newCallback verification is a control that voice cloning quietly broke.
Proveniro
The brief

Callback verification is a control that no longer controls anything.

Ringing someone back to confirm a payment has anchored treasury and vendor-management security for decades. It rested on one assumption — that a familiar voice is hard to fake — and generative AI made that assumption false for anyone with a browser. The control is still in every policy document. Almost nobody has updated it.

audio needed to clone
~3 s
cost of the ai model
$0
time to clone
minutes
controls triggered
none
Anatomy

Every control shows green while the money leaves.

This is not a sophisticated attack. It is a cheap AI attack against an expensive assumption, and it works precisely because the control it defeats is the one everyone trusts most.

the uncomfortable part

Nothing in this sequence is a failure of process. The team followed policy exactly. Dual authorisation happened. The callback happened, to a number on file. The control performed as designed — and the design was built for a world where voices could not be manufactured on demand by a model.

attacker
your controls
T-14 days
Harvests the CFO's voice from an earnings call and a conference keynote
Nothing to detect. Public audio, public event.
T-2 days
Clones the voice with an open model. Cost: nothing. Time: minutes.
No control exists at this stage.
T-1 day
Compromises a supplier mailbox, submits a bank detail change
Email controls flag nothing — the mailbox is legitimate.
T-0 · 10:42
Finance initiates the callback to the number on the amended form
Callback control engaged. This is the moment it is supposed to work.
T-0 · 10:43
Answers in the cloned voice. Knows the deal, the names, the tone.
Agent hears a familiar voice. Control returns PASS.
T-0 · 10:51
Payment released to the mule account
Four-eyes satisfied. Every control shows green.
T+3 days
Funds layered and gone
Discovered at reconciliation. Recovery window closed.
Why nothing catches it

Four controls, none of which are looking at the voice.

Most organisations assume something in the stack would notice. Walk through what each control actually inspects, and the gap becomes obvious.

Email security

inspects

Headers, domains, links, attachments

misses

The mailbox is genuine and compromised. There is nothing anomalous to score.

Payment screening

inspects

Sanctions, velocity, beneficiary history

misses

A first payment to a new supplier account is a normal business event.

Dual authorisation

inspects

Two approvers, separation of duties

misses

Both approvers rely on the same callback that the attacker just passed.

Voice biometrics

inspects

Does this sound like the enrolled speaker

misses

A generative AI clone is optimised to pass exactly this test. It was trained to.

The repair

Keep the callback. Add the one check it was always missing.

You do not need to rip out a control that your policies, auditors and staff already understand. You need to stop that control depending on human hearing, and let AI answer the one question a person no longer can.

Proveniro scores the live callback with a multimodal AI ensemble while it is happening. The question it answers is not ‘does this sound like the CFO’ — a clone passes that — but ‘was this audio produced by a human being, on a real line, right now’.

The verdict lands where the decision is made: a badge in the approver's queue, a hold on the payment file, an escalation to a second channel. Everything else about the process stays as it is, including the paperwork.

proveniro · verify.livelive
+44 20 7946 0812
Claims to be: Group CFO
Payment authorisation · callback
ref PA-40871
capturing 3.2 s sample16 khz · 5 ai models
  • codec_fingerprint
  • prosody_continuity
  • spectral_artefacts
  • replay_liveness
  • registry_match
establishing session…
  1. 01

    Callback initiated

    Unchanged. Same policy, same number on file, same approver.

    policy intact

  2. 02

    Media forked

    The call leg is mirrored to Proveniro. The caller notices nothing.

    passive

  3. 03

    Verdict returned

    Human, synthetic, or authorised AI agent — with model reason codes, inside the conversation.

    < 400 ms

  4. 04

    Decision enforced

    Release, hold or step up to a second channel — and it is all on the record.

    sealed

Objections

What we hear from treasury and fraud teams.

Shared secrets fail the same way they always have: they leak, they get written down, and a caller who has compromised a mailbox has often already seen the last three emails containing the phrase. They also do not scale past a handful of relationships. Use one if you like — but do not let it be the only thing standing behind the payment.

Get started

Update the control before the incident writes the business case.

We will run a shadow evaluation against your own callback traffic and show you, on your data, what the control is currently missing.

soc 2 type ii in progress · eu & uk data residency · no ai training on your data