Skip to content
aiconsulting.capital

AI abuses

Deepfake fraud and voice cloning: how it works and how to defend

AI-powered impersonation is now a mainstream fraud tactic. How deepfake and voice-cloning scams actually work in 2026, who they target, and the practical defences that stop them.

By Marta Breheny · Editor & lead writerPublished: June 20, 20263 min read· AI Consulting Capital

The most damaging AI abuses of 2026 aren’t exotic — they’re old scams with a new disguise. Cloned voices and deepfake video let criminals impersonate the people you trust, turning a transfer request from your “CFO” or a call from your “child” into something convincing enough to act on. This is how those scams work, and the defences that actually stop them.

This article focuses on the criminal pattern and how to defend; for the broader categories of AI misuse, see the pillar on AI abuses and scandals.

How the scam is built

The mechanics are now cheap and fast:

  1. Harvest a sample. A few seconds of a target’s voice — from a voicemail, a webinar, social video — is enough to clone it. Faces come from the same public sources.
  2. Generate the impersonation. AI produces speech in that voice, or video of that face, saying whatever the criminal scripts.
  3. Manufacture urgency. The message demands fast action: an “urgent” wire transfer, a password reset, a confidential acquisition that “can’t wait.”
  4. Exploit trust and hierarchy. People comply because the request seems to come from a boss, a relative or a known supplier — and because questioning it feels rude or risky.

The synthetic identity doesn’t invent a new crime; it removes the friction that used to make impersonation hard.

Who gets targeted

  • Finance and operations staff who can move money — the classic “CEO fraud,” now with a real-sounding CEO.
  • Anyone with elderly relatives — the “grandchild in trouble” call, made devastatingly believable with a cloned voice.
  • Companies mid-deal — fake executives injected into video calls to authorise payments or leak information.

The defences that work

Notice that none of these rely on spotting the fake — because, as we explain in how to detect AI content and deepfakes, detection alone isn’t reliable enough. Robust defence is about process:

  • Out-of-band verification. Any request to move money or change credentials gets confirmed on a separate, known channel — call back on a saved number, never the one provided in the message.
  • Code words. Agree a phrase in advance for sensitive requests, within families and finance teams alike. A cloned voice doesn’t know it.
  • Approval controls. Require dual authorisation for transfers above a threshold. One person can be fooled; two, on separate channels, is far harder.
  • A pause-to-verify culture. The scam weaponises urgency and deference. Make it explicitly safe — expected, even — to slow down and check a request that claims to come from the boss.
  • Reduce the attack surface. Be aware that public audio and video are training material for a clone. It doesn’t mean going silent, but it does mean assuming your voice can be faked.

The mindset shift

The single most useful change is to stop treating a familiar voice or face as proof of identity. In 2026 it isn’t. Authenticity now comes from the channel and the process, not from how convincing the message sounds. A team that has internalised “verify before you act” defeats this entire category — no detector required.

For detailed, step-by-step defensive playbooks on voice and video fraud, our sister project counterAI goes deeper than we do here.


Educational content. Describes general fraud patterns and defences, not specific incidents or named parties. Not legal advice.

We report facts with sources and dates. We never label a named company as fraudulent or "AI-washing" as a statement of fact — we present verifiable data and the questions an investor should ask.

Frequently asked questions

How do deepfake and voice-cloning scams work?+

Criminals use AI to clone a voice from a few seconds of audio, or to generate fake video of a known person, then use it to create urgency — a 'CEO' authorising a transfer, a 'relative' in trouble, a 'colleague' on a video call. The synthetic identity makes a routine fraud far more convincing.

How can I protect my business from voice-cloning fraud?+

Treat unexpected requests for money or credentials as unverified regardless of how the voice or face sounds. Require call-back verification on a known number, use agreed code words for sensitive instructions, and build a culture where pausing to verify a 'boss' is encouraged, not punished.

Can deepfakes be detected reliably?+

Not reliably enough to depend on alone. Detection tools lag the generators and produce errors. The robust defence is process — out-of-band verification and approval controls — rather than trying to spot the fake in the moment.

Related reading