • Involve your bank directly for anything involving a payment. Banks are increasingly aware of this fraud type and can help verify or pause a suspicious transfer.

If you think you’ve been targeted

If you’ve already acted on a fraudulent request, contact your bank immediately, and report it to the police via reportfraud.police.uk or on 0300 123 2040. Acting quickly gives the best chance of stopping or reversing a payment before it’s completed.

Businesses face this risk too

While the family-targeted version of this scam gets the most public attention, businesses are a significant target as well, particularly through impersonation of senior executives calling finance or payments teams with an urgent request. Any workplace that regularly handles payments or sensitive transfers benefits from a simple rule: no payment or sensitive data request is actioned based on a phone call or voice message alone, regardless of how senior or urgent it sounds, without separate written confirmation through an established, trusted channel. This mirrors the family-level advice of always verifying through a separate, known channel, just applied at an organisational level.

Staying informed without becoming anxious

It’s worth keeping this threat in proportion. Voice cloning scams are a real and growing risk, but the core defence — pausing before acting on any urgent request, and verifying independently rather than through the channel the request arrived on — is the same basic principle that protects against most forms of impersonation fraud, voice-cloned or otherwise. You don’t need to treat every phone call from a loved one with suspicion; you simply need a shared, agreed way of confirming identity for anything involving money or sensitive information, used consistently regardless of how convincing a call sounds.

Sources