You receive a call from your own child. Or from your boss. The voice sounds exactly the same: the tone, the pauses, even that way they have of ending sentences. They ask you to pay an urgent bill and, with your heart racing, you do it. Days later you discover it was never your child. Nor your boss. It was a robot.
Welcome to AI vishing: the phone scam that uses artificial intelligence to clone voices in real time. No longer does it take a kidnapping or a clumsily invented emergency. The technology does the dirty work for the scammer, and with ever more precision.
What is vishing?
Vishing comes from ‘voice’ and ‘phishing’ (impersonation). It is the scam carried out over the phone. Until now, the scammer disguised themselves as a bank or a technician and asked for data with an urgent tone. It worked, but it left traces: strange accents, questions that did not add up, implausible stories.
AI has eliminated almost all of those flaws. With just a few seconds of a person’s audio, you can train a model that imitates them convincingly. Before, several minutes of recording were enough; now there are tools that achieve decent results with a short WhatsApp voice note.
The attack, step by step
First, cybercriminals gather public information: social media, videos, recordings in any corner of the internet. Then they create a clone that responds and reacts. Finally they call a family member or an employee with a story tailored to them: an accident, a fine, a company problem.
The key to the deception is the live call. It is not a prerecorded message: it is a conversation in which the victim hears “their” voice and, moreover, receives answers. Emotion does the rest. In the face of fear, the brain stops questioning and obeys.
It is not a passing fad
Security centers in several countries have already warned about the rise of these calls. With a simple piece of audio circulating on the internet, financial fraud attempts can be set up. You do not need a hacked phone: it is enough that your voice is in some video, in a streaming meeting or in a voice note that ends up on social media.
And not only in calls. Video deepfakes take the same trick one step further: fraudulent video calls have been detected in which an executive of a multinational seemed to appear on screen asking for million-euro transfers. It looked so real that nobody suspected.
How can you protect yourself?
The good news is that there are simple and very effective countermeasures:
- Distrust urgency. Haste is the scammer’s weapon. With any call that asks for money, hang up and call the person yourself through the channel you know. Do not return the call to the number they gave you.
- Set a keyword. An old but effective trick: agree on a secret code for emergencies with your family. If the person does not know it, be suspicious.
- Confirm through another channel. In the face of a strange request, verify in writing or wait to talk in person. Cloned voices fail when you ask for details that no outsider should know.
- Do not share your voice lightly. Every video and voice note posted online can become training material. Be selective.
- Enable two-step verification on banking services and important transfers.
The future demands skepticism
Governments and companies are working on “watermarks” and voice identifiers to distinguish the real from the fabricated. Until those solutions arrive, the best defense is, ironically, the most human one: distrusting a little more and always checking.
When technology manages to make a machine sound exactly like someone you love, security stops being just an IT problem. It becomes a daily habit. And the first filter, more than software, is your ability to pause and ask: ““what if this is not who they say they are?””.






