Cloning a voice in 2026 takes three seconds and no budget at all

Cloning a voice in 2026 takes three seconds and no budget at all

OpenVoice, an open source voice cloning model built by researchers at MIT, needs about three seconds of audio to produce a convincing copy of someone's voice, and it is free to run, free to commercialize and available to anyone who can follow a setup guide on GitHub. The same speed and accessibility that make it useful for app developers and content creators also make it usable by anyone trying to sound like a chief financial officer on a phone call.

How little it actually takes

It doesn't take a studio or a trained actor, and the hardware requirements are minimal. OpenVoice has been free for commercial use since April 2024. The process is short: upload one clip of someone's voice, type the words, and the model generates new audio in that voice, matching tone, accent and speaking style. A browser-based version needs no installation and no technical skill, so trying it takes a few clicks, not a setup process. For a finance team, that lowers the bar on where a usable source clip comes from: an earnings call recording, a conference talk or a video posted to LinkedIn is enough raw material, and none of it requires the target's knowledge or consent. The model also works across six major languages, so teams operating across regions face the same exposure regardless of which language leadership speaks publicly in.

Cybersecurity firm McAfee tested how little source audio this actually requires and found that three seconds produces an 85% voice match, rising to 95% with more training data. U.S., UK, Indian and Australian accents were all easily replicated. In a two-week scan, the same researchers identified more than a dozen freely accessible cloning tools already in circulation. That isn't unique to OpenVoice; it reflects how far the barrier to entry has fallen across the entire category.

Why the numbers are moving

INTERPOL's 2026 fraud assessment found that AI-enhanced fraud is now 4.5 times more profitable than traditional methods, driven by tools like deepfake-as-a-service kits that lower the cost of convincing impersonation. In the U.S., the FBI's Internet Crime Complaint Center broke out AI-related fraud as a formal category for the first time in 2025, logging more than 22,000 complaints and close to $893 million in losses, including more than $30 million tied to Business Email Compromise (BEC) where a cloned voice confirmed wire transfer instructions.

The pattern is already showing up inside finance teams. Eftsure has documented several real cases where a cloned executive voice was used to request a transfer, including two that were caught before any money moved and one, a UK energy firm in 2019, that lost US$243,000 before anyone realized the CEO on the phone was not real. Eftsure has also covered other AI tools built for the same purpose, including a separate tool that rewrites bank details inside compromised email threads while leaving the formatting untouched. The methods differ, but the effect is the same: AI removes the friction that used to make this kind of fraud hard to pull off convincingly.

Verify by callback, not by voice

None of the incidents that were caught relied on anyone detecting the clone itself; each relied on procedure instead, whether that meant an employee noticing the channel or timing was wrong, or a second person independently confirming the request before money moved. That is the control that holds up against a cloned voice, because a clone can replicate speech but not a callback to a number the finance team already has on file, made outside the channel the request arrived on. A voice that sounds right is no longer a reliable signal by itself, but a verified callback still is.

The next voice on the line may sound exactly right, but whether that call ends in a wire transfer should not depend on how convincing it sounds.

What verification looks like in practice

A callback works when the right person remembers to make it at the right moment. Eftsure closes that gap by sitting inside the payment workflow itself, verifying every outgoing payment before funds move without adding friction for the finance team. See how it works.

Author

Catherine Chipeta

Published

26 Aug 2026

Reading Time

4 minutes

security-image

The New Security Standard for Business Payments

security-image
security-image