Your accounts manager gets a phone call. The voice on the other end sounds exactly like you. Same tone, same speech patterns, same slight pause before asking a question. The caller says they need an urgent payment processed before a supplier deadline. The accounts manager does what any trusted employee would do. They make the transfer.
Except you never made that call. An attacker did, using an AI-generated clone of your voice built from audio scraped off your company website, a podcast appearance, or even a voicemail greeting. This isn't science fiction. It's happening to Australian businesses right now, and cyber security training for small business needs to catch up.
How Voice Cloning Actually Works
The barrier to creating a convincing voice clone has dropped quickly. A few years ago, this required expensive equipment, technical expertise, and hours of audio samples. Today, free and low-cost AI tools can generate a usable voice clone from as little as 10 seconds of audio.
Think about where your voice exists online. Company videos. Conference recordings. Social media clips. LinkedIn audio posts. Podcast interviews. Even your phone's voicemail greeting. Attackers don't need to hack anything to get this audio. They just need to find it.
Once they have a voice sample, the AI does the rest. The resulting clone can speak any words the attacker types, in real time or pre-recorded. The technology improves every few months. Current tools produce audio that sounds natural enough to fool colleagues who've worked together for years.
Why This Threat Hits Small Businesses Harder
Large corporations often have formal approval processes for payments. Multiple sign-offs, splitting up financial tasks, mandatory callbacks on requests over certain amounts. These procedures exist precisely because big organisations know they're targets.
Small businesses typically operate differently. The owner might call the bookkeeper directly to authorise a payment. Staff know each other's voices. Trust is personal, not procedural. This informality, which makes small businesses pleasant places to work, also makes them vulnerable.
When someone who sounds exactly like the boss calls with an urgent request, questioning it can feel awkward. Especially if the caller (the attacker) says something like "I'm about to go into a meeting, just get this done." The social pressure to comply is enormous.
Research into cyber security preparedness of small-to-medium businesses suggests that some SMBs may lack formal verification procedures for financial requests. This gap is exactly what voice cloning attacks exploit.
The Attack Usually Follows a Pattern
Most voice cloning fraud attempts share common elements. Understanding the pattern helps staff recognise when something feels wrong.
The attacker typically researches the target organisation first. They identify who handles payments, who the decision-makers are, and what suppliers or clients the business works with. Much of this information is publicly available through websites, LinkedIn, and business registries.
The call usually comes at a busy time. Friday afternoon is popular. So is the hour before a known meeting or event. The attacker wants the target to feel rushed.
The request involves money or sensitive information. Bank transfer to a new account. Updated banking details for a regular supplier. Login details needed urgently. Gift cards for a client (yes, this still works).
The caller discourages verification. They might say they're about to board a flight, entering a meeting, or dealing with a family emergency. Any excuse that makes calling back seem inappropriate or impossible.
Cyber Security Training for Small Business Needs to Adapt
Traditional security awareness focuses heavily on email. Spot the dodgy link. Check the sender address. Don't open unexpected attachments. This training remains valuable, as AI is also rewriting the phishing playbook for email attacks.
But voice cloning requires additional preparation. Your team needs to understand that voices can be faked, and they need permission to verify requests even when the caller sounds familiar.
This cultural shift matters more than any technical solution. Staff must feel comfortable saying "I'll call you back on your mobile to confirm" without worrying about offending the boss. Building this culture requires explicit communication from leadership.
The Australian Cyber Security Centre recommends teaching staff about common cyber threats and protective measures. Voice cloning now belongs on that list.
Practical Defences That Actually Work
You don't need expensive technology to protect against voice cloning. Simple procedural changes make a real difference.
Establish a verification code. Agree on a word or phrase that must be used for any urgent financial request. Something that wouldn't appear in normal conversation. If the caller can't provide it, the request doesn't proceed.
Mandate callbacks for financial changes. Any request involving money or banking details gets verified through a separate channel. Call back on a known number, not one provided in the suspicious call. Send a text to confirm. Walk to their office if they're in the building.
Slow down urgent requests. Legitimate urgent requests can wait 10 minutes for verification. If someone insists they can't wait, that's a red flag. Real emergencies can handle a brief delay. Scams can't.
Limit public audio. Consider how much of your voice exists online. You may not want to remove all public appearances, but being aware of the exposure helps you understand the risk.
Training Staff to Question What They Hear
The hardest part isn't the procedure. It's getting staff comfortable with the idea that their own senses can deceive them.
We're wired to trust familiar voices. It feels natural and right. Asking people to second-guess this instinct goes against years of social conditioning.
Simulated phishing attacks help build this awareness for email threats. The same principle applies to voice attacks. When staff experience a simulated manipulation call (or understand that such simulations exist), they become more alert to the possibility of deception.
Regular phishing training for employees Australia-wide now needs to address voice and video impersonation alongside traditional email threats. The criminals have adapted. Training must adapt too.
What Happens When Verification Becomes Normal
Some business owners worry that verification procedures will slow things down or create an atmosphere of distrust. The opposite tends to happen.
When verification becomes routine, it stops feeling like suspicion. It's just how things work. Like locking the door when you leave, or backing up files. Nobody takes it personally.
Staff who know they're expected to verify feel confident to do so. They're not being paranoid. They're following procedure. This clarity actually reduces anxiety around security decisions.
And when an attack does come, the procedure catches it. The attacker asks for an urgent transfer. The staff member says they'll call back to confirm. The attacker hangs up. Thousands of dollars stay in your account.
Start With What You Can Control
You can't stop criminals from cloning voices. The technology is freely available and improving constantly. What you can control is how your team responds when they receive a suspicious request.
This means having conversations about verification before an attack happens. It means running simulated phishing attacks so staff experience the pressure of a fake urgent request in a safe environment. It means building a culture where questioning is expected, not discouraged.
If you're not sure where your team's awareness currently stands, find out. Send yourself a test phishing email and see how convincing it looks. Then consider whether your staff would catch it, or whether they'd click.
Ready to test your team's awareness? Sign up for a free trial and send yourself a sample phishing test. It takes less than a minute to set up, and you'll see exactly what your employees would see. No IT skills required.