TL;DR: AI voice cloning has made phishing calls dangerously convincing — and UK businesses are in the firing line.
As part of our ongoing threat research, we’ve been tracking a trend that we think every business owner needs to hear about — AI voice cloning. The technology has moved fast, and what was science fiction two years ago is now an off-the-shelf criminal tool. We’re flagging it now because the businesses that prepare early are the ones that don’t make the headlines later.
Alarmingly convincing. Modern voice-cloning tools need only a few seconds of audio to build a working copy of someone’s voice — complete with their accent, tone and speech patterns. And that audio is rarely hard to find. A clip from a company webinar, a LinkedIn video, a podcast appearance or a conference recording is more than enough.
In other words, if your managing director has ever spoken publicly online, their voice can be cloned. The National Cyber Security Centre’s assessment of AI’s impact on the cyber threat is blunt about where this is heading: AI will almost certainly increase both the volume and impact of cyber attacks, with more convincing social engineering leading the way.
It looks like an ordinary phone call. A member of your finance team gets a call from “the director” — same voice, same manner — asking for an urgent supplier payment before end of day. There’s pressure, there’s a plausible story, and there’s a voice they recognise. That’s the whole attack.
This isn’t hypothetical. In one of the most widely reported cases, an employee at the engineering firm Arup transferred around £20 million after joining a video call where every other “colleague” — including the CFO — was an AI-generated deepfake, as covered by the World Economic Forum.
Criminals stole almost £1.3 billion through payment fraud in 2025 — with AI-powered tools including deepfakes, cloned voices and synthetic identities used to impersonate trusted people. — UK Finance Annual Fraud Report 2026
The government’s own data shows the scale of the problem. According to the Cyber Security Breaches Survey 2025/26, 43% of UK businesses — around 612,000 companies — experienced a cyber breach or attack in the last 12 months. Phishing was the most prevalent attack type, hitting 38% of businesses, and 69% of those affected rated it the most disruptive threat they faced.
Phishing isn’t declining — it’s evolving. The dodgy email full of spelling mistakes is being replaced by a phone call in a voice you trust. Your team can’t rely on “spotting the fake” any more, which means your defences have to assume that, one day, someone will be fooled.
This is exactly the scenario Cyber Essentials exists for. Its five core controls — access control, secure configuration, firewalls, malware protection and security update management — are designed to limit how far an attacker can get once they’re through the door. If a cloned voice tricks one employee, properly enforced access controls and multi-factor authentication can be the difference between a near miss and a full breach.
Yet uptake remains remarkably low. The same government survey found only 5% of UK businesses currently hold Cyber Essentials certification — and just 17% are even aware of the scheme. That’s a huge gap between the threat and the protection.
Here’s the part we flag with every client: Cyber Essentials is not a certificate to frame and forget. If you answer the questionnaire generously in March and let your controls drift by June, you have the worst of both worlds — a false sense of security, and a compliance position that won’t stand up to scrutiny after a breach.
Genuine compliance means the controls are actually running, day in and day out — patches applied, access reviewed, MFA enforced. That’s also what insurers, regulators and your own clients increasingly expect to see evidenced after an incident. A certificate that doesn’t reflect reality can leave you in a worse situation than having no certificate at all.
Start with the human layer. Put a verification procedure in place for any payment or credential request made by phone or video — a call-back on a known number, or a second sign-off, no matter how senior the voice sounds. Urgency is the attacker’s favourite weapon, so build in a pause.
Then make sure the technical layer holds when the human layer slips. Our managed cyber security service keeps monitoring, patching and incident response running continuously, and our fully managed Cyber Essentials service takes you from gap assessment through to certification — and keeps you genuinely compliant between renewals, not just on submission day. If you’re not sure where you stand today, our free business security risk assessment is a sensible first step.
AI voice cloning isn’t a future problem — it’s a today problem, and it’s precisely why we keep researching and flagging these threats before they reach your phone lines. The businesses that treat security as an ongoing discipline, rather than an annual checkbox, are the ones that will take this new wave of phishing in their stride.