Deepfake Voice Calls Reach 1 in 4 Americans, Survey Finds

Marcus Chen··5 min read
Office worker answering an unexpected phone call at their desk

AI voice cloning has completed its journey from research demo to everyday nuisance. According to new 2026 survey data, a quarter of Americans say they have already received an AI deepfake voice call - and almost as many admit they are not sure they could tell a cloned voice from a real one. For security leaders, the question is no longer whether employees will encounter a synthetic voice. It is whether your organization has a policy that works when they do.

One in Four Received a Deepfake Call - and Another Quarter Cannot Tell

The headline numbers come from the Hiya State of the Call 2026 report, a survey of more than 12,000 consumers across the United States, United Kingdom, Canada, France, Germany and Spain. One in four Americans reported receiving an AI deepfake voice call in the past 12 months. A further 24 percent said they were not confident they could tell the difference between a cloned voice and a genuine one.

Read those two figures together and the picture is stark: the technology is already reaching a mass audience, and a large share of that audience concedes it has no reliable way to detect it. The inclusion of European markets such as Germany and France in the survey also makes clear this is not a US-only phenomenon - the same tooling and the same scripts work in any language the model has heard.

Why Cloning Got So Easy

The supply side of this problem is wide open. When Consumer Reports tested six leading AI voice cloning tools in research published in March 2025, it found that four of the six lacked meaningful safeguards against cloning someone's voice without their consent. In most cases, nothing stands between an attacker and a working clone except a short audio sample.

And short really does mean short. As CNN's consumer guidance notes, a few seconds of audio are enough to clone a voice convincingly. A conference talk, a podcast appearance, a voicemail greeting, a video posted to social media - any of these gives an attacker the raw material. For executives and public-facing employees, usable samples are effectively guaranteed to exist.

The Background Noise Is Getting Louder

Deepfake calls are landing on top of an already hostile phone environment. Across the surveyed markets, consumers receive an average of 7.4 unwanted calls per week, a volume growing 16 percent annually. The financial damage is unevenly distributed: adults aged 55 and over lose an average of $1,298 to phone scams - roughly triple the losses of younger adults.

That last number matters for workplaces more than it first appears. Senior employees often hold the most authority over payments, approvals and sensitive data, which makes the demographic most likely to be defrauded by phone also the demographic attackers most want to reach at work.

What This Means for the Enterprise

Consumer prevalence is the leading indicator; enterprise targeting is the trend that follows. Zimperium's 2025 Global Mobile Threat Report found that vishing attacks on mobile devices rose 28 percent year over year. The same voice that convinces a grandparent to wire money can convince an accounts-payable clerk to change banking details, a help desk agent to reset a password, or an assistant to release a confidential document - especially when the voice on the line sounds exactly like a known colleague or executive.

The uncomfortable truth is that human ears are not a control. Employees who believe they would 'just know' are the ones the 24-percent-unsure figure should worry you about, because overconfidence is precisely what a well-timed, well-cloned call exploits.

The Policy That Beats the Clone: Verify on a Second Channel

Since detection by ear is unreliable, the defense has to be procedural. The good news: the procedure is simple, cheap and completely effective against voice cloning.

  • Never act on voice alone. Any request involving money, credentials, data or access changes must be verified through a second, independent channel before action is taken.
  • Call back on known numbers. Verification means hanging up and dialing a number from the directory - not the number that just called, and not a number the caller provides.
  • No executive exceptions. Urgency and seniority are the attacker's favorite levers. If the CEO's voice demands an immediate transfer, the CEO can wait 90 seconds for a callback.
  • Pre-agree code phrases for high-risk workflows. Finance and HR teams handling wire transfers or payroll changes benefit from shared verification phrases that a cloned voice cannot know.

Policies only hold if people have internalized them before the phone rings. Security awareness training that covers voice cloning and second-channel verification - reinforced by regular phishing simulation so healthy skepticism becomes a reflex across every channel - is how organizations turn a written rule into an actual habit. That is exactly the muscle platforms like empowsec are built to train.

Key Takeaways

  • Prevalence is mainstream: 1 in 4 Americans received an AI deepfake voice call in the past 12 months, per Hiya's 2026 survey of 12,000+ consumers across six countries including Germany.
  • Detection by ear fails: another 24 percent are not sure they could tell a clone from a real voice - and Consumer Reports found 4 of 6 leading cloning tools lack meaningful consent safeguards.
  • Seconds of audio suffice to clone a voice, so assume samples of your executives and public-facing staff already exist.
  • Enterprise exposure is rising: vishing attacks on mobile devices grew 28 percent year over year in Zimperium's 2025 research.
  • The fix is a policy, not an ear: mandate second-channel verification for every sensitive request, with callbacks to known numbers and no exceptions for seniority or urgency.
Share: