Desk live·
ForensicPost
AI/Fraud/File 26-0421

Voice Cloning Now Standard in Executive Impersonation Fraud

Voice cloning has become a standard component of executive impersonation fraud. Every control that depends on recognising a person by how they sound is now obsolete.

Constructed geometry · not a chart of case data
TargetCorporate finance functions
ActorMultiple
S. Rosler11 min readConfidence: medium3 sources reviewed

Voice cloning is now routine in executive impersonation fraud, with real-time deepfake calls reported against finance functions and documented losses in the billions. One analysis puts global documented deepfake fraud losses at a minimum of $3.7 billion, and reporting describes AI voice and vishing volumes exceeding a thousand calls a day at major retailers.

A Recognisable Voice Was Always The Real Control

Payment authorisation procedures have long carried an unwritten backstop: if something looked wrong, someone would telephone the executive and recognise them.

That backstop is gone, and its removal is more consequential than the written procedures it sat behind, because it was the one people actually relied on when a request was unusual.

Executives Are The Easiest Voices To Clone

The material required is a few minutes of speech. A chief executive has earnings calls, conference keynotes, podcast appearances and promotional video — all published deliberately, by the organisation, for good reasons.

The seniority that makes an impersonation effective is the same seniority that makes the source material public. There is no remediation available on that side of the problem.

What Still Works

Callback to a number from an internal directory rather than one supplied on the call. Authorisation that requires a second person acting through a different channel. Payment changes that cannot be actioned on a single verbal instruction regardless of who appears to be giving it.

Each is procedural rather than technological, and each fails for the same reason: they are inconvenient for the most senior person in the organisation, who is also the person the control exists to protect against being impersonated.

How we reported this

This is a technique file compiled from published research and reporting, listed below. Loss figures are analyst estimates built from public incident databases and vary by methodology. Corrections: corrections@forensicpost.com.

Sources
  1. Voice cloning is the new BEC: deepfake CEO fraud in the USCybelAngel
  2. Deepfake fraud in 2026: the $3.7B problem and how to defendBrightside AI
  3. Deepfake CFO scam: how real-time attacks work in 2026DualMedia
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary