You get a call from your managing director. You know that voice – you’ve heard it in a hundred meetings. He’s on the road, something urgent has come up with a supplier, and he needs a payment sent within the hour. It sounds exactly like him: the same accent, the same pace, even that little pause before he says your name.
Except it isn’t him at all.
This is not a hypothetical. In 2019, the CEO of a UK-based energy firm was tricked into transferring 220,000 euros after receiving a call he believed was from the chief executive of the firm’s German parent company. The voice on the line had been generated using AI, convincing enough that the CEO recognised what he thought was his boss’s subtle accent and familiar speech pattern. It was widely reported as one of the first known cases of AI voice cloning being used to commit fraud. Six years on, the technology behind it has become dramatically more accessible – and considerably harder to spot.
How Voice Cloning Fraud Actually Works
Modern AI voice cloning tools need remarkably little to work with. A short clip from a company podcast, a conference talk uploaded to YouTube, a LinkedIn video, or even a voicemail greeting can be enough raw material to build a convincing synthetic version of someone’s voice. Once trained, that voice can be made to say almost anything, in real time, over a phone call.
For a small or medium-sized business, the appeal to a fraudster is obvious. Directors and senior staff are often the most publicly visible people in the company – featured in webinars, podcast interviews, award ceremony clips, or promotional videos on the company website. All of it is freely available, and all of it is potential training data.
The scam itself usually follows a familiar shape, borrowed from traditional Business Email Compromise: urgency, authority and isolation. A voice that sounds like your boss, your finance director, or a trusted supplier contact calls (or leaves a voice note) asking for a payment to be made quickly, often outside normal channels, and often framed as confidential or time-sensitive. The pressure is designed to short-circuit the normal instinct to double-check.
Why This Matters More for SMEs, Not Less
It’s tempting to assume this kind of attack is reserved for large corporates with deep pockets and a media profile to exploit. In reality, smaller businesses are often easier targets. Fewer layers of financial sign-off mean a single convincing call can be enough to authorise a transfer. Close-knit teams mean staff are used to acting quickly on a director’s instruction without a formal paper trail. And many SMEs simply haven’t updated their fraud awareness training to account for the fact that a familiar voice on the phone is no longer proof of anything.
The financial impact of a successful attack can be significant, but the fallout doesn’t stop there. Recovering funds sent to fraudulent accounts is notoriously difficult once money has moved between jurisdictions, and the incident can shake staff confidence in verbal instructions and phone-based processes for months afterwards.
What Businesses Can Do About It
The good news is that defending against voice cloning fraud doesn’t require exotic technology. It requires a shift in mindset: treating an unexpected, urgent financial request as suspicious by default, regardless of how convincing the voice sounds.
A simple, agreed verification step – such as always confirming payment instructions through a second channel, or calling back on a known number rather than continuing the original call – closes off most of these attacks before they succeed. Some businesses go further and set up a private verification phrase for high-value transactions, something a cloned voice couldn’t possibly know.
Staff awareness plays an equally important role. Finance teams and anyone with payment authority should understand that voice cloning exists, how convincing it can be, and that urgency and secrecy are red flags rather than reasons to act faster. It’s also worth thinking carefully about how much video and audio content featuring senior staff is publicly available, without going so far as to hide behind closed doors entirely.
Ultimately, this is a people-and-process problem as much as a technology one. No amount of spam filtering or antivirus software will catch a phone call. What catches it is a culture where “let me just check that” is normal, expected, and never seen as a lack of trust.
If your business doesn’t currently have a clear verification process for payment requests, now is a sensible time to put one in place – before a very convincing voice on the other end of the line makes the decision for you.
Worried your current security measures wouldn’t catch a scam like this? Get in touch with our IT Security team to find out how we can help protect your business.

