---
title: "AI-backed voice cloning may lead to vishing attacks! | Phish Protection"
description: "&#38;nbsp; A group of researchers believes that AI-based voice impersonation can enhance social engineering tactics and make them sound more perfect and convincing."
image: "https://phishprotection.com/og/blog/ai-backed-voice-cloning-may-lead-to-vishing-attacks.png"
canonical: "https://phishprotection.com/blog/ai-backed-voice-cloning-may-lead-to-vishing-attacks/"
---

Quick Answer

by Phishing Protection https://media.mailhop.org/phishprotection/images/2025/10/AI-backed-voice-cloning-may-lead-to-vishing-attacks.mp3 A group of researchers believes that AI-based voice impersonation can enhance social engineering tactics and make them sound more perfect and convincing. AI voice cloning has the ability to minimize the difference between reality and artificiality. Threat actors can misuse this AI-backed voice cloning technology to target organizations, their employees, and the general public.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fphishprotection.com%2Fblog%2Fai-backed-voice-cloning-may-lead-to-vishing-attacks%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=AI-backed%20voice%20cloning%20may%20lead%20to%20vishing%20attacks!&url=https%3A%2F%2Fphishprotection.com%2Fblog%2Fai-backed-voice-cloning-may-lead-to-vishing-attacks%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fphishprotection.com%2Fblog%2Fai-backed-voice-cloning-may-lead-to-vishing-attacks%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fphishprotection.com%2Fblog%2Fai-backed-voice-cloning-may-lead-to-vishing-attacks%2F&title=AI-backed%20voice%20cloning%20may%20lead%20to%20vishing%20attacks! "Share on Reddit") [ ](mailto:?subject=AI-backed%20voice%20cloning%20may%20lead%20to%20vishing%20attacks!&body=Check out this article: https%3A%2F%2Fphishprotection.com%2Fblog%2Fai-backed-voice-cloning-may-lead-to-vishing-attacks%2F "Share via Email") 

![Phish Protection blog post image](https://media.mailhop.org/phishprotection/images/2025/10/what-is-phishing-4926.jpg) 

##### AI-backed voice cloning may lead to vishing attacks!

by **Phishing Protection**

```
				<audio class="wp-audio-shortcode" id="audio-249524-6" preload="none" style="width: 100%;" controls="controls"><source type="audio/mpeg" src="https://media.mailhop.org/phishprotection/images/2025/10/AI-backed-voice-cloning-may-lead-to-vishing-attacks.mp3?_=6" />[https://media.mailhop.org/phishprotection/images/2025/10/AI-backed-voice-cloning-may-lead-to-vishing-attacks.mp3](https://media.mailhop.org/phishprotection/images/2025/10/AI-backed-voice-cloning-may-lead-to-vishing-attacks.mp3)</audio>
```

A group of[researchers](https://www.nccgroup.com/the-rising-threat-of-vishing-attacks-and-deepfakes/)believes that AI-based voice impersonation can enhance social engineering tactics and make them sound more perfect and convincing. AI voice cloning has the ability to minimize the difference between reality and artificiality. Threat actors can misuse this**AI-backed voice cloning technology**to target organizations, their employees, and the general public. 

The researchers have used an AI-generated **voice cloning** clip to prove their point

.

### **What is a vishing attack?**

A[vishing attack](https://www.technewsworld.com/story/researchers-mount-vishing-attacks-with-real-time-voice-cloning-179945.html)is basically a type of cyberattack where the threat actor makes highly convincing and **well-calculated voice calls** to convince the victims into sharing sensitive details such as passwords, bank account numbers, social security numbers, and so on.

![What is phishing](https://media.mailhop.org/phishprotection/images/2025/10/what-is-phishing-4926.jpg) 

A[cybercrook](https://wtop.com/local/2025/04/cyber-crooks-scam-dc-md-and-va-out-of-848-million-in-2024/)may connect with you on a call and pretend to be one of your closest friends or family members. The next thing they will do is to create a sense of panic and urgency so that you part with **personal data** or money.

Vishing attacks are already on the rise, with multiple incidents reported this year. Back in May, the notorious[3 AM ransomware gang](https://news.sophos.com/en-us/2025/05/20/a-familiar-playbook-with-a-twist-3am-ransomware-actors-dropped-virtual-machine-with-vishing-and-quick-assist/)blended**vishing with email bombing**to target the victims.

