TL;DR:

  • AI voice cloning tools can replicate a person’s voice from as little as 10-30 seconds of audio sourced from YouTube, LinkedIn, or voicemail
  • Fraudsters use cloned voices to call employees and impersonate the boss, accountant, or supplier — then request urgent bank transfers or credential disclosure
  • Small businesses are targeted more often than large ones because they typically lack the verification procedures that stop these calls cold

A business owner in Leeds receives a voicemail from her accountant asking her to call back urgently about a VAT payment. She calls back. The voice is familiar, the tone correct, the detail convincing. She authorises a £14,000 transfer to an “amended” supplier account. The real accountant had nothing to do with it.

This is AI voice cloning fraud — sometimes called vishing (voice phishing) or CEO fraud — and Action Fraud reported a 34% increase in voice-based impersonation cases in the first half of 2026. The technology that makes it possible has become cheap, fast, and accessible to criminals with no technical background.

How AI Voice Cloning Works

Modern voice synthesis tools — ElevenLabs, Resemble AI, and dozens of open-source equivalents — can clone a voice from a short audio sample. A 2024 Microsoft Research study found that some systems needed as little as three seconds of clean audio. In practice, fraudsters prefer 30-60 seconds for better quality, but that’s easily sourced from:

  • YouTube interviews, podcast appearances, or company videos
  • LinkedIn voice introductions (a newer feature many professionals don’t realise is public)
  • Voicemail greetings left on public business phone numbers
  • Previous phone calls, if the target has had any recorded calls published

Once cloned, the voice can be used in two ways: pre-recorded messages delivered via voicemail or automated calls, or real-time synthesis where a human operator speaks and the audio is converted to the cloned voice before it reaches the recipient. Real-time tools are increasingly available and make live phone conversations with a fake voice plausible.

The Typical Attack Pattern

UK small business fraud involving voice cloning tends to follow one of three scripts:

1. Urgent bank transfer An employee receives a call — or returns a spoofed voicemail — from someone sounding exactly like the business owner or a senior manager. The caller explains there’s an urgent, confidential deal that requires an immediate transfer. The employee is told not to discuss it with anyone else “for legal reasons.” Time pressure and confidentiality instructions are both red flags.

2. Supplier payment redirect A supplier’s voice is cloned, and an employee receives a call asking them to update bank details for future payments. This is combined with a follow-up email (easily spoofed) to reinforce the request. The next payment goes to a fraudster’s account.

3. IT access and credential handover An employee receives a call from someone claiming to be their IT provider or a senior colleague, asking for temporary access to an account to “fix a problem.” Voice cloning makes the caller sound like someone the employee trusts. The credentials are then used for account takeover or to send fraudulent invoices.

Why Small Businesses Are the Primary Target

Larger organisations have counter-measures that have become standard: multi-party authorisation for transfers above certain thresholds, call-back verification protocols, dedicated fraud awareness training, and treasury management systems that flag payment anomalies.

Small businesses typically have none of these. A single employee often handles finance, has authority to make payments, and works in an environment where the boss calling with an urgent request is normal. The personal nature of small business relationships — where staff genuinely know their employer’s voice and trust it — is exploited directly.

Fraudsters also know that small businesses are less likely to report fraud (reputational concern, belief recovery is unlikely) and less likely to have the forensic capability to investigate after the fact.

How to Protect Your Business

Establish a verbal code word for sensitive requests

Agree on a short code word with your accountant, key employees, and anyone who might request or authorise payments. Any phone request for a transfer or credential handover that doesn’t include the code word should trigger a call-back verification using a known, pre-saved number — not any number provided in the call itself.

This is low-tech and highly effective. Fraudsters operating at scale cannot know your internal code word.

Require two-channel verification for any payment change

If a supplier or colleague calls to request a change to bank details, the rule should be: no change is made without independent confirmation via a second channel. Call the supplier on their known office number (from your records, not from the call), or send an email to the address you already have on file and wait for a reply before acting.

Don’t rely on voice recognition alone

This is the core lesson of the voice cloning era. Recognising someone’s voice is no longer a reliable authentication method. Treat any unexpected phone request for money, credentials, or sensitive information as if the caller identity cannot be verified — because technically it cannot be.

Limit the audio footprint of senior staff

If the business owner appears in company videos, podcasts, or LinkedIn content, they’re providing raw material for cloning. This doesn’t mean avoiding all public-facing content, but it’s worth knowing the risk exists. For smaller businesses where the owner’s voice isn’t widely published, this slightly raises the effort required to clone it convincingly.

Train staff on the red flags

The social engineering elements of these calls are as important as the voice technology. Common red flags:

  • Unusual urgency (“this needs to happen in the next 30 minutes”)
  • Requests for secrecy (“don’t mention this to anyone else”)
  • Emotional pressure (disappointment, urgency, flattery)
  • Caller provides a new number to use rather than asking you to call back on a known one
  • Slight audio quality issues or unusual background noise (though this is less reliable as a tell as synthesis quality improves)

Use payment platforms with built-in confirmation steps

Modern business banking platforms from Starling, Monzo Business, Tide, and others include confirmation steps, payee verification (Confirmation of Payee), and anomaly flagging. These create friction that protects against impulsive action following a manipulative call.

If You’ve Been Targeted

Report to Action Fraud (actionfraud.police.uk) — even if you didn’t lose money. Reports help law enforcement track fraud networks and issue warnings. If money was transferred: contact your bank immediately using the number on the back of your card (not any number from the fraudulent call), ask them to invoke the Authorised Push Payment (APP) fraud reimbursement scheme, and request that the receiving bank is alerted.

The Contingent Reimbursement Model code, now mandatory for UK payment service providers following the Payment Systems Regulator’s October 2024 direction, means you have a clearer route to reimbursement for APP fraud — including impersonation fraud — than existed previously.

Voice cloning fraud will get easier to execute as the tools improve. The defences don’t depend on technological sophistication — they depend on verification procedures that create a step the voice alone can’t bypass.