Voice cloning is the cheapest convincing attack available today. A few seconds of someone speaking — a voicemail greeting, a conference talk, a story posted to social media — is enough to build a model that says anything in their voice, in real time, on a phone call.
The usual target is a finance team, a family member or a help desk. The script is always urgent, always involves a payment or a credential, and always gives a reason why you cannot verify through the normal channel. Here is what actually helps.
What to listen for
Breathing in the wrong places
People breathe where meaning breaks: after a clause, before a new thought. Synthetic speech either inserts breath on a fixed rhythm or leaves it out entirely, so long sentences arrive with no pause for air. If someone talks for twenty seconds without taking a breath, that is not stamina.
Emotion that lands a beat late
Cloned voices carry the timbre of a person very well and their timing badly. Urgency sounds like a flat sentence read slightly faster, not like a voice tightening. Laughter is the hardest thing of all to fake; a real laugh disrupts the breathing pattern for several seconds afterwards.
A noise floor that is too clean, or loops
Every real recording has a room in it: a hum, traffic, a fridge, the hiss of the microphone itself. That background is continuous and never repeats. Synthetic audio is often perfectly silent between words, or has a background that resets in a short loop. Listen to the gaps rather than the words.
Seams between sentences
When an attacker assembles a message from separately generated pieces, the joins show as tiny changes in level, brightness or room tone at sentence boundaries. Loudness that steps rather than drifts is a strong indicator of splicing.
Pronunciation slips
Uncommon names, local place names and technical terms are where clones stumble. So is code-switching — someone who normally shifts accent slightly on a foreign word will not do so if the voice is generated.
What to do while you are still on the call
- Hang up and call back on a number you already had, not one you were given in the call. This single habit defeats almost every voice-clone scam.
- Ask something only the real person knows — not a fact that is on LinkedIn. "What did we agree at the end of Tuesday's call?" is good. "What is your date of birth?" is useless.
- Introduce an interruption. Ask them to count backwards from twenty, or to repeat a nonsense phrase. Real-time systems handle unscripted, rhythm-breaking tasks poorly.
- Refuse urgency. No legitimate payment, password reset or account change collapses because you waited ten minutes to confirm it another way.
- Record it if your jurisdiction allows. A recording is the only thing you can analyse afterwards.
Checking a recording afterwards
If you have the audio, an automated check adds signals your ears cannot reach: the spectral envelope of synthetic speech, the statistics of the noise floor, discontinuities at splice points, and container metadata showing which app produced the file. A multimodal model then listens to the clip and reports concrete observations rather than a bare score.
Two practical rules:
- Use the original file. A recording forwarded through a messaging app has been re-encoded, and re-encoding erases exactly the fine detail that matters.
- Use the longest clean stretch. Ten seconds of uninterrupted speech is worth more than a minute of crosstalk.
If money has already moved
Speed matters more than certainty. Contact your bank's fraud line immediately, then preserve the evidence: the original audio file, any numbers involved, the exact times. Hash the recording so you can prove it has not changed since you received it, and keep an append-only record of who touched it. Banks, insurers and police all treat a properly preserved file very differently from one that has been emailed around an office.
Building this into a process
Individuals defend themselves with the call-back habit. Organisations need something stronger: a rule that no payment instruction is ever executed on voice authority alone, a shared code word for the finance team, and a place to submit suspect recordings that produces a documented result rather than an opinion in a chat thread.
You can test a recording below, or open the AI voice detector. If the call also came with video, our deepfake video guide covers what to watch for there.