drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

AI Voice-Cloning Attacks Expose a Business Continuity Blind Spot

A new, significant AI voice-cloning campaign targeting hedge funds like Point72, Two Sigma, and Citadel highlights a new but common challenge for business continuity and disaster recovery professionals: that identity has become a critical dependency in operational resilience.

While much of the attention surrounding these incidents has focused on the sophistication of generative AI, the larger issue is how organizations recover and maintain operations when attackers manipulate trusted business processes instead of exploiting software vulnerabilities.

Unlike traditional cyberattacks that disrupt systems, AI impersonation attacks target the people responsible for keeping organizations running. A convincing phone call to an IT help desk or service desk can trigger password resets, account recovery, privilege escalation, or emergency access requests. These actions are often essential to maintaining business continuity but can easily become points of compromise.

According to Bojan Simic, CEO and co-founder of HYPR, organizations should rethink where trust is placed during high-pressure operational scenarios.

"The reported AI voice attacks targeting major Wall Street firms expose a fundamental flaw in enterprise security: organizations still rely on humans to verify digital identities using their ears and intuition. Today, attackers need only seconds of publicly available audio to clone an executive's voice and manipulate helpdesks into approving password resets, privileged access, or financial transactions. In 2026, automated AI agents are leaking more credentials than human error ever did, shifting identity risk from human-scale mistakes to industrial-scale machine automation."

Identity Is a Resilience Issue

Business continuity plans traditionally account for system failures, natural disasters, and ransomware incidents. Increasingly, however, organizations must also prepare for scenarios where identity verification itself becomes unreliable.

Generative AI has dramatically lowered the barrier to impersonation. Publicly available recordings from earnings calls, webinars, podcasts, and media interviews can provide enough material for attackers to generate realistic executive voices capable of deceiving employees during time-sensitive situations.

This creates a difficult challenge for organizations whose emergency procedures depend on verbal approvals or manual identity verification.

"The industry needs to start recognizing deepfakes as a true identity problem," Simic says. "Sound and video are no longer trustworthy, and asking employees to distinguish real from fake is a losing battle. If your security policy depends on a human deciding whether a voice on the phone is authentic, you're setting them—and your organization's security posture—up for failure."

Rethinking Critical Recovery Workflows

Disaster recovery plans often prioritize restoring access as quickly as possible. But if identity assurance is weak, accelerating account recovery can inadvertently accelerate compromise.

Security and resilience leaders should review high-risk operational workflows to determine where human judgment remains the primary method of authentication.

Rather than placing the burden on employees to detect increasingly sophisticated AI-generated impersonations, organizations should incorporate stronger technical controls into recovery procedures.

"The answer is to eliminate human guesswork from high-risk workflows and replace subjective trust with continuous, deterministic cryptographic proof of identity," Simic explains. "High-risk actions like password resets, account recovery and privilege escalation should require phishing-resistant, device-bound authentication—not just recognition of a familiar voice. The organizations that embrace deterministic identity assurance will render AI impersonation attacks ineffective."

Building Resilience for the AI Era

As AI-powered impersonation becomes more common, resilience strategies must evolve beyond restoring systems and data. They must also ensure that the people requesting access during an incident are who they claim to be.

For disaster recovery and business continuity teams, identity assurance should become a core component of operational resilience planning. Recovery procedures that rely on subjective verification may have been sufficient in the past, but AI-generated voice cloning demonstrates that trust based on familiarity is no longer enough.

The organizations best prepared for the next generation of cyber threats will be those that embed strong, phishing-resistant identity verification into the very processes designed to keep the business running during a crisis.

Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.