04.08.2026 - This final instalment of the NCSC's summer series focuses on AI-generated, interactive videos produced using existing images and audio recordings, and on future developments in this field. Artificial intelligence (AI) can quickly generate videos from still images. At present, around ten seconds of audio is needed to clone a voice convincingly.
A scam of this kind might involve a call from someone who sounds like a relative or friend in distress, or from someone claiming to be your boss and demanding an urgent, high-value payment. In reality, the caller is not the person they appear to be, but a scammer using an AI-generated voice. These conversations can take place in real time and be interactive.
The NCSC currently receives only a small number of reports of attempted scams involving this technology. These are still isolated cases, although this is likely to change in future. In the age of social media, the pool of video material that can be used for deepfakes is virtually limitless. As increasingly sophisticated technologies become more accessible, this development is likely to accelerate. Where this will ultimately lead remains uncertain. Even when more advanced technology becomes available, scammers will only use it once it can be deployed profitably as part of a workable scam.
The following examples illustrate how scams may evolve in the future.
AI-enabled CEO Fraud
In a typical CEO fraud, someone impersonating an employee's boss instructs them to make an urgent payment to an alleged supplier abroad, or to purchase gift cards. The request is deliberately presented as urgent, leaving the employee little time to question it or verify the instructions. At the same time, the real boss or company president is supposedly unavailable by phone, preventing the employee from contacting them directly. Some scammers now deliberately contact employees by phone. They first search online for recordings of the person they are impersonating and use this material to clone that person's voice. Because a phone call may appear more convincing than an email, the additional effort can pay off. In a small number of cases, scammers have even used a deepfake of the boss in a video conference to reinforce their demand. Such cases are still rare, but are likely to become more common. They will primarily affect companies that make employee information openly available and, for example, proactively publish videos featuring individual employees.
Are cloned voices being used in shock calls?
The NCSC regularly receives reports of shock call scams, in which the callers pose as police officers and claim that the son or daughter of the person they're calling has been in a serious accident. To make the story seem credible, the caller briefly puts the supposed son or daughter on the phone, who then asks for help in a distressed voice. Many of those targeted by this scam are convinced that they heard their child's real voice. It is conceivable that scammers use cloned voices created from publicly available video material on social media. However, it is equally possible that, in this stressful situation, people simply believe they recognise a familiar voice. The NCSC is unable to determine whether AI was actually used in individual cases.
Can silent calls be used to clone your voice?
The NCSC is often asked whether scammers use calls from unknown numbers where no one speaks to collect voice samples. The NCSC is not aware of any cases in which scammers have cloned a person's voice from a brief "hello" or from someone introducing themselves, and then used it in a scam. In most cases, these silent calls are more likely to be automated tests to check if a phone number is active and if the person answers calls from unfamiliar numbers. There have, however, been reports of scammers calling specifically to obtain a voice sample, mainly in attacks targeting companies. They need to keep the person talking long enough to collect sufficient audio to create a convincing clone. This approach may become more common in targeted attacks, but it is too time-consuming to use on a large scale. For mass scams, criminals are more likely to rely on audio and video material that is already publicly available on social media.
Conclusion and outlook
Currently, videos are generally created from static images rather than by editing an existing video. This is because AI systems would need to analyse a very large volume of data. The resulting cost and processing time are still too high. Because the AI has only a single image to work from, it may struggle to reproduce how the person moves or the facial expressions they would naturally make. Their lip movements may not quite match the speech either, which can be a sign that the video is fake. As the technology improves, however, it will become easier to create more convincing videos with relatively little effort.
The NCSC is not currently aware of any widespread scams of this kind. For now, they are being used in a highly targeted manner because they still require manual work and generally focus on individual, potentially lucrative targets. Based on the current state of technology, using generative AI to edit videos is still quite labour-intensive. These interactive scams often require sophisticated (and therefore expensive) models, which makes widespread use unrealistic at present. However, cheaper models are becoming increasingly capable, and these attack methods are expected to be used on a large scale in the future.
As this technology improves, a video or phone call that appears to feature someone you know will no longer be enough to prove that it is really them. You will also need to pay close attention to their gestures, facial expressions and usual way of speaking. A deepfake may look convincing, but the person's behaviour or mannerisms may still seem unnatural or out of character. Do not rely on their appearance or voice alone. Consider whether the way they behave is consistent with the person you know.
Recommendations
- Do not automatically trust every caller.
- If you are not sure if the caller really is who they say they are, hang up and call them back on a number you know.
- Hang up immediately if a call seems suspicious.
- Do not allow yourself to be intimidated or put under pressure.
- Never share passwords or PINs over the phone.
- Never give unauthorised people access to your computer, even if they seem trustworthy.
Further information
Current statistics
Last week's reports by category:
Last modification 04.08.2026