Voice authentication, the bank security model in which your voiceprint is your password, has been defeated repeatedly with AI voice clones. A reporter cloned his own voice and got into his account, a BBC reporter passed two banks' voice-ID systems the same way, and University of Waterloo researchers reported defeating voice authentication with up to 99 percent success within six attempts.
The demonstrations
Using a consumer cloning tool, a journalist at Motherboard cloned his own voice and got into his account, past his bank's voice-based authentication. A BBC reporter then ran the same test against two UK banks' voice-ID systems, speaking the enrollment phrase through an AI clone, and was admitted to the accounts. These are not lab abstractions. They are reporters defeating the live authentication of named banks with off-the-shelf tooling.
The research backs the anecdotes. University of Waterloo researchers described a method that defeated voice-authentication systems with success rates reported up to 99 percent within six attempts, and at that rate the finding is not a marginal edge. It is a control that does not hold.
What actually got bypassed
The mechanism is direct, and it is worth stating precisely. A voice-authentication system enrolls a model of the acoustic properties of a speaker's voice, pitch, formant structure, spectral character, and at login it compares a new sample against that enrolled model and returns a match score. Reproducing those same acoustic properties closely enough, a high-quality clone earns a passing score.
So the control did exactly what it was built to do: it compared acoustics and found a match. The problem is that acoustics are now cheap to reproduce from a short sample of someone's voice, and samples are everywhere, in podcasts, webinars, earnings calls, voicemail greetings, and social video. No longer scarce, the biometric is no longer a secret, and no longer a secret, it is no longer a credential.
The industry already agrees
What makes voice the clearest case is that the defenders concede it. A BioCatch survey found that a large majority of US banks, reported around 91 percent, were rethinking voice biometric authentication in light of AI cloning. By mid-2025, OpenAI's chief executive was saying publicly that it terrified him that some financial institutions still accept a voiceprint as authentication, calling it a crazy thing to still be doing and stating that AI has fully defeated it.
When the people building the AI and the people defending the banks both say the control is beaten, the debate is over. What remains is operational: which deployments still rely on it.
What this means
If a voiceprint sits anywhere in your authentication or account-recovery flow, treat it as defeated for the purpose of standing alone. As a low-friction signal inside a layered system it can still contribute; as a gate that grants access on its own, it is the weakest link, and a cheaply reproducible one. The executive-impersonation attempts at Ferrari and WPP show the other side of the same coin, a cloned voice stopped only because a person asked for something the clone could not supply.
More broadly, voice is the leading indicator for every biometric control. The same logic, a matcher comparing a property that generative models can now reproduce, applies to face and to document checks; voice simply got there first because cloning got cheap first. The others are on the same path, which is the pattern our detector benchmark measures directly, and the reason the only honest answer to whether your control holds is a measured one.
The question is never whether a clone or a fake sounds or looks convincing. It is whether the control reads a property the attacker cannot supply. Margen does not sell authentication or detection; we measure that, as an independent third party, with a number and a margin of error.
Related reading
- Fraud storiesThe engineer a security firm hired was a North Korean operative.A North Korean operative cleared a security firm's background check, reference checks, and four video interviews using a stolen identity and an AI-augmented photo. The verification that failed was remote identity screening, and it fails at industrial scale.
- Fraud storiesThe AI-edited claim photos insurers are already catching.Admiral's own fraud examples are photoshopped damage and swapped number plates, and a Verisk study puts the gap in one line: a third of consumers would alter a claim image, and only a third of insurers are confident they could catch a deepfake.
- Methodology notesAUC is the wrong number for identity verification.Thirteen published synthetic-ID detectors, measured on 6,948 passport-style images. Nine change rank the moment you measure what they actually catch rather than how they rank, and that gap is visible before a document has been through a single scanner.