Deepfake and voice cloning

What is a deepfake and a voice clone?

A deepfake is video, image or audio that AI generated or altered so it looks and sounds like a real person, place or event, and that someone would take for genuine. Article 3 of the EU AI Act puts it in almost those words: a deep fake is "AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful".

A voice clone is the audio half. You give a model a recording of someone speaking and it produces new speech in that voice, saying whatever you type or whatever you say into a microphone. The video half either swaps a face onto a recorded clip or drives one live during a call.

What catches people out is how little source material this takes. ElevenLabs tells its own users that one to two minutes of clean audio is enough for an instant clone, and that some people get excellent results from thirty seconds. Your voicemail greeting is that sample. So is a podcast appearance, a webinar recording, or the video on your company page. Nobody has to break into anything to get it.

The AI Act also puts a labelling duty on whoever publishes a deepfake, in Article 50, which has its own entry here. That duty governs honest use. This entry is about the criminals, who were never going to label anything.

What is easy to fake and what is still hard

Recorded audio is the easy end. A voice message on your phone, thirty seconds of your managing director asking you to call back about something confidential: there is nothing to interact with, so there is nothing to catch.

Live video on a call takes more effort, but it does not have to be flawless. It has to be good enough for someone who is already half-convinced by a plausible email that arrived first.

The real limit is not the picture, it is the script. The attacker controls what the fake says, not what it knows. A cloned voice cannot tell you what the two of you argued about in Tuesday's meeting, and a face on a screen cannot answer a question nobody anticipated. So every check that works is an interactive one. Looking harder at the image is not a check, and we would not build a small company's defence on a detection tool.

How the fraud runs in practice

CEO fraud and payment redirection. Febelfin describes the classic version: someone impersonates the CEO or another person of trust to push an employee into a payment or into handing over information, with urgency and secrecy doing the work. A cloned voice removes the one check that used to break the scam, which was picking up the phone.

The case worth knowing is Arup. In January 2024 an employee in the British engineering firm's Hong Kong office received a message about a confidential transaction and suspected phishing. Then he joined a video call on which the CFO and several colleagues looked and sounded like themselves. All of them were generated. He made fifteen transfers to five Hong Kong bank accounts in one day, around 200 million Hong Kong dollars, roughly 25 million US dollars. The fraud came out when he followed up with head office. Hong Kong police reported the case in February 2024 and Arup confirmed in May that it was the victim.

Voice alone was enough before video was. Europol's 2022 report on deepfakes cites a case in which criminals used deepfake audio to impersonate a company director and had a bank move 35 million US dollars.

Invoice fraud. The letter announcing a supplier's new account number is an old trick. What is new is that the phone number printed on it now works. You call to verify, a familiar voice confirms the change, and you have just used one fake to validate another.

Voice authentication. In March 2023 a journalist at Guardian Australia cloned his own voice from four minutes of audio and used it, together with his customer reference number, to get into his own Centrelink self-service account. The same voiceprint technology was in use at the Australian tax office and at several banks. A voice says who you are. It is not a password.

Belgium is in this too. Febelfin's 2026 action plan on online fraud puts the phishing losses of 2025 at 93 million euros and says outright that fraudsters are trading mass phishing for targeted attacks built on AI and deepfake voices.

Deepfake fraud versus classic phishing

The two look like one crime with a new tool. They are not, because they ask the victim to believe different things.

Phishing asks you to believe an artefact is genuine: this email, this login page, this link. The forgery is a document, so the checks are document checks. Look at the sender domain, hover over the URL, notice the phrasing that is slightly off. Everything people have been trained on for years is about examining a thing.

Deepfake fraud asks you to believe a person is present. There is no document to examine. The forgery is the evidence of identity itself, and the senses you would normally check it with are exactly what has been reproduced. Examining harder makes it worse: the Arup employee's doubts went away after the video call, not before it.

So the control has to move. Against phishing you inspect the message. Against a deepfake you leave the channel entirely and confirm somewhere the attacker does not control.

What to put in place this week

  1. Call back on a number you already had. Any request to change a payment, an account number or a beneficiary gets verified on the number in your own contact list, not one from the message and not by staying on the call. Febelfin gives exactly this advice, and it is the one control that breaks both the Arup pattern and most invoice fraud.

  2. Agree a code word. One word, known to the handful of people who can authorise money, shared in person and never written down in email or Teams. Any urgent and confidential request has to include it. The FBI gives households the same advice, and it works in a company for the same reason: the attacker has the voice but not the word.

  3. Two people for every change of bank details. Not two signatures held by one person, which Febelfin warns about separately. The second person calls the supplier back and knows why they are calling.

  4. Say out loud that a voice and a face are not proof. Write it into the payment procedure. An employee who breaks a rule because the CEO was visibly on the screen is behaving reasonably given the training, which means the training is the problem.

  5. Train with a real case. Fifteen minutes on the Arup story in a team meeting does more than a slide deck. Then give people permission out loud: nobody is ever in trouble for delaying a payment by twenty minutes to make a call.

If it already happened

Speed decides whether the money comes back. Call your bank's fraud line straight away, or Fraudstop on 078 170 170, the single number Febelfin and the federal government launched in June 2026 to block payment cards and access to online and mobile banking in one call. File a police report; your insurer and your bank will ask for it. Forward the message that carried the approach to verdacht@safeonweb.be, the reporting address of the Centre for Cybersecurity Belgium.

When your own company is the one being faked

The other direction costs you customers instead of cash. Someone lifts your founder's face from a conference video and runs ads with it, or puts a phone number that reaches them where your support number should be.

This is happening in Belgium at scale. In June 2025 VRT NWS found YouTube ads in which its own news anchor Wim De Vilder and financial journalist Paul D'Hoore appeared to recommend an investment platform, built from four-year-old footage with generated voices and altered mouth movements. In the second half of 2025 alone, Belgian consumers reported more than 23 million euros of investment fraud losses to the FSMA. The trusted-number trick is here as well: Febelfin has had to state publicly that Card Stop never calls cardholders, because criminals were calling in its name.

What you can do about it is mostly dull. Search your own brand and your own name on the ad platforms now and then. Report what you find through the platform's impersonation form, which moves faster than a lawyer's letter. Put the real phone number and the real domain in one obvious place on your site and send people there. When someone reports a fake to you, say so on your own channels the same day, because a correction only works if it travels faster than the ad. Save the URL and screenshots first, because the platform takes down the evidence you may want for a police file.

Last Updated: September 3, 2026 Back to Dictionary
Keywords
deepfake voice cloning ceo fraud invoice fraud payment fraud social engineering transparency obligation ai act generative ai synthetic data multimodal model phishing