Voice deepfakes: why a familiar voice on the phone is no longer proof of identity

Die Stimme am Telefon ist kein Identitätsnachweis mehr – ilogixx myContactCenter

For decades, customer service ran on an unspoken rule: if someone sounds familiar on the phone, they are who they claim to be. That rule no longer holds. Germany’s Federal Criminal Police Office (BKA) puts it plainly: in 2026, a familiar voice on the phone is no longer proof of identity. For contact centres this is not an abstract warning but a concrete operational question, because this is exactly where information is given out, addresses are changed, passwords are reset and payments are approved every day.

Why voice cloning has changed the rules

The technical effort needed to clone a voice has all but disappeared. Where hours of audio and specialist knowledge used to be required, a few seconds of recorded speech are now enough to build a convincing voice model – material that can come from a voice message, a podcast appearance or a video on social media.

The consequences are measurable. Security vendors report a sharp rise in deepfake fraud attempts against contact centres within a single year. The BKA has recorded a clear increase in AI-assisted fraud since 2023, and consumer protection agencies are warning about a new version of the “grandchild scam”, in which relatives’ voices are imitated with deceptive accuracy. The attack does not target your technology. It targets your staff’s willingness to help.

The weakest point is the exception

Fraudsters rarely attack the standard process. They look for the exception: the customer who supposedly does not have their customer number to hand, who is under time pressure, who describes an emotional emergency. This is where social engineering comes in – and where well-meaning service cultures bend their own rules. An agent who has learned never to annoy a customer will lean towards accommodation when in doubt.

That is why deepfake defence in customer service is first a process question and only then a technology question. If there is no binding escalation rule for sensitive transactions, it cannot be enforced when it matters.

Four measures smaller companies can put in place now

Effective protection does not need a large budget. It needs consistency:

  • Define risk classes: Decide which transactions count as sensitive – changes to bank details, password resets, address changes, invoice cancellations – and which verification is mandatory for each.
  • Establish out-of-band verification: Confirmation happens through a second, independent channel: a call back to the number on file, a one-time code by SMS or email, an approval in the customer portal. A caller can fake a voice, but will struggle to control the second channel at the same time.
  • Allow agents to say no: Make it unmistakably clear that following the verification process will never be judged as poor service. Without that backing, any policy collapses under pressure.
  • Record anomalies: Unusual pauses, robotic intonation, background noise that does not fit the story or conspicuous pressure belong in the case record – it is the only way to spot patterns beyond individual incidents.

What the contact centre platform has to contribute

A sound process needs a system that supports it. With myContactCenter from ilogixx, these measures can be built into day-to-day operations instead of being parked in a policy nobody reads.

Because telephony, email, chat, WhatsApp and ticketing come together in one interface, the agent sees the complete customer history across all channels – and notices sooner when a supposedly known customer has a history that does not fit the call. Switching channel for the second confirmation is no longer a break in the process but a single click: the one-time code goes out by SMS or email without the agent leaving the system. Ticketing and case documentation keep every sensitive case traceable, and recurring anomalies become visible in the history instead of getting lost in individual cases.

Security and service quality are not opposites

The common worry that stricter verification costs customer satisfaction does not hold up in practice. Customers mostly respond well to transparent security steps, provided they are briefly explained and handled quickly. A sentence such as “For your protection, I’m now sending a code to the number we have on file” comes across as care, not mistrust.

Speed is what decides it. If verification takes 20 seconds, it is a mark of quality. If it takes three minutes because the agent has to switch between five systems, it will be bypassed. That is another reason why the depth of integration in the platform is a security factor.

Conclusion: harden your processes now

Voice deepfakes are not a future scenario but part of today’s fraud landscape – and contact centres are a favoured target because trust is part of their business model. The good news: the most effective countermeasures are organisational and can be introduced within a few weeks. Defining risk classes, establishing second-channel confirmation and empowering staff to stay firm when in doubt significantly lowers the risk.

Would you like to know how to build practical verification processes into your customer service? Book a no-obligation consultation through the online calendar at ilogixx.de. We will show you how myContactCenter makes your service processes both secure and efficient.

Read more