The control only works when the number is retrieved independently. Attackers routinely include a phone number in the fraudulent request, and a callback to that number produces a confident confirmation from the attacker.
Voice cloning has weakened the assumption that a familiar voice is proof of identity. Mature processes therefore pair the callback with a shared secret, a known contact who did not originate the request, or verification of the account itself rather than the person.
Common questions
What number should a callback use?
Only a number obtained independently of the request, such as one already stored in the vendor master record or published on the supplier's official site.
Is a callback still effective against voice cloning?
Partially. It still defeats email only attacks, but it should be paired with a shared secret or with verification of the account itself rather than the speaker.
Primary sources
Citing this entry? Cite as Coffr, LLC and link to https://getcoffr.com/glossary/callback-verification.