Threat Intelligence Directory
Business Email Compromise

AI Voice Clone + BEC Combo Attack

Attack Trigger

Email confirms a wire transfer "authorized verbally by your CEO" using AI-cloned voice

What Attackers Want

$50,000–$25,000,000+ in a single wire transfer; no recourse once funds are moved internationally

How This Attack Works

In this hybrid attack, employees receive an email from an impersonated executive claiming a confidential wire transfer was verbally authorized — referencing a phone or voicemail the victim may actually have received. Attackers use AI voice-cloning tools to generate a brief, convincing audio clip mimicking the executive's voice, sent as a follow-up email attachment or embedded link. The combination of email authority and realistic voice confirmation bypasses skepticism that pure-email BEC would not.

Red Flags to Watch For

  • Email from a "C-suite executive" references a phone call you just received asking for urgent wire transfer
  • Wire request is confidential, time-sensitive, and outside normal approval channels
  • Voicemail or audio attachment sounds like your executive but the call-back number is different
  • Request bypasses your organization's dual-authorization payment controls
  • Executive is described as traveling, in a meeting, or unreachable for follow-up
  • AI voice clones can replicate a voice from as little as three seconds of public audio

Known Malicious Domains

These domains have been associated with this attack. Never click links going to these addresses.

  • cfo-urgent-wire-request.comMALICIOUS
  • exec-payment-approval.netMALICIOUS
  • voice-confirmed-transfer.comMALICIOUS

Glance automatically blocks emails from domains on this list. Domain list is not exhaustive — attackers register new domains continuously.

How Glance Stops This

  • Domain similarity analysis catches lookalike sender addresses at millisecond speed
  • SPF / DKIM / DMARC validation flags authentication failures before you ever see the email
  • VirusTotal + Google Safe Browsing checks every link in real time
  • Urgency language detection scores the email higher for manual review
  • Known malicious domain blocklist updated continuously from live scan data

Don't wait to get hit.

Glance scans every incoming email against 12 detection layers — including the exact tactics described above — before it reaches your inbox.

Protect My Inbox — Free