The Threshold We Quietly Crossed
For as long as telephones have existed, recognising someone's voice has been an entirely sensible way to know who you were speaking to. It was never formalised as a security control, which is precisely why nobody noticed when it stopped working. It was simply how business ran: the accounts clerk knew what the general manager sounded like, so a call from the general manager was a call from the general manager.
Somewhere in the last two years that stopped being true. Voice synthesis reached the point that security researchers describe as the indistinguishable threshold — the point at which human listeners can no longer reliably tell a cloned voice from a real one. Over a phone line, which strips out much of the audio spectrum that might have given a clone away, and under deliberate time pressure, the odds are not close.
The consequence is that a control your business depends on — probably in dozens of small unwritten ways — has been retired without anyone updating the process that relied on it.
Seconds
Of sampled audio reportedly sufficient to produce a usable voice clone
442%
Reported surge in voice phishing attacks through 2025, attributed to AI-driven techniques
Zero
Reliable ways for staff to detect a good clone by ear on a phone line
1 rule
Callback verification to a number you already hold stops nearly all of it
A note on the figures in this article
The percentages above come from published industry and vendor reporting on 2025–2026 attack volumes rather than from our own measurement, and different sources define and count these incidents differently. Treat them as indicative of a clear direction rather than precise. The direction is not in dispute, and the controls in this article are worth adopting whether the true figure is 100% or 500%.
Anatomy of an Attack, Step by Step
These are not opportunistic calls. A voice-cloning attack on a business is researched, and understanding the sequence is what makes the defences obvious.
Target selection
Your website names your directors. LinkedIn names your finance manager. That is enough. Attackers favour businesses lean enough that one person can authorise a payment but large enough for the payment to be worth taking — which describes an enormous share of Australian SMEs.
Voice harvesting
A webinar recording, a conference talk, a company video, a podcast appearance, a radio interview, or simply ringing the target and letting their voicemail greeting play. Seconds of clean audio is reportedly enough.
Context gathering
Who reports to whom, what your invoices look like, who your suppliers are, when your board meets, whether the director is travelling. Much of this is public; the rest is often gathered in earlier, entirely innocuous phone calls to reception.
Pretext construction
A request that is plausible, urgent, and comes with a reason the normal process cannot be followed right now. "I'm about to board, the deposit has to go today or we lose the site."
The call
Often to a junior or mid-level staff member rather than the CFO, because the target is chosen for their reluctance to challenge a senior person. Frequently outside business hours, when there is nobody to check with.
The follow-through
Sometimes a single call is enough. Increasingly there is a second contact reinforcing the first — an email, a text, or a call from an "assistant" — because two channels feel like corroboration even when both are controlled by the attacker.
Notice that step five is the only point where a control is applied, and every traditional control at that point is auditory. That is the design flaw.
The Four Patterns Hitting Australian Businesses
1. Executive impersonation
A cloned director or owner rings finance with an urgent payment that must bypass the usual approval. The most common and most costly pattern. Works because challenging a director feels socially expensive and urgency removes the pause.
2. IT helpdesk impersonation
A cloned or convincing "IT support" voice walks a staff member through a password reset, a multi-factor approval, or installing remote access. Targets the one instruction people have been trained to comply with quickly.
3. Supplier bank-detail change
A familiar supplier contact rings to advise new account details ahead of an invoice. Quiet, patient and often the largest single loss, because it looks like routine administration rather than an emergency.
4. Customer impersonation
Aimed at your staff. A cloned customer voice requests an address change, an account detail, a refund redirect or a release of goods. Your team is trained to be helpful, which is exactly the vulnerability.
The fourth pattern is the one businesses consistently overlook, because security thinking tends to be about protecting the company from external instruction rather than about your own helpfulness being weaponised against a customer. If your staff can change a delivery address or reset a customer's access over the phone, that process needs verification too.
Why It Works on Sensible People
It is worth being clear that people who fall for these attacks are not careless. The attack is engineered against three things that have nothing to do with intelligence.
Hierarchy. Questioning a director's instruction feels expensive in a way that questioning a stranger does not. Most workplaces have, without ever intending to, trained people that senior requests get actioned rather than interrogated.
