Signal Over Noise #27
November 5th, 2025
Dear Reader,
Last week, I showed you how to make AI sound like you.
This week, I’m going to explain why you shouldn’t.
Before we dive in: This week I’m talking about AI-generated clones of your actual voice and image—the kind scammers can use for fraud. This is not about text-based AI agents trained on your writing style (we’ll cover those properly next week in Part 2).
Your CEO is on 47 podcast episodes. Your CTO does quarterly webinars. Your CMO has a YouTube channel.
Congratulations! Scammers now have everything they need to clone your executives’ voices.
And the timing couldn’t be worse. We’re heading into the season when vishing (voice phishing) attacks spike dramatically, with November and December alone accounting for 27 billion scam calls and over $10 billion in losses. The numbers are stark enough, but they don’t capture the real problem: vishing attacks increased 442% between the first and second half of 2024, and the trajectory isn’t slowing down.
But the push for “perfect” AI voice clones isn’t just misguided during vishing season — it’s actively dangerous. When your digital twin sounds exactly like you, bad actors get the same tool.
Why This Week Matters
The technology has crossed a critical threshold. AI voice cloning now takes 3 seconds of audio — not the minutes or hours that used to be required, but literally three seconds of someone speaking. Public figures have hundreds of hours of audio online, freely available to anyone who wants to scrape it. Everyone’s racing to build “authentic” AI assistants that sound exactly like their users, and scammers are specifically targeting the holiday vulnerabilities that make November and December their most profitable season.
The business impact tells the story more clearly than any warning could. Seventy percent of businesses share sensitive information during fake vishing calls, with the average loss per successful attack reaching $137,000. Manufacturing and engineering sectors show 19.2% vulnerability rates — the highest of any industry — which means nearly one in five attempts succeeds.
Real examples from the last year drive this home. A UK energy CEO lost £220,000 after a deepfake voice call from someone impersonating his boss — an attack that happened in 2019 but has become trivially easier to execute with today’s technology. Arup engineering firm lost $25 million via deepfake video conference in 2024. LastPass detected CEO deepfake impersonation attempts via WhatsApp early this year. Ferrari stopped a CEO voice clone only because an executive had the presence of mind to ask a verification question the impersonator couldn’t answer.
Then there are the grandparent scams using cloned grandchild voices, the President Biden deepfake robocalls during US election primaries, and countless other incidents that never make headlines because companies settle quietly. This isn’t theoretical anymore.
Why I Know This Works
In 2023, I demonstrated this attack to security teams at a major European energy provider, walking them through the complete process from audio collection to convincing voice generation. The exercise took 20 minutes total — from finding audio online to generating clones that could fool people who knew the executive personally. I scraped eight voice samples from YouTube, none of them clean recordings. Background noise, music, overlapping speakers, all the imperfections you’d expect from conference footage and webinar recordings. Three generations to get the pacing and pauses right, adjusting for the slight delays and rhythms that make speech sound natural rather than synthesised.
The result was convincing enough that the security team created an awareness campaign. That was 2023 technology, which means it’s gotten significantly easier since then. The barrier to entry isn’t technical expertise anymore — it’s simply knowing your target has public audio online.
If your executive has done any podcast appearances, webinars, conference talks, or YouTube videos, they do.
The “Thought Leadership” Trap
Here’s how this could potentially play out in practice. Social engineers create a legitimate-looking podcast website, complete with previous episodes featuring real guests and professional production values. They invite your executive as a “special guest” to discuss their expertise in energy, finance, or whatever sector you’re in. The host conducts a thoughtful 45-minute interview, asking strategic questions that draw out not just information but emotional range — frustration about industry challenges, excitement about new opportunities, contemplative analysis of market trends, decisive statements about the future.
Your executive thinks they’re building thought leadership and industry authority. The attackers just captured 45 minutes of clean, high-quality voice data with the varied emotional tones that make voice cloning convincing. One podcast appearance contains enough voice data for years of potential scams, and the audio quality is better than anything they could scrape from conference footage or webinar recordings.
How many of these did your leadership team do last quarter?
That’s intentional collection, which is bad enough. The passive collection is worse. Every podcast appearance, webinar, conference keynote, and LinkedIn video becomes voice data collection, building a library of your executives’ speech patterns that anyone can access and use. The compound effect means each new appearance doesn’t just add to the total — it improves the quality of potential clones by providing more varied contexts and emotional ranges.
Why “Perfect Authenticity” Is Your Enemy
Everyone’s racing toward perfect AI voice clones, treating authenticity as the goal rather than recognizing it as a vulnerability. But in security terms, perfect authenticity equals perfect vulnerability because when your AI clone sounds exactly like you, so does the scammer’s version.
No distinguishing markers exist to tell them apart. No way to verify authenticity through voice alone. Social engineering bypasses security protocols because “trust your instincts” fails when the technology produces perfect matches. The human ability to recognise familiar voices — once a reliable security feature — becomes useless when both legitimate and fraudulent calls sound identical.
