Discover your interests, together

Real deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Discover your interests, togetherReal deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

AI Voice Clones and Spear Phishing Are Now Scalable People Hacks

AI Voice Clones and Spear Phishing Are Now Scalable People Hacks
Interest|AI Application Exploration

AI social engineering: from rare trick to scalable threat

AI social engineering threats are cyberattacks that use artificial intelligence to convincingly impersonate trusted people and generate personalized messages, shifting the focus from exploiting technical vulnerabilities to manipulating human judgment through scalable voice cloning, deepfake impersonation risks, and tailored spear phishing texts at a speed and volume that manual attackers could not match before.

The uncomfortable takeaway is this: the hardest part of many cyberattacks is no longer breaking into systems, it is tricking people—and AI now makes that part cheap and scalable. Recent AI voice cloning attacks against multiple major investment firms show how easily attackers can mimic familiar voices and request routine access without touching malware or network exploits. At the same time, AI-generated texts can be tailored to a single employee’s job, habits, and online posts, turning every inbox and phone call into a potential attack surface. Treat AI-driven social engineering as a first-class cyber risk, not science fiction. The tools exist, and they are already being tested against some of the most security-conscious organisations.

Voice clones targeting hedge funds prove deepfake impersonation can scale

Employees at several of the world’s largest hedge funds recently answered phone calls that sounded like they came from top-level colleagues. The voices were convincing, the requests were routine, and the callers were not colleagues at all, but AI voice clones trying to trick staff into handing over access to highly sensitive systems. This campaign reportedly hit firms such as Point72 Asset Management, Two Sigma Investments, Citadel and Millennium Management in close succession, rather than focusing on a single target. That shift—from one-off con to coordinated wave—signals that deepfake impersonation risks have moved firmly into the realm of scalable cyber threats.

What makes these AI voice cloning attacks so dangerous is their focus on human weakness, not technical flaws. Attackers cloned voices using publicly available audio—conference talks, interviews, earnings calls—then phoned employees, asking for login credentials or other internal access. The operation did not try to bypass security controls directly; it tried to persuade staff to bypass them, exploiting trust in familiar voices. That capability makes verification over the phone far harder than it was only a few years ago, because a warm, recognisable voice is now cheap to fake at scale. If top-tier financial institutions can be tested this way, everyone else is on notice: identity on the phone is no longer proof of authenticity.

AI-crafted spear phishing: your gut is a poor detector

If voice can be cloned, text can be personalised—and a pilot study with 25 volunteers shows how badly human intuition performs against AI-written spear phishing messages. Participants handed over details about their job, workplace, hobbies, city, and recent social media posts. Those details went into a short prompt template, which was sent to GPT-4 to generate six messages per person, while trained students wrote the other half under time pressure. Each participant then sorted twelve printed messages from “most likely to click” to “least likely,” drawing a line where they would have clicked.

The AI messages landed above that click line 28% of the time, while student-written ones landed above it 21.3% of the time. Yet the gap is less important than what produced it: a one-line prompt produced phishing attempts that performed in the same range as hand-crafted messages screened by cybersecurity experts. After sorting, participants were asked to mark which messages they believed were AI-written. Across 300 judgments, they scored 52%—effectively a coin flip. Their theories (“AI is too formal,” “humans make typos,” “too many exclamation points means machine,”) failed. One quotable conclusion from the researchers is blunt: “Do not try to decide whether it sounds like a robot. That is the one thing the study shows people cannot do.”

Personalization is the weapon: work-themed lures hit hardest

The study’s most worrying insight is that the most effective AI spear phishing detection strategy is not “trust your instincts,” but “assume personalized messages can be traps.” Each participant received three flavours of message: one about their job, one about a hobby, and one based on recent social media posts. Work-themed messages were markedly more dangerous, clearing the click line 38% of the time, compared with 19% for hobbies and 17% for social media topics. That comparison holds up statistically, so if you remember one number, make it this one.

Why does this matter? Because attacks are shifting away from breaking systems and toward manipulating people with convincing personalization. Job-related messages slot neatly into existing workflows—fraud alerts, HR notices, IT tickets—so they look “normal” and trigger faster responses. Meanwhile, getting personal details into a message is easy for AI now, but getting them right still demands real knowledge of the target. When details are wrong (“there’s no Mike at work,” “there’s no Sarah on that team,” “I quit dancing years ago”), recipients notice and become suspicious. That tension cuts both ways: attackers who combine AI with accurate reconnaissance will craft lures that evade instinct almost completely, while defenders must learn to question even familiar, well-targeted requests.

Defending against AI voice cloning and spear phishing: change the playbook

Traditional security awareness training still tells people to “trust your gut” about suspicious messages. The evidence now says that advice is incomplete at best and dangerous at worst. When participants tried to separate AI from human messages by tone, grammar, or punctuation, they failed, landing almost exactly at chance. Emojis were a real pattern—66% of GPT-4 messages contained them versus 2% of human messages—but only a handful of participants noticed, and they disagreed on what emojis meant. In contrast, software trained on message embeddings hit 88.7% balanced accuracy in sorting AI from human texts under strict test conditions. People are bad at spotting AI; machines are much better.

The practical response must be both behavioural and technical. Behaviourally, staff should follow the study’s closing advice: check the sender, the channel, the link, and the request against what you would expect to receive, and do not try to decide whether it “sounds like a robot.” Treat any request for credentials, financial access, or sensitive data—whether by email, text, or phone—as untrusted until verified through a second, independent channel. Technically, organisations should invest in spear phishing detection tools that analyse message patterns rather than relying on human hunches, and update incident response procedures to include AI voice cloning attacks as a standard scenario. The conclusion is clear: you cannot train people to outguess generative models, but you can train them to slow down, cross-check channels, and let systems do the pattern recognition.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!