A three second clip pulled from a podcast, webinar, or voicemail greeting is now enough to clone a voice convincingly. Advisory firms are learning that a familiar voice on the phone is no longer proof of anything.

Every recorded webinar, every conference keynote, every voicemail greeting an advisor has ever left is now potential training data for someone who wants to sound exactly like them. Voice cloning technology has crossed a threshold security researchers call the indistinguishable line, meaning a listener can no longer reliably tell a real voice from a synthetic one, and the amount of source audio required to get there has collapsed to almost nothing.

According to research from McAfee, as little as three seconds of clear audio is enough to produce a voice clone with roughly 85 percent accuracy. A few additional samples push that closer to 95 percent. For advisory firms, whose principals speak publicly at conferences, appear on podcasts, and leave voicemail greetings by design, the raw material for an attack is already sitting in public view.

The trust channel fraud actually targets

Advisors have spent years training clients to expect a phone call before a large transfer or an account change. That habit, built for their protection, is exactly what current attacks exploit. Fraudsters clone a client’s voice, or an advisor’s, and use it to authorize a wire transfer, request a password reset, or walk a service team through a change that would normally trigger suspicion.

3 sec

Of audio needed to produce a voice clone with roughly 85 percent accuracy, per McAfee research

84%

Of financial organizations report facing a sophisticated voice based attack in the past year

0.1%

Of people could reliably identify a deepfake voice or video in controlled testing, per iProov

$40B

Projected annual AI driven fraud losses in the United States by 2027, per Deloitte

He used to think of it as an IT problem. He now thinks of it as a client trust problem, and the distinction changes where he invests his attention.

— Describing a Sovereign Financial Group principal’s shift in thinking, InvestmentNews, 2026

It has already cost real money

The clearest evidence that this threat is not theoretical came out of Hong Kong in early 2024. A finance employee at the engineering firm Arup joined what looked like an ordinary video call with the company’s chief financial officer and several colleagues. Every person on that call was synthetic. Over the course of the meeting, the employee authorized fifteen separate transfers totaling 25.6 million dollars before anyone realized what had happened. Arup confirmed the incident publicly in May 2024, and the funds were never recovered.

The pattern is not new, only faster and more convincing than it used to be. A UK based energy firm lost 220,000 euros back in 2019 after an employee received a phone call from what sounded exactly like the company’s chief executive, directing an urgent wire to a supplier. As recently as January 2026, a businessman in the Swiss canton of Schwyz was defrauded of millions of dollars after a series of phone calls over two weeks convinced him he was speaking with someone he trusted. The case remains under investigation.

Why voice is no longer sufficient verification

The gap between how confident firms feel and how exposed they actually are is the real story here. Most advisors still treat a recognized voice, or a familiar caller ID, as a legitimate form of verification. The data suggests that confidence is badly misplaced.

Voice attack exposure versus organizational readiness
Share of financial organizations reporting each condition
Source: Trusona and Keepnet deepfake fraud research, cited in 2026 industry reporting

Eight in ten firms across industries have no formal deepfake response plan at all. For a wealth management firm, where a single successful impersonation can mean an unauthorized wire transfer, reputational damage, and a very uncomfortable client conversation, that gap is not one to leave unaddressed.

A verification protocol that doesn’t rely on trust

The fix is not more suspicion toward every client call. It is a small number of procedural changes that remove voice as the sole point of failure.

Four controls advisory firms are adopting now:

1. A spoken safe phrase for high risk requests

Established with the client in advance, changed periodically, and never sent over a channel that could be intercepted.

2. Out of band verification for money movement

Confirm any wire or account change through a second channel, such as a callback to a number already on file, not one provided during the request.

3. Dual authorization above a set dollar threshold

No single team member, however senior, should be able to approve a large transfer alone based on a phone call.

4. Slower, more deliberate client verification by default

Build a pause into the process for unusual requests. Urgency is the fraudster’s favorite tool, and it works best against a fast, informal culture.

None of these controls require exotic technology. They require a written protocol, a team trained to follow it consistently, and leadership willing to treat a thirty second delay as an acceptable cost of doing business safely. Firms that already run tabletop exercises for cybersecurity incidents can extend the same discipline to voice based fraud without building a program from scratch.

Prepared for a call that isn’t who it sounds like?

Aurmis provides Fractional CTO and CISO leadership to help advisory firms build practical, tested protocols against the threats their clients actually face.

SHARE:

Get Aurmis News, Updates, and Articles Direct to Your Inbox

Related