A fake AI voice cloning scam call does not need perfect technology to cause harm. It only needs a rushed employee to treat a familiar voice, an urgent story or a known-looking phone number as proof. This 2026 guide explains how to train staff to stop, verify and report voice-cloning calls before money, credentials or sensitive information leave the business.
Why this matters
Voice cloning changes the social-engineering conversation. A caller can sound like a manager, supplier, IT contact or family member and still be a scammer. The call usually targets one high-impact decision: approve a payment, share a verification code, reset an account, reveal information or install remote-access software.
ASD’s social-engineering guidance, last updated 9 April 2026, says vishing callers can impersonate staff or executives, spoof caller IDs and use AI voice cloning or deepfake technology to sound convincing. ASD also recorded phishing in 60% of incidents reported to the ACSC in FY2024–25. Voice attacks deserve the same disciplined response as a suspicious email: stop, verify through an independent channel and report.
Cyber Aware uses security awareness training and simulated phishing to turn that response into a habit. The goal is not to make staff suspicious of every call. It is to make sensitive requests safe even when the caller sounds familiar.
What you will need
Set these foundations before the first voice-cloning training session in 2026:
- A written callback rule for payments, password resets, access changes, customer data and one-time codes.
- Verified contact details for executives, finance approvers, IT support, key suppliers and the managed service provider.
- A clear internal route for reporting suspicious calls, voicemail, SMS and follow-up emails.
- A named owner for urgent financial, account-recovery and security decisions.
- A 20-minute initial briefing plus 5-minute quarterly practice drills.
- A policy that treats prompt reporting after an accidental disclosure as the right action, not a disciplinary event.
Do not tell staff to become audio experts. Deepfakes, stress, background noise and imperfect calls make that unrealistic. Train the process that defeats the attack: sensitive requests never proceed on an incoming call alone.
1. Define which requests require independent verification
Start by naming the actions a voice-cloning caller wants. The obvious request is a money transfer, but the most damaging calls often ask for a smaller first step: an MFA code, a password reset, a payroll update, a customer list, access to a shared drive or remote-control software.
Build a simple trigger list. Any request involving money, credentials, account recovery, privileged access, personal information, changes to bank details or software installation requires independent verification. The employee does not need to judge whether the voice is real before following the rule.
Write the rule in plain language: “No urgent financial or access change is approved from an incoming call. End the call, verify using a trusted contact, then report it.” Put it in finance procedures, service-desk guidance, onboarding and manager training.
Expected outcome: staff recognise the protected action before the caller’s story creates pressure.
Common mistake: treating only large payments as risky. A shared one-time code or a password-reset approval can give an attacker a foothold that leads to a larger loss.
2. Teach the trusted callback rule
The trusted callback rule has three steps: end the call, find a contact method already held by the business, and confirm the request without using any number, link or email supplied by the caller.
For a manager request, call the manager’s saved corporate number or use the organisation’s established messaging channel. For a supplier payment change, use the number in the approved supplier record. For an IT request, contact the service desk through the official portal or known number. Do not search the web while the caller is waiting and do not call back a number displayed on the handset.
ASD advises organisations to verify sensitive requests independently and says urgency must never override security. Set a 10-minute escalation target in 2026 for any call seeking a payment, password reset, access change or code. The call recipient records the claimed identity, time, displayed number and request, then passes it to the right owner.
Expected outcome: the decision moves to a channel the caller does not control.
Common mistake: placing the caller on hold and returning after a quick internet search. That keeps the attacker in control of the conversation and is not independent verification.
3. Give staff a safe script to end pressured calls
Social engineering works when a helpful person feels they must resolve the issue before the caller hangs up. Give employees a short script that ends the call without a negotiation.
Use one of these lines in every 2026 drill:
- “I cannot approve payments, access or account changes on an incoming call.”
- “I will verify this through our normal process. I am ending the call now.”
- “I cannot provide passwords, verification codes or customer information by phone.”
Practice each line twice: once against a calm caller and once against a caller claiming a manager is travelling, a system is about to fail or a payment deadline is minutes away. The words should stay the same. Urgency is the signal to verify, not a reason to bypass the process.
Cyber Aware phishing simulations reinforce the same decision in email scenarios. The simulation reporting records both clicks and reports, helping teams reward the protective action rather than focusing only on failure.
Expected outcome: any employee can end a high-pressure call in under 30 seconds.
Common mistake: asking the caller to prove their identity. A prepared scammer can offer more persuasive details, keep the employee on the line and exploit the conversation.
4. Practise the four voice-cloning scenarios that matter
Use scenarios tied to real business processes, not movie-style deepfake tests. A convincing voice is only one component; the requested action is what makes the scenario useful.
- Executive payment request: a familiar voice asks finance to send an urgent transfer while the executive is in a meeting.
- IT reset request: a caller claiming to be support asks for a verification code or says a password must be reset immediately.
- Supplier bank-detail change: a caller says the supplier’s account changed and the invoice needs payment today.
- Customer-data request: a caller claiming to be a colleague or client asks for records to be sent to a new address.
For every scenario, require four actions: end the call, record the facts, verify through a known channel and report the attempt. Do not use real account details, employee recordings or live verification codes in training.
Scamwatch says voice-cloning technology can replicate a family member’s voice within minutes, and its scam guidance warns that impersonators use spoofing to make calls seem legitimate. These sources support one operational lesson: a familiar voice and caller ID are context, not authentication.
