What is voice cloning?
Voice cloning is the use of AI to reproduce a specific person's voice from a recording of them speaking. You supply a sample, type or speak a sentence, and the model returns that sentence in that person's voice, complete with their accent, pitch and pacing.
The technology is not new and it is not illegal. Audiobook narrators licence their own voices. Call centres use synthetic speech to read out account balances. A Hong Kong retailer might clone a presenter's voice so one recording can be reissued in three languages without booking a studio.
What changed is the price and the speed. What used to require a studio session and a specialist now runs on a consumer graphics card for a few dollars, in real time, while the call is happening. That single change turned a production tool into a fraud tool.
How much of your voice does it take?
Less than most owners assume, but more than the marketing suggests. Vendors advertise usable clones from a few seconds of clean audio. Independent testing tells a more careful story: short samples produce something recognisable, while convincing, emotionally natural speech generally needs a longer recording.
Resemble AI, one of the better-known commercial providers, was cloned from a 25-second sample in one 2026 comparison of ten tools, which the reviewer noted was the shortest minimum requirement of the group. Other security vendors report that roughly three seconds is enough to produce a clone that fools a listener who is not expecting a fake.
Both numbers can be true at once, because they measure different things. Three seconds is enough for a 20-second phone instruction delivered in a hurry over a bad line. Twenty-five seconds is closer to what you need for a clone that survives a long, relaxed conversation.
The practical conclusion for a business owner is uncomfortable but simple. If you have ever recorded a company video, spoken on a podcast, presented at an industry lunch that was livestreamed, or left a 30-second WhatsApp voice note with a supplier, there is enough of your voice in the world.
How does a voice-clone attack on a small company work?
Almost always through urgency and hierarchy, not technology. The clone is used for one short instruction to one junior person, at a moment when checking feels rude or impossible. The fraud succeeds because of the approval process, not because the audio was flawless.
Consider a nine-person trading company in Wan Chai. The owner travels to a Guangdong factory most Thursdays and habitually sends instructions as WhatsApp voice notes rather than typing them, because typing Chinese on a phone in a taxi is slow.
At 6:40pm on a Friday, the accounts clerk receives a voice note. It is the owner's voice, unmistakably. A long-standing supplier has changed bank accounts, the payment of HK$180,000 must go out tonight or the container will not be released on Monday, the new account details follow in a text message, and the owner is about to board a flight so please do not call.
Every element of that message is designed to remove the one step that would stop it. The Friday evening timing removes the colleague who normally counter-signs. The flight removes the callback. The container removes the option of waiting until Monday. The familiar voice removes the doubt.
Notice what the attacker needed and what they did not. They needed a sample of the owner's voice, the name of a real supplier, and the knowledge that this owner communicates by voice note. All three are obtainable from a company website, a LinkedIn post and one previously compromised email account. They did not need to break anything.
The defence that works here costs nothing and takes sixty seconds: the clerk calls the owner on the number already saved in her phone. If he does not answer, the payment waits. A supplier who genuinely changed banks will still accept the money on Monday. A fraudster will not wait.
Why is Hong Kong a target?
Because the city combines high-value cross-border payments, a business culture that moves fast on trust, and a fraud industry that has already industrialised locally. Hong Kong Police recorded 43,212 deception cases in 2025, and deception accounted for 48.5% of all reported crime in the city.
The overall trend is genuinely improving. According to the Anti-Deception Coordination Centre, cases fell 2.9% in 2025, the first decline since 2019, and monetary losses dropped 11.3% from about HK$9.2 billion to about HK$8.1 billion. Police intervened in 4,060 cases and intercepted HK$480 million in payments.
But the technique matters more than the total. Hong Kong holds the most-cited deepfake fraud case in the world: in February 2024 a multinational's Hong Kong office lost about HK$200 million after a finance employee joined a video call on which every other participant, including the chief financial officer, was synthetic. Police reported the loss across 15 separate transfers.
A second Hong Kong office of a UK-based firm was reported to have lost roughly HK$4 million to a similar attack. That second figure is the one small companies should read carefully. HK$200 million makes headlines; HK$4 million is the size of loss an SME can actually suffer, and it is small enough that it never makes the news.
What do people get wrong about voice cloning?
Four beliefs do most of the damage. Each one sounds sensible, and each one is the reason a well-run company approves a payment it should have questioned.
Misconception 1: I would recognise a fake.
You might, in a quiet room, on a good line, expecting nothing. The attack is not delivered that way. It arrives as a 15-second instruction on a poor connection while you are closing the shop. Detection vendors report their best models catching synthetic audio at roughly 94% accuracy, which means the machines built for this job miss one in sixteen. An untrained ear at 6:40pm on a Friday is not the control you think it is.
Misconception 2: this only happens to big companies.