The uncanny valley is actually a security feature, not a bug to be eliminated. That “something’s off” feeling you get when listening to a not-quite-right voice clone is your best defense against impersonation. Slight differences create red flags that trigger verification protocols. “Too perfect” should make you suspicious rather than confident. Your imperfections — the pauses, the verbal tics, the slight variations in pacing — are your signature, and eliminating them for convenience creates risk.
If you’ve built a perfect clone for your use, you’ve also built a perfect model for their use. The same technology that makes your AI assistant sound exactly like you makes it trivial for attackers to do the same.
Holiday Season Makes This Worse
November through December is vishing season, and the numbers explain why. People are more relaxed about verification when they’re thinking about gifts and holiday plans. “Urgent” requests feel normal during a season already filled with last-minute shopping, charitable giving, and package deliveries. Social engineers know this, which is why they time their attacks to exploit holiday pressure and reduced corporate vigilance.
The scale is staggering. These two months alone account for 27 billion scam calls — nearly half the annual total compressed into 60 days. December 25 consistently ranks as the highest fraud activity day of the year, with the week leading up to Christmas showing the sharpest rise in attempted scams. Losses during this period exceed $10 billion, driven by a combination of relaxed security protocols, skeleton staffing, and people’s natural inclination to be more trusting during the holidays.
Cold weather plays a role too. People stay inside, near their phones, more available to answer calls they’d normally ignore. The combination of availability, distraction, and seasonal urgency creates perfect conditions for voice-based attacks.
Translation: The next 60 days are when a perfect AI voice clone is most likely to be weaponised against you.
The Red Flags Most People Miss
For individuals, watch for unexpected urgent requests from “family” during holidays, especially ones involving gift card payments—a massive holiday scam vector that exploits both emotional manipulation and the difficulty of reversing these transactions. Charity calls with immediate pressure tactics should trigger suspicion, as should package delivery “issues” requiring immediate payment before you can receive something you may not have actually ordered. The warning sign isn’t that the voice sounds fake—modern technology makes that distinction nearly impossible. It’s that the voice sounds perfect but the context feels off.
For businesses, financial requests during holiday periods deserve extra scrutiny, particularly wire transfers authorized via voice only without the usual paper trail or verification steps. When your “CEO” makes requests outside normal channels, or urgent matters suddenly bypass the established protocols that exist specifically to prevent fraud, that’s a red flag even if the voice is a perfect match. The timing matters more than the technology, because attackers know that holiday staffing creates gaps in verification processes.
The “too perfect” test works like this: If your CEO sounds exactly like themselves on a cold call during the holidays asking for an urgent wire transfer before everyone leaves for Christmas, that’s probably not your CEO. The combination of perfect voice replication, unusual timing, and pressure to act quickly is the signature of a sophisticated attack, not a legitimate emergency.
What’s Next
The solution isn’t avoiding AI voice tools—they’re too useful for productivity and communication to give up entirely. And it’s not trying to detect deepfakes through technology alone—that’s an arms race you’ll lose as both attack and defence capabilities improve at roughly the same pace.
The solution is strategic differentiation. Building an AI agent that thinks like you and communicates with your knowledge and decision-making patterns, but doesn’t sound exactly like you in ways that create security vulnerabilities.
Next week, I’ll show you exactly how to do this. How to define differentiators that feel natural in your communication style but are hard for attackers to clone from public audio. How to build multiple versions for different contexts—internal team communication versus client-facing work versus public content. How to train your team to recognize your agent versus you without creating friction in daily operations. How to create verification protocols that actually work under pressure rather than getting bypassed when urgency seems justified. And how to implement all of this before Thanksgiving, because you should have these protections in place before the holiday vishing season hits full force.
This isn’t theoretical framework development. It’s the same approach I used with European critical infrastructure companies, and it works because it acknowledges that perfect voice replication is here to stay while building practical defenses around differentiation rather than detection.
Action Items For This Week
Before next Thursday’s newsletter, you need to do five things.
- Audit your audio footprint — YouTube appearances, podcast episodes, webinar recordings, conference talks, social media videos, anything where your voice (or your team’s voice) is publicly available.
- Inventory your team’s exposure by identifying who has public audio, how much exists, and where it’s hosted.
- Document your current practices around AI voice tools to establish a baseline for what changes when you implement differentiation strategies.
- Identify your most vulnerable team members—who handles financial decisions, who has access to sensitive data, who could authorise significant transactions.
- Brief your team on the 442% increase in vishing attacks and implement extra verification requirements during the holiday period.
Next week delivers the practical implementation guide for building your differentiated AI agent with specific steps, copy-paste templates, and verification protocols.
Until next week,
Jim
Signal Over Noise is weekly, reader-first publication on AI “without the hype” published by Jim Christian. If you’ve been forwarded this issue, you can subscribe for free: go.signalovernoise.at. You can also Join the free Signal Over Noise Community on Skool.
Made with ❤️ in Valencia by Jim Christian. For feedback, please reach out to [email protected].