Deepfakes, Voice Cloning, and the New Era of AI-Powered Social Engineering

Oct 7, 2026
Deepfakes, Voice Cloning, and the New Era of AI-Powered Social Engineering

A finance employee joins a video call with the company’s chief financial officer and several colleagues. Everyone looks and sounds exactly right. The CFO asks for a series of urgent, confidential transfers, and the employee follows instructions. Only later does the truth come out: everyone else on that call was an AI-generated deepfake.

That scenario is not hypothetical. It happened to global engineering firm Arup in early 2024, costing the company about $25 million. Deepfakes and AI voice cloning have opened a new chapter in social engineering, one where attackers no longer need to fake an email. They can fake a face, a voice, or an entire meeting.

This guide explains what deepfake scams and voice-cloning attacks are, how they work, real-world examples, warning signs to watch for, and how organizations and security professionals are fighting back.

What Is Social Engineering?

Social engineering is the practice of manipulating people into giving up information, money, or access. Instead of breaking through technical defenses, attackers exploit human trust, urgency, fear, and helpfulness. Understanding the psychology of hackers helps explain why these tactics work so well.

Classic social engineering includes phishing attacks, pretexting phone calls, and business email compromise (BEC), where criminals impersonate executives or vendors to request payments. What has changed is the toolkit. Generative AI now lets attackers produce convincing fake audio and video in minutes, making old scams far more believable.

What Are Deepfakes?

A deepfake is synthetic media, usually video, images, or audio, created or altered with artificial intelligence to make someone appear to say or do something they never did. The term combines “deep learning” and “fake.”

Deepfakes are built with deep learning models trained on real recordings of a person. Given enough sample footage, these models can map one person’s face onto another’s body, sync lip movements to new audio, or generate entirely new video of a target speaking. If you want to understand the technology behind these tools, our guide to generative AI vs. predictive AI is a good place to start.

Not every deepfake is malicious. The same technology powers film effects, dubbing, and accessibility tools. The security problem arises when it is used to deceive.

What Is AI Voice Cloning?

AI voice cloning uses machine learning to replicate a specific person’s voice, including their tone, accent, pacing, and speech patterns. Some modern tools can produce a usable clone from just a few seconds of recorded audio.

That audio is often easy to find. Executives speak on earnings calls, podcasts, webinars, and conference stages. Everyday people post videos to social media. Attackers collect these clips, generate a voice model, and then use it to make phone calls or leave voicemails that sound authentic.

Voice-based phishing, known as vishing, has existed for years. Voice cloning makes it dramatically more convincing because the caller no longer just claims to be the CEO. They sound like the CEO.

How AI-Powered Social Engineering Attacks Work

Most deepfake and voice cloning scams follow a similar playbook.

1. Target Research

Attackers identify who to impersonate and who to target. They study organizational charts, LinkedIn profiles, press releases, and social media to learn names, roles, relationships, and how money or data moves inside the company.

2. Data Collection

Next, they gather audio and video of the person they plan to impersonate. Public interviews, keynote recordings, and social posts provide raw material for training AI models.

3. Building the Fake

Using widely available AI tools, the attacker creates a cloned voice, a deepfake video, or both. Some attackers use real-time tools that alter their face and voice during a live call.

4. The Pretext

The attacker creates a believable scenario: a confidential acquisition, an overdue vendor invoice, a locked account, or a family emergency. Urgency and secrecy are almost always part of the story, because they discourage the victim from double-checking.

5. The Ask

Finally, the attacker requests something valuable, such as a wire transfer, gift cards, login credentials, a password reset, or access to sensitive systems. In some cases, the deepfake is only the first step, used to gain a foothold that leads to a larger breach or even a ransomware attack.

Common Types of Deepfake and Voice Cloning Scams

  • CEO and CFO fraud: Attackers impersonate senior executives to authorize urgent payments or share confidential data.
  • Vendor and invoice fraud: A cloned voice of a known supplier calls to “confirm” new banking details.
  • Help desk impersonation: Attackers call IT support pretending to be an employee and request a password reset or a new multi-factor authentication device.
  • Fake job candidates: Deepfake video is used in remote interviews so fraudulent applicants can be hired and gain insider access.
  • Government official impersonation: Fake messages from officials build trust and steal credentials or information.
  • Family emergency scams: A cloned voice of a relative claims to be in trouble and needs money immediately.
  • Identity verification bypass: Synthetic faces and voices fool biometric checks at banks and online services.

