Professional person on a video call looking concerned at a laptop representing voice fraud
News

BEC 3.0: How AI Voice Cloning and Deepfake Calls Are Driving the Next Wave of Business Email Compromise

AI voice cloning powers BEC 3.0: attackers clone CFO voices and make calls that finance teams cannot tell apart from the real executive.
Sami Malik
Copywriter

Business email compromise has been one of the highest-revenue cybercrime categories for most of the past decade, generating more financial losses per incident than ransomware in many years tracked by the FBI's Internet Crime Complaint Center. The defining characteristic of classic BEC, a compromised or spoofed email account sending payment redirection instructions or vendor fraud instructions to a finance team employee, has been well-understood for years. Awareness training, domain-based email authentication (DMARC/SPF/DKIM), and internal approval processes for payment changes have made the classic form of BEC harder to execute successfully. The adversary response, documented extensively in 2025 and 2026 research, is BEC 3.0: the addition of AI-generated voice calls that impersonate the executive the email is pretending to be from, resolving the credibility gap that awareness-trained employees have learned to identify.

The BEC 3.0 model requires remarkably little in the way of technical sophistication or upfront investment. Commercially available voice cloning services, some marketed openly for legitimate use cases like content creation and accessibility tools, can produce a convincing clone of any person's voice from as little as 15 to 30 seconds of audio sample. LinkedIn profiles, YouTube interviews, conference recordings, company videos, and earnings call recordings for public companies provide ample audio material for any executive whose role makes them a likely BEC impersonation target. The resulting voice clone can generate arbitrary speech in real time, enabling a phone call in which the "CFO" answers questions and responds to hesitation in a way that a recorded audio file cannot.

The Attack Flow: From Audio Harvesting to Transfer Authorisation

A well-executed BEC 3.0 campaign begins with target selection and reconnaissance well before any communication is sent. The attacker identifies an organisation where the financial processes are accessible through public information: the CFO's name and LinkedIn profile, the finance team's email structure from a breach dataset or data aggregator, the company's bank relationships from public filings or social media, and the approval thresholds that trigger additional verification for payment changes.

The audio sample for voice cloning is harvested from publicly available sources. For a CFO of a public company, earnings call recordings on the company's investor relations page provide minutes of high-quality audio. For a private company executive, LinkedIn video posts, conference talks on YouTube, webinar recordings, and podcast appearances provide the raw material. The quality of the resulting voice clone is highly dependent on the quality and quantity of the source audio, and professional voice cloning services now produce results that are difficult to distinguish from live speech in a phone call context where audio quality is already variable.

The actual attack combines email and voice in a coordinated sequence. The email, arriving from a spoofed or compromised executive address, instructs the finance employee to process an urgent wire transfer for a confidential acquisition or vendor payment. The email requests that the employee not discuss the matter with others due to its confidentiality. Minutes later, the employee receives a phone call from the "CFO" confirming the request and urging speed. The finance employee, having received both a written instruction from the executive's email address and a phone call in the executive's recognisable voice, has two independent channels of confirmation that the request is legitimate. The verification process they would normally apply, calling the executive back on a known number, has been preemptively addressed by the fake confirmation call.

Why Traditional Verification Fails Against Voice Cloning

The primary defence against classic BEC that has been widely adopted is the callback verification protocol: before processing any payment change or unusual financial instruction, the finance employee calls the requesting executive back on a phone number from the internal directory, not from the caller ID on an inbound call. This protocol directly addresses the email spoofing problem because it introduces an out-of-band verification step.

BEC 3.0 undermines this protocol in two ways. First, in many cases the fake call arrives before the finance employee initiates a callback, and the employee's awareness that they "already spoke to the CFO" reduces their motivation to call again. Second, in more sophisticated campaigns, the attacker uses number spoofing to make their call appear to originate from the executive's internal extension or mobile number. When the finance employee, following protocol, calls the number they see on their phone's recent calls list, they are calling a number controlled by the attacker. The callback verification protocol assumes that the initial caller's number is the attacker's real number. Number spoofing eliminates this assumption.

Several documented BEC 3.0 incidents in 2025 and 2026 involved follow-up calls rather than preemptive calls: the finance employee, suspicious of the email, called a number from their contacts and reached what sounded exactly like the executive they expected. These cases represent the complete circumvention of the callback protocol because the attacker anticipated it and had deployed voice cloning infrastructure capable of handling a live inbound conversation.

The Enabling Services: Where Voice Cloning Meets the Criminal Market

Several layers of service infrastructure support BEC 3.0 campaigns. At the technical layer, voice cloning is available from both legitimate commercial providers, some of which have terms of service that prohibit impersonation but minimal enforcement mechanisms, and from dedicated criminal services that explicitly advertise impersonation capabilities. The criminal market for voice cloning services includes offerings that provide real-time voice conversion, allowing an attacker to speak into a microphone and have their voice rendered in the cloned target's voice in near-real time, which enables live conversation without requiring pre-scripted audio.

