DEF CON 33 - Cloned Vishing : A case study  - Katherine Rackliffe

DEF CON 33 - Cloned Vishing : A case study - Katherine Rackliffe

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 18:55

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Optimized Summary (Final Version):

Voice cloning is a growing, real-world cybersecurity threat—no longer a futuristic concept, but a present-day danger enabled by accessible AI tools. A recent study demonstrates that AI-generated voice clones are nearly indistinguishable from real human voices, especially over phone calls, with even trained individuals failing to detect them. This makes voice-based phishing attacks highly effective and difficult to identify.

Key findings:

  • Accessibility: Voice cloning can be created in as little as 5 minutes using publicly available tools and just a short voice recording.
  • Vulnerability of financial institutions: Banks like Schwab and Chase use voice verification for authentication, making them prime targets. Cloned voices can successfully bypass these systems.
  • Attack vectors: Common scams include:
    • Family emergencies (e.g., a child being held for ransom),
    • Authority impersonation (e.g., a boss calling to request urgent action),
    • Phishing via voice verification (e.g., impersonating a bank employee).
  • Human detection fails: People rely on contextual cues—like an unknown caller ID—to spot scams. However, attackers can easily spoof caller IDs, rendering this defense ineffective.
  • Real-world responses: In a controlled study, students responded to a voice-cloned message from a professor as if it were legitimate, sharing personal information (e.g., student IDs) or requesting verification—demonstrating how easily trust is exploited.
  • Low public awareness: Most people are unaware that voice cloning is a real and active threat, especially in everyday scenarios involving family or authority figures.
  • Research gap: Despite the rapid rise of voice cloning attacks (popularized in 2022–2023), academic research has lagged behind. This delay means defenses remain reactive, not proactive.

Study methodology:

  • Researchers cloned voices of five professors (across discipl

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, I think we're good to get started. So, yeah, thank you all so much for coming here. Um, I'm here today to talk about my research on voice cloning and visioning. Uh, specifically, and I'll just get right into it. Um, unfortunately, I have had so many Wi-Fi issues, which I should have anticipated considering that this is Defcon, but uh, so I just have I don't have any of my demos or audio clips or anything for um, what the actual voice cloning sounds like. So, just uh, keep that in mind and bear with me on this. Right. Okay. We'll just uh get right into it. Um yeah, so my name is Katherine Rackliffe and uh I just graduated with a bachelor's degree in cyber security for Brigham Young University and I'm starting my PhD in like two weeks uh at the University of Wisconsin Madison and …