Banana Navy
Catalog FR
Lab · Threat modeling IA · Fiche détaillée

Voiceprint theft and reuse

the attacker uses a stolen voiceprint, a false match or a lifted voice sample to pass a speaker verification.

SheetF4
CategoryS-TB7-01 (spoofing de biométrie vocale)
Layers8 · Speaker Verification
Systemvoicebot IA

never use speaker verification alone (weak signal); pair it with out-of-band proof (MFA, callback) and a context control on sensitive actions.

The threat

the attacker uses a stolen voiceprint, a false match or a lifted voice sample to pass a speaker verification.

Angle mortWhy classic frameworks miss it

voice biometrics are treated as strong proof even though a stolen sample or a cloned voice neutralises them; frameworks do not tell the voice matches from the speaker is present and consenting.

MitigationProposed approach

never use speaker verification alone (weak signal); pair it with out-of-band proof (MFA, callback) and a context control on sensitive actions.

The proposed control
voice alone is insufficient.

Expected evidence
a stolen sample alone is not enough for a critical action.

SourcesReferences and public research

MITRE ATLAS 2026.07AML.T0043 Craft Adversarial Data
Recherche publiquePublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (catégories par abus de modèle), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic sheet, no rating, no verdict.
couche 8 · Speaker Verification

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot