The Voice on the Phone Wasn't Real
The oldest fraud in the book, a fake instruction from someone in authority, got a significant upgrade in this case. The voice on the phone was not a stranger pretending. It was a machine pretending to be someone real.
What Happened
In 2019, the head of a UK-based energy firm received a phone call that sounded, in every respect, like his German parent company's chief executive. The voice instructed him to urgently wire funds to a Hungarian supplier, citing time pressure and confidentiality. He complied.
The Damage Caused
Approximately $243 000 (roughly £200 000) moved to the fraudsters' account before anyone realised the call had never come from the real CEO at all. It is reported as one of the first known criminal uses of AI-generated voice cloning for financial fraud, a milestone that mattered less for the amount stolen than for what it demonstrated was now possible.
What Caused the Breach
No device was hacked and no password was stolen. The fraud combined AI voice-cloning technology, built from recordings of the real CEO's voice, with a familiar business email compromise pattern: urgency, invoked authority and an unusual but plausible payment instruction. The phone itself worked exactly as intended. The voice on the other end was the only thing that was fake. In 2019, that alone was still novel enough to catch an experienced executive off guard.
What Could Have Been Done to Avoid the Issue
The specific defence against this attack has not changed since 2019, even as the technology behind it has become dramatically more convincing and accessible. Any unusual or time-pressured payment instruction, regardless of how familiar the voice or face behind it sounds, should be verified out-of-band: a callback to a known number (not one provided by the caller) or confirmation through a separate channel entirely before funds move.
Staff who handle payments should be trained on the specific assumption that voice and video can now be forged convincingly, not as a hypothetical future risk but as a routine part of assessing any unexpected financial request. Given how far voice-cloning tools have advanced since this case, that training is arguably more urgent now than it was in 2019.
Every security measure involves a trade-off between protection and convenience. Where that balance should sit depends on the resources a realistic attacker would bring to bear against you specifically. For most people, a handful of consistent habits closes the majority of that gap. For those whose assets or profile make a determined, well-funded attacker plausible, a more considered approach becomes worth the investment.
At Executive Privacy Advisors, we build that approach around your specific threat profile rather than a generic checklist. We extend the same thinking to your whole household, not just one set of accounts.
Need your digital life secured?
Request an AssessmentPublished by Executive Privacy Advisors.
This article is for general informational purposes only and does not constitute security, legal or risk advice. Services described are subject to assessment, licensing and availability in your area. Your circumstances may differ and you should seek a professional assessment before making decisions.