Real-World Deepfake Attacks

The $25 Million Deepfake Video Call

In January 2024, an employee in the Hong Kong office of engineering firm Arup was invited to a video conference that appeared to include the company’s UK-based CFO and other colleagues. All of them were deepfakes. Convinced the meeting was real, the employee made multiple transfers totaling about HK$200 million, or roughly US$25 million, to five bank accounts. The fraud was discovered only after the employee followed up with company headquarters. (CFO Dive)

The case is a turning point because it showed that seeing a familiar face on a live video call is no longer proof of identity.

AI Voice Messages Impersonating U.S. Officials

In May 2025, the FBI warned that malicious actors had been sending text messages and AI-generated voice messages that impersonated senior U.S. officials. The campaign targeted current and former federal and state officials and their contacts, aiming to build rapport before directing victims to malicious links or requesting information. The FBI advised people not to assume such messages are authentic and to verify the sender independently. (AHA News)

Why Deepfake Scams Are So Effective

  • They exploit trust in our senses. People have learned to doubt suspicious emails but still trust what they see and hear.
  • They create urgency. Pressure to act quickly overrides normal caution.
  • They target authority. Few employees want to question a request that appears to come from a senior leader.
  • The tools are cheap and accessible. Creating a convincing fake no longer requires advanced skills or expensive equipment.
  • Detection is hard. Deepfake quality improves constantly, and real-time calls leave little time for careful analysis.

Warning Signs of a Deepfake or Cloned Voice

Deepfakes are getting harder to spot, but these red flags still help:

  • Unusual urgency, secrecy, or pressure to bypass normal procedures
  • Requests involving money transfers, gift cards, credentials, or changes to payment details
  • Contact through an unexpected channel or a new phone number
  • Video glitches around the face, mouth, hairline, or eyes, especially when the person turns their head
  • Lip movements that do not quite match the audio
  • Flat emotion, odd pauses, or robotic phrasing in voice calls
  • Reluctance to answer personal questions or switch to a different communication channel
  • Poor call quality offered as an excuse for strange behavior

The most important warning sign isn’t technical: any request that could cause real harm if it turns out to be fake deserves independent verification.

How Organizations Defend Against AI-Powered Social Engineering

No single tool stops deepfake fraud. Strong defense combines process, people, and technology.

Verify Through a Separate Channel

The most effective control is out-of-band verification. If a request arrives by phone, video, or email, confirm it using a known, trusted contact method, such as calling back a number from the company directory. Never use contact information provided in the suspicious message.

Require Multi-Person Approval for Payments

Require multi-person approval for high-value transfers and changes to banking details. Dual authorization makes it far harder for a single deceived employee to cause major losses.

Use Code Words and Challenge Questions

Some organizations and families agree on private code words or verification questions that a deepfake would not know.

Strengthen Help Desk Procedures

IT help desks should follow strict identity verification steps before resetting passwords or enrolling new authentication devices, regardless of who is calling or how urgent the request sounds.

Adopt a Zero Trust Mindset

A zero trust security model assumes no user or request is trustworthy by default. Applied to people and processes, that means verifying identity and authority before acting, every time.

Train Employees on AI-Driven Threats

Security awareness training should now include deepfake and voice cloning scenarios, not just phishing emails. Employees who know these attacks exist are far more likely to pause and verify.

Limit Public Exposure

Organizations can reduce risk by reviewing how much executive audio and video is publicly available and by being thoughtful about what employees share online.

Use Detection Technology

Deepfake detection tools, liveness checks, and AI-driven anomaly detection can help flag synthetic media and unusual behavior. These tools work best as one layer within a broader security strategy. Learn more about how data analytics, AI, and machine learning support cybersecurity.

The Bigger Picture: AI on Both Sides of Cybersecurity

Deepfakes are one example of a larger shift. Attackers are using AI to write more convincing phishing messages, automate reconnaissance, and scale fraud. Defenders are using AI to detect threats faster, analyze huge volumes of data, and respond automatically.

That makes AI literacy an essential skill for today’s security professionals. Our article on AI in cybersecurity covers how the field is changing, and our guide to securing AI and machine learning assets explains how organizations protect the AI systems they deploy.

