Governments are responding to deepfakes by shifting from “detecting fakes” to building systems that prove where digital content came from and whether it was altered. The article cites real AI-impersonation activity targeting government officials, including text and AI-voice impersonation intended to build trust and then gain access to accounts or move conversations to other platforms.
How the attack worked
An impostor used an AI-generated version of Secretary of State Marco Rubio's voice to contact three foreign ministers and two U.S. political figures through Signal. This is one example cited within a broader pattern the FBI has warned about: malicious actors using text messages and AI-generated voices to impersonate senior U.S. officials. The tactic is not a one-off stunt but part of a documented trend targeting government executives, executive assistants, policy staff, and public affairs teams.
According to the FBI, the underlying goal in these campaigns is often to build relationships with government officials and other trusted contacts before attempting to gain access to accounts or move conversations to different communications platforms. In other words, the impersonation itself is often just the opening move, meant to establish enough credibility that a target will comply with a follow-up request.
Why it succeeded
The scenario relies on a few compounding factors. Voice-only authentication over messaging apps like Signal gives targets no easy way to independently confirm identity in the moment. Combined with the assumed authority of a senior official, and the natural instinct to respond promptly to someone who appears to hold real power, targets have limited opportunity to pause and verify. A convincing fake voice message, video call, or text exchange could be used to establish trust, gain access to an account, or induce someone to disclose sensitive information, and none of those outcomes require the attacker to breach any system directly.
What to watch for
- Unsolicited outreach claiming to be a senior official, especially messages urging quick action
- Any request to move a conversation from one platform to another
- Requests for help accessing an account, including codes, resets, or login assistance conveyed through messaging or voice
- Pressure toward urgency or secrecy paired with a claim of high-level authority
Building resistance
Organizations in government and public sector roles should treat unexpected voice or text messages from apparent senior leaders as untrusted until verified through a known, independent contact method, not through the channel the message arrived on. Staff should be trained to pause and question any request to switch communications platforms mid-conversation. Because convincing synthetic voice and video can now be used to build trust or extract sensitive information, high-risk requests, such as account access, credential resets, or sensitive disclosures, should require stronger verification steps regardless of how authoritative the requester sounds. Executive assistants and policy staff who regularly field outreach on behalf of senior officials are especially valuable targets and should have clear escalation procedures for unverified contact.
Key findings
- The FBI warned that attackers are using AI-generated voices and texts to impersonate senior U.S. officials to build trust and then attempt account access or move conversations to other platforms.
- A real impersonation incident is cited: an attacker used an AI-generated version of Secretary of State Marco Rubio’s voice to contact multiple high-profile targets via Signal.
- The article highlights broader government efforts to counter deepfakes through provenance/labeling (EU AI Act, California AI Transparency Act) and identity-trust infrastructure (C2PA Content Credentials, verifiable credentials, biometric protections).
- French authorities attributed a coordinated deepfake/disinformation campaign to the pro-Russian Matryoshka network (Operation Overload / Storm-1679).
Who’s being targeted
- Commonly targeted roles: Government executives, Executive assistants, Policy staff, Public affairs / communications, IT / identity and access management teams.
- Affected industries: Government, Election administration / public sector communications.
- Attack channels: smishing, vishing.
- Impersonated: Senior U.S. government official (e.g., Secretary of State / senior U.S. official), Secretary of State Marco Rubio.
Red flags to watch for
- Unsolicited outreach claiming to be a senior official and urging quick action
- Request to move the conversation to a different platform
- Any request for access help (codes, resets, logins) coming through messaging/voice
- Unexpected call claiming to be a top official without normal verification steps
- Pressure for urgency and secrecy
- Voice-only authentication (no independent callback/verification)
Frequently asked questions
What happened in the Marco Rubio voice impersonation incident?
An impostor used an AI-generated version of Secretary of State Marco Rubio's voice to contact three foreign ministers and two U.S. political figures through Signal.
Why did the FBI warn about this type of attack?
The FBI warned that malicious actors are using text messages and AI-generated voices to impersonate senior U.S. officials, often to build relationships with government officials and trusted contacts before attempting account access.
What is the goal of moving a conversation to another platform?
According to the FBI, the goal is often to build trust before attempting to gain access to accounts or move conversations to different communications platforms.
How can government staff verify a suspicious call from a senior official?
Staff should treat unexpected voice or text messages from senior leaders as untrusted until verified through a known, independent contact method rather than the channel used to reach them.
Read the video transcript
Imagine Signal lights up: a voice says, “This is Marco Rubio. I need a quick word on an urgent diplomatic issue.” This actually happened: someone used an AI-generated version of Rubio’s voice on Signal to reach foreign ministers and U.S. political figures, exactly the kind of AI voice scam the FBI’s been warning about. The playbook is simple: a text or call says, “Hi, it’s a senior official, can you talk now? I need to move this to another platform and get help with an access code.” That channel switch plus any request for codes or resets is your red flag. If any “senior leader” pings you out of the blue, voice or text, don’t trust the channel, hang up, then call them back using a number or contact method you already know is real.