---
title: "Six Attempts Should Suffice for Expert Cyber Attackers to Break Voice Authentication with a 99% Success Rate | DuoCircle"
description: "The University of Waterloo computer scientists have discovered a unique cyberattack methodology that can break voice authentication security systems with an."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/"
---

Quick Answer

University of Waterloo researchers Andre Kassis and Urs Hengartner published a method that defeats voice authentication systems with a 99% success rate within six attempts on less-sophisticated systems. Voice authentication extracts a voiceprint from a spoken phrase and compares it on subsequent logins. Earlier deepfake attacks used about five minutes of recorded audio to clone a target's voice, prompting vendors to add spoofing countermeasures that detect machine-generated speech. Kassis and Hengartner identified the specific markers those countermeasures rely on, then built a program to remove them, making the deepfake indistinguishable from a real recording. Against Amazon Connect they hit 10% in a 4-second attack and 40% in under 30 seconds. Their paper appeared at the 44th IEEE Symposium on Security and Privacy. The takeaway: voice authentication is not standalone-safe and should be combined with other factors.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Six%20Attempts%20Should%20Suffice%20for%20Expert%20Cyber%20Attackers%20to%20Break%20Voice%20Authentication%20with%20a%2099%25%20Success%20Rate&url=undefined%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F&title=Six%20Attempts%20Should%20Suffice%20for%20Expert%20Cyber%20Attackers%20to%20Break%20Voice%20Authentication%20with%20a%2099%25%20Success%20Rate "Share on Reddit") [ ](mailto:?subject=Six%20Attempts%20Should%20Suffice%20for%20Expert%20Cyber%20Attackers%20to%20Break%20Voice%20Authentication%20with%20a%2099%25%20Success%20Rate&body=Check out this article: undefined%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F "Share via Email") 

![Break Voice Authentication](https://media.mailhop.org/duocircle/images/2023/07/spf-record-8844.jpg) 

_The University of Waterloo computer scientists have discovered a unique cyberattack methodology that can **break** [voice authentication](https://www.aware.com/voice-authentication/) security systems with an exceptional success rate of 99% within six attempts. It points to the fact that such systems are not entirely secure in front of malicious actors’ sophistication._

[Cybersecurity](/) implies securing your information systems and making it difficult for cyber attackers to infiltrate the network and access critical and protected data. It encompasses advanced cybersecurity tools like OTP (One-time Password), MFA (Multi-factor Authentication), biometrics, etc., to ensure that only genuine users access restricted network systems.

Voice authentication security systems are also handy in strengthening cybersecurity strategies. However, [malicious actors](/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/) have become smarter and more innovative in discovering ways to **bypass voice authentication** and access network systems.

## Voice Authentication, The Concept

Organizations in the [banking sector](https://www.channelnewsasia.com/singapore/cybersecurity-csa-phishing-ransomware-ai-3578216) and other businesses where security is paramount increasingly adopt voice authentication as an additional security layer to grant access to authorized users. This cybersecurity strategy involves users repeating a **specific phrase in their voice**.

> A computer security and privacy Ph.D. researcher, Andre Kassis, explains that the [authentication system](https://www.csoonline.com/article/574877/legacy-password-based-authentication-systems-are-failing-enterprise-security-says-study.html) extracts a **unique vocal signature** from the words, also known as ‘voiceprint’, from the phrase and stores it on the central server.

This ‘voiceprint’ or voice signature can help authenticate genuine clients and authorize them to **access network** systems. The user is asked to **repeat a different phrase** when attempting future access to the system. _The system extracts features from this voice recording and compares it with the stored voiceprint to determine whether the user can access it._

[![voice biometrics](https://media.mailhop.org/duocircle/images/2023/07/DMARC-report-service-1.jpg)](https://media.mailhop.org/duocircle/images/2023/07/DMARC-report-service-1.jpg)

## How Can Voice Authentication Help Secure Systems?

In this age of advanced technology, ensuring that only genuine users access network systems is crucial. Otherwise, malicious actors can access network systems and launch [ransomware attacks](/resources/ryuk-ransomware-attacks) or compromise confidential and **critical data assets**.

Therefore, organizations have various cybersecurity tools in place to secure access to the network. Using **multi-factor authentication (MFA)** is one cybersecurity strategy where the user must provide additional confirmation to corroborate their credentials. It can be through randomly generated OTPs, fingerprint verification, or other biometric identification.

