Home Articles Get your free assessmentComing soon

Tag: voice cloning

  • The Board Member on the Call Wasn’t Real

    The Board Member on the Call Wasn’t Real

    The finance committee meets at seven on Thursday, on video, the way it has since 2020. Four squares on the screen. The treasurer joins eight minutes late, apologises, says the audio on his end is bad, and keeps his camera on anyway.

    He’s brief. The contractor for the roof project needs the deposit moved tonight to hold the crew for next month — the account details came through this afternoon and he’s forwarded them to the administrator. He asks whether anyone objects. Nobody does. His camera freezes twice while he’s talking, which is completely normal on a church Wi-Fi connection, and which is also the reason nobody looks too closely.

    The treasurer was at his daughter’s recital that evening and did not attend the meeting.

    What a deepfake actually is

    Deepfake is a plain word wearing a technical costume. It means a fake image, video, or audio recording generated by software that has studied real recordings of a person until it can produce new ones — a video of someone saying something they never said, or a voice speaking words the person never spoke.

    There’s no mystery in it and nothing exotic. The software needs examples of the person, and it produces convincing new material from them. The more examples it has, the better the result.

    The two forms that matter to a church are different in maturity, and it’s worth being precise about which is which, because the difference determines how you should think about the risk.

    Where the technology actually is

    Synthetic voice is here, it is cheap, and it is fast. This is the mature threat. Software that clones a voice from a short sample is widely available and requires no skill to operate. The FBI’s public warning on generative AI fraud describes criminals using AI-generated audio to impersonate people — a relative in a crisis asking for immediate financial help, or an account holder calling their own bank — in order to extract funds or gain access to accounts. If a caller’s voice sounds exactly like your finance chair, that no longer tells you anything.

    We’ll cover voice cloning on its own in a later post, because it deserves the room.

    Live synthetic video on a call is real but harder. This is where it’s easy to overstate, so here are the actual facts of the best-documented case.

    In January 2024, an employee at Arup — a London-headquartered engineering and design firm — joined a video conference at the company’s Hong Kong office with people who appeared to be the chief financial officer and other colleagues. They were digital recreations. Over the following week the employee made fifteen transfers totalling HK$200 million, roughly US$25 million. Hong Kong police disclosed the case in February 2024, and Arup confirmed in May 2024 that it had been the victim, with a spokesperson saying the firm notified police in January.

    That is one very large fraud against a global firm with thousands of employees, and it should be read as a demonstration rather than as a description of what happens on a typical Tuesday. The everyday version of this attack is still a plain email or a phone call. But the Arup case establishes something that is no longer arguable: a video call is not proof of who you are talking to.

    The FBI’s guidance reflects the same conclusion, noting that criminals generate AI video to depict executives and authority figures in real-time chats or to lend credibility in private communication.

    Why a church is unusually exposed

    Voice cloning needs reference material. Consider what your organization publishes, on purpose, every single week.

    Sermons. Livestreamed services, archived and public. Podcast episodes. Announcement videos. Staff introduction clips on the website. A capital campaign video with the board chair speaking directly to camera for three minutes.

    Most small businesses have almost nothing like this. A church typically has hours of clean, well-recorded audio of its most authoritative voices, freely downloadable, indexed and organized by name.

    None of that is a reason to stop. The livestream is ministry, and taking it down to prevent a hypothetical fraud would be trading something real for something speculative. The right response is not to publish less. It is to stop treating a familiar voice as identification — because for your organization specifically, a familiar voice is public information.

    The rest of the reference material is public too. Your board members are listed on your website or in your 990 filing. Your bank is on your checks. Your building project is in the newsletter. A fraudster does not need to research you; they need to read you.

    The rule that works no matter how good the fake is

    Everything above is about how convincing the impersonation can be. The control below doesn’t care.

    A decision to move money is never made on a call. It is confirmed on a channel the requester did not choose.

    Sit with that second sentence, because it’s the load-bearing part. If the request came in on a video call, confirmation happens by phone. If it came by phone, confirmation happens by a text to the number in your records, or in person, or on a second call you place. The attacker controls the channel they contacted you through — that’s the one thing you can be certain of. So verification has to happen somewhere else.

    This is the same money rule that runs through everything else on this blog: any change to payment details is verified by voice, on a number you already had, before the payment goes out. The deepfake era changes exactly one thing about it. Voice alone is no longer sufficient confirmation. The channel is doing the verifying now, not the sound of the person.

    Three specific mechanisms make that rule practical.

    A shared verbal passphrase for leadership. Agree on a word or short phrase, in person, among the small group of people who can authorize payments — pastor, treasurer, board chair, administrator. It is never written in email, never stored in a shared drive, never said on a video call. When a request to move money arrives from a person rather than a process, the recipient asks for it. The FBI recommends exactly this technique for families targeted by AI voice fraud: “Create a secret word or phrase with your family to verify their identity.” A leadership team is the same idea with a different roster.

