AI Voice Cloning Is Now Behind 40% of Business Email Compromise AttacksAI-generated deepfakes — mostly cloned voices — now show up in roughly 40% of business email compromise (BEC) attacks, up from under 5% in 2023, and the average loss per AI-deepfake incident has climbed to $4.1 million compared to $1.3 million for traditional BEC (Digital Applied, 2026). This is a different threat than the fake-IT-support phone calls making headlines lately — here, attackers clone the voice of an executive or vendor to authorize a wire transfer, not to get remote access to a machine.

How Little Audio Does It Actually Take?

Cloning a convincing voice now takes as little as three seconds of audio — a voicemail greeting, a conference call recording, a video posted publicly is enough — and dark-web deepfake-as-a-service tools that generate the clone cost under $20-$100 (Digital Applied, 2026). Real-time voice conversion now runs at sub-200 millisecond latency on ordinary consumer hardware, meaning an attacker can hold a live, responsive phone conversation in a cloned voice rather than playing a pre-recorded clip.

Can Software Reliably Catch a Cloned Voice?

Not yet, reliably. Deepfake audio detection tools hit 80-85% accuracy in lab conditions but drop to 50-65% on real phone calls, and accuracy degrades further on the compressed, low-bandwidth audio typical of standard phone lines (Digital Applied, 2026). No detection tool available today reliably beats 85% accuracy against this kind of attack, which means technology alone isn't a sufficient defense — process has to carry most of the weight.

Why Is This So Hard to Catch in the Moment?

Because the entire attack is built to exploit trust and urgency in a single phone call, and by the time anyone realizes something was wrong, the money is usually already gone. The average time between a fraudulent transfer and detection is about 18 hours, and only 15-20% of BEC losses ever get reported to law enforcement — meaning the true scale is likely far larger than the FBI's reported $2.9 billion in 2024 BEC losses suggests (Digital Applied, 2026).

What Actually Stops This?

A callback verification policy on a known, pre-saved number — never a number provided during the suspicious call itself — stops nearly all of these attacks, because it breaks the live-conversation format the fraud depends on. Pair that with a strict rule that no wire transfer or payment change gets approved from a voice or video call alone, always requiring a second, independent confirmation channel for any request involving money movement or urgency.

Frequently Asked Questions

How much audio does someone need to clone a voice?

As little as three seconds — a voicemail, a video, or a recorded call is enough for current voice-cloning tools to produce a convincing clone.

Can antivirus or email security software stop voice cloning scams?

No. This attack happens over a phone call, not email or a compromised device, so traditional security software doesn't detect it. A verification process — callbacks to known numbers, second-channel confirmation — is the effective defense.

How much money is typically lost to AI-deepfake BEC attacks?

The average loss per incident involving an AI-generated deepfake is around $4.1 million, roughly three times the average for traditional business email compromise without AI involved.

What's the single most effective policy against this?

Requiring a callback to an independently verified, pre-saved phone number before authorizing any wire transfer or payment change — never calling back a number given during the suspicious call itself.

Worried your team could be targeted by a cloned voice on the next "urgent wire transfer" call? Infortech helps Bay Area businesses build verification processes that don't depend on catching the fake in the moment? Book a discovery call to learn more about how to protect your business.