Case Study: Scammers Cloned an Executive’s Voice and Stole 3 Million Euros
- 3N1 IT Consultants
- Aug 27
- 3 min read

Imagine your phone rings and somebody you know is on the other end. Maybe it’s a coworker, close friend, or networking connection. In fact, you can even recognize their voice. They sound completely normal, discuss relevant topics from recent projects, and then ask you to do something important.
Would you trust them?
For many people, the answer is yes. The more time-sensitive the request, the less care people take. Although that sounds counterintuitive, the external pressure of a deadline or authority figure can make it hard to turn down these types of requests.
Until recently, we didn’t have to worry about that. Recognizing someone’s voice provided pretty strong reassurance that you were actually speaking with that person. Now AI has changed that assumption.
In July 2026, Capillary Technologies disclosed that scammers used sophisticated impersonation techniques, including AI voice cloning, to steal approximately €3 million from one of its overseas subsidiaries. In short, the attack proved exactly why a familiar voice is no longer proof of identity.
What Happened?
According to Capillary Technologies’ disclosure, criminals impersonated senior company personnel and convinced employees to authorize fraudulent bank transfers.
Now, the scam is more complex than someone sending an email claiming to be the CEO. Instead, the attackers combined several techniques. They cloned voices, forged signatures, and used social engineering to make the requests appear legitimate. By the time the company discovered the fraud, approximately €3 million had gone to unauthorized third-party bank accounts.
Capillary later recovered about €450,000 and said the incident did not compromise customer data. Still, the attack showed how powerful impersonation can be when AI enters the picture.
Would you fall for it if you worked there?
Voice Cloning Changes an Old Scam
Impersonation scams are nothing new. For years, criminals have pretended to be executives, government officials, bank employees, family members, and practically anyone else they thought a victim might trust.
The difference? AI removes one of the biggest weaknesses those scams once possessed. Now, attackers don’t have to blindly mimic executive officers and hope that they sound convincing. They can conjure convincing photos, videos, and sound bites in mere minutes.
Modern voice-cloning technology can imitate a person’s voice using recorded audio. Depending on the circumstances, criminals may find usable samples in videos, podcasts, social media posts, voicemail greetings, or other publicly available recordings. Think about how much more convincing that makes these scams!
The Threat to Your Data
Imagine receiving a call from someone who sounds like your manager, and they urgently need a password reset. Maybe your “bank” calls about suspicious activity and asks you to verify an account number.
Quickly, the same basic threat tactic becomes much more personal.
A scammer could impersonate a child, spouse, parent, or friend of yours and claim that they’ve had an emergency.
That possibility becomes particularly concerning when you consider the sheer scale of impersonation fraud. The Federal Trade Commission reported that people lost over $3.5B to imposter scams in 2025. AI gives criminals another way to make those impersonations more believable.
Listen to the Request, Not Just the Voice
We need to change how we think about phone calls and approach them with more caution, even if the name and number look (and sound) familiar. Just because someone sounds exactly like your manager doesn't necessarily mean your boss is really calling.
Instead, pay attention to what they want you to do. Are they asking for money? Do they want a password or verification code? Are they telling you to ignore a normal procedure or describing an emergency that requires you to act immediately?
Those warning signs matter even when the voice sounds completely legitimate.
Create Another Way to Verify
If a request seems unusual, then take the time to verify it separately.
Hang up and call the person using a known, approved phone number
Send them a message through a secondary, encrypted communication channel
Follow your job’s established approval process instead of accepting verbal authorization alone
With close friends and family, create a simple verification phrase or question for emergencies
The key to better security? Don’t verify someone’s identity using the same suspicious communication that created the doubt. If a caller says they are your bank, for example, then hang up and call the number printed on your card instead!
Why Cloning Voices is So Effective
The Capillary Technologies incident involved millions of euros, senior executives, and international banking—but these incidents happen regardless of your company’s size or your role within it.
AI voice cloning makes scams more convincing against businesses, employees, parents, grandparents, and practically anyone else who answers a phone. That means we have to practice extra caution.
Listen carefully to what someone is asking you to do, especially when it involves money, passwords, accounts, or sensitive information. In short: If the request seems unusual, verify it another way.
Because today, hearing should not always mean believing.


.png)


Comments