AskVantage

Security and privacy

Criminals cloned a directors voice to steal $35 Million in yet another spoofing attack

When your voice is your password and your voice can be cloned it's not that easy to get a new password ...

Key takeaways

  • In early 2020, a bank manager in the Hong Kong received a call from a man whose voice he recognized - a director at a company with whom he’d spoken before.
  • The director had good news: His company was about to make an acquisition, so he needed the bank to authorize some transfers to the tune of $35 million.
  • A lawyer named Martin Zelner had been hired to coordinate the procedures and the bank manager could see in his inbox emails from the director and Zelner, confirming what money needed to move where.
Cite or link to this article

Griffin, M. (2022) 'Criminals cloned a directors voice to steal $35 Million in yet another spoofing attack', 311 Institute, 25 February. Available at: https://www.311institute.com/criminals-cloned-a-directors-voice-to-steal-35-million-in-yet-another-spoofing-attack/ (Accessed: 1 October 2026).

After a $76 million heist in China, and in yet another example of how criminals are using Artificial Intelligence (AI) to clone people’s voices and other biometric and biomarker information for nefarious purposes it turns out that yet another company has been scammed, and you can now consider this as part of a growing trend.

In early 2020, a bank manager in the Hong Kong received a call from a man whose voice he recognized - a director at a company with whom he’d spoken before. The director had good news: His company was about to make an acquisition, so he needed the bank to authorize some transfers to the tune of $35 million. A lawyer named Martin Zelner had been hired to coordinate the procedures and the bank manager could see in his inbox emails from the director and Zelner, confirming what money needed to move where. The bank manager, believing everything appeared legitimate, began making the transfers.

What he didn’t know was that he’d been duped as part of an elaborate swindle, one in which fraudsters had used “deep voice” technology to clone the director’s speech, according to a court document unearthed by Forbes in which the UAE has sought American investigators’ help in tracing $400,000 of stolen funds that went into US based accounts held by Centennial Bank. The UAE, which is investigating the heist as it affected entities within the country, believes it was an elaborate scheme, involving at least 17 individuals, which sent the pilfered money to bank accounts across the globe.

Little more detail was given in the document, with none of the victims’ names provided. The Dubai Public Prosecution Office, which is leading the investigation, hadn’t responded to requests for comment at the time of publication. Martin Zelner, a US based lawyer, had also been contacted for comment, but had not responded at the time of publication.

It’s only the second known case of fraudsters allegedly using voice-shaping tools to carry out a heist, but appears to have been far more successful than the first, in which fraudsters used the tech to impersonate a CEO of a UK based energy firm to steal $243,000 in 2019.

The UAE case shows how devastating such high tech swindles can be and lands amidst warnings about the use of AI to create so called deep fake images and voices  in cybercrime.

“Audio and visual deep fakes represent the fascinating development of 21st century technology yet they are also potentially incredibly dangerous posing a huge threat to data, money and businesses,” says Jake Moore, a former police officer with the Dorset Police Department in the U.K. and now a cybersecurity expert at security company ESET. “We are currently on the cusp of malicious actors shifting expertise and resources into using the latest technology to manipulate people who are innocently unaware of the realms of deep fake technology and even their existence.

“Manipulating audio, which is easier to orchestrate than making deep fake videos, is only going to increase in volume and without the education and awareness of this new type of attack vector, along with better authentication methods, more businesses are likely to fall victim to very convincing conversations.”

Once a technology confined to the realm of fictional capers like Mission: Impossible, voice cloning is now widely available. Various tech startups are working on increasingly sophisticated AI voice technologies, from London’s Aflorithmic to Ukraine’s Respeecher and Canada’s Resemble.AI. The technology caused a stir in recent months with the revelation that the late Anthony Bourdain had his voice synthesized for a documentary on his life. Meanwhile, recognizing the potential for malicious use of the AI, a handful of companies, such as $900 million-valued security firm Pindrop, now claim they can detect synthesized voices and thereby prevent frauds.

If recordings of you speaking are available online, whether on social media, YouTube or on an employer’s website, there may well be a secret battle going on for control of your voice without you knowing.

FAQ

Why does this matter?

When your voice is your password and your voice can be cloned it's not that easy to get a new password ...

Matthew Griffin

About the author

Matthew Griffin Founder, 311 Institute

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."

Read full bio

Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.

An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.

As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.

Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.

What future do you need to see?

Choose one to get started on security and privacy and the future of your organisation.

Where should Matthew reply?

Takes 30 seconds. No obligation. Matthew replies quickly. Privacy

Tag Cloud

Starburst opens that technology on the interactive 311 Starburst.

Sources and further reading

  1. 21085009 hackers use deep voice tech in 400k theft documentcloud.org
  2. Centennial Bank my100bank.com
  3. Business 57761873 bbc.co.uk
  4. Aflorithmic aflorithmic.ai
  5. Respeecher respeecher.com
  6. Resemble.AI resemble.ai
  7. Pindrop pindrop.com

Source: first published by the 311 Institute on 25 February 2022. Cite as: Griffin, M. (2022). Criminals cloned a directors voice to steal $35 Million in yet another spoofing attack. 311 Institute. https://www.311institute.com/criminals-cloned-a-directors-voice-to-steal-35-million-in-yet-another-spoofing-attack/

You are welcome to quote this article with credit and a link to the original.

Book a Keynote