Deepfakes, Voice Cloning and Social Engineering at Scale

The oldest attack in security is convincing a person to do something they should not, and AI has just made it far more effective. Deepfake video, cloned voices and AI-generated text mean an attacker can now impersonate a specific, trusted individual convincingly and at scale — the executive on the video call, the CEO’s voice on the phone, the supplier’s email in their exact style. Social engineering was always the weak point; synthetic media removes the tells that used to give it away, which turns a known risk into a sharper and more urgent one.

Why this is different from old-fashioned fraud

Traditional impersonation fraud relied on the target not looking too closely — a slightly-off email address, an unusual request, a voice that did not quite sound right. Those tells are disappearing. A cloned voice can sound like the real person; a deepfake can put a familiar face on a video call; AI-generated text can match someone’s writing style. The defences that depended on a human noticing something wrong are undermined, because increasingly there is nothing obvious to notice. And the effort required to produce a convincing fake has collapsed, so this is no longer reserved for high-value targets — it scales.

Where firms are actually exposed

  • Payment authorisation. The classic and costly one: a convincing call or message from a “senior executive” instructing an urgent payment. If your controls rely on recognising the person, they are exposed.
  • Credential and access requests. An impersonated colleague or IT contact persuading someone to hand over access or reset a credential.
  • The executive as target and as weapon. Senior people are both prime impersonation subjects (their voice and face are often public) and high-value targets, which makes them a specific exposure.
  • Supplier and partner impersonation. Fraudulent changes to payment details, convincingly delivered as if from a real supplier.

Defending when you cannot trust your senses

The key shift is to stop relying on human detection and rely instead on process — controls that do not depend on whether the voice or face was real.

Free · 4 minutes

Is your engineering team shipping safely, or quietly accumulating risk?

Fourteen questions on how work gets from idea to production — cadence, testing, rollback, and the key-person risk in your delivery. Banded finding on screen, full sheet by email.

  • Verify through a separate channel. Any sensitive request — a payment, a detail change, an access grant — should be confirmed via an independent, pre-agreed channel, not the one the request came in on. This defeats impersonation regardless of how convincing it is.
  • Build process that assumes the person might be fake. Payment and access controls should not hinge on recognising the requester; they should require verification that a fake cannot satisfy.
  • Train people on the new reality. Staff need to know that a familiar voice or face is no longer proof, and that the safe response to an urgent, unusual request is to verify, not to comply quickly.
  • Reduce the exposure of executives. Where feasible, limit the public material an attacker can use to clone a voice or face, and make senior people aware they are targets.

Synthetic media has industrialised the oldest attack in the book, and no amount of alertness will reliably catch a good fake. The firms that stay safe are the ones that move their defences from “will someone spot it?” to “does our process require verification that a fake cannot provide?” — because the only reliable defence against not being able to trust your senses is not having to.

Who this is for

This reading is for:

  • Boards and executives who are themselves the target
  • CISOs whose controls assume a human can spot a fake
  • Finance teams that authorise payments on a call or an email
  • Firms whose fraud defences predate convincing synthetic media

Sixteen Pillars helps firms move payment and access controls from can-someone-spot-it to process that requires verification a convincing fake cannot provide. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming