AI Voice Clone + BEC Combo Attack
Attack Trigger
Email confirms a wire transfer "authorized verbally by your CEO" using AI-cloned voice
What Attackers Want
$50,000–$25,000,000+ in a single wire transfer; no recourse once funds are moved internationally
How This Attack Works
In this hybrid attack, employees receive an email from an impersonated executive claiming a confidential wire transfer was verbally authorized — referencing a phone or voicemail the victim may actually have received. Attackers use AI voice-cloning tools to generate a brief, convincing audio clip mimicking the executive's voice, sent as a follow-up email attachment or embedded link. The combination of email authority and realistic voice confirmation bypasses skepticism that pure-email BEC would not.
Red Flags to Watch For
- ✗Email from a "C-suite executive" references a phone call you just received asking for urgent wire transfer
- ✗Wire request is confidential, time-sensitive, and outside normal approval channels
- ✗Voicemail or audio attachment sounds like your executive but the call-back number is different
- ✗Request bypasses your organization's dual-authorization payment controls
- ✗Executive is described as traveling, in a meeting, or unreachable for follow-up
- ✗AI voice clones can replicate a voice from as little as three seconds of public audio
Known Malicious Domains
These domains have been associated with this attack. Never click links going to these addresses.
- cfo-urgent-wire-request.comMALICIOUS
- exec-payment-approval.netMALICIOUS
- voice-confirmed-transfer.comMALICIOUS
Glance automatically blocks emails from domains on this list. Domain list is not exhaustive — attackers register new domains continuously.
How Glance Stops This
- Domain similarity analysis catches lookalike sender addresses at millisecond speed
- SPF / DKIM / DMARC validation flags authentication failures before you ever see the email
- VirusTotal + Google Safe Browsing checks every link in real time
- Urgency language detection scores the email higher for manual review
- Known malicious domain blocklist updated continuously from live scan data
Don't wait to get hit.
Glance scans every incoming email against 12 detection layers — including the exact tactics described above — before it reaches your inbox.
Protect My Inbox — Free