The Clone Is Already on the Call

In January 2024, a finance employee at the Hong Kong office of the British engineering firm Arup received an email appearing to come from the company's UK-based chief financial officer, asking him to carry out a secret transaction. He suspected phishing. Then he joined a video call, and there on screen were the CFO and several colleagues, looking and sounding just like people he recognized.1

He made 15 transfers to five bank accounts, totaling roughly HK$200 million, or about US $25.6 million. Every other participant on that call was an AI-generated deepfake. Arup confirmed the incident publicly in May 2024, with a spokesperson stating that fake voices and images had been used and that none of the firm's internal systems were compromised.1

That last detail is the one worth sitting with. Arup's global chief information officer, Rob Greig, has described the incident not as a conventional cyberattack but as technology-enhanced social engineering.2 No servers were breached. No passwords were stolen. The attackers didn't break into Arup's systems. They broke into its trust.

And the threat has moved well beyond one headline. In December 2024 the FBI warned that criminals use AI-generated audio to impersonate public figures and personal contacts in order to elicit payments, and use AI-generated video to stage real-time video chats with supposed company executives and authority figures.3 In May 2025 the Bureau issued a further advisory about an ongoing campaign impersonating senior US officials through text and AI-generated voice messages, with blunt guidance: if you receive a message claiming to be from a senior US official, do not assume it is authentic.4

If a cloned voice can impersonate a federal official, it can impersonate your collections manager.

Why "Listen Carefully" Doesn't Work Anymore

The raw material for a clone is everywhere: earnings calls, conference talks, LinkedIn videos, podcast interviews, voicemail greetings. Researchers note that advances in speech synthesis make it possible to produce a realistic-sounding clone from only a small number of audio samples.5

Meanwhile, the human ear is losing the arms race. In a University College London study of 529 participants, listeners correctly identified deepfake audio only about 73% of the time when judging clips one at a time — meaning roughly a quarter of the time they got it wrong. Showing participants examples of deepfakes beforehand improved their accuracy by less than four percentage points. Listening to clips repeatedly didn't help. Spending more time on the task didn't help. The authors' conclusion was that trying to improve human detection is unrealistic, and they noted that as synthesis algorithms improve, detection will only get harder.5

Automated detectors are not a clean answer either. In the same study, detectors performed nearly perfectly on audio resembling their training data, but collapsed when conditions changed — frequently misclassifying genuine audio as fake.5 That is the gap between a laboratory benchmark and a live phone call.

Security awareness training still matters. But "spot the fake" is a strategy that gets weaker every time the models get better. And note what the FBI's own mitigation advice ultimately reduces to: verify identity independently, through a separately confirmed channel.4

Any defense that depends on how someone sounds or looks is a defense the clone was built to beat.

Where Your Business Is Exposed

This isn't only a CFO problem. Consider every moment when someone says, "I'm calling from [your company]," and expects to be believed:

In every case the damage lands twice: once on the victim, and again on your brand, which the scammer borrowed to make the lie believable. We covered the scale of that problem in Inside America's $3.5 Billion Impersonation Scam Crisis.

Stop Detecting. Start Verifying.

PPLCARD takes a different approach. It doesn't try to decide whether a voice is real. It asks for something a clone can't produce: proof, generated in the moment, that the person is a verified employee.

  1. Your employee logs in. A verified member of your team, provisioned by your administrator, signs into PPLCARD.
  2. They generate a one-time passcode. Before or during the call or visit, the employee creates a short code.
  3. They share it. The employee reads the code aloud on the call or shows it in person.
  4. The recipient checks it independently. The person on the other end enters the code at pplcard.com and sees the employee's verified name and company.

A deepfake can copy your CFO's accent. It cannot produce a valid, single-use passcode that only exists inside an authenticated employee account.

The clone has the voice. It doesn't have the credentials.

Because the recipient does the checking, trust never depends on anything the caller says. It is the same principle behind the FBI's guidance to independently confirm identity before acting4 — built into a step that takes seconds instead of a callback.

Why This Holds Up Against AI

It doesn't care how real the fake is. Detection tools have to keep pace with every new model. Verification doesn't. A flawless clone and a clumsy one fail the same way: no code.

It works on the phone and at the door. Caller ID and branded calling only indicate which number is calling, and numbers can be spoofed. PPLCARD verifies the person, whether the interaction is a phone call, a video meeting, or a knock at the door.

It leaves a record. Each successful verification is logged, which matters when a customer later disputes whether your team contacted them at all.

It asks almost nothing of the recipient. No app, no enrollment, no account. PPLCARD does not store your customers' phone numbers. They need a browser.

The Takeaway

AI clones have turned "I recognize that voice" into a vulnerability. The organizations that get ahead of this won't be the ones with the sharpest ears. They will be the ones that give every customer, every employee, and every counterparty a simple way to confirm who they are really talking to.

Your voice can be copied. Your verification process shouldn't be.

Sources

  1. Magramo, K. "British engineering giant Arup revealed as $25 million deepfake scam victim." CNN, May 16, 2024. cnn.com
  2. "This engineering firm was hit by a deepfake fraud. Here's what it learned." World Economic Forum, Centre for Cybersecurity (remarks by Rob Greig, Global Chief Information Officer, Arup). weforum.org
  3. Federal Bureau of Investigation, Internet Crime Complaint Center. "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud." Alert Number I-120324-PSA, December 3, 2024. ic3.gov
  4. Federal Bureau of Investigation, Internet Crime Complaint Center. "Senior US Officials Impersonated in Malicious Messaging Campaign." Alert Number I-051525-PSA, May 15, 2025. ic3.gov
  5. Mai, K. T., Bray, S., Davies, T., & Griffin, L. D. "Warning: Humans cannot reliably detect speech deepfakes." University College London, Departments of Security and Crime Science and Computer Science. arxiv.org/abs/2301.07829