The
call began with an emergency. Two men on the line identified themselves as detectives. They told the father
of Nazmul Hossain Atul that his son had been arrested following an offence at work. The allegation was
serious, they warned. The consequences could be severe.
Then Atul spoke.
“Dad,
they’ve arrested me,” the voice on the phone pleaded. “Please get me released. Don’t tell anyone. My
wife and child are here. If my in-laws find out, it will destroy me.”
To his father, the voice sounded exactly like his son.
The call lasted nearly an hour. During that time, Atul’s father
did not hang up and call his son’s mobile number. He left his home in Lakshmipur, hurried to a nearby
market, and transferred BDT 80,000 in two transactions through Nagad, believing the money would secure
Atul’s release.
Then he called his son directly.
“I was
sitting in my office when my father called to check on me,” Atul said. “That’s when we realised we had
been scammed.”
One
hour in Lakshmipur
Source audio
Unverified
Whether the callers used artificial intelligence to reproduce Atul’s voice has not been established. No
forensic examination has confirmed the voice was synthetically generated. But the case points to a growing
and troubling problem: a convincing voice is no longer reliable
proof of who is speaking.
Fraudsters have long impersonated police officers, bank
employees, mobile financial service representatives, and relatives in distress. What appears to be changing
is the sophistication of the tools available to them.
Voice-cloning technology that once required specialised
knowledge and expensive software has become significantly cheaper and easier to deploy.
Researchers at
McAfee Labs found that a voice clone can now be generated from as little as three seconds of audio,
achieving an 85% accuracy match to the original voice. Scammers no longer need a long recording, a technical
background, or expensive hardware. They need only a short clip, which social media provides in abundance.
Three
seconds
0.0
s
85%
accuracy
match to the original voice
The scale of what has followed is striking. The share of
deepfakes in global fraud attempts grew from 0.1% in 2022 to 6.5% in 2025, a 2,137% increase over three
years, according to Signicat’s report. INTERPOL’s March 2026 Global Financial Fraud Threat Assessment
estimated that global financial fraud losses reached $442 billion in 2025 alone, rating the overall risk as
“High” with significant escalation projected over the next three to five years.
The
scale
0
%
increase in the share of global fraud attempts involving deepfakes, 2022–2025
2022
0.1%
2025
6.5%
Signicat
$
0
bn
global financial fraud losses in 2025 alone, with risk rated “High” and further escalation projected
Voice phishing, in particular, has seen an extraordinary
acceleration. Attacks surged 442% in the second half of 2024 alone, according to CrowdStrike’s 2025 Global
Threat Report. Deepfake‑enabled vishing attacks increased a further 1,600% in the first quarter of 2025,
based on threat data reported by Right‑Hand Cybersecurity and related analyses. Synthetic voice scams
targeting family members, specifically those posing as relatives in emergencies, increased by 45% in 2025.
In the Asia‑Pacific region, deepfake scams surged 194% in 2024, as documented in Sumsub’s Asia‑Pacific
Identity Fraud Report.
Voice
phishing, by the numbers
0
%
surge in voice-phishing attacks in the second half of 2024 alone
0
%
further rise in deepfake-enabled vishing in Q1 2025
0
%
rise in synthetic voice scams posing as relatives in emergencies, 2025
0
%
growth in deepfake scams across Asia-Pacific in 2024
Information harvested from social media, including names,
family circumstances, and workplaces, can lend further credibility to a caller’s story before a single word
has been spoken. Studies have found that over 53% of people share voice recordings online at least once a
week, through videos, voice notes, and podcasts, providing a steady stream of source material for cloning.
They need only a short clip, which social media provides in abundance.
Cybersecurity specialists nonetheless caution against labelling
every convincing impersonation an AI scam. Skilled callers, manipulated recordings, and traditional social
engineering remain common methods. Without original audio, technical records, and forensic analysis, proving
a voice was synthetically generated is extremely difficult, a gap that complicates both criminal
investigations and victims’ attempts to recover their money.
In a 2023 online survey involving 7,000 adults across nine
countries, commissioned by cybersecurity company McAfee, one in four respondents said they had experienced
an AI voice-cloning scam or knew someone who had. Of those who said they had received a message containing
what they believed was a cloned voice, 77% said they had lost money. The findings were self-reported and
should not be treated as official crime statistics, but they illustrate how widely the threat had already
spread. Separately, 70% of respondents said they were not confident they could distinguish a cloned voice
from a genuine one.
7,000
adults, nine countries
0
%
of those who received what they believed was a cloned voice said they lost money
0
%
were not confident they could tell a cloned voice from a real one
1 in 4
had experienced a voice-cloning scam, or knew someone who had
Practical
guidance
Every one of these steps buys the same thing: the few seconds of verification a fraudster is working
to deny you.
01
If you
receive a distress call from a known number, hang up and call that person directly on a number you
have saved yourself.
02
Establish a
family code word that can be used to verify identity in an emergency.
03
Do not
transfer money under time pressure. Fraudsters rely on urgency to prevent verification.
04
Report
suspicious calls immediately to the police and, if money has been transferred, to your mobile
financial service provider.
05
Be cautious
about how much voice content you share publicly on social media.
