Home » Latest news » Tech firms race to fix deepfake voice scams as criminals target banks and families

Tech firms race to fix deepfake voice scams as criminals target banks and families

Phone call security
Phone call security. Photo by Zulfugar Karimov on Unsplash.

What used to require a Hollywood studio can now be done on a mid‑range laptop: cloning someone’s voice from a short audio clip. In the past year, deepfake voice scams have shifted from fringe curiosities to a serious security problem for banks, businesses and families.

Technology companies, telecom operators and financial institutions are now rolling out a mix of AI detection tools, call‑verification systems and new security policies in an attempt to keep up. The battle is turning into one of the most visible tests of how fast the industry can respond when AI tools fall into criminal hands.

From novelty to everyday scam tool

Until recently, synthetic voice technology required large training datasets and specialist skills. Today, widely available tools can generate a convincing voice clone from less than a minute of audio, often scraped from social media, podcasts or online meetings.

Criminal groups have begun to integrate these tools into familiar fraud schemes. Instead of a simple phishing email, victims may receive a phone call that sounds like a manager, a bank employee or a family member in distress, asking for urgent transfers or sensitive information.

High profile cases spark policy changes

Several highly publicised incidents in 2024 and 2025, including reports of deepfake CEO voices used to authorise large corporate transfers, pushed the issue up the agenda for regulators and boards. Insurers have also started to ask detailed questions about voice security controls during cyber‑risk assessments.

Banks and payment providers have responded with tighter procedures for phone‑based approvals. Many now require secondary verification through secure apps or in‑person confirmation for large or unusual transfers, even if the request appears to come from a known voice or number.

Why traditional voice security is failing

For years, some contact centres promoted “voice biometric” authentication as a convenient alternative to passwords. These systems analyse characteristics like pitch, tone and speaking style to create a voiceprint that should be hard to imitate.

Deepfake tools undermine that assumption. By learning from multiple samples, they can approximate the same vocal patterns that voice biometric systems rely on. Security researchers have shown that, in some configurations, AI‑generated voices can significantly increase the chance of passing automated voice checks.

New defensive tools enter the market

Bank call center
Bank call center. Photo by CDC on Unsplash.

In response, a new category of “synthetic speech detection” products has emerged. These tools analyse incoming audio in real time, looking for signs typically associated with AI generation, such as certain spectral patterns, inconsistencies in breathing sounds or artefacts introduced during synthesis.

Major cloud providers and specialist startups now offer APIs that banks, call centres and telecom operators can plug into their systems. When a call is flagged as likely synthetic, organisations can trigger extra verification steps or route the caller to specially trained fraud teams.

Limits of AI detection and the need for layers

While detection tools are improving, they are not perfect. Accuracy can drop if calls are noisy, heavily compressed or routed through multiple network layers. Attackers can also adapt by adding background sounds or deliberately degrading audio quality to hide artefacts.

For this reason, security teams recommend treating voice only as one factor in authentication. Stronger approaches combine call analytics, device reputation, behavioural patterns and out‑of‑band confirmation through secure apps, SMS codes or hardware tokens.

Telecom networks add call authentication

Telecom operators are also making changes. In several regions, carriers are expanding protocols that verify caller ID authenticity along the route of a call. Although these standards were originally designed to combat number spoofing, they now play a role in deepfake mitigation too.

If organisations can trust that a call truly originated from a known business line, they can focus their defences on the content of the call rather than the identity of the number. This does not solve the problem of cloned voices, but it reduces one layer of uncertainty in the fraud chain.

Consumer apps and family safeguards

Phone call security
Phone call security. Photo by David Hahn on Unsplash.

The impact is not limited to large organisations. Consumer protection agencies have seen a rise in reports of “imposter” scams where a synthetic voice pretends to be a relative in an emergency, often claiming they need money immediately for bail, hospital fees or travel issues.

Security experts now encourage families to agree on simple “verification phrases” or questions that would be hard for a stranger to guess. Some messaging and banking apps are also experimenting with prominent warnings when a user is about to send funds after receiving a phone call that shows signs of known scam patterns.

Regulators weigh liability and disclosure rules

Lawmakers in multiple countries are beginning to draft rules that address synthetic media and impersonation. Proposals range from stricter penalties for using AI tools in fraud, to requirements that certain automated calls include clear disclosure when a synthetic voice is used.

Financial regulators are also asking banks to show how they assess deepfake risks as part of operational resilience and anti‑fraud frameworks. That pressure is accelerating investment in monitoring systems and staff training, particularly in high‑value corporate banking and wealth management services.

Practical steps for organisations and individuals

For organisations, the priority is to update procedures so that voice or caller ID is never the only reason to trust a request. Clear playbooks for staff, especially in finance and HR, can reduce the success of social engineering attempts that rely on urgency and apparent authority.

Individuals can take simple precautions: be wary of urgent calls that demand secrecy, call back using verified numbers from official websites, and avoid sharing long voice recordings publicly when not necessary. Staying sceptical of what you hear on the phone is becoming as important as treating suspicious links with caution.

As the quality of synthetic voices improves, the line between genuine and fake audio will continue to blur. The next few years will show whether layered security, industry cooperation and updated regulations can keep enough trust in phone‑based communication to match the speed at which AI tools evolve.

0 comments