Pindrop analysis has identified the four ways that attackers are using deepfakes to target contact centers.
While to most people, the idea of deepfakes generally relates to counterfeit celebrity photos and videos – the use of synthetic voice is a growing concern for contact center safety.
Deepfake voice works by using AI to clone a person’s voice, with the recent advancements in generative AI making it possible to emulate the tone and likeness to an alarmingly accurate level.
With the proliferation of homemade videos across social media channels like Instagram, Facebook, and especially TikTok, it is becoming incredibly easy for fraudsters and scammers to find examples of customers’ voices through basic internet searches.
In a study of a selection of its clients, Pindrop – an expert in audio traffic monitoring – was able to detect and analyze a number of calls with "low liveness scores" and determine that they were being perpetrated with synthetically generated voices – underscoring just how prevalent contact center deepfake attacks already are.
But what exact tactics are fraudsters using to target contact centers? And how can companies identify and prevent them?
Pindrop analyzed all of the synthetic calls that its customers received and outlined the following four patterns:
1. Deepfake Voice Is Not Limited to Duping Authentication
Despite the ability of deepfake technology to allow a bad actor to conduct a full conversation in a cloned voice, most scam calls were actually far more simplistic – focusing on using synthetic voice to gain an understanding of the IVR navigation and steal basic account details.
Armed with this information, fraudsters would then make the calls themselves, reverting back to traditional social engineering methods.
2. Deepfake Voice Is Helping Attackers IVR Bypassing Authentication
If the above example was akin to sending a singular scout to have a quick look at the lay of the land, this one is a fully blown reconnaissance mission.
Synthetic voices were able to completely bypass the IVR authentication steps, allowing fraudsters access to more sensitive information, such as bank/account balances, which could be used to identify which customers were worth targeting further.
While these sorts of tactics have been around for some time, the combination of deepfake voice and automation means that scammers can operate at a far higher scale.
3. Deepfake Voice Is Helping Attackers Alter Account Details
Another classic weapon in the fraudsters’ arsenal that has been enhanced with deepfake technology, like when Johnny Cash took the Nine Inch Nails song, ‘Hurt’ to an entirely different level – but, you know, with his legitimate voice.
By emulating customers’ voices, scammers were able to alter email and home addresses, opening up a number of fraud opportunities, including accessing one-time passwords and ordering new bank cards.
4. Deepfake Voice Is Helping Attackers Mimicking IVRs
In arguably the most innovative fraud strategy, some deepfake voice recordings revealed that scam callers were using their own voicebots to mimic IVRs.

