
Deepfake FBI Videos Push Victims to Fake IC3 Sites
The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…
Researchers tested AI and human voice scam calls and found people comply mainly because the caller’s script is persuasive, not because the voice sounds perfectly human. Even when listeners correctly suspect the voice is synthetic, many still continue the conversation and may hand over sensitive information. The article argues security training should focus on verification procedures (callbacks, identity checks) rather than trying to “hear” deepfakes.
Researchers examined AI and human voice scam calls across several pretexts, including an urgent help desk password reset requested by someone posing as a senior manager rushing to catch a flight, a bank or fraud-team caller asking for a credit card security code, and a fake relative-in-trouble emergency call designed to trigger fast emotional action. In each case, the caller relied on urgency, partial identity details, or emotional pressure rather than any technical exploit. The help desk scenario used a Friday-afternoon timing and a caller who supplied the last four digits of a badge number, banking on the target wanting to help quickly rather than verify carefully.
The key finding is that persuasiveness, not vocal realism, predicted whether someone complied. Even participants who correctly identified a voice as likely synthetic often continued the conversation and, in some cases, still handed over sensitive information like a card security code. Some listeners even reinterpreted robotic-sounding speech as a nervous human call center worker rather than a red flag. This suggests that training people to listen for artifacts of AI speech targets a skill that doesn't reliably protect them, since a well-written script can win compliance regardless of how the voice sounds.
Because suspicion alone does not stop compliance, defenses need to be procedural rather than perceptual. Recommended controls include:
Service desks, finance teams, and executive support staff are the most exposed groups, since they handle the kinds of requests, resets, wires, and account changes, that these pretexts specifically target. Reinforcing verification steps rather than voice-detection skills is the more durable fix.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Sometimes, but research found that even when listeners correctly suspected a voice was synthetic, many still continued the call and complied with requests like sharing a credit card security code.
Compliance was driven by how persuasive the caller's script was, not by how human the voice sounded. A convincing story can override doubts about the voice itself.
Out-of-band verification such as callbacks to known numbers, help desk identity checks that don't rely on voice recognition, and rules preventing an inbound caller alone from triggering resets, wires, or credential changes.
A fake relative-in-trouble emergency call produced the highest stated compliance among the scenarios tested, reaching 36.1%.
It’s 4:40 on a Friday. You get a call: a senior manager needs a password reset before her flight. The voice might even sound a bit synthetic. Doesn’t matter. What moves people is the script: polite, urgent, last four of her badge number ready to go. Researchers saw people peg a voice as AI and still stay on the line, even hand over credit card security codes, because the talk-track felt convincing. So don’t argue with the voice. Follow the process: hang up, then call back using our official number before doing any reset or sharing any codes.

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Cofense reports that attackers target finance teams with phishing emails designed to look like normal invoices, contracts, and payment notices, not urgent “act…