However, instances of malicious actors [bypassing MFA](https://www.darkreading.com/threat-intelligence/cyberattackers-double-down-bypassing-mfa) are increasing because of technological advancements. Hence, more innovative methods like voice authentication can serve as **better options** to distinguish genuine users from malicious actors, as they can be more foolproof than methods like MFA.

## How Have Cyberattackers Improved?

Very soon after the introduction of voice authentication technology, [threat actors](/email-security/threat-actors-are-using-google-ads-to-launch-sophisticated-phishing-campaigns/) came up with methods to **manipulate the voice samples** of users. They could use ML-enabled ‘deepfake software’ to generate identical copies of the target’s voice sample using as little data as five minutes of recorder audio, rendering the security technology useless.

## The Developer’s Response

Due to malicious actors’ innovativeness in breaking voice authentication, as mentioned above, developers have introduced additional tools called ‘**spoofing countermeasures.**‘

_They are a series of cybersecurity checks that examine a speech sample to determine whether it is original or **machine created**._ It ensures threat actors cannot easily break the voice authentication system with [deepfake](https://www.hackread.com/deepfake-cyber-attack-russia-fake-putin-message/) voice duplication attempts. Incorporating [software composition analysis (SCA)](https://www.wiz.io/academy/software-composition-analysis) into the development process can further strengthen these defenses by identifying vulnerabilities in open-source or third-party components used within authentication systems, ensuring that weaknesses in underlying code are addressed before attackers can exploit them.

## The Research

However, the University of Waterloo cybersecurity scientists have discovered a method of evading even ‘spoofing countermeasures’ and **deceiving** **voice authentication** security systems within six tries.

They identified **specific markers** in the [deep fake audio](https://securityboulevard.com/2023/06/deep-fake-audio-visuals-how-that-can-affect-your-cyber-security-awareness-program/) that indicate it as computer-generated. They then developed a program to remove them and make them indistinguishable from authentic audio recordings. It means malicious actors can easily fool even the spoofing countermeasures by eliminating the elements from their deepfake voice imitations that help authentication systems identify it as fake.

The researchers tested the software against Amazon Connect’s Voice Authentication System and achieved a 10% success in one 4-second attack. They improved it to 40% with less than half a minute of audio. When used against less sophisticated voice authentication cybersecurity systems, the program achieved **99% accuracy** within six attempts.

[![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/07/sender-policy-framework-6644.jpg)](/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/attachment/concept34)

## So, Is Voice Authentication a Reliable Cybersecurity Tool?

Kassis says that something is always better than nothing. The voice authentication security system might not be fully cyberattack-proof, but it is always better than having no [security measures](https://www.gov.uk/government/news/government-launches-new-cyber-security-measures-to-tackle-ever-growing-threats--2). Besides, the research shows that existing spoofing countermeasures need to be revised.

_Voice authentication should not be the sole authentication method_. It is good security and provides adequate **ransomware protection** if you can use it as a safeguard in addition to other [cybersecurity measures](https://fintech.global/2023/06/12/us-government-ramps-up-cybersecurity-measures-with-new-omb-guidelines/). It is still better than many anti-phishing services organizations use as cybersecurity tools.

> Kassis opines that thinking like a malicious actor is the **best way** to develop a cybersecurity strategy. That gives you the edge because if you do not do so, you are a sitting duck for [cyberattacks](https://www.darkreading.com/risk/ssh-servers-hit-in-proxyjacking-cyberattacks).

Urs Hengartner, Kassis’ supervisor and computer science professor, adds that this study should encourage organizations relying on voice authentication security systems to deploy additional or more robust authentication measures.

Such a step is necessary because this research has proved that voice authentication alone is an **inadequate** cybersecurity strategy, making network systems relying on no other authentication mode [vulnerable](/email-security/vulnerable-npm-api-exposes-private-packages-why-you-need-to-be-aware-of-it/) to cyberattacks.

## Final Words

The best way to devise new cybersecurity strategies is to **think like a threat actor**. This outlook provides insights into how malicious actors think and plan cyberattacks. While it exposes the network system’s vulnerabilities, it also offers insights into formulating effective strategies to plug the gaps and prevent cyberattacks.

