AI voice cloning: How Criminals Borrow Trust 

Author: Samuel Watterson

In February 2025, several of Italy's best-known families received telephone calls that appeared to come from government offices in Rome. An official explained that Italian journalists had been kidnapped in the Middle East and that their release depended on an urgent payment. He then passed the call to the Defence Minister, Guido Crosetto, who asked for help and explained that the government could not be seen to make the payment itself. 

The voice was not actually the minister's and had been produced using artificial intelligence to imitate him (known as 'voice cloning'). Giorgio Armani and the Prada co-founder Patrizio Bertelli were among those approached, as were the Beretta and Aleotti families. Most of those approached did not make the requested payment. Massimo Moratti, the former owner of Inter Milan, was one who did, sending two payments totalling nearly one million euros. He said afterwards that the callers had been very convincing and that anyone could have been taken in. 

Mr Moratti reported the matter promptly, and within days the police had traced the money to an account in the Netherlands and frozen it completely. He credited the speed of his complaint with making the recovery possible. 

How these calls work 

A convincing copy of someone's voice can now be made from a short recording, sometimes only a few seconds long, and anyone with a public life leaves far more than that: interviews, speeches, investor presentations, a video shared at a family celebration. Though the voice is only part of the method, as the calls in Italy relied on authority the listener had no reason to question, and with a reason why it had to be both quick and confidential. 

Take away the urgency and the secrecy, and the voice alone achieves very little. The arrangements we suggest below are designed to do exactly that. 

It is happening now 

In January 2026, police in the canton of Schwyz reported that a Swiss business owner had been telephoned by someone posing as a long-standing business partner. The caller's voice had been imitated using artificial intelligence, and the pretext was a confidential international transaction. The owner made several transfers, worth several million francs in total, to an account in Asia and the fraud came to light only after the money had already gone. 

In its most recent annual report, published in April 2026, the FBI recorded fraud involving artificial intelligence as a separate category for the first time. It received 22,364 such reports from victims in the United States during 2025, with losses of over 893 million dollars. The figures cover every kind of fraud involving artificial intelligence, of which cloned voices are one. 

The people who act on your behalf 

These calls often go to the people who act on someone's instructions, rather than to that person directly. 

In January 2020, a branch manager at a Japanese company took a call from a director of the parent company, whose voice he recognised. The director explained that an acquisition was under way and that a lawyer would coordinate a series of transfers. Supporting emails from the director and the lawyer arrived as expected. The manager made transfers of around 35 million dollars. Investigators in Dubai later established that the director's voice had been cloned, and that he had made no such call. 

In early 2024, an employee in the Hong Kong office of the engineering firm Arup joined a video call with the company's chief financial officer and several colleagues. Every other face and voice on the call had been generated. He made fifteen transfers totalling 25.6 million dollars. 

Wherever one person's word is enough to move money or release a document, the people who act on it are the ones a fraudster most needs to persuade. It might be a family office with a dozen staff, a business, or someone in the public eye who relies on a single assistant. 

Money is not always what the caller asks for, as a copy of a sensitive document or details of someone's travel can be just as valuable to a fraudster. The information may be sold, or kept to make the next approach more convincing. 

What has stopped these attempts 

Not every attempt succeeds, and two failed attempts in 2024 made the news. In the first, fraudsters set up a video meeting in which they imitated Mark Read, the chief executive of the advertising group WPP, and another senior executive. His colleagues were not persuaded, and the company credited their vigilance with preventing any loss though without providing details of what made them suspicious. In the second example, an unnamed executive at Ferrari received a call from someone imitating the chief executive, Benedetto Vigna. After becoming suspicious, he tried to verify the callers identity by asking which book Mr Vigna had recently recommended to him. The caller rang off. 

In both cases the voices were good enough to begin a conversation, while in the second example, someone stopped the fraud by checking something the caller could not have prepared for. 

Arrangements that hold 

We would suggest that every family, office and household, however small, agrees a few arrangements in advance. None of them should depend on recognising a voice. 

The first is that any unusual or urgent request involving money or sensitive information is confirmed by calling back on a number you already hold, never one supplied during the originating call. The second is a private word or question, agreed in person and known only to the family and those closest to it, which anyone may ask for before acting. For larger sums, two people should approve a payment rather than one. 

These arrangements only work if everyone who might be called knows about them. That includes household staff, relatives, and anyone in the office who handles your information or the information of those you work with. It also means making clear that no one will be criticised for pausing to check, however senior the voice on the line appears to be. 

We help families, offices and individuals put these arrangements in place. If you would like to talk about your own, get in touch today.

About the author  

Samuel Watterson is a coc00n Cyber Security Advisor with a legal background in commercial litigation. With sharp analytical skills and the ability to distil complex issues into clear, actionable advice, Samuel helps individuals and organisations strengthen their cyber security posture. 

Next
Next

Before You Post: What’s Changed About Sharing Photographs of Children Online