In Dhaka, Nuzhat Chowdhury received a call built around a
different fear. The person on the phone claimed to have kidnapped her daughter and demanded money for her
release. In the background, she could hear a young woman crying and calling for help. The voice appeared to
be her daughter’s.
Rather than complying immediately, Chowdhury checked her
daughter’s live location on her phone. It showed that her daughter was at work. She sent a text message. Her
daughter replied within moments. She was safe.
“I realised it was a scam,” Chowdhury later wrote on social
media.
The tactic resembles what law enforcement agencies in several
countries call virtual kidnapping, a scam in which no one is physically abducted, but callers manufacture
the sounds and pressure of an unfolding emergency, demanding payment before the target has time to verify
the story.
For Atul’s family, the fraud did not end with the transfer. He
contacted the mobile financial service provider immediately, hoping the money could be frozen before it was
withdrawn. Customer service told him that the BDT 50,000 transaction had been blocked, while the remaining
BDT 30,000 had already been withdrawn. His family filed a General Diary with the police and submitted the
documents required to pursue a dispute claim.
TWO
ENTIRELY DIFFERENT VERSIONS
BDT
0
BDT 50,000
reported blocked, on the day of the fraud
Total transferred
BDT 80,000
Gone
Still in the wallet
Version one
The same
day
Blocked, and recoverable
BDT
50,000
Already withdrawn
BDT
30,000
Told to Atul by customer
service when he called to have the transfer frozen.
Version two
One month
later
Actually remaining
BDT
10,429
Unaccounted for
BDT
39,571
“The person told me there
was a mistake.”
A month later, Atul said, the company gave him a different
account.
“The
person told me there was a mistake. Instead of BDT 50,000 being blocked, only BDT 10,429 remained.”
The reversal, he said, felt almost as distressing as the
original deception.
Bangladesh has no standalone criminal offence called
voice-cloning fraud. That does not mean such conduct falls entirely outside existing law.
Nowzin Khan, executive director at Legalized Education
Bangladesh Ltd, and a legal expert specialising in AI governance, says sections 21 and 22 of the Cyber
Security Act, 2026 cover forgery and cheating in cyberspace. Section 21 expressly recognises offences
carried out through an “artificial intelligence agent”, which could potentially bring AI-assisted
impersonation within its scope. Sections 415 and 420 of the Penal Code, covering cheating and dishonest
inducement, may also apply alongside cybercrime provisions.
The
legal patchwork
Relevant provisions are spread across multiple pieces of legislation. Tap each to read more.
Cover forgery and cheating in cyberspace. Section 21 expressly recognises offences carried out through
an “artificial intelligence agent”, which could potentially bring AI-assisted impersonation within its
scope.
Cover cheating and dishonest inducement. These may be applied alongside cybercrime provisions when the
primary deception is conducted through a fraudulent voice call, whether AI-generated or not.
The Bangladesh Financial Intelligence Unit has powers to freeze accounts containing traceable criminal
proceeds. Immediate reporting to both police and the relevant financial institution is critical for
victims who wish to recover funds.
Providers are required to maintain governance systems, conduct identity checks, and oversee their
agents. Where weak KYC procedures contributed to a fraud, victims may have grounds to pursue
negligence claims against financial service providers.
Neither the Evidence Act nor the Cyber Security Act provides detailed standards for determining
whether a recording is authentic, manipulated, or AI-generated. Courts will require credible forensic
methods and specialist training as these cases increase in frequency.
But even where criminal liability is established, recovering
money is a separate challenge. The Bangladesh Financial Intelligence Unit has powers under the Money
Laundering Prevention Act, 2012 to freeze accounts containing traceable criminal proceeds, making immediate
reporting to both police and the relevant financial institution critical for victims.
More structural gaps remain. Neither the Evidence Act nor the
Cyber Security Act provides detailed standards for determining whether a recording is authentic,
manipulated, or AI-generated. No specific statutory obligations exist for the developers of voice-cloning
tools, the cloud companies that host them, or the platforms through which they are distributed.
There is also a gap in how authorised payment fraud is treated.
Financial rules have traditionally focused on transactions carried out without a customer’s knowledge. In
impersonation scams, victims typically approve the payment because they have been deceived into believing an
emergency is real. Bangladesh has no dedicated reimbursement scheme for this form of fraud and no clearly
defined emergency procedures allowing authorities to pause a suspicious transfer while a victim is being
manipulated.
A cloned voice may also constitute biometric data, raising a
separate set of questions under data protection law, questions whose practical enforcement in Bangladesh, as
elsewhere, remains undeveloped.
“
The principal challenge is no longer whether AI-enabled fraud is criminalised. The greater need is to
strengthen the institutional ecosystem.
Nowzin Khan
Strengthening that ecosystem, Nowzin says, would require faster
coordination among police, the Bangladesh Financial Intelligence Unit, telecommunications companies, and
mobile financial service providers, as well as stronger transaction monitoring, rapid fraud-reporting
protocols, and temporary delays for transfers that display characteristics associated with impersonation.
For Atul’s father, none of that institutional architecture existed in the moment it was needed.
He heard a voice that sounded like his son. He acted on what he heard.
That, in the end, was all the technology required.