Skip to main content
    Cybersecurity11 min read

    AI Can Now Clone Your CFO's Voice. Vishing Is the Attack Surface Nobody Budgeted For.

    By StealthNet Team

    Vishing attacks jumped 442% in 2024 and AI voice cloning made every call more convincing. Here is how AI vishing works, real examples that cost millions, and how a vishing simulation tests your team before attackers do.

    StealthNet AI platform card for the Vishing Pentest social engineering module

    Quote in 48 hours

    Get a custom quote

    Fixed-fee scoping in 24 hours. No sales pitch.

    Most security budgets are built around things you can patch. Firewalls, endpoints, cloud misconfigurations, the CVE of the week. Almost none of it covers the one interface every company still runs on and almost nobody tests: a human being answering the phone.

    That gap is where attackers are moving, fast. Voice phishing, or vishing, is the practice of using a phone call to manipulate someone into handing over credentials, resetting an account, or wiring money. It has existed for years. What changed is that generative AI took the two hardest parts of a convincing vishing call, sounding like a real person and sounding like a specific real person, and made them cheap, instant, and scalable.

    This post covers how voice AI vishing actually works, why it is growing faster than almost any other attack category, real examples that cost real companies real money, and what you can actually do about it.

    Every screenshot below is taken from the StealthNet AI platform, where you can scope a vishing campaign, pick the pretext and synthetic voice, run the calls, review every transcript, and score how your team performed. In other words, everything an attacker would do to you, run safely and on your terms.

    Vishing is exploding, and the numbers are not subtle

    If you only remember one statistic, make it this one. According to CrowdStrike's 2025 Global Threat Report, vishing detections rose 442% between the first and second half of 2024, with a roughly 40% compounded monthly growth rate across the year (CrowdStrike). CrowdStrike calls it one of the most significant shifts in how attackers gain initial access, because adversaries are increasingly targeting human psychology instead of technical vulnerabilities.

    The financial side is tracking right alongside it. In 2025 the FBI's Internet Crime Complaint Center broke out artificial intelligence as its own fraud category for the first time in the agency's history, logging tens of thousands of complaints and hundreds of millions in reported losses tied to AI-enabled fraud (SecureWorld summary of FBI IC3). Voice cloning is showing up specifically as a layer inside business email compromise, where attackers place a follow-up call in a cloned executive voice to "confirm" a wire transfer they already requested over email.

    Looking forward, Deloitte projects that generative-AI-enabled fraud losses in the US will reach $40 billion by 2027, up from $12.3 billion in 2023, a 32% compound annual growth rate (Deloitte, via Deepstrike). Whatever the exact figure lands at, the direction is not in question.

    How does an AI vishing attack work?

    A modern AI vishing attack usually runs in four steps. None of them require the attacker to be technically sophisticated, which is exactly why the volume is climbing.

    1. Reconnaissance. The attacker scrapes LinkedIn, your website, breach databases, and social media to learn who reports to whom, who handles finance, and who staffs the help desk. Org charts are basically public.
    2. Voice collection. A few seconds of audio is enough for many voice-cloning tools. Executive interviews, earnings calls, conference talks, podcast appearances, and webinar recordings are all fair game, and most leaders have plenty of public audio.
    3. Pretext and cloning. The attacker builds a believable scenario, an urgent wire, a "locked" account, an IT ticket, and generates a synthetic voice that matches the person they are impersonating. Newer tools adapt in real time and respond to objections.
    4. The call. The target picks up, hears a familiar voice and an urgent request, and acts before verifying. That is the whole attack.

    Step 1: Scope the campaign and build the target list

    Vishing campaign scoping screen showing company context and redacted target details
    StealthNet AI platform. Attackers do the same reconnaissance work, just without your permission. Target names and phone numbers redacted.

    The reason this works has nothing to do with the victim being careless. It works because a trusted voice plus time pressure plus a plausible story shortcuts the part of the brain that would otherwise stop and check.

    What is a common tactic used in vishing attacks?

    The most common tactic is authority plus urgency: the caller impersonates someone the target is inclined to trust and obey, then manufactures a reason it has to happen right now. A cloned executive demanding an emergency wire before a deal closes. An "IT technician" who needs your MFA code to fix an outage. A "vendor" updating their payment details before an invoice is due.

    Other recurring tactics worth knowing:

    • Help desk impersonation. The attacker calls your IT help desk pretending to be an employee, then talks the agent into resetting a password or MFA device. This flips the usual model. The target is not the victim, the support team is.
    • Caller ID spoofing. The number on the screen shows your bank, your office, or a known contact. It is trivial to fake and it does a lot of the persuasion for free.
    • MFA fatigue paired with a call. The attacker triggers a flood of push notifications, then calls posing as IT to "help you make them stop" by approving one.
    • Vendor and payment fraud. A caller impersonates a known supplier and requests a change to banking details, redirecting real payments to the attacker.

    Step 2: Choose the pretext and the synthetic voice

    Vishing scenario and synthetic voice selection screen inside the StealthNet AI platform
    StealthNet AI platform. Pretexts like "Software Update" and "Password Reset" mapped to synthetic voices. Real attackers assemble the same building blocks in minutes.