Large firms are worth more per attack, but they also have dual authorisation, a treasury function and a security team. A nine-person company where one person can move HK$180,000 after a voice note is a cheaper target with a shorter path to the money.
Misconception 3: it is a technology problem, so IT will handle it.
No software product stops a phone call from being persuasive. The controls that work are procedural: who may approve a payment, what evidence a bank-detail change requires, and who is allowed to say "I will call you back". Those are the owner's decisions, not the IT vendor's.
Misconception 4: video calls are safer than phone calls.
They were, until 2024. The HK$200 million case was a video meeting. Real-time video deepfakes are harder to produce than voice, but they exist, and seeing a familiar face on a screen now proves less than most people assume.
How do you protect a small business without buying anything?
With six rules that cost nothing and can be written on one page this afternoon. Detection software exists and works reasonably well, but for a company under 50 people the return comes from changing the approval process, not from buying a tool.
--- Set a callback rule and make it unbreakable. Any instruction to move money, change bank details or release goods gets verified by calling the requester on the number already stored in your contacts. Not the number in the message. Say out loud, in front of everyone, that nobody will ever be criticised for taking sixty seconds to check.
--- Require a second approver above a threshold. Pick an amount that matters to your business, perhaps HK$20,000, and require two people above it. A perfect voice clone then only gets the attacker halfway.
--- Treat a bank-detail change as the highest-risk event in your company. New account numbers are verified by calling the supplier's main switchboard, never a number supplied in the same message, and never by replying to the email that carried the request.
--- Agree a spoken passphrase for urgent payments. Two ordinary words, chosen in person, never written in email or WhatsApp. Anyone who cannot produce it does not get the transfer, whatever they sound like.
--- Reduce the free samples. You cannot remove your voice from the internet, and trying is a waste of an afternoon. What you can do is stop the finance team from accepting voice notes as payment authorisation, which removes the channel the clone was built for.
--- Write down what happens when someone gets it wrong. The single most useful sentence in the policy is the one that says a staff member who pauses a payment and turns out to be mistaken has done the right thing. Without it, the junior person will approve rather than risk annoying the boss, and that instinct is the whole attack.
Total cost: one afternoon. Compare that with a HK$180,000 transfer that no bank is obliged to recover.
Frequently asked questions about voice cloning
Can I tell a cloned voice from a real one by listening?
Sometimes, and not reliably enough to depend on. Clues include flat emotion, unnatural breathing, odd pacing around numbers, and a caller who resists being interrupted. Treat all of those as reasons to call back, never as proof either way.
Is voice cloning illegal in Hong Kong?
Cloning a voice is not itself an offence, and legitimate commercial uses are common. Using a clone to obtain money by deception is fraud, and impersonating someone can engage other laws. This is general information rather than legal advice, so take proper advice on your own situation.
Should I buy deepfake detection software?
Probably not first. Detection tools such as those offered by Pindrop, Reality Defender and Resemble AI are designed for banks, insurers and contact centres processing thousands of calls. For a small company, the callback rule and the second approver stop the same attack for nothing.
Does this affect service businesses with no big payments?
Yes, in a different form. A cloned voice can authorise the release of goods, a change of delivery address, the disclosure of a customer list, or a password reset. Anything an employee would do because the boss asked is exposed.
My team communicates by voice note constantly. Do we stop?
No. Keep voice notes for coordination and ban them for authorisation. Discussing a delivery by voice is fine. Approving a payment or a bank-detail change requires a live conversation on a known number.
What is the first thing to do if we think we have been hit?
Call your bank immediately to attempt a recall, then report it to the police. Hong Kong's Anti-Deception Coordination Centre operates the 18222 Anti-Scam Helpline, and the interception scheme that recovered HK$480 million in 2025 works best within hours, not days.
The takeaway
Voice cloning did not create a new crime. It removed the last piece of evidence that small companies were quietly relying on, which was the assumption that a familiar voice is proof of identity. That assumption is now worth nothing, and it was never written into a policy, so nothing changes until an owner decides to change it.
The fix is not technical and it is not expensive. It is a callback rule, a second approver, a passphrase, and permission to pause. An afternoon of work protects the payment that would have ended your quarter.
If AI feels like a series of threats you did not ask for, that reaction is reasonable, and it is also incomplete. The same technology answering your enquiries at 2am is the technology being pointed at your accounts clerk. Understanding one helps you handle the other. We understand AI. UD stands with you.
For related reading, see our guides on keeping a human in the loop and telling customers when they are talking to AI.
Reviewed by the UD AI team, Hong Kong, August 2026.
Not sure where your gaps are?
Most owners discover their real exposure is one unwritten approval rule, not a missing product. UD has spent 28 years helping Hong Kong businesses find those gaps, and we will walk you through every step, from a plain-language review of how AI touches your operations to the controls worth putting in writing first.