Cloned Voices on the Phone: 6 Concrete Defenses Your Quebec SMB Needs in 2026 (Before the Next Fraud Costs You $47,000) | Agent IA Vocal
    Back to blog
    Sécurité & Conformité8 min readMay 3, 2026

    Cloned Voices on the Phone: 6 Concrete Defenses Your Quebec SMB Needs in 2026 (Before the Next Fraud Costs You $47,000)

    Canada's Competition Bureau just warned about AI-cloned voices. 3 seconds of audio is enough. Here are 6 concrete defenses for Quebec SMBs in 2026.

    MA

    Masdouk Adelakoun

    Cofondateur & CTO

    Cloned Voices on the Phone: 6 Concrete Defenses Your Quebec SMB Needs in 2026 (Before the Next Fraud Costs You $47,000)

    In March 2026, Canada's Competition Bureau issued a warning no Quebec SMB owner should ignore: fraudsters are now using AI-generated voices to impersonate government officials. Not in ten years. Now. And the technical bar to clone your voice just dropped to a ridiculous level: 3 seconds of audio.

    Three seconds. That's shorter than your voicemail greeting.

    If you run an SMB in Quebec — a law firm, a retail shop, a clinic, a workshop — here's the uncomfortable question: a fraudster who calls your bookkeeper using your cloned voice to authorize a $47,000 transfer, does your current process catch it? And if the call comes in on the main line and your AI voice agent picks up, is it configured to spot the trap, or does it politely transfer the scam to Réjean in accounts payable?

    Group-IB's 2026 report estimates deepfake voice fraud losses will reach US$40 billion by 2027. Most of that won't land on the big banks with their $3M-a-year SOCs. It will land on SMBs. On you.

    Here are the 6 concrete defenses — not theoretical, not "general best practices," real ones — your team and your AI voice agent need in place this week.

    1. The shared voice passphrase (the defense nobody uses, that actually works)

    This is the lowest-tech defense on the list. It's also the most effective, which is why cybersecurity firms always rank it #1.

    The principle: you, your spouse, your finance director, and anyone who can authorize money movement or a sensitive decision in your business — you all agree on a word or phrase that is never written down, never texted, never said in public. Something personal and weird, like "Uncle Réal's lawnmower."

    If anyone calls to authorize anything unusual, ask for the passphrase. An AI cloning your voice from your LinkedIn podcast doesn't know it. It can't improvise it. It will panic, hang up, or invent something — and that's your signal.

    For SMBs: extend the concept to your main supplier and your external accountant. Five minutes of conversation with them is enough to set this up.

    Mot-code vocal écrit sur un post-it à côté d'un téléphone de bureau

    Mot-code vocal écrit sur un post-it à côté d'un téléphone de bureau

    2. The callback-to-known-number rule (zero trust applied to the phone)

    This is the defense banks have used for twenty years and most SMBs ignore: no money movement ever happens on the basis of an inbound call. Ever. Even if the displayed number looks familiar (caller-ID is trivial to spoof).

    The procedure:

    1. Someone calls to ask for a wire transfer, a supplier IBAN change, an urgent signature. It doesn't matter who they claim to be.
    2. The employee says: "I'll call you back in 5 minutes at the number we have on file."
    3. The employee hangs up, pulls the number from your CRM or contact book, and dials themselves.
    4. If the person on the other end says "no no, call me back at this number, I'm traveling," that's a red flag.

    This procedure breaks 95% of voice frauds. Put it in writing. Post it next to the phone. Have your employees sign it. If it only exists in your head, it doesn't exist.

    3. Configure your AI voice agent to detect suspicious signals

    If your AI voice agent answers the main line, it becomes your first line of defense. Most SMBs configure it to be polite and efficient. Very few configure it to be suspicious. That's a mistake in 2026.

    Four behaviors your agent should have, baked into its system prompt:

    • Refuse any call asking for a money transfer or banking details change, regardless of stated urgency. Standard response: "I can't process that type of request by phone. Please email accounts@smb.com and we'll call back at the number on file."
    • Detect artificial-urgency markers ("it's urgent, the CEO is in a meeting, this needs to happen in 5 minutes"). Response: systematic transfer to a manager, never to a junior employee.
    • Ask for a customer ID or reference number before sharing any non-public information. A fraudster will almost never have it; a real customer will.
    • Log every suspicious call with timestamp and reason for the flag, for weekly review.

    Before pushing this logic to production, run your agent through the 7 tests to do before connecting it to your phone line — and now add a "fraud scenario" test to the list. If your agent transfers an urgent wire request to Réjean without flinching, you have work to do.

