X
Information Systems & Technology
Chapman Blogs

When the Scam Sounds Like Your Boss

A quick note from your CISO: the next phishing attempt may not look fake. It may sound familiar!

A few years ago, spotting a scam was usually a matter of catching the obvious signs: bad grammar, strange formatting, or the classic “Dear User” greeting — the cybersecurity equivalent of a fake mustache. Today’s version may reference a real project, use the right tone for your department, or include a voicemail that sounds exactly like someone you know. That last part is where things get uncomfortably interesting. 

Wait; They Can Clone Voices Now? 

Yes! AI voice-cloning tools can now create a convincing version of someone’s voice from a surprisingly small audio sample: a public video, a podcast, a conference recording, or a short clip posted online. A call or voicemail may sound familiar without being legitimate, especially when it asks you to move quickly, share information, or do “one small favor,” which in scam language is rarely small. 

Put another way: “It sounded like them” is useful context. Attackers do not need access to Chapman systems to be convincing. A little public information, a familiar name, and a well-timed sense of urgency can do a lot of damage. Cybercriminals are persistent — basically the raccoons of the internet. 

What Does This Look Like in the Real World? 

The most common version is vishing or voice phishing. In practice, that could be a voicemail from “your supervisor” asking for a quick favor, a call about payroll or vendor payments, or a follow-up to an email that already seemed believable. Add voice cloning, and the request does not just feel convincing; it sounds familiar. That combination of urgency and familiarity is what makes these attacks effective, especially on a busy day when everyone is trying to keep things moving. Attackers are counting on our desire not to be difficult. Rude, but effective. 

Why This Works (Even If You Know About It) 

These scams work because the message lines up just enough: it sounds like someone you trust, it arrives at a busy moment, and the context feels close enough to be real. AI helps attackers research, personalize, and scale those interactions, which means more attempts can sound believable and land with the right person at the wrong time. It is not magic. It is automation with bad manners. 

The Microsoft Digital Defense Report 2024 notes that deepfakes and AI-enabled impersonation are being used to create convincing interactions, including real-time voice and video impersonation designed to build trust. The goal is not to fool everyone. It is to catch one person at the wrong moment. If something sounds exactly like a colleague, your brain may not stop to run a full security review; it moves straight to “how do I help?” That instinct is good. It is also what attackers are counting on. 

What You Should Do Differently (Practical Version) 

  • Slow down urgent requests, especially ones involving money, credentials, access, or sensitive data. “Urgent” is often the first red flag, not the last. 
  • Verify through a second channel. Call the person back on a saved number, send a quick Teams message, or check with your department. Not because you distrust people, but because you do not want to trust the wrong version of them. 
  • Do not assume familiar means safe. If something feels slightly off, that feeling is worth a second look. Your “that’s weird” instinct is often doing useful work. 
  • Report it, even if you are unsure. Early reporting helps us spot patterns, block similar attempts, and protect others across campus. We would much rather review a false alarm than clean up a real one.

Final Thought 

Cybersecurity used to be about spotting the obvious fakes. Now the fakes may sound familiar, reference real work, and arrive at exactly the wrong time. If something feels off, especially around money, access, sensitive information, or urgency, pause, verify it through another channel, and report it to abuse@chapman.edu. Trust is good. Verified trust is better.


Stay safe, stay vigilant!

Keith Barros
Chief Information Security Officer (CISO) 

Scroll to Top