The phone call is fake and it sounds exactly like your boss

The phone call is fake and it sounds exactly like your boss

The tell-tale signs of a scam used to be easy: broken grammar, a strange address, urgency that did not fit. Generative AI removed all three.

In 2026, 87% of security professionals report encountering AI-enabled attack tactics, concentrated in phishing, fraud and social engineering. Deepfake audio and video have become simultaneously more convincing and more accessible — a usable voice clone now needs only a few seconds of public audio, and most people in a public-facing role have posted far more than that.

The attack that works is not technically sophisticated. It is a short call from a familiar voice, asking for something ordinary and slightly urgent: approve this transfer, read me the code you just received, send the client list before the meeting.

What actually stops it:

  • A verification channel agreed in advance. Hang up and call back on the number you already have. A cloned voice cannot control the callback.

  • A rule with no exceptions for seniority. Fraud works precisely because nobody wants to make the director wait.

  • Phishing-resistant MFA. A code read aloud over the phone is a code stolen. Passkeys and hardware keys cannot be recited.

  • A no-blame reporting path. People who fear looking stupid report incidents late, which is when they become expensive.

The technology defending you has not changed. What changed is that you can no longer trust that a voice belongs to the person it sounds like.