    4. Reduce the executive's public voice footprint

    Three seconds of clear audio. That's all it takes. Ask yourself honestly: how many minutes of your voice are publicly available right now?

    Quick inventory:

    • LinkedIn and YouTube videos of your speaking engagements
    • Podcasts where you've been a guest
    • Voice greetings on your IVR ("Hello, you've reached X, I'm the CEO, leave me a message...")
    • Instagram reels, corporate TikTok
    • Recorded online conferences

    For most SMB owners, this easily adds up to 20–60 minutes of public audio. Way more than enough for a fraudster to clone your voice with a $22/month consumer tool.

    You don't have to go invisible. But: (1) remove personal voice greetings from your IVR — let your AI voice agent answer with a generic professional voice; (2) avoid signing your marketing emails with a "Hey, it's me, I wanted to reach out..." video message; (3) do an annual audit of your public voice footprint.

    5. Strict procedure on money movement (where the AI actually helps)

    No transfer above a defined threshold should ever happen without:

    1. A written email from the requester, sent from their corporate address
    2. An oral confirmation via the number on file (not a number given to you on the call)
    3. A second internal pair of eyes (the famous four-eyes principle)

    The threshold depends on your SMB. For many Quebec retailers and firms, $5,000 is a reasonable starting point. Revenu Québec has a dedicated page for reporting phishing and fraud attempts — post the link next to the procedure to remind your team this is a real problem, not paperwork.

    Bonus: your AI voice agent can automate step 2 — when an employee triggers a transfer request, the agent automatically calls back the requester at the number on file to confirm. It removes the friction of the manual procedure and makes it impassable for a fraudster.

    Bureau d'un dirigeant de PME avec une alerte de fraude à l'écran

    Bureau d'un dirigeant de PME avec une alerte de fraude à l'écran

    6. Test your team with a quarterly vishing simulation

    Nobody believes they'd fall for it. Everybody falls for it.

    The defense: test. Once a quarter, run (or have someone run) a vishing simulation — a scripted call that mimics a fraud attempt, ideally with a rough cloned voice of yourself generated for the exercise. It's not to trap people, it's to calibrate.

    What you measure:

    • How many employees spot the scam?
    • How many report it immediately?
    • How many follow the callback procedure?
    • How many share info they shouldn't have?

    Three exercises and your detection rates typically jump from 30% to 85%. It's the highest-ROI training investment you can make in 2026.

    What your AI voice agent can do — and what it can't

    Let's be clear: an AI voice agent is not a deepfake detector. Today, in 2026, no SMB should rely on automatic real-time synthetic voice detection — the tech exists, but it lives in enterprise labs and doesn't hold up in production on noisy Quebec French.

    What your AI voice agent can do in 2026:

    • Systematically refuse high-risk requests (money transfers, banking detail changes)
    • Force procedural routing (callback to number on file)
    • Detect and log artificial-urgency markers
    • Act as a buffer — a fraudster prefers a rushed human to an agent that asks 4 verification questions before transferring
    • Verify customer identity via case number or secondary question

    With multimodal capabilities now available in 2026, your agent can even request visual verification for high-stakes transactions — a pure-voice fraudster can't respond.

    30-day action plan for your SMB

    If you're reading this today and none of the above is in place, here's the order:

    Week 1: define a voice passphrase with your financial circle (max 5 people). Put the callback-to-number-on-file rule in writing. Post the procedure next to every phone.

    Week 2: audit your AI voice agent's system prompt. Add the 4 suspicious behaviors (section 3). Test with a fake fraud scenario.

    Week 3: inventory your public voice footprint. Remove personal voice greetings from the IVR. Review your email signature.

    Week 4: write the "money movement" procedure with threshold and triple validation. Have the team sign it. Schedule the first vishing simulation for the following month.

    Total cost: basically your time and your team's. No new software. No SOC.

    If you run a Quebec SMB that takes calls, this isn't optional

    The Competition Bureau doesn't issue alerts for fun. The projected $40 billion in 2027 losses isn't a conservative estimate — it's what's coming before most SMBs have taken any action at all. The window where the absence of defense passively distinguished you from a target is closed. Now, the absence of defense identifies you as the target.

    The good news: the 6 defenses above are within reach of any Quebec SMB, with no cybersecurity budget, no dedicated IT team. They take a few hours to set up and sustained discipline. That's it.

    If your AI voice agent isn't configured to detect and block voice fraud attempts, talk to our TECHMA team — we handle the configuration and integration end-to-end. That's our job. Not yours.

    voice deepfakeAI fraudAI voice agentQuebec SMBphone securityvishingvoice cloning
    Share