The reconnaissance layer is supplied by the same criminal markets that support other forms of corporate fraud. Data brokers on dark web markets sell detailed profiles of corporate employees including their reporting structure, the names of their direct reports and managers, their email format and internal communication patterns extracted from previous breach datasets, and in some cases internal documents obtained through earlier intrusions. This reconnaissance data allows the attacker to customise the social engineering component of the BEC campaign with details that make the request sound internally coherent.

The fraud completion layer, where the transferred funds are collected and laundered, uses a network of mule accounts and cryptocurrency conversion that has been refined across years of BEC operations. The same dark web forums that sell voice cloning services and employee data also provide money mule recruitment and payment processing services for BEC actors. Monitoring these forums for discussions targeting specific organisations or industries, or for newly advertised services that lower the barrier to voice cloning attacks, is the intelligence function that gives defenders advance warning before campaigns reach their intended victims. Organisations that monitor for their brand and executive names in criminal forum discussions can detect targeting activity before it produces financial losses. Understanding your exposure in criminal market discussions is the foundation of proactive BEC defence.

Technical and Process Controls That Resist BEC 3.0

Several controls provide meaningful resistance to voice-augmented BEC that traditional awareness training and callback protocols do not fully address. The most effective process control is a dual-authorisation requirement for wire transfers above a defined threshold, where both the requester and the approver must authenticate through the financial institution's own portal rather than by phone. This control is resistant to voice cloning because the authorisation happens in an authenticated system rather than through a voice channel, regardless of how convincing the social engineering was.

Pre-authorisation of vendor accounts and payment destinations is a complementary control: any payment to a new bank account or a new country must go through an approval workflow that cannot be bypassed by an urgent call. Routine payments to pre-approved accounts are processed normally; only changes to those approved accounts trigger the additional review. This design makes the most common BEC scenario, redirecting a payment to a new account, require approval through a process that voice cloning cannot circumvent.

For organisations that want to implement technical voice authentication, some financial institutions and enterprise communication platforms now offer voiceprint verification, establishing a baseline voiceprint for executives through authenticated sessions and then flagging calls that claim to be from those executives but do not match the voiceprint. This is an emerging control that is not yet widely deployed, but it represents the logical technical countermeasure to voice cloning in high-value financial contexts. Meanwhile, the most reliable early warning for a BEC 3.0 campaign targeting your organisation remains intelligence about the targeting itself, surfaced through monitoring of criminal markets where reconnaissance data about your executives and financial processes may be traded. Executive credential and data exposure in these markets is the leading indicator that a BEC campaign is being prepared.

Intelligence Signals That Precede BEC 3.0 Campaigns

BEC 3.0 campaigns are not improvised attacks. They require reconnaissance, voice sample collection, and in many cases the purchase of internal information from criminal markets. Several of these preparatory steps produce observable signals that threat intelligence monitoring can detect before the attack is executed.

Executive data packages, which bundle an executive's personal and professional information including LinkedIn profile, known email addresses, phone numbers, voice samples from public sources, and in some cases internal documents, are sold on dark web markets. An organisation whose executives appear in recently listed data packages on these markets has a signal that targeting preparation is underway. This signal is available weeks before the actual BEC attempt, providing time to alert the likely targets, brief finance teams about the risk of voice-based fraud, and temporarily increase verification requirements for large payments.

The criminal forums where BEC actors discuss campaigns and share information about successful techniques also produce intelligence about target selection and preferred organisations. Monitoring these discussions for mentions of your organisation's name, executives' names, or financial institution relationships provides an early warning capability that is uniquely accessible through dark web monitoring. The combination of executive data exposure monitoring and criminal forum monitoring gives security teams the intelligence foundation to be proactive rather than reactive against BEC 3.0 campaigns.

The AI Infrastructure Behind BEC 3.0 Attacks

The AI tools that power BEC 3.0 attacks are not theoretical or expensive. Voice synthesis tools capable of producing convincing voice clones from 30-second audio samples are available as consumer products. Some are sold through legitimate channels as creative tools for content producers; others are marketed specifically on criminal forums as voice cloning services for hire. The cost of generating a voice call that sounds like a specific executive has fallen to the point where it is a viable attack option for campaigns targeting mid-market companies, not just large enterprises where the potential financial return justifies higher operational costs.

The training data for executive voice models is the other enabling factor. Public audio of senior executives is abundant. Quarterly earnings calls are recorded and published. Conference keynote recordings are freely available on YouTube. Media interviews exist for any executive who has spoken publicly. A voice synthesis tool that requires five minutes of audio to produce a convincing clone can be trained entirely on public material without the attacker ever having access to the target organisation's internal systems. The combination of abundant training data and accessible tools means that any organisation whose executives speak publicly is potentially subject to this attack technique.

Operational security for BEC 3.0 also benefits from stolen identity data. When attackers know from breach datasets that a CFO uses a specific email client and signs off emails with a specific phrase, the text component of a BEC message can be crafted to match the executive's writing style with enough precision to reinforce the credibility of the voice call. The multi-channel approach, a voice call followed by an email, or an email followed by a Teams message, means that even if one channel triggers suspicion, the presence of multiple apparently consistent communication channels tends to override that suspicion.

