Voice deepfakes: why a familiar voice on the phone is no longer proof of identity

For decades customer service worked on a tacit rule: whoever sounds familiar on the phone is the person they claim to be. That rule no longer holds. For contact centres this is not an abstract warning but a practical operating question — because that is exactly where information is given out, addresses changed, passwords reset and payments released every day.

Why voice cloning changed the rules

The technical effort behind a cloned voice has all but vanished. What once needed a studio and a specialist now takes a few seconds of publicly available audio — a voicemail greeting, a conference recording, a video posted online. European law enforcement agencies have been warning for some time about the sharp rise in AI-assisted fraud, and consumer protection bodies report a new generation of impersonation scams in which a relative’s voice is imitated convincingly.

The attack is not aimed at your technology. It is aimed at your people’s willingness to help.

The exception is the weak point

Fraudsters rarely attack the standard process. They look for the exception: the customer who supposedly does not have their reference number to hand, who is under time pressure, who describes an emotional emergency. That is where social engineering starts — and where a well-meant service culture undermines its own rules. An agent trained never to annoy a customer will, in case of doubt, be accommodating.

Deepfake defence in customer service is therefore first a question of process, and only then one of technology.

Four measures any company can take now

Effective protection does not require a large budget, but it does require consistency:

  • Define risk classes. Decide which transactions count as sensitive — changing bank details, resetting a password, changing an address, cancelling an invoice — and which verification is mandatory for each.
  • Verify out of band. Confirmation goes through a second, independent channel: a call back to the number on file, a one-time code by SMS or email, an approval in the customer portal. A caller can fake a voice, but rarely controls the second channel at the same time.
  • Allow agents to say no. Make it unmistakably clear that following the verification process is never treated as poor service. Without that backing, any policy collapses under pressure.
  • Record anomalies. Unusual pauses, robotic emphasis, background noise that does not match the story, or a caller who deflects a routine question — worth a note in the case file. Patterns only become visible when someone writes them down.

What technology can contribute

A contact centre platform helps at the points where process needs support. Risk-dependent routing sends sensitive requests to a queue with stricter rules. Call-back on the number held on file is a configuration, not a manual step. And a written record of every conversation — transcript and notes in the CRM — makes it possible to reconstruct afterwards what was said, by whom, and on what basis a decision was made.

None of that detects a cloned voice. It removes the need to.

What this means for service quality

The fear that stricter verification annoys customers is understandable but usually unfounded. Customers accept a security question when it is explained briefly and applied consistently. What annoys them is arbitrariness: being asked one day and not the next.

Read more