This research on voice authentication [vulnerabilities](https://www.psu.edu/news/information-sciences-and-technology/story/deepfakes-expose-vulnerabilities-certain-facial/) is a welcome step in the right direction. The research findings titled ‘Breaking Security-Critical Voice Authentication’ by Andre Kassis and Dr. Urs Hengartner were published in the 44th IEEE Symposium on Security and Privacy’s proceedings.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F) [ ](https://twitter.com/intent/tweet?text=Six%20Attempts%20Should%20Suffice%20for%20Expert%20Cyber%20Attackers%20to%20Break%20Voice%20Authentication%20with%20a%2099%25%20Success%20Rate&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fphishing-protection%2Fphishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts%2F) Copy 

Related Articles

- [ ![spf-permerror-4555](https://media.mailhop.org/duocircle/images/2023/05/spf-permerror-4555.jpg)  10 Applications of ChatGPT that Hackers Are Already Exploiting Phishing ](/blog/phishing-protection/10-applications-of-chatgpt-that-hackers-are-already-exploiting/)
- [ ![remote code execution](https://media.mailhop.org/duocircle/images/2022/07/spf-record-tester-7560.jpg)  A Summary of Forescout’s OT: ICEFALL Outlining 56 Vulnerabilities in Vendors Worldwide Phishing ](/blog/phishing-protection/a-summary-of-forescouts-ot-icefall-outlining-56-vulnerabilities-in-vendors-worldwide/)
- [ ![Default Email Security](https://media.mailhop.org/duocircle/images/2023/04/spf-record-7398.jpg)  Default Email Security Offering Turning Obsolete, a Threat to SMBs and SMEs Phishing ](/blog/phishing-protection/default-email-security-offering-turning-obsolete-a-threat-to-smbs-and-smes/)
- [ ![Cybersecurity Tips](https://media.mailhop.org/duocircle/images/2022/10/SPF-record-checker-4392.jpg)  How to be Cyber Smart: The Best Cybersecurity Tips to Empower Your Team this Cybersecurity Awareness Month Phishing ](/blog/phishing-protection/how-to-be-cyber-smart-the-best-cybersecurity-tips-to-empower-your-team-this-cybersecurity-awareness-month/)

## Related Articles

[  Phishing 5m  10 Applications of ChatGPT that Hackers Are Already Exploiting  May 3, 2023 ](/blog/phishing-protection/10-applications-of-chatgpt-that-hackers-are-already-exploiting/)[  Phishing 7m  A Summary of Forescout’s OT: ICEFALL Outlining 56 Vulnerabilities in Vendors Worldwide  Jul 5, 2022 ](/blog/phishing-protection/a-summary-of-forescouts-ot-icefall-outlining-56-vulnerabilities-in-vendors-worldwide/)[  Phishing 6m  Default Email Security Offering Turning Obsolete, a Threat to SMBs and SMEs  Apr 4, 2023 ](/blog/phishing-protection/default-email-security-offering-turning-obsolete-a-threat-to-smbs-and-smes/)[  Phishing 6m  How to be Cyber Smart: The Best Cybersecurity Tips to Empower Your Team this Cybersecurity Awareness Month  Oct 13, 2022 ](/blog/phishing-protection/how-to-be-cyber-smart-the-best-cybersecurity-tips-to-empower-your-team-this-cybersecurity-awareness-month/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Six Attempts Should Suffice for Expert Cyber Attackers to Break Voice Authentication with a 99% Success Rate","description":"The University of Waterloo computer scientists have discovered a unique cyberattack methodology that can break voice authentication security systems with an.","url":"https://www.duocircle.com/blog/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/","datePublished":"2023-07-04T13:00:54.000Z","dateModified":"2025-08-26T19:07:42.000Z","dateCreated":"2023-07-04T13:00:54.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/"},"articleSection":"phishing-protection","keywords":"News, Security, Updates","wordCount":962,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/07/spf-record-8844.jpg","caption":"Break Voice Authentication","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Phishing"},{"@type":"ListItem","position":3,"name":"Six Attempts Should Suffice for Expert Cyber Attackers to Break Voice Authentication with a 99% Success Rate","item":"https://www.duocircle.com/blog/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Phishing","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Six Attempts Should Suffice for Expert Cyber Attackers to Break Voice Authentication with a 99% Success Rate","item":"https://www.duocircle.com/blog/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Six Attempts Should Suffice for Expert Cyber Attackers to Break Voice Authentication with a 99% Success Rate","description":"The University of Waterloo computer scientists have discovered a unique cyberattack methodology that can break voice authentication security systems with an.","url":"https://www.duocircle.com/blog/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/","datePublished":"2023-07-04T13:00:54.000Z","dateModified":"2025-08-26T19:07:42.000Z","dateCreated":"2023-07-04T13:00:54.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/phishing-protection/phishing-protection-voice-authentication-expert-cyber-attackers-break-in-6-attempts/"},"articleSection":"phishing-protection","keywords":"News, Security, Updates","wordCount":962,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/07/spf-record-8844.jpg","caption":"Break Voice Authentication","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
