BID® Daily Newsletter
Sep 23, 2026
BID® Daily Newsletter
Sep 23, 2026

Article Lead Image

The Vendor Voice Fraud Threat

Summary: CFIs are aware of the risks of voice cloning and identify impersonation when it comes to customers, but some of the biggest risks organizations face on this front may actually be within their B2B supply chains.

Key Insights

  • Voice cloning fraud is increasingly targeting B2B supply chains and vendors, not just customer-facing interactions.
  • Criminals need less than one minute of recorded audio to convincingly clone a vendor's voice.
  • Out-of-Band (OOB) verification is the recommended defense for validating third-party vendor requests and system changes.
The Mona Lisa by Leonardo da Vinci is one of the world’s most popular paintings, attracting between 6 million and 8 million visitors to Paris’ Louvre Museum each year. Based on its 1962 assessment at $100MM (roughly $1B today), Mona Lisa holds the Guinness World Record for the highest insurance valuation for a painting. The work is so important that a 17th-century replica by an unknown artist (known as the “Hekking Mona Lisa” for the French art collector who discovered it in an antique shop) was sold for roughly $3.44MM by auction house Christie’s in 2021 – a value boosted largely by the collector’s assertion that his painting was the original and that the Louvre was housing a fake.
Despite the high-quality of the replica, experts ultimately discredited claims that the Hekking Mona Lisa was the original work because the hands in the painting were not refined enough to match da Vinci’s original. Unfortunately for the banking industry, artificial intelligence can now help replicate things so closely that it can be nearly impossible to tell the difference between an original and a fake, particularly when it comes to voice cloning. As voice cloning becomes commonplace among cyber criminals, community financial institutions (CFIs) need to be aware that some of the biggest risks may lie within their supply chains.

The Risks of B2B Interconnectivity

CFIs are well aware of the risks of voice cloning and identity impersonation when it comes to customers. But many organizations don’t realize that some of the biggest risks regarding voice cloning lie within the business to business (B2B) supply chain. A growing number of cyber criminals are turning their efforts to cloning the voices of the third-party providers that financial institutions and other organizations work with. From outsourced IT support to compliance vendors, CFIs work with a wide range of external partners they have trusted relationships with and cyber thieves recognize that impersonating these companies can pay off big if they are able to convince a CFI’s staff members to do things such as running “emergency patches” or temporarily overriding wire transfer limits.
There are many instances where cyber criminals have already successfully used voice cloning, coupled with other fraud tactics such as spoofed phone numbers, to imitate individuals within a B2B supply chain and trick employees into compromising an organization’s security measures. In the industrial sector, criminals are increasingly taking advantage of the convergence of information technology (IT) and operational technology (OT) – the software and hardware that monitors and controls industrial processes, infrastructure, and physical devices.
One such example is Qantas airlines, where a cyber criminal using voice cloning posed as a member of the company’s IT support team and called an overseas employee asking for help to close out a support ticket. Since the phony support staff individual had detailed knowledge of the company’s customer relationship management platform and described seemingly legitimate steps, the employee who had been targeted was easily tricked into unknowingly taking steps that connected the company’s CRM system with a data extraction tool that exposed 5.76 million customer records. Threats to the OT systems within the industrial sector are distinctly different than the back-office threats to the banking industry, but the risks are just as severe. While a compromised vendor channel won’t shut down a physical machine, it could expose a CFI’s entire financial and payment infrastructure.

How Does Voice Cloning Fraud Work? 

Open Source Intelligence (OSINT) – the aggregation, analysis, and use of information pulled from public and openly available sources - has made it easier for criminals to gain valuable information, not only about employees and executives within organizations, but about key people and processes within the third-party vendors they rely on. In a world where executives, product specialists, and technology leaders regularly take part in industry discussions, panels, podcasts, and even promotional videos, criminals have a wealth of sources they can pull from. Such audio files can be used to clone a speaker’s voice, with criminals needing less than a minute of recorded speech to do so. Cyber criminals have gotten so good with these technologies that, in the case of OT systems, Microsoft’s security team has warned that a single compromise can potentially turn an OT system into a breach gateway.
As with Quantas, one of the biggest areas of risk in the B2B chain for organizations, including CFIs, is help desks. Cyber criminals often contact the help desks of organizations they are targeting by posing as an employee and asking for help to reset their password and a multi-factor authentication device (MFA). Given this reality, CFIs should ensure that security training and awareness efforts extend to all areas of their B2B networks, including help desks and other areas that aren’t as obvious as customer-facing employees. Employees that interact with third-party vendors should be taught about the importance of applying security measures and skepticism to such relationships.

What Defense Measures Can CFIs Take?

To help defend against the risk of voice cloning to their B2B networkers, CFIs should establish mandatory Out of Band (OOB) verification requirements for any administrative or system-level changes. OOB is the verification of a transaction or any sort of request through a separate communication channel from the one that a request is made through. For example, if a third-party vendor contacts an organization’s help desk insisting that an emergency patch needs to be made, the help desk employee must verify that individual’s identity and request using a separate and pre-determined communication channel such as direct line or a physical hardware token.
While OOB verification is an important safeguard, it should not be the only defense against voice-cloning fraud. OOB can fail if an employee uses a spoofed number supplied by a criminal or if a legitimate vendor account has been compromised. CFIs should therefore use layered controls for high-risk requests, including password resets, MFA-device changes, privileged-access requests, emergency patches, payment-limit changes, and wire-related activity.

To reduce risk, CFIs should:

  • Require employees to end unsolicited calls and use a contact number from an approved vendor directory, contract record, or authenticated portal - never a number or link provided by the caller.
  • Require high-risk requests to be documented through an authenticated ticketing or vendor-management channel and approved by a second employee, system owner, or security team member.
  • Restrict third-party access using least-privilege and time-limited credentials, rather than allowing standing administrative access where possible.
  • Train help-desk, IT, payment, and vendor-management staff to follow established escalation procedures rather than relying on a caller’s voice, urgency, or familiarity.
  • Log and review vendor-access activity, MFA resets, privileged-account changes, and unusual data exports for signs of compromise.
In a B2B environment with growing technology connections, the most effective defense is not an employee’s ability to recognize a fake voice. It is a documented process requiring independent verification, authenticated workflows, and appropriate approvals before a high-risk request is completed.
Subscribe to the BID Daily Newsletter to have it delivered by email daily.

Related Articles:
National Preparedness Month Part 2 - How CFIs Can Support SMBs
Educating SMBs about the importance of disaster preparedness can help CFIs both strengthen ties to this group and diminish lending portfolio risks that can occur following natural disasters.
FinCEN's 314(b) Update: A New Tool Against Payments Fraud
In June, FinCEN updated guidance that financial institutions can now share incidents of suspected fraud with each other under the Patriot Act’s safe harbor provision. Such real-time sharing can be particularly beneficial in stymieing instant payment fraud. We detail action items for community financial institutions to consider.