Recent reporting suggests a rise in attempted cyberattacks that rely heavily on voice phishing or “vishing.” Scammers are using AI-powered voice-cloning technology to imitate trusted contacts and make fraudulent requests appear legitimate. By exploiting trust and creating a sense of urgency, they persuade employees to disclose sensitive information and grant access to internal systems. The incidents highlight a broader trend: AI is transforming social engineering attacks, making them more persuasive and easier to scale.
Social engineering is not new. The objective remains the same: gain trust, create urgency and manipulate someone’s behavior so that they take an action they otherwise wouldn't.
What has changed is the speed and scale at which scammers can operate. AI can generate hyper-realistic emails, clone voices, images and videos and tailor communications to specific individuals, teams and business activities in a matter of minutes. Capabilities that once required specialized expertise are now available through widely accessible tools.
How criminals are using AI
Today, criminals can:
- Generate professional-looking emails with minimal effort.
- Personalize messages using publicly available information.
- Clone voices to imitate trusted individuals.
- Create manipulated or synthetic audio, images and videos, commonly referred to as deepfakes.
- Conduct coordinated attacks across email, phone calls, messaging platforms and social media simultaneously.
Deepfakes are becoming more accessible
Deepfakes are AI-generated or manipulated audio, video and images that can convincingly imitate real people. As voice-cloning and synthetic media technologies continue to improve, it is becoming easier to create content that appears authentic.
Criminals are increasingly using these capabilities to impersonate executives, colleagues, family members and other trusted contacts. In many cases, the goal is to create an imitation believable enough to prompt immediate action before any verification.
Slow down. Verify.
As AI-generated content becomes more sophisticated, taking a moment to verify can make all the difference.
Before responding to an unexpected request, consider the following best practices:
- Verify requests involving credentials, approvals, payments or sensitive information.
- Confirm unusual requests through a separate trusted communication channel.
- Follow your organization’s established business processes and approval procedures.
- Be cautious when urgency is used to pressure immediate action.
- Report suspicious communications promptly to the organization’s incident response channel.
For suspected deepfake or voice-cloning attempts, independently verifying the request through a trusted communication channel can help prevent fraud and impersonation attempts.
As AI is making social engineering attacks faster, more scalable and harder to detect, the most effective defense remains simple: slow down, verify and report suspicious activity.