Back to Blog
Emerging Threats
4 min read

Deepfake Voice Fraud: Defending Approvals Against a Convincing Call

Voice cloning removed the last reason to trust a familiar voice. The process changes that work, and the awareness training that does not.

GuardsArm Team

Security Experts

September 25, 2026

Deepfake voice fraud and vishing defence

Voice cloning is now good enough, cheap enough and fast enough that a familiar voice on a phone call is no longer evidence of identity. A short sample from a conference talk, a podcast, a voicemail greeting or a social video is sufficient.

This does not create a new attack. It removes the friction from an old one. Pretexting over the phone has always worked; sounding exactly like the chief financial officer makes it work far more often.

Not a new attack
An old one with the friction removed
Help desk is the target
An MFA reset turns a call into access
Detection is the wrong answer
The weakness is process, not audio

Where it is used

Payment fraud. A call to finance, apparently from an executive, authorising or urging an urgent transfer — often reinforcing an email already sent, which is what makes it persuasive. The voice resolves the doubt the email created.

Help desk compromise. A call to IT support, apparently from an employee, requesting an MFA reset or a new device enrolment. This is currently the most damaging variant, because it converts a phone call directly into authenticated access.

Vendor and payment detail changes, confirmed by a voice call that was supposed to be the verification step.

Family emergency scams against individuals, including your executives, which matter because a distressed executive is more susceptible to the next workplace approach.


Why detection is not the answer

Stop training staff to listen for the fake
Advice to listen for flat intonation or odd pauses describes a generation of the technology that has passed. It teaches an unreliable detection method and builds false confidence. Train the verification procedure instead, which works regardless of how convincing the voice is.

Detection tools exist and improve, and so does generation. Relying on a detector creates a system that fails the moment the technology moves, and it puts the decision in the hands of a tool the person on the call does not have.

More importantly, the vulnerability is process, not audio. If your payment approval depends on recognising a voice, the control was already weak — voice was never a good authenticator, it was just hard enough to imitate that nobody noticed.


Process controls that hold

Controls that work regardless of how good the voice isCallback on a known number, dual authorisation, and help desk verification that does not rely on knowledge questions. Supported by an explicit rule against urgent exceptions and management backing for refusal.Callback on a number held on fileDefeats the attack entirely; costs a minuteDual authorisation through a systemNot verbal, for payments above a thresholdNon-knowledge-based help desk verificationEnrolled device or manager, not security questionsAn explicit no-urgent-exceptions ruleRemoves the lever the attack depends onA code word for executive requestsSimple and effective for payment authorisationPermission to refuse and escalateStated by leadership, or agents will not use it
None of these depend on anyone detecting anything.

Out-of-band callback on a number held on file. Not a number given during the call, not one from an email signature. This defeats the entire attack and costs a minute.

Dual authorisation for payments above a threshold, through a system rather than verbally.

No urgent exceptions. Attacks depend on urgency defeating procedure. A policy that explicitly states urgency is never a reason to bypass verification — and executives who visibly follow it — removes the lever.

Help desk identity verification that is not knowledge-based. Knowledge questions fail because the answers are discoverable. Options that work: verification through an existing enrolled device, a manager confirming through a separate channel, or in-person verification for high-risk requests such as MFA resets.

A code word for executive verification. Simple, and effective for the payment-authorisation case.


Help desk deserves particular attention

MFA reset is the highest-value request an attacker can make, because it converts a phone call into authenticated access. Treat it accordingly:

RequestVerification standard
Password resetExisting enrolled device, or manager confirmation
MFA reset or new device enrolmentHighest — separate channel, or in person
Access to a new systemThrough the normal approval workflow, not by phone
Contact detail changeOut-of-band confirmation to the existing detail

Staff also need explicit permission to refuse and escalate. Most help desk compromises succeed because an agent felt unable to say no to someone senior and insistent. That is a management problem, and it is fixed by leadership stating plainly that following procedure will never be held against them.


Training that reflects reality

Awareness training telling staff to listen for robotic speech is now actively harmful — it teaches a detection method that fails and creates false confidence.

Train the process instead: which requests always require callback, what the callback procedure is, that urgency is a warning sign rather than a reason, and that refusing and verifying is always supported. See security awareness training and BEC defence.


Where to start

Ask your help desk what they would do if a senior executive called, urgently, asking for an MFA reset. The answer tells you your actual exposure, and if it is "reset it", that is a fifteen-minute policy change away from being fixed.

GuardsArm runs social engineering testing including voice-based pretexting. See social engineering testing or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.