Voice clones, QR codes, and texts: why 'watch for bad grammar' is dead advice now
Voice cloning, QR fraud, and smishing are 2026's fastest-growing scam vectors, and none are caught by reading copy carefully. What protects a business is process.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
Two federal data sets, released within a few months of each other in 2026, describe the same shift from different angles. The FTC’s Consumer Sentinel data puts imposter-scam losses at $3.5 billion for 2025 — up nearly 20% year over year, and the most-reported fraud category for the fifth year running. The FBI’s 2025 Internet Crime Report tracked AI as its own fraud category for the first time in the center’s 25-year history, logging $893 million in reported losses tied to it. Neither of those numbers is about email phishing in the classic sense. They’re about voice clones on the phone, QR codes on a poster or an invoice, and texts that look like they came from a bank or a delivery service — and Dark Reading’s reporting on the trend describes exactly these three as the fastest-growing social-engineering vectors this year, alongside phishing retaking the top spot for initial access ahead of vulnerability exploitation.
Why “train your team to spot bad grammar” doesn’t cover any of this
The old advice for phishing awareness training assumed the attack arrives as text you have time to read carefully: an email, sitting in an inbox, that a skeptical employee can reread before acting. None of the fastest-growing vectors work that way anymore.
- Voice cloning doesn’t give anyone text to scrutinize. A cloned voice — built from as little as thirty seconds of audio pulled from a public talk, a podcast appearance, or a company video — arrives as a phone call, in real time, with all the urgency a live conversation carries and none of the pause a written message allows.
- QR fraud hides the destination entirely. A code on a parking meter, an invoice, or a poster doesn’t show a URL to inspect before scanning — the “read it carefully first” instinct has nothing to read.
- Smishing compresses everything into a text message short enough that the usual red flags (a spoofed display name, a slightly-off domain) are hard to see on a phone screen, and normalized enough — delivery notifications, bank alerts — that urgency doesn’t feel out of place.
What actually protects a business
If the content-based defense doesn’t transfer, the fallback has to be process-based: a rule that doesn’t depend on anyone correctly judging a voice, a code, or a text in the moment. The pattern that holds up across all three vectors is the same one finance teams have used for decades against wire-fraud, extended to cover more request types:
A verification workflow that doesn't rely on spotting the fake
Define what triggers out-of-band confirmation
Any request involving money movement, credential resets, or access changes gets a second channel of confirmation — not an exception process, the default one.
Use a channel the requester didn't initiate
If the request came by phone, confirm by a known number or in the ticketing system — never by calling back a number the caller provided.
Make the callback number a fixed, published one
Store verified contact numbers and email addresses for vendors and executives ahead of time, so nobody is looking one up under pressure.
Give staff explicit permission to slow down
The scams that work best exploit urgency and the fear of seeming unhelpful — a written policy that says 'verification first, always' removes that social pressure from the individual.
None of this requires anyone to detect a deepfake voice or notice a malicious QR code. It requires a rule that a request involving money or access gets confirmed through a second, known channel before anyone acts — a rule that works exactly the same whether the original request was real or synthetic.
Why this belongs at the leadership level, not just IT’s
The instinct is to route “voice cloning and QR fraud” to the security team and move on. The FTC and FBI numbers argue against that framing: imposter scams are now the single most-reported fraud category in the country, and the AI-related share of it is large enough that the FBI gave it a dedicated line item for the first time in the center’s history. That’s not a niche IT risk — it’s a category of business risk that shows up in finance (wire-transfer requests), HR (fake job interviews used to gain network access), and vendor management (invoice and payment-detail changes) at once. A verification workflow that only IT knows about doesn’t cover any of those. The policy has to be something finance, HR, and frontline staff all know applies to them by default, not something they discover after the fact.
Where this connects to how you run outbound
The same principle applies to a company’s own outbound programs. A prospect or customer receiving unexpected requests to click, scan, or call back is exactly the pattern this year’s fraud growth is built on, and a legitimate sender doesn’t want to look like it. Keep requests to click a link or reply tied to something the recipient already expects — a reply to their own inquiry, a step in a sequence they opted into — and make it easy for a recipient to verify who’s actually asking, the same way you’d want your own team to verify an inbound request before acting on it. The fraud numbers this year aren’t a reason to be more suspicious of every message; they’re a reason to make sure the messages you send don’t require anyone to guess.
That’s the part of this problem a sending platform actually controls. Norbelys sends cold email from domains that have verified SPF, DKIM, and DMARC alignment before a campaign can go live, and ramps a new mailbox’s volume gradually through warmup instead of the sudden burst of unfamiliar volume that both spam operations and account-takeover fraud rely on. Neither control stops a voice clone or a smishing text — those channels don’t touch email authentication at all — but for the channel Norbelys does own, a recipient who checks where a message actually came from finds a domain that’s provably who it claims to be, which is the exact verification step this whole pattern of fraud is built to route around. Norbelys DMARC monitoring is how you keep that authentication status visible on an ongoing basis, rather than assuming a domain you set up correctly once is still enforcing correctly now.