The fast pace of development in artificial intelligence (AI) is delivering clear benefits - but it is also creating new risks.
One particularly worrying pattern is the misuse of voice cloning. Within seconds, scammers can copy someone’s voice and persuade victims that a friend or family member urgently needs money.
News organisations, including CNN, have warned that these scams could affect millions of people.
As technology increasingly enables criminals to intrude into our private lives, it has never been more important to be cautious about how it is used.
What is voice cloning?
The growth of AI has opened up new possibilities in image creation, text generation, voice generation and machine learning.
Although AI brings many advantages, it also hands fraudsters additional ways to exploit people for financial gain.
You may already be familiar with "deepfakes", where AI is used to fabricate images, videos and even audio - often featuring celebrities or politicians.
Voice cloning is one form of deepfake technology. It produces a digital copy of a person’s voice by extracting speech patterns, accent and breathing from short audio clips.
After those patterns are captured, an AI voice generator can turn written text into remarkably lifelike speech that sounds like the intended target.
As the tools improve, cloning a voice can be done with as little as a three-second audio sample.
Even a short phrase such as "hello, is anyone there?" can be enough to enable a voice cloning scam. A longer exchange, however, helps scammers gather more vocal detail - which is why it is best to keep calls brief until you have confirmed who you are speaking to.
Voice cloning also has legitimate, valuable uses in entertainment and health care - for example, allowing artists to record voice work remotely (including after death) and supporting people with speech disabilities.
Even so, the technology creates major privacy and security issues, which underlines the need for effective safeguards.
How it’s being exploited by criminals
Cybercriminals use voice cloning to impersonate celebrities, authorities or everyday individuals as part of fraud.
Typically, they manufacture urgency, build trust and then ask for money through gift cards, wire transfers or cryptocurrency.
It usually starts with gathering audio from public sources such as YouTube and TikTok.
The audio is then processed by the technology to produce newly generated recordings.
After a voice has been cloned, it can be deployed in misleading calls and messages, often alongside spoofing Caller ID so the contact appears credible.
A number of voice cloning scam incidents have attracted media attention.
In one case, criminals copied the voice of a company director in the United Arab Emirates and arranged a $A51 million heist.
In another, a businessman in Mumbai was deceived by a voice cloning scam involving a bogus call supposedly from the Indian Embassy in Dubai.
More recently in Australia, scammers used a voice clone of Queensland Premier Steven Miles in an attempt to persuade people to invest in Bitcoin.
Teenagers and children are also in scammers’ sights. During a kidnapping scam in the United States, a teenager’s voice was cloned and her parents were pressured into meeting the criminals’ demands.
How widespread is it?
Recent research found that 28% of adults in the United Kingdom encountered voice cloning scams last year, while 46% did not know this type of scam even existed.
This points to a substantial gap in public knowledge - and leaves millions vulnerable to fraud.
In 2022, close to 240,000 Australians said they had been targeted by voice cloning scams, with total losses of $A568 million.
How people and organisations can safeguard against it
Because the dangers linked to voice cloning are complex, responding effectively requires a multidisciplinary approach.
There are several steps people and organisations can take to reduce the chance of voice cloning being misused.
First, education and public awareness campaigns can help people and organisations protect themselves and limit this kind of fraud.
Working together across the public and private sectors can also help deliver clear information and meaningful consent options around voice cloning.
Second, individuals and organisations should consider biometric security with liveness detection - an emerging approach that can identify and authenticate a live voice rather than a fake. Organisations that rely on voice recognition should also weigh up the use of multi-factor authentication.
Third, strengthening investigative capability to tackle voice cloning is another key step for law enforcement.
Finally, countries need accurate, up-to-date regulation to manage the associated risks.
Australian law enforcement recognises the potential advantages of AI.
At the same time, anxieties about the "dark side" of the technology have led to calls for research into the criminal use of "artificial intelligence for victim targeting".
There are also calls for possible intervention strategies that law enforcement could adopt to address this challenge.
These efforts should align with the broader National Plan to Combat Cybercrime, which emphasises proactive, reactive and restorative approaches.
That national plan sets out a duty of care for service providers - mirrored in new Australian Government legislation designed to protect the public and small businesses.
The legislation is intended to introduce new requirements to prevent, detect, report and disrupt scams.
It will apply to regulated organisations including telcos, banks and digital platform providers. The aim is to protect customers by preventing, detecting, reporting and disrupting cyber scams that rely on deception.
Reducing the risk
With cybercrime estimated to cost the Australian economy A$42 billion, strong safeguards and widespread public awareness are vital.
Countries such as Australia are increasingly acknowledging the scale of the threat. How well measures work against voice cloning and other forms of fraud will depend on how adaptable they are, what they cost, whether they are practical to implement and how well they meet regulatory requirements.
All stakeholders - government, citizens and law enforcement - need to remain alert and invest in raising awareness to reduce the likelihood of victimisation.
Leo S.F. Lin, Senior Lecturer in Policing Studies, Charles Sturt University; Duane Aslett, Senior Lecturer in Policing Studies, Charles Sturt University; Geberew Tulu Mekonnen, Lecturer, School of Policing Studies, Charles Sturt University, and Mladen Zecevic, Lecturer at the School of Policing Studies, Charles Sturt University
This article is republished from The Conversation under a Creative Commons licence. Read the original article.
Comments
No comments yet. Be the first to comment!
Leave a Comment