AI-generated voices are now convincing enough to authorise a payment or talk a finance assistant into bypassing a check, and the call usually sounds like a colleague or the managing director. Vishing attack prevention in the UK has become more urgent because the controls most businesses rely on (a familiar voice, a recognisable number, a plausible request) no longer hold up. This guide covers how the attacks work and seven practical steps you can take before money or data moves.
How AI voice cloning is changing the vishing threat
AI voice cloning has changed the cyber security risk for UK SMEs in 2026. The UK Government’s latest Cyber Security Breaches Survey reports that 43% of UK businesses experienced a breach in the last twelve months, with 38% facing phishing attempts, making it the most common attack by a wide margin. The same survey found AI adoption outpacing security readiness, and only around a quarter of organisations already using AI report having practices in place to manage the risks.
The Arup case shows what AI impersonation now makes possible. In January 2024, a finance employee at the Hong Kong office of London-headquartered Arup authorised 15 transfers totalling around £20 million after joining a video call with what appeared to be the UK-based CFO and several colleagues. Every participant on the call was an AI-generated deepfake. The request was framed as a confidential, time-sensitive transaction, exactly the kind of pretext that pushes verification to the back of the queue.
7 vishing attack prevention steps for UK businesses
The principle behind every step below is to assume the voice can be faked and build verification into the process before anything moves.
- Verify every payment instruction on a second channel. Don’t act on a voice alone, no matter how familiar. Call back on a number you already hold, not one given during the call, and confirm new bank details or urgent transfer requests that way. The NCSC’s phishing guidance recommends out-of-band verification for any sensitive request.
- Agree a verbal challenge phrase for finance and IT requests. A pre-agreed word or short question, shared only with a small group, makes voice impersonation much harder to pull off. It’s a low-cost control that catches AI vishing the moment the caller can’t respond correctly.
- Require dual sign-off on transfers above a sensible threshold. Set a clear value at which a second approver gets involved, and make sure that approval happens on a separate device or channel. If both approvers can be reached through the same compromised inbox, the control isn’t doing its job.
- Move high-risk users to phishing-resistant MFA. Standard SMS or push-based MFA can still be defeated by a confident caller talking a user through a verification prompt. Hardware keys or passkeys for finance and IT admin accounts close that gap, and the cost per user is modest.
- Audit the executive audio already public. Just a few seconds of clean audio is enough to clone a voice. Reviewing public-facing content from senior staff doesn’t have to mean going quiet. It does mean knowing what’s out there and weighing the risk against the reward.
- Make security awareness training a routine, not a one-off. A single induction session won’t keep pace with the way these attacks evolve. Short, regular refreshers, ideally tied to a human risk score, build the muscle memory staff need when a call sounds urgent. MT Services offers security awareness training for West Midlands businesses built around exactly this kind of risk.
- Run vishing simulations alongside your email phishing tests. Most businesses now run simulated phishing emails, but few test for vishing. Adding vishing scenarios to your testing programme gives you a real picture of how staff react under pressure and a meaningful baseline to improve from.
Why human error remains the biggest vulnerability
Technology controls catch most things, but voice phishing is designed to bypass technology entirely. The Arup attackers never touched a firewall or stole a password. They convinced a person to act. The breach often begins with someone reasonable doing what seems like a reasonable thing.
The way to push back on this isn’t to expect every employee to spot every deepfake. It’s to give staff explicit permission to say “I’ll call you back” and to back that up with payment processes that can absorb a few minutes of verification friction.
How a technology partner supports vishing attack prevention
A good IT provider does more than supply tools. They help you put the right verification process in place and back it up with the training and technical controls (email security, MFA, monitoring) that catch what people miss.
MT Services has worked with West Midlands businesses for over 50 years from its Tamworth base. Our cyber security solutions cover user training, email security, and a free external penetration test for local businesses that want a starting view of where they’re exposed.
If you’d like a closer look at where your business is most at risk from vishing and other forms of phone fraud, the team at MT Services can talk you through it. We work with businesses across Tamworth, Lichfield, Sutton Coldfield, Birmingham and the wider West Midlands.
Get in touch on 01827 219540 or send us a message and we’ll set up a conversation that fits your week.
Frequently Asked Questions
What is ‘vishing’, and how is it different from email phishing?
Vishing is voice phishing. It uses phone calls (and increasingly video calls) rather than emails to trick staff into authorising payments or sharing credentials. Email phishing relies on written cues that filters and trained users can spot. Vishing exploits the instinct to trust a familiar voice, which AI cloning now makes harder to dismiss.
How quickly can someone clone a voice?
Modern voice synthesis tools can produce a usable clone from as little as a few seconds of clean audio, often taken from public sources such as podcasts or company videos.
What should I do if my business receives a suspected vishing call?
Hang up without acting on the request, then call the supposed requester back on a number you already hold. Report attempted fraud to Report Fraud on 0300 123 2040 and forward any related suspicious emails to report@phishing.gov.uk.