    Pick something unguessable and unGoogleable. Not the church’s founding year, not the pastor’s dog. A random pair of words is ideal, and you should agree in advance that anyone may ask for it without it being awkward, including from the senior person in the room.

    A callback rule. No payment instruction is executed on the strength of the call it arrived on. The administrator hangs up, dials the number already in the personnel file or the vendor contract, and confirms. It adds ten minutes and defeats the entire category.

    Dual approval above a threshold. Pick a dollar figure appropriate to your budget and require two named people to approve anything above it — with the second approval given through a channel other than the one the request came in on. This is the control that survives even when the first person is completely fooled, and it’s why it belongs in your written policy rather than in someone’s habits.

    Write all three down. A control that lives only in the treasurer’s head disappears the moment the treasurer is on vacation, which is the week the request will arrive.

    Tells on a live call, and why they expire

    If you find yourself on a call and something is off, there are things worth trying.

    Ask the person to turn their head fully to one side, or to stand up and step back from the camera. Current systems handle a straight-on face far better than a sharp profile or an unusual angle, and artifacts often appear at the edges — around the ears, the jawline, the hairline, or where hair meets background.

    Ask them to hold a hand up beside their face. Hands are still difficult.

    Better than either: ask something only the real person would know, and make it specific and recent. Not “what’s our budget” — anything published is available. Ask what they ordered at lunch on Tuesday, or what the sanctuary thermostat has been doing, or the name of the person who fixed the parking lot lights. A synthetic impersonation is usually driven by someone reading from research, and research does not include last Tuesday’s lunch.

    Now the honest caveat, which matters more than the tips: these tells are expiring. Every one of them exists because the technology has a current limitation, and current limitations do not stay current. Head turns will get better. Hands will get better. The list above may be substantially useless in two years, and there is no version of it that stays reliable.

    That’s not a reason to skip them. It’s the reason the procedure matters more than the perception. A passphrase and a callback rule work identically whether the fake is crude or flawless, because they never ask anyone to judge how real something looks. They’re the only part of this article with a shelf life.

    If it already happened

    Move fast; recovery is a race measured in hours.

    Call your bank’s fraud line first, before anything else, and ask them to attempt a recall. Wire transfers are hardest to reverse and ACH transfers sometimes possible — either way, the first hour matters more than everything you do afterward.

    Report to the FBI at ic3.gov, and say business email compromise even if the request arrived by video, because that’s the category the Bureau’s recovery process runs on. The FBI’s Recovery Asset Team ran 3,574 domestic cases in 2025 and froze $507,042,623, and that process works dramatically better inside the first 24 to 72 hours.

    Tell your board and your insurer the same day. Many policies have prompt-notice requirements, and a delay can affect coverage.

    Then look at the mailbox. These attacks are frequently preceded by someone reading email inside your organization for weeks. Change passwords from a different device, sign out all sessions, enable multi-factor authentication if it isn’t on, and check every mailbox for forwarding rules nobody remembers creating.

    For scale: the FBI logged 24,768 business email compromise complaints in 2025, with losses of $3,046,598,558 — an average of about $123,005 per report. This is where the money in fraud actually goes, and a synthetic voice or face is simply a new way to open the same door.

    What to do this week

    Choose a passphrase with your leadership team — pastor, treasurer, board chair, administrator — in person or on a call where you can see each other, and agree it is never written down or emailed. Then send one message to whoever executes payments, in your own words: no payment or change of payment details goes out on the strength of a call, however convincing. Hang up, call the number we already have, confirm.

    That’s twenty minutes, and unlike every visual tell in this article, it doesn’t stop working next year.

    Procedures are what hold up when the technology stops helping you tell real from fake. MissionDefend’s free assessment asks plain-English questions about how your organization approves payments, handles email, and manages accounts, then returns a baseline score and a ranked list of what to fix first — including whether your money controls depend on someone recognizing a voice.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud; South China Morning Post, UK multinational Arup confirmed as victim of HK$200 million deepfake scam; CNN, Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    AI Voice Cloning: When the Caller Sounds Exactly Like Your Director

    The bookkeeper answers on the second ring, and it’s the executive director’s voice. Not a voice like hers — her voice. The slight rasp. The way she says “listen” at the start of a sentence when she’s stressed.

    Listen — I’m about to get on a flight and the auction deposit didn’t go through. I need you to send it again before we lose the venue. I’ll text you the details. Don’t call back, I’m boarding.

    It’s her voice. It is not her.

