When a plan participant calls a support lineand stateshis or her namefor authentication, they might not thinkthere is anydanger.
However, according to voice security provider Mutare Inc.’s 2026 Voice Threat Survey, voice communication tools are often a preferred pathway from scammers to bypass traditional cybersecurity controls. Criminals regularly use impersonation, a sense ofurgency,misplaced trust and human psychology to turnphone calls intoan effective means ofgathering personal information. Generative artificial intelligence and deepfake technologies are also making impersonation easier.
For more stories like this, sign up for the PLANADVISERdash daily newsletter.
Asked which voice threats were impacting their business, 53.6% ofsurveyed organizations cited robocalls, 51.2% said spam calls and 38.9% said voice phishing.
Such instances are drawing companies’ attention toward voice security tools, with 93% of respondents saying they believed voice security should be included in cybersecurity and risk management programs.
“Organizations are beginning to understand that awareness training alone is no longer sufficient. A modern cybersecurity strategy must include technical controls that reduce opportunities for malicious callers to ever reach employees, executives, help desks or contact center agents,” said Brian McDonald, Mutare’s chief security officer, in a statement.
The increased focus on voice security comes in part becausemore retirement industry firms haveadopted voice recognition and voice biometric technologies to authenticate participants and customers.
Companiessuch asTIAA, Transamerica, Fidelity, Schwab and Empower Retirement use voice-based tools to verify identities, reduce reliance on passwords and security questions, and detect potential fraud.
For example, TIAA customers can create a “voiceprint” to securely identify themselves when they call to speak to a representative, transfer funds or check their account balances.
A TIAA spokesperson said thatprotecting the voice interactions of itscustomers is integrated into the firm’s broader cybersecurity strategy.
“Since introducing voice biometrics in 2016, we have continued to evolve our voice authentication capabilities to stay ahead of emerging threats, including the rise of AI-generated voice attacks and deepfakes,” wrotea spokesperson from TIAA in an email to PLANADVISER. “Our fraud detection strategies combine advanced technology with trained human experts who monitor calls into our national contact center for unusual activity, helping us identify and stop bad actors before they can cause harm.”
Similarly, Transamerica’s Voice Pass, a feature developed with Nuance Communications Inc., lets customers call Transamerica’s customer care service to securely authenticate and access their accounts.
Such firms will have to be cautious of how advances in voice recognition technology are also making it easier for bad actors to mimic voices.
“Cybersecurity strategies have evolved dramatically over the past decade, but voice security has largely remained a blind spot,” said McDonald. “Our survey shows that security leaders and business owners are beginning to recognize voice as a legitimate attack vector that deserves the same strategic attention as email, endpoints, data, identity and cloud security.”
Nearly half (45%) of Mutare’srespondents said they were somewhat concerned about generative AI-based voice attacks and deepfakes, while 22.3% said they were extremely concerned.
Mutare’s survey respondents cameprimarily from healthcare (29.4%) and technology and innovation organizations (29.4%), while 7.1% represented financial services firms.
« Novel 401(k) Case Argues Fossil Fuel-Free Investments Are ‘Religious Accommodation’
