
Voicemail Lure Drives Microsoft Device-Code Phish
A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page…
The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic impersonation can override normal suspicion.
A finance employee received suspicious emails and then was invited to join an urgent video conference to approve wire transfers. On the call, deepfake video renders of his coworkers appeared, giving the appearance of a legitimate internal meeting. That realism was enough to override his earlier doubts, and he went on to complete several wire transfers during the session.
The core reason this attack worked is that the deepfake video created a stronger signal of trust than the suspicious emails that preceded it. The worker had reason to be cautious, but seeing familiar faces on a live call reduced that doubt. This shows how synthetic media can be used specifically to neutralize the skepticism that email-based warning signs would normally trigger. Attackers also don't need to fool basic camera checks; they can inject synthetic video directly into the data stream using virtual cameras or tampered and emulated devices, which means simple visual verification is not a reliable control on its own.
Organizations should treat video calls as untrusted for money movement decisions. Payment instructions delivered or confirmed on a video call should always be verified through a separate, known-good channel, such as calling a previously verified phone number or requiring a secondary approver who was not on the call. Earlier warning signs, like suspicious emails, should not be dismissed just because a later interaction appears more convincing; those signals should trigger a pause and independent verification rather than being overridden.
Because attackers can bypass simple camera checks, verification programs should layer multiple signals, including device recognition, location, and behavioral analytics, with additional step-up verification whenever something does not align. This reduces reliance on any single input, including video realism, as proof of identity.
Finally, as biometric verification becomes more common for account recovery and identity checks, it is worth remembering that biometric identifiers such as a face or fingerprint cannot be changed if they are ever compromised, unlike a password. Understanding how biometric data is stored, used, protected, and deleted is an important part of managing this risk across both personal and organizational contexts.
This technique aligns with known adversary behaviors for phishing via voice or video (T1566.002) and impersonation for information gathering (T1598).
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A finance worker was convinced to join a conference call featuring deepfake renders of his colleagues, and the realistic video overrode his earlier suspicion about related emails, leading him to complete several wire transfers.
Yes. Attackers can bypass camera checks entirely by injecting synthetic video directly into the data stream through virtual cameras and tampered or emulated devices, so video alone should not be treated as proof of identity.
Verification should be layered with device recognition, location, and behavioral analytics, and payment requests should always be confirmed through a separate, known-good process rather than relying on a video call.
Although he was suspicious of the emails leading up to the meeting, his doubt was assuaged by the realistic deepfakes shown on the call, illustrating how convincing synthetic video can override normal caution.
Imagine joining a video call with your whole finance team… and every single person on screen is a deepfake. That actually happened: a finance worker got an email saying, “Hi, please join this conference call now to review and urgently approve today’s wire transfers,” then saw deepfake versions of coworkers on the call and sent out multiple wires. Here’s the scary part: he was already suspicious of the emails, but the realistic faces on video overruled his gut. Attackers can even bypass camera checks by injecting synthetic video through virtual cameras or tampered devices. So if a call pushes you to move money fast, treat the video as untrusted: stop, and confirm the request through a separate known-good channel before you send a single wire.

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…