HIGHPhishing
Verified
United States

Scattered Spider Uses AI Voice Cloning to Bypass Voice-Based MFA

Monday, March 16, 2026 at 01:00 PM UTC·Source: FS-ISAC

Updated: Tuesday, March 17, 2026 at 10:00 AM UTC

Executive Summary

Scattered Spider adopts AI voice cloning to defeat voice verification MFA at financial institutions. Three banks confirm successful bypass.

Analysis

Scattered Spider has adopted AI voice cloning technology to defeat voice-based multi-factor authentication used by financial institutions. Attackers clone customer voices from social media and publicly available audio, then use the cloned voices to authenticate to banking systems via phone. Three major banks have confirmed successful MFA bypass incidents. Industry group recommends transitioning away from voice-based authentication.

Timeline

Discovered
Mar 10, 2026
Exploitation Detected
Mar 10, 2026
Published
Mar 16, 2026
Source Attribution

Originally published by FS-ISAC on Mar 16, 2026. Verified by: FS-ISAC, FBI.

Related Threats