The phone rings and it's the owner. The voice is unmistakable: same tone, same way of getting to the point. There's an urgent favor: wire a payment to lock in a new supplier, or pull together some confidential client details, and do it now. It feels completely normal, so the person on the other end gets to work.
Except it isn't the owner. Every word and inflection has been faked by a scammer using AI, and a routine-feeling call has just turned into a wire transfer that's gone for good. This used to sound like science fiction. Today it's a real threat to ordinary businesses, and the tools to pull it off are cheap and easy to find. Here's how the scam works, and the simple habit that defeats it.
Why a familiar voice fools us
We've spent years training ourselves to spot a dodgy email: the misspelled web address, the odd grammar, the attachment we didn't ask for. What we've never trained ourselves to do is question the voice of someone we know and trust. That blind spot is exactly what these scams exploit.
The unsettling part is how little a scammer needs. A few seconds of someone's voice, lifted from a podcast, a webinar recording, a conference talk, or a social media clip, is enough. Feed that sample into a widely available AI tool, and the attacker can make the cloned voice say anything they type. No technical wizardry required; just a recording and a script.
The next step up from fake emails
For years the classic version of this was "business email compromise," a scammer getting into, or imitating, a real email account to trick someone into sending money or data. Those attacks still happen, but spam filters and email security have gotten good at catching them.
A phone call slips right past all of that. You can study an email's details before you reply. But when the boss is on the line sounding stressed and rushed, your instinct is to help, not to investigate. The industry calls the phone-based version "vishing," or voice phishing, and it works because it targets the human being directly, manufacturing urgency so the victim feels they have to act before they have time to think.
Why it works so well
These scams lean on simple human wiring. Most of us are conditioned to say yes to the person in charge, and few people feel they can push back on a direct request from a senior leader. Attackers know this, which is why the calls often land right before a weekend or holiday, when there's pressure to wrap things up and fewer colleagues around to sanity-check the request.
The AI can even fake emotion convincingly: frustration, stress, fatigue. That emotional charge is the part that short-circuits clear thinking, and it's the whole point of the attack.
You can't just "listen harder"
It's tempting to assume you'd catch a fake by ear. Don't count on it. There are occasional tells, like a slightly robotic edge on a complicated word, an odd pause, breathing that doesn't sound quite natural, strange background noise. But human ears are unreliable, and the technology keeps getting better at smoothing those flaws away. Relying on detection is a losing game. The real defense is a process, not a sharper ear.
Train your team for the threat that's actually out there
A lot of security training is still stuck on passwords and suspicious links. Those matter, but they're no longer the whole picture. Everyone needs to understand that caller ID can be faked and that a familiar voice is no longer proof of who's calling.
Good training today includes practice for voice scams, not just a slideshow, but realistic scenarios that test how people respond under pressure. It's especially important for anyone who can move money or touch sensitive data: finance, anyone with admin access to systems, HR, and the people who support your leadership.
The one habit that stops it: verify on a second channel
The single best defense is a firm rule that any voice request involving money or sensitive data must be confirmed a second way before anyone acts. Treat the phone call as a request, not an authorization.
In practice that's simple: if "the boss" calls asking for a wire transfer, the employee hangs up and calls back on the known internal number, or confirms over a trusted channel like Teams or a quick message. Some businesses go a step further with an agreed-upon code word that only the right people know: if the caller can't give it, the request is declined, no exceptions. The key is that this becomes the normal, expected step, so no one feels awkward slowing down to check.
Slow down: that's the whole trick
Scammers depend on speed and panic. The most effective counter is deliberately unglamorous: build small pauses and verification steps into how your business approves payments and shares data. A request that has to clear one extra check is a request a scammer can't rush through.
It's also worth thinking a step ahead. Voice is just the first wave; as these AI tools get better at faking video too, the same playbook will apply. A business that already has a "verify before you act" reflex is in far better shape for whatever comes next than one scrambling to invent the rule mid-incident.
Where to start
You don't need fancy technology to shut this down. You need clear rules and a team that knows them. Decide today how money and sensitive data get approved, write it down, and make second-channel verification the default. If you'd like help building those protocols so they protect you without bogging down day-to-day work, that's exactly what we do. Our guide to stopping account takeovers is a good companion read.