leadforensics

Fake Phone Call Scams: How West Midlands Businesses Can Protect Themselves

AI phone scams West Midlands

A finance worker pays out millions after a video call with their CFO, only to find the CFO was an AI-generated copy. That is what’s known as a modern vishing attack. Birmingham businesses, and others across the West Midlands, are now being targeted by criminals using cheap voice-cloning tools to impersonate directors, finance leads and IT support. Here’s how these scams work and what you can do.

AI-powered vishing in 2026

For years, phishing was an email problem. Now it has a voice. The UK Government’s Cyber Security Breaches Survey 2025/2026 reports that phishing affected 38% of UK businesses in the last twelve months, and the survey’s qualitative interviews highlighted that AI is making these attacks easier for criminals to run at scale.

One of the clearest cases of this shift is Arup, the British engineering firm behind the Sydney Opera House. In early 2024, an employee in Arup’s Hong Kong office joined a video call with what looked and sounded like the company’s UK-based CFO and several colleagues. Every face on the call was fake. By the time anyone noticed, around $25 million had been transferred across fifteen separate payments.

Two years on, the same techniques are reaching smaller businesses. The voice-clone tools used by Arup’s attackers now reportedly cost a few pounds a month and can be trained on thirty seconds of audio scraped from LinkedIn or a podcast appearance.

How AI voice cloning works

Voice cloning uses generative AI to reproduce a person’s voice from a short sample of their speech. The source material is rarely hard to find: a LinkedIn video, a podcast appearance, a recorded webinar, or a conference talk uploaded to YouTube. From there, attackers feed the audio into a consumer-grade cloning tool, of which several are now available on subscription. The result is a synthetic voice convincing enough to pass casual recognition, especially over a phone line where audio quality is already compressed. Combined with caller ID spoofing, the call sounds and looks like it’s coming from the person it claims to be.

What a vishing attack in Birmingham typically looks like

The AI voice scams now reaching West Midlands firms usually play out in three stages.

First, reconnaissance. Criminals find a target company, identify a director or finance lead, and gather audio of them speaking. The source is often a LinkedIn video, a conference recording, or a local news clip. A few seconds of clean speech is enough to train a workable clone.

Second, the trigger. A finance officer or office manager receives an unexpected call from someone who sounds exactly like the boss. The caller ID may even appear to match the real number, since spoofing is easy. The story usually involves an urgent supplier payment, a last-minute deal, or a transfer that needs to go out before close of business.

Third, the pressure. The fake voice insists on secrecy and speed, often asking the employee not to mention the call. By the time the genuine director is back at their desk, the money has already left the account, usually moved through several intermediary banks within minutes.

Why West Midlands SMEs are an attractive target

Two things make smaller businesses across Birmingham, Tamworth, Lichfield and Sutton Coldfield appealing to vishing gangs.

The first is exposure. Directors at owner-managed firms are usually visible: their voices appear in promotional videos, podcast interviews and chamber of commerce events. That gives attackers all the audio they need.

The second is verification. Many smaller firms haven’t yet built out the second-channel checks that larger organisations now treat as standard for payments. If your finance team can authorise a transfer based on a phone call alone, you’re carrying the same risk Arup carried, just at a smaller scale.

The UK Government’s 2025/2026 survey found that just 47% of UK businesses use two-factor authentication, and only 25% have a formal cyber incident response plan. Those gaps are precisely what a 2026 business phone scam is built to exploit.

Defending against a deepfake phone fraud in the UK

The good news is that most defences against deepfake phone fraud UK businesses can put in place don’t need an enterprise budget.

Agree on a verification rule for payments

Any unexpected request to move money, change bank details, or release sensitive data should be confirmed through a separate channel. A callback on a known number, a Teams message, or a face-to-face check all work. The National Cyber Security Centre recommends second-channel verification for any high-value or unusual request.

Limit public audio where it makes sense

Marketing matters, but weigh how much director-voice content sits openly on LinkedIn and YouTube against the access it gives attackers.

Turn on multi-factor authentication

MFA stops most follow-up attacks even when an employee has been talked into clicking a malicious link.

Train staff regularly

Short, repeated sessions on AI voice scams and verification habits make a measurable difference. Our security awareness training is built around smaller businesses without a dedicated security team.

How MT Services can help

We’ve supported West Midlands businesses for over fifty years from our Tamworth HQ. Finance directors and office managers are now trying to work out whether the person on the phone is real, alongside spotting a phishing email.

Our cyber security work covers the layers that close the door on this kind of attack, such as multi-factor authentication, email and call-handling protocols, user awareness training, and incident planning right-sized for smaller organisations. We talk in plain English, work with what you’ve already got in place, and only recommend what genuinely reduces your risk. That’s what businesses across Tamworth tell us they want when it comes to cyber security.

Think your business could be at risk? Get in touch with our team for a free cyber security review.

Frequently Asked Questions

Vishing (voice phishing) is a scam where criminals impersonate a trusted person over the phone to extract money or sensitive information. With AI voice cloning, the call can now sound exactly like a colleague or director.

There’s no foolproof tell. Look for unusual requests, urgency, and secrecy. The safer approach is to assume any unexpected payment or data request needs verifying through a separate channel before you act.

Yes. Smaller firms tend to have fewer verification controls in place, which is what these scams rely on. Attackers don’t always go after the biggest targets; they go after the easiest ones.

Stop any in-progress payments, contact your bank’s fraud team immediately, report it to Action Fraud on 0300 123 2040, and speak to your IT provider.

1732024282120
Neil Norton

Went to Birmingham City University and achieved his BSc. (Hons) from 1989-1992 in Industrial Information Technology.