Cys Infotech

Smarter sites, safer businesses — no strings attached.

Home / Blog

What Are Deepfake Scams, and How Do They Actually Work?

Short answer: Deepfake scams use AI to clone a real person's voice from public audio, then use it on an urgent call to talk someone into sending money or information. A familiar voice is no longer proof of who's calling, so hang up and call back on a number you already trust.

Invoice fraud and gift card scams both rely on someone believing a message really came from a person they trust. Deepfake scams are the same underlying trick, upgraded with one thing that makes it far more convincing: a voice — sometimes even a video — that sounds and looks exactly like that person, because AI made it that way.

What's actually happening

AI voice-cloning tools can now produce a convincing fake of someone's voice from a surprisingly small amount of real audio — well under a minute, and by some current reports as little as a few seconds. That source audio doesn't require any special access: a voicemail greeting, a video posted on social media, a recorded webinar or conference talk, even a short reply in a public comments section can be enough. Anyone whose voice exists publicly online, in any form, has source material a scammer could use.

Once cloned, the fake voice gets used the same way the text-based version of this scam always has — an urgent, emotionally-charged call claiming to be a boss, a colleague, or a family member, asking for money, gift cards, or sensitive information right now, with a reason not to verify through normal channels ("I'm stuck in a meeting," "don't tell anyone yet"). The only thing that's changed is that it now arrives as a voice that sounds exactly right, instead of a text message that could be scrutinized for typos or a mismatched number.

Why "I recognized the voice" doesn't work anymore

Every scam covered so far in this series has had some detectable flaw for a careful person to catch — a mismatched link, a stolen password that still needs a second factor, an unfamiliar bank account. Deepfake scams remove one specific check that people have relied on their whole lives without thinking about it: recognizing a familiar voice. That's no longer reliable proof of anything, because the voice itself is exactly what got faked. Verifying "does this sound like them" doesn't help when sounding like them is the entire point.

Hearing the right voice proves nothing anymore — call back on a number you already trust

A local business scenario

(A composite, illustrative pattern — not one specific business's story.)

A business owner records a short welcome message for their company's phone system and posts a few marketing videos featuring their own voice online — completely ordinary things to do. Weeks later, an employee gets a phone call that sounds exactly like that owner: same voice, same cadence, audibly stressed, saying they're locked out of the business banking app during a time-sensitive payment and need the employee to send funds to a new account right away, with an apology for the odd request and a promise to explain later.

The employee, hearing a voice they recognize without any doubt, does it without a second thought — the entire point of hearing a familiar voice is that it normally ends the need to double-check. The real owner finds out only when the actual payment they were expecting never arrives, and confirms they never made that call at all.

Best practices

  1. Stop treating a familiar voice alone as proof of identity, no matter how certain it sounds — this is the one habit this whole post is asking you to update.
  2. Hang up and call back on a number you already have on file. Never continue on the same call, and never use a number given to you during it — call a number you already trusted before this call started.
  3. Set up a shared verification phrase with close family or key employees for exactly this situation — something a cloned voice reading from a script has no way to know, following the FBI's own recommendation on this.
  4. Stay suspicious of urgency and secrecy over the phone, regardless of how convincing the voice is — that emotional pressure is the same playbook as every other scam in this series; only the voice technology is new.
  5. Be mindful of how much of your own voice is easily accessible publicly where you have a choice — a long, detailed voicemail greeting or an easily found recording is source material. This isn't about never speaking publicly, just being aware public audio and video are a real source for this.

Helpful, free resources

A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.