[Salesforce employees](https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion)were targeted in June, when the **ransomware gang** pretended to be IT support team members . Something similar happened with Cisco, as a cybercrook managed to carry out a vishing attack and gain access to[Cisco’s sensitive data.](https://www.darkreading.com/cyberattacks-data-breaches/cisco-user-data-stolen-vishing-attack)

Previously, during vishing attacks, cybercriminals either attempted to impersonate someone without actually sounding like them or played **pre-recorded audio clips**

. In both these cases, there was room for suspicion. Some scammers also used text-to-speech systems. But that would sound unnatural and robotic to the victims, or could lead to delayed replies.

This is why **AI-backed voice cloning** technology is incredibly popular among[threat actors](https://www.cybersecuritydive.com/news/microsoft-crowdstrike-other-cyber-firms-collaborate-on-threat-actor-taxon/749614/)

- the element of flawlessness it adds to vishing attacks.
![What is a zero day attack](https://media.mailhop.org/phishprotection/images/2025/10/what-is-a-zero-day-attack-3582.jpg) 

### **What is AI voice cloning technology?**

> “Zero-day phishing URLs have an average lifespan of just 12 hours before they’re added to blocklists. During that window, traditional signature-based filters are blind. Our real-time behavioral analysis catches these threats by pattern, not by signature - which is how we detect attacks that no database has seen yet.” - **Adam Lundrigan**, CTO, DuoCircle

Artificial Intelligence-backed voice impersonation technique refers to the process of training AI models to imitate a given voice. With AI technology, it is now possible to imitate a specific voice with even a **short recorded audio clip**. AI voice cloning enables[cybercriminals](https://www.cnn.com/2025/06/28/business/cyberattacks-airlines-fbi-criminal-group)to speak in real-time, responding naturally during phone conversations. It is also possible to use a pre-written text and deliver it flawlessly in the cloned voice. The degree of perfection tricks the victims into believing that they are talking to someone they already know well. 

The**NCC group researchers**trained an AI voice cloning tool by using a publicly available, short audio clip. Within an hour or so, they managed to develop a[vishing](/phishing-awareness/phishing-smishing-vishing-cyber-attacks-you-must-be-aware-of)system that could mimic any voice in real-time

Here’s what makes the situation all the more scary!

The researchers did not use any high-end, **state-of-the-art equipmen**t or machinery

. They created the[AI voice cloning](https://www.cbc.ca/news/marketplace/marketplace-ai-voice-scam-1.7486437)tool using readily available and affordable tools and equipment.

### **What does your future look like with AI voice cloning on the rise?**

![Vishing info](https://media.mailhop.org/phishprotection/images/2025/10/vishing-info.jpg) 

Researchers and[cybersecurity](https://www.welivesecurity.com/en/cybersecurity/black-hat-usa-2025-successful-cybersecurity-cyber-risk/)experts warn that AI voice impersonation could significantly escalate cyberattacks and social engineering schemes in the near future. For example, cybercriminals may soon clone the voices of famous public figures and celebrities to execute **large-scale scams**. 

Additionally, sophisticated attackers could exploit AI voice cloning to bypass enterprise security systems by mimicking the voices of key decision-makers such as CEOs, founders, and directors. This emerging threat underscores the critical need for advanced[phishing protection](/)and robust security measures to safeguard organizations against **AI-driven attacks**.

Besides, the **degree of feasibility** of AI voice[cloning tools](https://www.newsbreak.com/wish-tv-2107872/3855075448196-consumer-reports-warns-about-some-ai-voice-cloning-tools)and the easy learning curve can attract a huge wave of noob threat actors . 

Even though **threat actors** are still majorly using conventional[vishing tactics](https://www.infosecurity-magazine.com/news/phishing-attack-combines-vishing/), they will soon migrate to AI-backed voice cloning, making it difficult for victims to detect any foul play.

![Phishing prevention](https://media.mailhop.org/phishprotection/images/2025/10/phishing-prevention-7328.jpg) 

### **How to prepare for an upsurge in vishing attacks?**

First things first! You can no longer trust your ears. Even if the voice on the other side sounds exactly like your**closest friend or family member**, it is highly likely that you are talking to a cunning, AI-savvy[cyber scammer](/resources/protect-yourself-from-phishing). 

Next, you must put an immediate limitation on the public availability of voice clips of your executives

. You must closely monitor things like podcasts, speeches, and **recorded meetings** and put a limit on their easy accessibility. 

Also, setting up a pre-agreed code word can be a brilliant move to tackle such **malicious vishing attempts**. You should also deploy the[Multi-Factor Authentication](https://www.ibm.com/think/topics/multi-factor-authentication)technique to add an extra layer of protection. Lastly, organize proper employee training to help them identify vishing attacks.

![How to prevent phishing](https://media.mailhop.org/phishprotection/images/2025/10/how-to-prevent-phishing-3964.jpg) 

As[AI](/cybersecurity/increasing-role-of-ai-in-shaping-phishing-techniques)approaches perfection, one day at a time, it is essential to remain skeptical. If the person on the call wants you to share your personal details or requests that you send money urgently, it is better to hang up, pause, and**think clearly before responding**. 

Next time your senior calls you asking for your account details or a close friend calls you and asks for immediate monetary help, ask yourself - **can that be AI**

?

## Topics

[ Phishing Awareness ](/tags/phishing-awareness/) 

![Brad Slavin](https://media.mailhop.org/phishprotection/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead across DuoCircle's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Protect your inbox from phishing attacks

Real-time email security with 60-day free trial. No credit card required.

[Start Free Trial](https://portal.duocircle.com/cart.php?a=add&pid=101&brand=phishprotection) [View Pricing](/pricing/) 

## Related Articles

[  Foundational 5m  0ktapus, Okta Breach Helps Attackers Launch Sophisticated Supply Chain Attacks  Sep 5, 2022 ](/blog/0ktapus-okta-breach-helps-attackers-launch-sophisticated-supply-chain-attacks/)[  Foundational 14m  12 Real-World Spear Phishing Examples And The Red Flags You Missed  Feb 4, 2026 ](/blog/12-real-world-spear-phishing-examples-and-the-red-flags-you-missed/)[  Foundational 2m  8 million Android users fell prey to SpyLoan malware on Google Play Store  Dec 5, 2024 ](/blog/8-million-android-users-fell-prey-to-spyloan-malware-on-google-play-store/)[  Foundational 1m  A Big Part of the Phishing Problem is You  Sep 17, 2019 ](/blog/a-big-part-of-the-phishing-problem-is-you/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://github.com/duocircle"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://phishprotection.com/contact/"},"knowsAbout":["Phishing Protection","Email Security","Anti-Phishing","Business Email Compromise","Ransomware Protection","Time of Click Protection","Office 365 Email Security","Advanced Threat Defense"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"Phish Protection","url":"https://phishprotection.com","description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","publisher":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"AI-backed voice cloning may lead to vishing attacks!","description":"&nbsp; A group of researchers believes that AI-based voice impersonation can enhance social engineering tactics and make them sound more perfect and convincing.","url":"https://phishprotection.com/blog/ai-backed-voice-cloning-may-lead-to-vishing-attacks/","datePublished":"2025-10-07T12:28:50.000Z","dateModified":"2026-04-17T16:29:18.000Z","dateCreated":"2025-10-07T12:28:50.000Z","author":{"@type":"Person","@id":"https://phishprotection.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://phishprotection.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/phishprotection/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"Phish Protection","url":"https://phishprotection.com","logo":{"@type":"ImageObject","url":"https://phishprotection.com/images/phishprotection-logo.png"},"description":"Advanced phishing protection and email security for businesses. Real-time threat defense, time-of-click protection, and seamless Office 365 integration.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://github.com/duocircle"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://phishprotection.com/contact/"},"knowsAbout":["Phishing Protection","Email Security","Anti-Phishing","Business Email Compromise","Ransomware Protection","Time of Click Protection","Office 365 Email Security","Advanced Threat Defense"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://phishprotection.com/blog/ai-backed-voice-cloning-may-lead-to-vishing-attacks/"},"articleSection":"foundational","keywords":"Phishing Awareness","wordCount":951,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/phishprotection/images/2025/10/what-is-phishing-4926.jpg","caption":"Phish Protection blog post image","width":1200,"height":630},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://phishprotection.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://phishprotection.com/blog/"},{"@type":"ListItem","position":3,"name":"Foundational","item":"https://phishprotection.com/foundational/"},{"@type":"ListItem","position":4,"name":"AI-backed voice cloning may lead to vishing attacks!","item":"https://phishprotection.com/blog/ai-backed-voice-cloning-may-lead-to-vishing-attacks/"}]}
```