    This is voice cloning — using artificial intelligence to generate speech that sounds like a specific, real person. The software behind it is cheap, legal, widely available, and needs surprisingly little to work with: a short sample of someone talking is enough to produce a convincing copy saying anything an attacker types. The FBI warned about exactly this in a December 2024 public service announcement: criminals are generating “short audio clips containing a loved one’s voice” to fake a crisis and demand immediate money. The Federal Trade Commission issued the same warning back in March 2023 — all a scammer needs is “a short audio clip of your family member’s voice,” which, the FTC notes, “he could get from content posted online.”

    Read that last part again, and then think about where your pastor’s voice lives.

    Churches are uniquely exposed, and it’s worth saying plainly

    For most small organizations, the boss’s voice isn’t on the internet. For a church, the entire leadership team is on the internet, every single week, in high-quality audio, saying thousands of words in every register — calm, urgent, warm, commanding. The livestream. The sermon podcast. The YouTube archive going back years.

    None of that is a mistake, and the answer is absolutely not to stop. Public preaching is the work. But it changes the math your staff should carry in their heads: for your organization, “it sounded exactly like him” is not evidence of anything. Not anymore. A scammer targeting your church has a better voice sample of your senior pastor than most attackers have of a Fortune 500 CEO.

    How the scam is actually run

    Voice cloning didn’t invent a new con. It upgraded three old ones we’ve already covered in this series.

    The urgent-request call. The gift card scam — “I need you to handle something quietly” — has historically arrived by email or text, where the impersonation is only a display name. A cloned voice moves it to the phone, where the impersonation is your ears telling you it’s really him. The structure is identical: urgency, secrecy, an odd payment method.

    The family emergency. A grandparent gets a call from a grandchild — the grandchild’s actual voice — in trouble, needing bail or a hospital deposit, begging them not to tell mom and dad. This is the version the FTC’s alert describes, and it targets exactly the older adults a church is best positioned to warn.

    The verification call. The FBI’s PSA notes criminals also use AI-generated audio of a victim’s own voice to get past phone-based identity checks at banks. That one you can’t train away — but it’s a reason to prefer app-based verification over “we’ll call you” security wherever your financial institutions offer a choice.

    One more thing makes the phone version stronger than it should be: the number on the screen can lie. Caller ID spoofing — displaying a number the caller doesn’t own — remains routine, as the FCC documents, and the STIR/SHAKEN verification system that carriers use confirms which network a call came from, not whether the person speaking is honest. A familiar voice from a familiar number can still be neither.

    Why “listen carefully” is not a defense

    You’ll find advice suggesting you listen for robotic cadence or odd pauses. The FBI’s own PSA suggests paying attention to tone and word choice — and that’s worth doing — but treat it as a tripwire, not a wall. The technology improves monthly, the clips are short by design, and a stressed listener on a bad connection hears what they expect to hear. Any defense that requires your bookkeeper to out-listen a machine on the worst morning of her month is not a defense.

    The defense that works is procedural, and it’s the same one that stops every impersonation scam regardless of how good the impersonation is: the request and the verification must travel on different channels.

    What to do this week

    Set the callback rule for money and credentials. Any request to move money, buy gift cards, change banking details, or share a password — no matter who it comes from, no matter how it arrives, no matter how real the voice sounds — is confirmed by hanging up and calling the person back on the number already in your contacts. Not the number that just called. Not a number from the message. The clone can call you; it cannot answer the real person’s phone.

    Agree on a family-style code word for leadership. Pick a phrase the executive team knows and would never appear in a sermon. If a “boarding a plane right now” call ever demands money and can’t take a callback, ask for the word. It’s thirty seconds of setup for a control no voice model can generate. Encourage staff to set the same thing up with their own aging parents — this scam reaches homes before it reaches offices.

    Kill the secrecy lever in policy. Write it down: no financial request at this organization is ever confidential from the treasurer or bookkeeper’s normal verification steps. “Don’t tell anyone” or “don’t call back” is not a request a real leader here will ever make — which converts the scammer’s favorite pressure line into an alarm.

    Tell the congregation about the grandparent version. One announcement, one bulletin line: if a family member calls in crisis asking for money, hang up and call them back on their own number — a voice can be faked. The FTC’s guidance is exactly that — don’t trust the voice, verify through a known channel — and older members are far more likely to hear it from you than from a federal agency’s blog.

    The voice on the phone used to be proof. It’s now just another sender name, as forgeable as the “From” line on an email. The organizations that handle this well won’t be the ones with the sharpest ears — they’ll be the ones where calling back is so routine that nobody even feels awkward doing it.

    The free MissionDefend assessment checks whether verification rules like these actually exist at your church — not just in someone’s head — along with the rest of your security baseline. Join the launch list to get first access.


    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Alert I-120324-PSA (December 3, 2024); Federal Trade Commission, Scammers use AI to enhance their family emergency schemes (March 20, 2023); Federal Communications Commission, Caller ID Spoofing.