Urgency. Every pretext includes a reason the normal process cannot be followed right now. Urgency exists specifically to remove the pause in which someone would otherwise think, check, or ask a colleague.
Isolation. The call comes when the person who would normally be consulted is unavailable — after hours, during a meeting, on the Friday before a long weekend. The staff member is asked to decide alone, which is not how they would ever choose to decide.
The uncomfortable implication for management
If your culture makes it awkward for a junior staff member to say "I'll ring you back on the number I've got" to a director, then your culture is the vulnerability, and no amount of security training will fix it. The single most valuable thing a business owner can do about voice cloning costs nothing: tell your team in writing, and then again out loud, that they are required to verify you, that you will never be annoyed by it, and that anyone who follows the rule has done their job correctly even if it turns out to have been you all along.
Stop Teaching Staff to Spot Fakes
A lot of security awareness material still tells people to listen for flat intonation, unnatural pauses, missing breath sounds or robotic artefacts. That advice was reasonable in 2023. In 2026 it is not merely outdated, it is actively harmful, and it is worth understanding why.
A staff member who has been trained to listen for tells will listen for tells. If they hear none — which, with current synthesis over a phone line, is the likely outcome — they will conclude the call is genuine. The training has not protected them; it has manufactured confidence and removed the doubt that might otherwise have prompted a callback.
The correct framing is much simpler, and much easier to teach: it does not matter whether the voice is real. Any request that moves money, changes bank details, resets credentials or bypasses an approval gets verified out-of-band, every time, regardless of how convincing the caller is. That rule requires no judgement, no audio expertise, and no courage to apply — which is precisely why it works.
The Seven Controls That Still Work
Callback verification to a number you already hold
The single highest-value control. Hang up, ring back on the number in your records — never one the caller supplies. This works because the attacker controls the inbound call but not your contact list. Applies to everyone, including the owner.
Out-of-band confirmation on a different channel
If a call asks for something, confirm by a channel the caller did not choose — a message to a known mobile, a Teams message to their account, a face-to-face. Two contacts on channels the attacker controls is not corroboration.
Dual authorisation above a threshold
Any payment above an amount you set requires two named people. Removes the possibility of a single pressured individual being the whole control, and it is the reason well-run finance functions rarely lose money this way.
A standing rule on bank-detail changes
Supplier account changes are never actioned from a phone call or an email alone. Always verified by callback to a pre-existing number, and always by someone other than whoever received the request.
A shared verbal passphrase for genuine emergencies
Low-tech and remarkably effective. A word known to your leadership team and finance staff, never written in email, used when an unusual request genuinely must be made by phone. An attacker with a perfect clone of your voice still does not have it.
Never approve MFA or credentials by voice
Make it absolute: nobody from IT, your provider, your bank or your telco will ever legitimately ask a staff member to read out a code or approve a prompt during a phone call. No exceptions means no judgement calls.
Recording and transcription on the calls that matter
Not prevention, but it converts an incident from a contested memory into evidence — for your bank, your insurer and any investigation. It also lets you search whether the same pretext was tried on three other staff.
If you only do one thing this week
Write four sentences and send them to everyone: "Any request to move money, change bank details, reset a password or skip an approval must be verified by ringing the person back on the number already in our systems. This applies to requests that appear to come from me. You will never be criticised for doing it. If in doubt, do it." That message, from the owner, is worth more than a security platform.
How Your Phone System Becomes a Defence
Most of the controls above are process, not technology. But your phone platform does four things that materially change how well you can respond — and they only work if they were switched on before the incident.
| Capability | What it does for you | Why it has to be in place first |
|---|---|---|
| Call recording | Turns "I think he said..." into an artefact your bank, insurer and investigators can act on | You cannot retrospectively record a call that already happened |
| AI transcription & search | Lets you check whether the same pretext was attempted on other staff — how you spot a campaign, not an incident | Untranscribed audio is effectively unsearchable at volume |
| Centralised number screening & blocking | Block or flag a hostile number for the whole business in one change, rather than device by device | Per-handset blocking does not scale during a live campaign |
| Verified business identity outbound | Makes it harder for your brand to be used against your own customers | Sender identity registration is not an emergency lever |
Uniden Voice Over Cloud provides recording, AI transcription and centralised call controls as part of the platform on 100% Australian infrastructure, which also keeps the resulting evidence onshore under the Privacy Act 1988 rather than in a jurisdiction you then have to reason about mid-incident.
