Back to Blog

Criminals Can Clone Your Voice From a 3-Second Voicemail. Here’s What That Means for Your Business.

Picture this. Your bookkeeper gets a call. It sounds exactly like you. The voice says you’re tied up in a client meeting but need them to wire $8,000 to a vendor right away. Can they handle it?

That’s not hypothetical. That’s an AI voice cloning attack, and they’re hitting small businesses in 2026 at a rate I haven’t seen with any other threat in recent memory.

Voice phishing, called vishing, isn’t new. Scammers have been calling people and pretending to be their bank for decades. What changed is the technology. Attackers no longer need acting skills or even a convincing accent. They feed a few seconds of someone’s recorded voice into an AI model, and the model generates audio that matches the speaker’s pitch, cadence, and tone closely enough to fool people on a phone call. The source material doesn’t need to be a studio recording. A voicemail greeting works. A podcast interview works. A short video on your company’s LinkedIn page works.

The numbers reflect how bad this has gotten. Voice phishing attacks surged 442% from the first half to the second half of 2024 alone, making it the fastest-growing attack vector tracked last year.[1] Deepfake fraud cost businesses $1.1 billion in 2025, and has already racked up $96 million in losses in just the first four months of 2026.[2] The FBI classifies AI-powered voice fraud as one of the highest-value fraud categories targeting U.S. businesses right now, with AI-enabled schemes generating $2.77 billion in losses across more than 21,000 incidents in 2024 alone.[3]

The Case That Should Have Been a Warning

If you haven’t heard about Arup, here’s the short version. A finance employee at the engineering firm’s Hong Kong office transferred roughly $25 million across multiple wire transfers after sitting in on a video conference where every other participant, including the apparent CFO and several colleagues, was an AI-generated deepfake.[4] Everyone looked and sounded exactly right. The employee had no reason to question what they were seeing and hearing.

That’s a large enterprise with a full IT department. But the attack technique scales down to a two-minute phone call just fine. Small businesses are actually easier targets because there are fewer layers between the person receiving the call and the person who can authorize a payment.

How the Small Business Version Works

The typical attack against a small business doesn’t involve a deepfake video conference. It’s a phone call.

The attacker does basic research first. Your name is on your website. Your role is on LinkedIn. Maybe you have a short video from a local chamber of commerce event, or a podcast you appeared on two years ago. That’s enough to clone your voice. They call your office manager, your bookkeeper, or your accounts payable contact, pretending to be you, and ask for something that requires urgency: a wire transfer, a gift card purchase, login credentials to a vendor portal.

From initial recon to completed payout, attacks like this can finish in under two business days.[5] By the time anyone realizes what happened, the money is gone. Customer support and office staff are the most vulnerable, with susceptibility rates in some studies running as high as 11.5%.[1] Those are the same people who answer your phones.

70% of organizations have already experienced at least one vishing attack.[1] This isn’t theoretical for most businesses. It’s already arrived.

What Actually Helps

The fix doesn’t require new technology. It requires a process, and you can put it in place today.

Set up a verbal code word with anyone at your company who handles financial transactions or account access. Something random that isn’t connected to anything public. If your “voice” calls and can’t say it, the request doesn’t go through. Full stop. Larger firms call this a safe-word protocol. It works because it’s one thing AI can’t fake if the attacker doesn’t know it.

Any request involving money or credentials should require a callback on a number you already have, not a number the caller provides. Urgency is a red flag, not a reason to skip the verification step. Attackers manufacture urgency specifically to cut off critical thinking.

Think about your public-facing audio. If you have a voicemail greeting, a podcast episode, or any recorded video that’s publicly accessible, that material is out there. You don’t necessarily need to take it down, but knowing what exists helps you understand what an attacker could use as source material.

Train your team. Not a full-day cybersecurity seminar, just a short conversation about this specific threat with a real example. Show them the Arup story. Make it concrete. One briefing with an actual case study does more than a policy document they signed at onboarding.

The attacks are getting more convincing every month. The countermeasures are low-tech and free. Don’t wait until someone on your team falls for one to start talking about it.

Want to talk through your current verification procedures, or put a plan in place before this becomes your problem? Reach out here or call us at (412) 307-8313.

Share
  1. Programs.com, “Vishing Statistics 2026: 442% More Incidents, $40B In Losses,” programs.com
  2. SQ Magazine, “AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now,” sqmagazine.co.uk
  3. CybelAngel, “Voice Cloning Is the New BEC: Deepfake CEO Fraud in the US,” cybelangel.com
  4. Unbox Future, “The Rise of AI Voice Cloning Scams in 2026: How the ‘Grandparent Fraud’ Went High-Tech,” unboxfuture.com
  5. Breach Security, “AI Voice-Cloning Attacks on SMBs: What Is Real in 2026,” breachsecurity.io