NewThe detectors that scored perfect collapsed the hardest under attack.
Back to publications
Fraud story

A cloned voice that said the password, and the bank let it in.

Of the control bypasses worth studying, voice authentication is the one where the evidence is least ambiguous, because the people defeating it published exactly how, and the targets were live production systems.

Article · June 2026 · 6 minute read

Voice authentication, the bank security model in which your voiceprint is your password, has been defeated repeatedly with AI voice clones. A reporter cloned his own voice and got into his account, a BBC reporter passed two banks' voice-ID systems the same way, and University of Waterloo researchers reported defeating voice authentication with up to 99 percent success within six attempts.

The demonstrations

Using a consumer cloning tool, a journalist at Motherboard cloned his own voice and got into his account, past his bank's voice-based authentication. A BBC reporter then ran the same test against two UK banks' voice-ID systems, speaking the enrollment phrase through an AI clone, and was admitted to the accounts. These are not lab abstractions. They are reporters defeating the live authentication of named banks with off-the-shelf tooling.

The research backs the anecdotes. University of Waterloo researchers described a method that defeated voice-authentication systems with success rates reported up to 99 percent within six attempts, and at that rate the finding is not a marginal edge. It is a control that does not hold.

What actually got bypassed

The mechanism is direct, and it is worth stating precisely. A voice-authentication system enrolls a model of the acoustic properties of a speaker's voice, pitch, formant structure, spectral character, and at login it compares a new sample against that enrolled model and returns a match score. Reproducing those same acoustic properties closely enough, a high-quality clone earns a passing score.

So the control did exactly what it was built to do: it compared acoustics and found a match. The problem is that acoustics are now cheap to reproduce from a short sample of someone's voice, and samples are everywhere, in podcasts, webinars, earnings calls, voicemail greetings, and social video. No longer scarce, the biometric is no longer a secret, and no longer a secret, it is no longer a credential.

The industry already agrees

What makes voice the clearest case is that the defenders concede it. A BioCatch survey found that a large majority of US banks, reported around 91 percent, were rethinking voice biometric authentication in light of AI cloning. By mid-2025, OpenAI's chief executive was saying publicly that it terrified him that some financial institutions still accept a voiceprint as authentication, calling it a crazy thing to still be doing and stating that AI has fully defeated it.

When the people building the AI and the people defending the banks both say the control is beaten, the debate is over. What remains is operational: which deployments still rely on it.

What this means

If a voiceprint sits anywhere in your authentication or account-recovery flow, treat it as defeated for the purpose of standing alone. As a low-friction signal inside a layered system it can still contribute; as a gate that grants access on its own, it is the weakest link, and a cheaply reproducible one. The executive-impersonation attempts at Ferrari and WPP show the other side of the same coin, a cloned voice stopped only because a person asked for something the clone could not supply.

More broadly, voice is the leading indicator for every biometric control. The same logic, a matcher comparing a property that generative models can now reproduce, applies to face and to document checks; voice simply got there first because cloning got cheap first. The others are on the same path, which is the pattern our detector benchmark measures directly, and the reason the only honest answer to whether your control holds is a measured one.

The question is never whether a clone or a fake sounds or looks convincing. It is whether the control reads a property the attacker cannot supply. Margen does not sell authentication or detection; we measure that, as an independent third party, with a number and a margin of error.