Cybersecurity Skills and Certifications for Fighting AI-Driven Threats

Organizations need professionals who understand both traditional social engineering and the new AI-powered variants. Roles such as security analysts, SOC analysts, fraud investigators, and security awareness specialists are on the front lines. Explore the full range of cybersecurity jobs to see where these skills apply.

These certifications help build the right foundation:

CIAT’s Unlimited Certification Exam Retake Policy covers all CompTIA certifications, including Security+, CySA+, and SecAI+. The policy excludes CISSP and EC-Council CEH.

Prepare for AI-Powered Threats at CIAT

Deepfakes and voice cloning are changing how attackers operate, and organizations need security professionals who can keep up. CIAT’s cybersecurity programs build skills in threat detection, incident response, and AI security, with industry certifications built into your coursework.

Already working in security? The 5-day CompTIA SecAI+ Bootcamp prepares you to defend against AI-driven threats and secure the AI systems organizations rely on, with live online instruction and hands-on labs. Newer to the field? Start with the CompTIA Security+ Bootcamp.

Frequently Asked Questions About Deepfake Scams and Voice Cloning

What is a deepfake scam?

A deepfake scam uses AI-generated video, images, or audio to impersonate a real person, usually to trick victims into sending money, sharing credentials, or granting system access.

How does AI voice cloning work?

AI voice cloning uses machine learning models trained on recordings of a person’s voice. Once trained, the model can generate new speech that mimics that person’s tone, accent, and speaking style. Some tools need only a few seconds of audio.

Can deepfakes be used in live video calls?

Yes. Real-time deepfake tools can alter an attacker’s face and voice during a live call, as attackers did when they impersonated an Arup executive and other employees in a video conference that led to a roughly $25 million loss.

How can you tell if a voice call is AI-generated?

Listen for flat emotion, unnatural pauses, odd phrasing, or audio that sounds slightly too clean. The most reliable test is to hang up and call the person back on a number you already know is legitimate.

What is vishing?

Vishing, or voice phishing, is a social engineering attack carried out over the phone. AI voice cloning makes vishing more dangerous because attackers can sound exactly like a trusted person.

Who is most at risk from deepfake scams?

Finance teams, executive assistants, IT help desks, HR departments, and anyone who can approve payments or reset access are prime targets. Scammers also target individuals through family emergency scams.

Can deepfake detection tools stop these attacks?

Detection tools help, but they are not perfect, and attackers keep improving. The strongest defense combines detection technology with verification procedures, multi-person approvals, and employee training.

What should you do if you suspect a deepfake scam?

Stop the interaction, do not send money or information, and verify the request through a separate trusted channel. Report the incident to your security team and, if needed, to law enforcement or the FBI’s Internet Crime Complaint Center (IC3).

Is creating a deepfake illegal?

Creating synthetic media is not automatically illegal, but using deepfakes for fraud, impersonation, harassment, or non-consensual content can violate a growing number of laws. Rules vary by state and country.

What cybersecurity certifications cover AI-powered threats?

CompTIA Security+ covers social engineering fundamentals, CompTIA CySA+ covers threat detection and response, and CompTIA SecAI+ focuses specifically on AI security and AI-driven threats.

California Institution

401 Mile of Cars Way #100, National City, CA 91950

New Mexico Institution

1717 Louisiana Blvd., NE., Suite 208 Albuquerque, NM, 87110

California Institute of Applied Technology participates in the State Authorization Reciprocity Agreements.

California Institute of Applied Technology Logo

© 2026 California Institute of Applied Technology | info@ciat.edu | (877) 559 - 3621 | Privacy Policy

California Institute of Applied Technology has shared ownership and management of two distinct institutions. California Institute of Applied Technology located in California, and California Institute of Applied Technology located in New Mexico.

GI Bill® is a registered trademark of the U.S. Department of Veterans Affairs (VA). More information about education benefits offered by VA is available at the official U.S. government website at https://www.benefits.va.gov/gibill. CIAT is approved to offer VA benefits. Financial aid is available for those who qualify.

* Students are encouraged to take certification exams while actively enrolled in their Bootcamp, Certificate or Degree program. Unlimited certification exam attempts expire 180 days after program completion. Select exams are not eligible for unlimited retakes - see certification exam policy for details. Industry certifications and/or courses may change at any time to address industry trends or improve student outcomes.