One thing not to rely on
Caller ID is not identity. A displayed number is metadata, not authentication, and it can be manipulated. Any process whose verification step is "the number matched" has no verification step. This is worth saying to your team explicitly, because a matching number is exactly the kind of detail that persuades a careful person to proceed.
The Other Half: Protecting Your Own Customers
Everything so far is about calls coming in. There is a second exposure that gets far less attention: your business being impersonated to your own customers.
If scammers can call your customers claiming to be you, or text them from something that looks like your brand, the damage lands on your reputation regardless of who was at fault. Australia has tightened significantly here, and the practical steps are not difficult.
Register your sender identity so your messages arrive attributed rather than carrying an "unverified" label — we cover the mechanics in how Uniden Voice fixes the unverified SMS problem as an ACMA-approved provider and the background in the "unverified" label and ACMA's sender ID changes. Tell your customers plainly, on your website and in your messages, what you will and will not ever ask for by phone. And make sure the story is consistent, because a customer who has been told "we will never ask for your password" has a rule to fall back on that survives a convincing voice.
The First Hour After a Suspected Attack
Print this and put it somewhere findable. The order matters, because two of these steps decay by the minute.
- If money has moved, ring your bank now. Before any internal discussion, before working out what happened. Recall prospects fall away by the hour.
- Preserve the evidence. The recording, the transcript, the number, the exact time, what was said, and any accompanying email or text. Do not delete anything, including things that feel embarrassing.
- Check whether others were targeted. Search your call transcripts and ask the team directly. These are campaigns far more often than single calls, and the second attempt may still be in progress.
- Reset any credentials discussed. Even if you believe nothing was disclosed. Cheap, fast, and removes a lingering unknown.
- Report it. Scamwatch, ReportCyber if there is a cyber element, and your insurer — notification windows are frequently shorter than businesses expect, and a late notification can affect a claim.
- Review without blame. This is the one that determines whether you find out about the next one. A staff member who fears consequences reports late, and late reporting is what turns a contained incident into a loss.
The One-Page Policy You Can Adopt Today
You do not need a security consultant to write this. Six lines will cover the overwhelming majority of realistic attacks. Adapt the amounts, circulate it, and mean it.
Voice request verification policy — draft
1. Any phone request to move money, change bank or payment details, reset credentials, approve a multi-factor prompt or bypass an approval must be verified by calling the requester back on a number already held in our systems.
2. Numbers supplied by the caller are never used for verification.
3. This applies to requests that appear to come from directors, owners and managers. No seniority exemption exists.
4. Payments above $[amount] require authorisation by two named people.
5. Supplier bank-detail changes are verified by callback and actioned by someone other than the person who received the request.
6. No staff member will ever be criticised, formally or informally, for applying this policy. Following it is doing the job correctly.
Line six is not filler. It is the line that determines whether the other five are ever used.
Where Australian Regulation Actually Helps
Australia has moved faster than most jurisdictions on scam prevention, and it genuinely helps — within limits worth understanding.
Under the Scams Prevention Framework, providers including telcos carry obligations to prevent, detect, disrupt and report scam activity, and that has improved blocking of high-volume scam traffic at the network level. Sender ID registration has made it materially harder to impersonate a business by SMS. We covered the detail in Australia's Scams Prevention Framework becomes law.
What none of that does is stop a single, well-researched call to your finance manager. Network-level controls are strong against mass campaigns and inherently weak against a targeted one, which is exactly why voice cloning is aimed there. The regulation reduces the volume of noise reaching your staff. Your internal verification rules are what stop the attack actually aimed at you.
The honest summary
Treat regulatory protection as the floor. Treat callback verification, dual authorisation and a culture where verifying the boss is expected, as the walls. Treat recording and transcription as the thing that lets you prove what happened. Nobody gets to skip the middle one.
Frequently Asked Questions
What to Read Next
Voice fraud sits at the intersection of telephony, security and Australian regulation. These cover the neighbouring ground.