Organisational controls that address BEC 3.0 require out-of-band verification procedures for high-value financial transactions, regardless of how convincing the requesting communication appears. A process that requires the finance team to verify any wire transfer request above a defined threshold through a pre-established phone number in a known directory, rather than a number provided in the requesting message, addresses both traditional BEC and voice-cloned BEC 3.0. Monitoring for executive personal data in criminal markets identifies when the targeting data for BEC 3.0 campaigns is being assembled, providing an early warning of specific targeting that allows organisations to heighten controls before an attack is attempted.

Verifying Authenticity in a World of AI-Generated Voice

The rise of voice cloning as a BEC attack vector has created a new category of security question for organisations: how do you verify that a voice call is from the person it claims to be, when voice alone is no longer sufficient authentication? The traditional approach, which assumes that you can identify a trusted person by their voice, their speech patterns, and the personal details they reference in conversation, is directly undermined by voice synthesis tools that can replicate all of these characteristics.

Several verification approaches are emerging as responses to this problem. Out-of-band verification codes, where sensitive requests are accompanied by a pre-shared code that the requester provides to prove they are who they claim to be, add a second factor that voice synthesis cannot replicate. These codes need to be established in advance and kept out of band, transmitted through a channel the attacker cannot access, which means they cannot be sent via email or communicated in the same voice call where they are meant to be used. A code shared at the beginning of a business relationship, stored by both parties in a secure location, and used to verify the identity of high-stakes requests provides authentication that voice cloning cannot circumvent.

Callback procedures through a known, verified number in a pre-existing directory provide a complementary control. If an executive requests an action via voice call, the recipient can say they need to confirm through a callback, then call the executive's known office or mobile number through the company directory rather than any number provided in the original call. This procedure is particularly effective against voice cloning attacks because the attacker's synthetic voice call cannot be answered by returning a call to the executive's real number, which would go to the real executive rather than to the attacker.

Frequently Asked Questions About BEC 3.0 and AI Voice Cloning

How much audio is needed to create a convincing voice clone?

Modern voice synthesis tools can produce convincing clones with as little as 30-60 seconds of clean audio. For public figures and executives who have spoken at conferences or on earnings calls, hours of audio are typically available. The quality of the clone improves with more training data, but even short samples are sufficient to produce a clone that fools people in real-time voice calls, particularly when the call is brief and the context makes the caller's claimed identity plausible.

Are there technical methods to detect AI-generated voice in calls?

Voice liveness detection tools exist and are used in some authentication systems, but they are generally not deployed in normal business phone or video call infrastructure. Detecting synthetic voice in a real-time call requires audio analysis capabilities that are not present in standard phone or conferencing software. Some organisations are experimenting with real-time audio analysis tools that flag potentially synthetic voices, but these tools have false positive rates that make them impractical as a blocking control. The more reliable approach is procedural rather than technical: verification procedures that do not depend on voice authentication.

What data should organisations audit to assess their BEC 3.0 exposure?

Key audit areas include the amount of public audio available for each executive, the accessibility of each executive's personal contact information through data broker sources, the volume of executive personal data in known breach datasets, and the financial transaction authorisation procedures currently in use and whether they can be bypassed by a sufficiently convincing voice request. Dark web monitoring specifically covering executive personal data and voice cloning service offerings targeting your sector provides the external intelligence component of this exposure assessment.

Organisations that want to assess their current exposure to BEC 3.0 attacks can audit several specific risk factors: the amount of public audio available for each executive, the financial transaction authorisation processes in use and whether they include out-of-band verification requirements for wire transfers, and whether employees who receive financial requests have received specific training on voice call verification procedures. A gap analysis against these three factors gives a practical baseline from which to prioritise BEC 3.0 controls without requiring a broad security programme overhaul. The controls that address BEC 3.0 are the same controls that address all forms of business email compromise: verification procedures that do not rely solely on the authenticity of a communication channel that can be spoofed or synthesised.

How Defendis Monitors the Threats Covered in This Article

The threats described in this article, PhaaS kits sold on criminal markets, MFA bypass infrastructure sold as subscriptions, BEC campaigns sourced from infostealer logs, and AI-generated voice calls impersonating executives, all share a common thread. Their infrastructure and operational planning appear in criminal channels before they reach your organisation. Phishing kit listings, adversary-in-the-middle proxy infrastructure, voice cloning service advertisements, and targeted organisation data all circulate in forums and marketplaces that are visible to those monitoring in the right places.

Defendis monitors dark web forums, criminal marketplaces, and threat actor channels continuously for indicators related to your organisation's domains, employees, and brand. Intelligence surfaced before an attack reaches your users gives your security team time to act rather than react.

Book a demo to see how Defendis approaches phishing infrastructure monitoring and dark web threat intelligence for your organisation.

About the author
Sami Malik is a copywriter passionate about crafting clear, engaging, and impactful content that helps brands connect with their audience through storytelling and strategy.

Related Articles

Discover simplified
Cyber Risk Management
Learn how to prevent cyberattacks proactively with a free trial of Defendis.