Smarter sites, safer businesses — no strings attached.
Short answer: Deepfake scams use AI to clone a real person's voice from public audio, then use it on an urgent call to talk someone into sending money or information. A familiar voice is no longer proof of who's calling, so hang up and call back on a number you already trust.
Invoice fraud and gift card scams both rely on someone believing a message really came from a person they trust. Deepfake scams are the same underlying trick, upgraded with one thing that makes it far more convincing: a voice — sometimes even a video — that sounds and looks exactly like that person, because AI made it that way.
AI voice-cloning tools can now produce a convincing fake of someone's voice from a surprisingly small amount of real audio — well under a minute, and by some current reports as little as a few seconds. That source audio doesn't require any special access: a voicemail greeting, a video posted on social media, a recorded webinar or conference talk, even a short reply in a public comments section can be enough. Anyone whose voice exists publicly online, in any form, has source material a scammer could use.
Once cloned, the fake voice gets used the same way the text-based version of this scam always has — an urgent, emotionally-charged call claiming to be a boss, a colleague, or a family member, asking for money, gift cards, or sensitive information right now, with a reason not to verify through normal channels ("I'm stuck in a meeting," "don't tell anyone yet"). The only thing that's changed is that it now arrives as a voice that sounds exactly right, instead of a text message that could be scrutinized for typos or a mismatched number.
Every scam covered so far in this series has had some detectable flaw for a careful person to catch — a mismatched link, a stolen password that still needs a second factor, an unfamiliar bank account. Deepfake scams remove one specific check that people have relied on their whole lives without thinking about it: recognizing a familiar voice. That's no longer reliable proof of anything, because the voice itself is exactly what got faked. Verifying "does this sound like them" doesn't help when sounding like them is the entire point.
(A composite, illustrative pattern — not one specific business's story.)
A business owner records a short welcome message for their company's phone system and posts a few marketing videos featuring their own voice online — completely ordinary things to do. Weeks later, an employee gets a phone call that sounds exactly like that owner: same voice, same cadence, audibly stressed, saying they're locked out of the business banking app during a time-sensitive payment and need the employee to send funds to a new account right away, with an apology for the odd request and a promise to explain later.
The employee, hearing a voice they recognize without any doubt, does it without a second thought — the entire point of hearing a familiar voice is that it normally ends the need to double-check. The real owner finds out only when the actual payment they were expecting never arrives, and confirms they never made that call at all.
A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.
"Malware" covers more than the one type everyone thinks of. What it actually is, the common ways it gets in, and the signs something is already there.
Security awarenessAll sectorsBoth the ransomware and malware posts named this as a common way in — what "unpatched" actually means, and why the update you keep postponing matters more than it seems.
Security awarenessAll sectorsThe classic warning is outdated for most browsing today, but one real risk hasn't gone away. What's actually changed, what still matters, and how to stay safe on public Wi-Fi.
Security awareness