AI Voice Impostor Posed as Marco Rubio on Signal

Biometric Update · High sophistication
Last updated August 20, 2026

Governments are responding to deepfakes by shifting from “detecting fakes” to building systems that prove where digital content came from and whether it was altered. The article cites real AI-impersonation activity targeting government officials, including text and AI-voice impersonation intended to build trust and then gain access to accounts or move conversations to other platforms.

How the attack worked

An impostor used an AI-generated version of Secretary of State Marco Rubio's voice to contact three foreign ministers and two U.S. political figures through Signal. This is one example cited within a broader pattern the FBI has warned about: malicious actors using text messages and AI-generated voices to impersonate senior U.S. officials. The tactic is not a one-off stunt but part of a documented trend targeting government executives, executive assistants, policy staff, and public affairs teams.

According to the FBI, the underlying goal in these campaigns is often to build relationships with government officials and other trusted contacts before attempting to gain access to accounts or move conversations to different communications platforms. In other words, the impersonation itself is often just the opening move, meant to establish enough credibility that a target will comply with a follow-up request.

Why it succeeded

The scenario relies on a few compounding factors. Voice-only authentication over messaging apps like Signal gives targets no easy way to independently confirm identity in the moment. Combined with the assumed authority of a senior official, and the natural instinct to respond promptly to someone who appears to hold real power, targets have limited opportunity to pause and verify. A convincing fake voice message, video call, or text exchange could be used to establish trust, gain access to an account, or induce someone to disclose sensitive information, and none of those outcomes require the attacker to breach any system directly.

What to watch for

  • Unsolicited outreach claiming to be a senior official, especially messages urging quick action
  • Any request to move a conversation from one platform to another
  • Requests for help accessing an account, including codes, resets, or login assistance conveyed through messaging or voice
  • Pressure toward urgency or secrecy paired with a claim of high-level authority

Building resistance

Organizations in government and public sector roles should treat unexpected voice or text messages from apparent senior leaders as untrusted until verified through a known, independent contact method, not through the channel the message arrived on. Staff should be trained to pause and question any request to switch communications platforms mid-conversation. Because convincing synthetic voice and video can now be used to build trust or extract sensitive information, high-risk requests, such as account access, credential resets, or sensitive disclosures, should require stronger verification steps regardless of how authoritative the requester sounds. Executive assistants and policy staff who regularly field outreach on behalf of senior officials are especially valuable targets and should have clear escalation procedures for unverified contact.

Key findings

  • The FBI warned that attackers are using AI-generated voices and texts to impersonate senior U.S. officials to build trust and then attempt account access or move conversations to other platforms.
  • A real impersonation incident is cited: an attacker used an AI-generated version of Secretary of State Marco Rubio’s voice to contact multiple high-profile targets via Signal.
  • The article highlights broader government efforts to counter deepfakes through provenance/labeling (EU AI Act, California AI Transparency Act) and identity-trust infrastructure (C2PA Content Credentials, verifiable credentials, biometric protections).
  • French authorities attributed a coordinated deepfake/disinformation campaign to the pro-Russian Matryoshka network (Operation Overload / Storm-1679).

Who’s being targeted

  • Commonly targeted roles: Government executives, Executive assistants, Policy staff, Public affairs / communications, IT / identity and access management teams.
  • Affected industries: Government, Election administration / public sector communications.
  • Attack channels: smishing, vishing.
  • Impersonated: Senior U.S. government official (e.g., Secretary of State / senior U.S. official), Secretary of State Marco Rubio.

Red flags to watch for

  • Unsolicited outreach claiming to be a senior official and urging quick action
  • Request to move the conversation to a different platform
  • Any request for access help (codes, resets, logins) coming through messaging/voice
  • Unexpected call claiming to be a top official without normal verification steps
  • Pressure for urgency and secrecy
  • Voice-only authentication (no independent callback/verification)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in the Marco Rubio voice impersonation incident?

An impostor used an AI-generated version of Secretary of State Marco Rubio's voice to contact three foreign ministers and two U.S. political figures through Signal.

Why did the FBI warn about this type of attack?

The FBI warned that malicious actors are using text messages and AI-generated voices to impersonate senior U.S. officials, often to build relationships with government officials and trusted contacts before attempting account access.

What is the goal of moving a conversation to another platform?

According to the FBI, the goal is often to build trust before attempting to gain access to accounts or move conversations to different communications platforms.

How can government staff verify a suspicious call from a senior official?

Staff should treat unexpected voice or text messages from senior leaders as untrusted until verified through a known, independent contact method rather than the channel used to reach them.

Read the video transcript

Imagine Signal lights up: a voice says, “This is Marco Rubio. I need a quick word on an urgent diplomatic issue.” This actually happened: someone used an AI-generated version of Rubio’s voice on Signal to reach foreign ministers and U.S. political figures, exactly the kind of AI voice scam the FBI’s been warning about. The playbook is simple: a text or call says, “Hi, it’s a senior official, can you talk now? I need to move this to another platform and get help with an access code.” That channel switch plus any request for codes or resets is your red flag. If any “senior leader” pings you out of the blue, voice or text, don’t trust the channel, hang up, then call them back using a number or contact method you already know is real.

Categories

Similar attacks

Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026
Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026
Singapore Runs AI Scam Call “Fire Drills”

Singapore Runs AI Scam Call “Fire Drills”

Singapore’s Cyber Security Agency is running a national exercise where volunteers receive simulated robocalls that mimic government impersonation scams, including AI-enabled calls. The article also points to real-world cases where criminals impersonated company executives on WhatsApp and even used…

August 15, 2026
Wrong-Number Texts That Turn Into Scams

Wrong-Number Texts That Turn Into Scams

The article describes how “wrong-number” SMS messages are used as a first-step social engineering test to identify people who will engage with strangers. If the target replies, scammers may either build a long relationship that leads to fake investment fraud (“pig butchering”) or recycle the…

August 19, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026