Deepfake vishing: detect and stop AI voice attacks on Swiss organisations
Deepfake vishing combines AI-generated voices with voice phishing. Attackers clone the voice of a CEO, CFO or IT admin from a few seconds of public audio. They then call employees to trigger payments, password resets or MFA approvals. For Swiss organisations the vector is dangerous because classical email filters, MFA and EDR do not see it. Effective defence requires process controls (call-back, second channel) and awareness with realistic voice samples. It also requires a SOC that correlates accompanying signals in M365 and Entra ID.
Scope: deepfake vishing vs BEC vs AI attacks
This page covers deepfake vishing as a concrete attack vector: cloned voices over phone or voice-over-IP, often combined with a preparatory email. The text-based path via M365 mailboxes sits on Business Email Compromise in M365. The broader trend perspective on how AI accelerates attacks overall is on AI-driven cyber attacks. For the defence side with AI in the SOC see AI in the SOC. Human preparation through training belongs to Security Awareness.
Deepfake vishing is the vocal variant of social engineering. It bypasses email filters entirely and targets the person on the phone, usually under time pressure and with authority framing.
How a typical attack unfolds
- Reconnaissance: attacker collects voice material of the target (interviews, podcasts, webinars, LinkedIn videos, voicemail greetings). 10 to 30 seconds are already enough for modern voice-cloning models.
- Context building: research on active projects, travel times and absences via LinkedIn, commercial register and company news.
- Preparation: optionally a preparatory email from a compromised or spoofed mailbox announcing the call.
- Call: cloned voice of the CEO or CFO calls finance, HR or IT. Typical requests: urgent payment to a new supplier, password reset, MFA approval, consent to an OAuth app.
- Follow-up: on success the trail is obscured across several accounts; for payments often via foreign accounts with a short recovery window.
Voice cloning is achievable in minutes today with publicly available tools. Even close colleagues often cannot reliably distinguish the cloned voice on the phone. A poor line or emotional pressure makes this harder.
Why Swiss organisations are especially exposed
- Executives in SMEs and enterprises are publicly present in media; voice material is freely available.
- Payments to new suppliers are routine; a plausible CFO call under time pressure often goes unchallenged.
- Cyber insurers scrutinise social-engineering cases. Without documented process controls (call-back, four-eyes), insurers may classify a payment as gross negligence. See SOC and cyber insurance.
- revFADP (revised Federal Act on Data Protection) traceability also applies to processes where staff release personal data, such as HR or customer data, via a phone call. See revFADP and SOC.
Effective defence in three layers
| Layer | Measure | Why it works |
|---|---|---|
| Process | Mandatory call-back: confirm payments and sensitive actions only through a call-back on a stored number or a second channel (Teams, Signal). | Removes the attacker's only runway; works independently of voice quality. |
| Process | Four-eyes principle for new payees and changes to account data; documented approval workflow in the ERP. | Breaks the single-call path; creates an audit trail for insurance and revFADP (revised Federal Act on Data Protection). |
| Human | Awareness with realistic voice samples and live drills, not only email phishing. See Security Awareness. | Only those who have heard the attack once in a calm setting recognise it under pressure. |
| Technology / SOC | Correlation of accompanying signals in M365 and Entra ID: unusual mail rules, consent grants, MFA bombing, atypical sign-ins shortly before or after the call. | Deepfake vishing is rarely isolated; the preparation leaves traces in the identity layer, visible via ITDR. |
| Technology / SOC | Incident playbook for vishing cases: immediate session invalidation, block new payment runs, contact bank, forensic capture of call metadata. | Recovery window for wire transfers is hours, not days; playbook must be rehearsed in advance. See Incident response plan. |
Automatic detection of synthetic voices in real time is an active research area but not yet a reliable standard for enterprise telephony. Do not rely on a detector product alone; process controls and awareness remain the load-bearing pillars.
Placement in SOC operations
SOC as a Service Switzerland explains how deepfake and vishing detection fits into continuous 24/7 operations. It covers awareness signals, callback processes and identity telemetry.
Frequently asked questions
How much audio do attackers need to clone a voice?
Current voice-cloning models produce usable results from 10 to 30 seconds of clean audio. For executives with public interviews, podcasts or conference appearances this bar effectively does not exist.
Is MFA enough against deepfake vishing?
MFA alone is insufficient against deepfake vishing. The attack often aims exactly at getting an employee to approve an MFA prompt or reset a password. Phishing-resistant MFA (FIDO2, passkeys) makes technical abuse harder. Process controls such as call-back and four-eyes remain necessary.
What is the difference between deepfake vishing and CEO fraud?
CEO fraud is the umbrella term for fraud in the name of executive management, traditionally by email. See [BEC in M365](/en/soc/business-email-compromise-m365). Deepfake vishing is the current variant via phone with an AI-cloned voice. Both vectors increasingly appear combined.
Can a SOC even detect a vishing call?
A SOC cannot directly detect the call itself unless telephony is integrated with the SIEM. It can detect and correlate accompanying traces: compromised mailboxes, MFA bombing, consent grants and unusual payment runs in ERP logs. A mature SOC links these signals into one case and stops the follow-up actions.
What to do when a deepfake call has come in?
Verify immediately through a second channel using a stored number. If actions were already triggered, stop the payment through your bank, lock affected accounts, engage the SOC and launch the incident-response playbook. Capture call metadata (CLI, time, duration, trunk) forensically. Assess revFADP (revised Federal Act on Data Protection) notification duties if personal data is involved.
Related terms
- Phishing Phishing is an attack that uses fake emails and messages to trick people into taking an action.
- BEC Business Email Compromise is a type of corporate fraud where attackers trick staff into making payments to accounts controlled by the attackers.
- MFA Multi-Factor Authentication requires a second form of verification in addition to a password during login.
- Insider Threat An insider threat comes from individuals with legitimate access who misuse it, either intentionally or negligently.