Expected outcome: staff recognise the manipulation pattern even when the voice, subject and urgency change.
Common mistake: running a single CEO-fraud role-play every year. Attackers rotate their claimed identity and target different departments.
5. Make managers model the behaviour
A callback rule fails when a senior person tells staff to make an exception. Managers, finance leaders and IT administrators must use the process visibly, especially during an urgent request.
Run a 15-minute manager workshop in 2026. Ask each manager to state which requests they can approve, which require a second person and how staff should verify a call that appears to come from them. Document the answers in the relevant financial, account-recovery and help-desk procedures.
Cyber Aware human risk reporting keeps phishing outcomes, overdue learning and quiz failures in one Human Risk Score. Use that data to identify where managers or high-risk roles need a focused refresher without naming people publicly.
Expected outcome: staff see consistent behaviour from people whose authority attackers try to imitate.
Common mistake: assuming an executive’s voice is enough to skip an approval threshold. The point of an approval threshold is to remain reliable when a person’s identity is uncertain.
6. Preserve evidence and contain a mistake quickly
When a suspicious call ends, the recipient should report it internally and retain the voicemail, follow-up message or call notes. Record the time, displayed number, claimed organisation, caller’s request, information shared and any link, email or code mentioned.
If someone shared credentials, a one-time code or account-recovery details, reset the relevant credentials and revoke sessions where the organisation’s process permits. If a payment was made, contact the bank or payment provider immediately through a known channel. If sensitive information was sent, contain further sharing and alert the security, privacy or legal owner as required.
ASD advises people to report suspected social engineering immediately to IT or the cyber security team and preserve the communication for investigation. Use Scamwatch’s report form to report the scam after immediate internal containment starts. Use ReportCyber for suspected cybercrime or a cyber security incident.
Expected outcome: the organisation can contain the actual exposure and spot repeat attempts aimed at other staff.
Common mistake: deleting the voicemail or text because no money was lost. A short message can identify the caller’s tactic and protect the next employee.
7. Measure report-first behaviour monthly
Do not measure only course completion. Track the actions that show whether the training works under pressure:
- Suspicious voice-call reports received each month.
- Median minutes from call to useful report.
- Percentage of drill participants who use the callback rule correctly.
- Number of cases where a verification request was escalated before a payment, access change or disclosure.
Review the results monthly through 2026. If finance completes the callback drill correctly but reception does not know where to report a call, assign reception a short focused lesson. If help-desk staff still share reset codes, review both training and the reset process.
A gap assessment can place these findings beside wider controls, using custom health checks mapped to Essential 8, ISO 27001 and NIST. It turns one voice-scam drill into a clear question about response ownership, account recovery and approval evidence.
Expected outcome: each drill shows the next process gap to fix rather than producing a generic completion rate.
Common mistake: measuring the number of calls received. The leading indicator is the time from the first suspicious call to a useful internal report.
Troubleshooting
The caller sounds exactly like a manager
Follow the callback rule. A familiar voice cannot substitute for a known contact method and the normal approval process.
Caller ID displays a trusted number
Treat caller ID as an unverified signal. Spoofing can make an incoming call appear to come from a legitimate number, so end the call and use the trusted contact record.
A staff member gave out an MFA or verification code
Report the event immediately, change the affected credentials, revoke active sessions where available and review account recovery settings. Do not wait to see whether the caller uses the code.
A caller insists that a payment must happen today
Do not make an exception. Verify the request through the supplier record and apply the usual payment approval threshold. A deadline set by an incoming caller is not proof.
Staff worry that reporting a false alarm wastes time
Make the policy explicit: uncertain, urgent or unusual requests must be reported. A false alarm is a low-cost outcome; an unreported access change or transfer is not.
Tools and resources
- ASD social-engineering guidance, updated 9 April 2026, covers vishing, deepfakes, caller-ID spoofing and independent verification.
- Scamwatch guidance on why anyone can be a scam victim explains that voice cloning can replicate a familiar voice quickly.
- Cyber Aware awareness training provides 120-plus story-driven modules with quizzes and tracked completion.
- Cyber Aware phishing simulations provide a safe way to rehearse reporting and remediation.
FAQ
How can staff spot AI voice-cloning scam calls?
Do not authenticate a caller by voice alone. Treat urgent requests involving money, access, codes or data as unverified, end the call and confirm through a trusted contact method.
Can a scammer make caller ID look real?
Yes. Caller-ID spoofing can make a call appear to come from a legitimate number, so the displayed number is not enough to prove identity.
What should an employee do if a caller sounds like their manager?
End the call, use the manager’s known corporate contact details to verify the request and report the suspicious call internally.
What happens if an employee shares an MFA code?
Report it immediately, reset the relevant password, revoke sessions where available and review account recovery settings.
How often should a business train staff on voice-cloning scams in 2026?
Deliver an initial 20-minute briefing and run a 5-minute voice-scam drill each quarter. Repeat it after an incident, role change or process change.
Should finance staff approve a payment requested by phone?
No. Finance should use the existing approval process and independently verify a changed payment instruction with a trusted supplier or internal contact.
One last thing
A voice clone can make a caller sound credible, but it cannot pass a process that requires a trusted callback and a second approval. Train that process until it is automatic in 2026.