AI Vishing Works Because Scripts Persuade

Help Net Security · Medium sophistication
Last updated July 30, 2026

Researchers tested AI and human voice scam calls and found people comply mainly because the caller’s script is persuasive, not because the voice sounds perfectly human. Even when listeners correctly suspect the voice is synthetic, many still continue the conversation and may hand over sensitive information. The article argues security training should focus on verification procedures (callbacks, identity checks) rather than trying to “hear” deepfakes.

How the Attack Worked

Researchers examined AI and human voice scam calls across several pretexts, including an urgent help desk password reset requested by someone posing as a senior manager rushing to catch a flight, a bank or fraud-team caller asking for a credit card security code, and a fake relative-in-trouble emergency call designed to trigger fast emotional action. In each case, the caller relied on urgency, partial identity details, or emotional pressure rather than any technical exploit. The help desk scenario used a Friday-afternoon timing and a caller who supplied the last four digits of a badge number, banking on the target wanting to help quickly rather than verify carefully.

Why It Succeeded

The key finding is that persuasiveness, not vocal realism, predicted whether someone complied. Even participants who correctly identified a voice as likely synthetic often continued the conversation and, in some cases, still handed over sensitive information like a card security code. Some listeners even reinterpreted robotic-sounding speech as a nervous human call center worker rather than a red flag. This suggests that training people to listen for artifacts of AI speech targets a skill that doesn't reliably protect them, since a well-written script can win compliance regardless of how the voice sounds.

What to Watch For

  • Urgency paired with a deadline, such as needing something done before travel or before the weekend
  • Use of partial or plausible-sounding identifiers instead of full verification
  • Authority framing, where the caller claims to be a manager or executive to push past normal exception handling
  • Requests for one-time codes or card security numbers over the phone
  • Emotionally charged emergency stories involving a relative, which produced the highest stated compliance among tested scenarios

Building Resistance

Because suspicion alone does not stop compliance, defenses need to be procedural rather than perceptual. Recommended controls include:

  • Out-of-band verification, such as calling back a known number before acting on any request
  • Help desk identity proofing that does not depend on recognizing a caller's voice
  • Written procedures ensuring an inbound caller alone can never trigger a password reset, wire transfer, or credential change
  • Pre-agreed family code words for relative-in-distress scenarios, paired with a habit of hanging up and calling back

Service desks, finance teams, and executive support staff are the most exposed groups, since they handle the kinds of requests, resets, wires, and account changes, that these pretexts specifically target. Reinforcing verification steps rather than voice-detection skills is the more durable fix.

Key findings

  • A realistic “urgent help desk reset” pretext was used as an example scenario: a Friday afternoon call from someone who sounds like a senior manager requesting a password reset before a flight.
  • People may correctly suspect a voice is AI but still comply because the script is persuasive: “A caller can sound synthetic, get pegged as synthetic, and still walk away with a credit card security code.”
  • In the study, persuasiveness strongly predicted compliance; human-likeness of the voice did not once other factors were considered.
  • Across multiple scam scenarios, a meaningful minority indicated potential compliance (including “maybe” responses), and the “fake relative in trouble” scenario produced the highest stated compliance.
  • The article recommends procedural controls: out-of-band verification, stronger help desk identity proofing, and rules so an inbound caller alone can’t trigger sensitive changes (resets, wires, credential changes).

Who’s being targeted

  • Commonly targeted roles: Service Desk / IT Support, Finance, Fraud/Risk teams, All employees, Executives and executive assistants.
  • Affected industries: Banking / financial services, IT help desks / corporate services, General consumers / households.
  • Attack channels: vishing.
  • Impersonated: Senior manager (internal employee), Bank/fraud team representative or payment verification caller, Family member (or someone claiming to be calling on their behalf).

Red flags to watch for

  • Urgency pressure (“before a flight”) right before the weekend
  • Relies on partial identifiers instead of strong verification
  • Uses authority (senior manager) to push exception handling
  • Asks for sensitive one-time or card security information over the phone
  • Relies on persuasive talk-track rather than verifiable process
  • Pushes to keep the target on the line and continue despite doubts
  • Emotionally charged urgency and secrecy
  • Pressure to act immediately without verification
  • No agreed family verification step (code word)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Can people tell if a voice on a call is AI-generated?

Sometimes, but research found that even when listeners correctly suspected a voice was synthetic, many still continued the call and complied with requests like sharing a credit card security code.

Why does AI vishing still work if people suspect it's fake?

Compliance was driven by how persuasive the caller's script was, not by how human the voice sounded. A convincing story can override doubts about the voice itself.

What is the most effective defense against AI voice phishing?

Out-of-band verification such as callbacks to known numbers, help desk identity checks that don't rely on voice recognition, and rules preventing an inbound caller alone from triggering resets, wires, or credential changes.

Which scam pretext got the highest compliance rate in the research?

A fake relative-in-trouble emergency call produced the highest stated compliance among the scenarios tested, reaching 36.1%.

Read the video transcript

It’s 4:40 on a Friday. You get a call: a senior manager needs a password reset before her flight. The voice might even sound a bit synthetic. Doesn’t matter. What moves people is the script: polite, urgent, last four of her badge number ready to go. Researchers saw people peg a voice as AI and still stay on the line, even hand over credit card security codes, because the talk-track felt convincing. So don’t argue with the voice. Follow the process: hang up, then call back using our official number before doing any reset or sharing any codes.

Similar attacks

Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026