The Voice You Trust Is No Longer Proof

The Voice You Trust Is No Longer Proof

In early 2024, a finance worker at Arup’s Hong Kong office received an email from the company’s UK CFO about a confidential transaction. Something felt off, and he reported it as phishing. Then came the video call. The CFO from the email was on it, plus colleagues he knew – their faces, their voices, talking to each other. That was enough to ease his ill feeling and to make fifteen transfers, roughly $25 million. Everyone on that call except him was a deepfake.

If you haven’t read about it before, the Arup deepfake fraud is one of the most significant real-world examples of AI-enabled social engineering to date.

Easy to write off this heist as a professional gig, requiring a highly skilled crew and a significant amount of money, but as time goes on and the barrier for entry falls in both complexity and required hardware, the focus is not just targets with $25 million lying around. Across 2025 alone, more than 274,000 Australians reported losing money to scams, totalling $2.18 billion.

As time goes on, deepfakes are more frequently reaching phones of ordinary people. It’s quietly invalidating the advice we were all taught.

It starts with “Hi Dad, it’s your favourite kid, dropped my phone down the sink, this is my new number.”

Then benign chit-chat for a day while you get comfortable speaking to the new number. The urgency comes later – a locked account, a deposit due today, urgent medical bills – and then comes the ask.

That’s what it was: a scam that couldn’t talk. They would stack the reasons why you couldn’t hear your child’s voice because the scam fell apart the moment you rang back. Which is why the advice never changed: hang up and call the person on the number you already had for them. Not clever, but it worked. The one thing the scammer couldn’t produce was thirty seconds of a familiar voice.

Now instead of a text, it’s a call – and it’s your kid. Their voice, live, responding to whatever you say. Arup and “Hi Dad” were always the same scam with different budgets, and that gap has largely closed. Voice cloning itself isn’t new. What’s changed is how little it needs. Fifteen seconds of decent audio. A voicemail greeting, an Instagram video, an uploaded podcast- Or simply answering a phone call. According to Scamwatch, scammers are increasingly using artificial intelligence to create convincing voice clones and deepfake videos to manipulate victims.

A quick web search will show you a marketplace full of companies that provide voice cloning and avatar generation. Platforms such as ElevenLabs and HeyGen have made high-quality AI voice and avatar technology widely accessible. Many of these services have safeguards, like requiring the person to be cloned to record a consent statement. Luckily, bad actors wouldn’t lie or fake something.

But in reality, it does not really matter, because none of this needs a hosted service or specialist company. Many models now run locally using free software and a standard home computer. So where does this leave us? An entire generation of people were told that if something feels off, get on the phone. When they do, they hear the voice they expected and end up more convinced than if they’d never checked. That’s exactly what happened at Arup- The email was flagged, the call talked them around.

So where does that leave us?

Awareness is becoming our strongest defence, because verification alone is no longer enough. If something feels off, or you have any doubt at all, remember that real-time imitation, that was once a dream is now trivial and accessible. There is nothing wrong with slipping in a question only that individual would know.

If you believe you’ve encountered a scam or want to better understand how modern scams operate, the National Anti-Scam Centre and Scamwatch provide practical advice, current alerts and reporting resources.

More Blogs

May 31, 2021

Upgrading from AppLocker to Windows Defender Application Control (WDAC)

Windows Defender Application Control (WDAC), formerly known as Device Guard, is a Microsoft Windows secure feature that restricts executable code, including scripts run by enlightened Windows script hosts, to those that conform to the device code integrity policy. WDAC prevents the execution, loading and running of unwanted or malicious code, drivers and scripts. WDAC also… Continue reading Upgrading from AppLocker to Windows Defender Application Control (WDAC)

Read More
cyber security companies | penetration testing | managed security service provider | cyber security consultant
June 22, 2021

Bypassing LSA Protection (aka Protected Process Light) without Mimikatz on Windows 10

Starting with Windows 8.1 (and Server 2012 R2) Microsoft introduced a feature termed LSA Protection. This feature is based on the Protected Process Light (PPL) technology which is a defense-in-depth security feature that is designed to “prevent non-administrative non-PPL processes from accessing or tampering with code and data in a PPL process via open process… Continue reading Bypassing LSA Protection (aka Protected Process Light) without Mimikatz on Windows 10

Read More
cyber security companies | penetration testing | managed security service provider | cyber security consultant
June 7, 2020

Using Zeek to detect exploitation of Citrix CVE-2019-19781

Using the tool Zeek, formally known as bro, is a high-level packet analysis program. It originally began development in the 1990s and has a long history. It does not directly intercept or modify traffic, rather it passively observes it and creates high-level network logs. It can be used in conjunction with a SIEM to allow… Continue reading Using Zeek to detect exploitation of Citrix CVE-2019-19781

Read More