    Real vishing examples that cost millions

    Abstract risk is easy to ignore. These are not abstract.

    Arup, the $25.6 million deepfake video call. In early 2024, a finance employee at the Hong Kong office of British engineering firm Arup was invited to a video conference with the company's CFO and several colleagues. Everyone on the call except the employee was an AI-generated deepfake. Convinced by the familiar faces and voices, the employee executed 15 wire transfers totaling $25.6 million (CNN). The funds were never recovered. This is the clearest public proof that voice and video cloning has moved from theory to operational fraud.

    Scattered Spider and the casino breaches. The group behind the 2023 MGM Resorts and Caesars Entertainment attacks did not break through the firewall. They called the help desk. By impersonating employees and social-engineering support agents into resetting MFA and passwords, they walked in with legitimate credentials. MGM absorbed an estimated $100 million in lost revenue and recovery costs, and Caesars reportedly paid a $15 million ransom (Cybersecurity Dive). A phone call took down two of the largest gaming companies in the world.

    Cloned-voice family and executive scams. The FBI has documented voice-cloning scams ranging from fake "kidnapping" calls using a cloned family member's voice to CEO-fraud follow-up calls that reinforce a fraudulent wire request already sent by email. The common thread is that the voice is the weapon.

    Step 3: Review every call transcript and what was given away

    Call review screen showing a vishing call transcript, summary, and captured credentials
    StealthNet AI platform. A recorded simulation where a help desk agent reset a password over the phone under pressure. Names, phone numbers, and captured secrets redacted.

    Why your existing security stack does not cover this

    Here is the uncomfortable part. Almost everything in a typical security budget assumes the attack comes through a system. Vishing comes through a person, over a channel most tools cannot even see.

    • Your email gateway does not screen phone calls.
    • Your EDR does not flag a help desk agent doing exactly what help desk agents are supposed to do.
    • Your annual phishing simulation tests whether people click links, not whether they hang up on a cloned voice.
    • Your SOC has near-zero telemetry on what happens on a voice call.

    The result is a large, growing attack surface that most organizations have never measured. You cannot manage a risk you have never quantified, and you almost certainly have not quantified this one.

    What you can actually do about it

    Awareness posters do not move the needle. The organizations that hold up against vishing treat it as something to be tested and measured, the same way they treat their network perimeter. A few concrete moves:

    • Harden the help desk process. Require callback verification and out-of-band identity checks before any password or MFA reset. Never let urgency override the process. This one change would have stopped the casino breaches.
    • Set a verification norm for money and access. Any wire transfer, payment-detail change, or credential request that arrives by phone gets verified through a second, known channel. Make it a rule, not a judgment call, so no employee has to feel awkward enforcing it.
    • Reduce your public voice footprint where you reasonably can, and assume executives cannot. If your CEO speaks publicly, their voice is already clonable. Plan for that reality instead of hoping otherwise.
    • Test your people the way attackers do. Run realistic vishing simulation campaigns against your actual staff, measure who is susceptible, and target training where the data says it is needed. This is the only way to turn a vague fear into a number you can track and improve.

    Step 4: Score answer rate, failure rate, and voice susceptibility

    Vishing pentest dashboard showing answer rate, failure rate, and voice susceptibility score
    StealthNet AI platform. The dashboard turns "we are probably exposed" into numbers you can track quarter over quarter.

    That last point is the whole reason StealthNet AI built a vishing simulation agent. Our AI agents run hyper-realistic voice phishing assessments at scale, with voice cloning, multi-language support, and real-time adaptation, so you can test hundreds of employees simultaneously instead of being capped by how many calls a human operator can make in a day. You get a measurable susceptibility baseline, the specific pretexts that worked, and the exact groups that need training, in about 24 hours. It runs on the same StealthNet AI platform as our AI-native penetration testing, so your human attack surface gets tested with the same rigor as your technical one.

    Step 5: Turn each failed call into a finding with a fix

    Vishing finding write-up explaining why a help desk employee complied with the attacker
    StealthNet AI platform. Every failed interaction becomes a written finding with the psychology behind it and the control that would have stopped it. Identifying details redacted.

    Attackers already automated this. Testing your defenses by hand is bringing a clipboard to a scale fight.

    Frequently asked questions

    What is vishing?

    Vishing, short for voice phishing, is a social engineering attack that uses a phone call to trick someone into revealing sensitive information, resetting an account, or transferring money. AI voice cloning has made these calls far more convincing by letting attackers impersonate specific, trusted people.

    What does vishing stand for?

    Vishing is a blend of "voice" and "phishing." It refers to phishing attacks carried out over a phone call or voice channel rather than email.

    How is AI vishing different from regular vishing?

    Traditional vishing relied on a human caller and a generic script. AI vishing uses generative voice tools to clone a specific person's voice, run in multiple languages, and adapt to the target's responses in real time, which makes the calls more believable and far easier to run at scale.

    What is a common tactic used in vishing attacks?

    The most common tactic is combining authority with urgency: the attacker impersonates a trusted figure such as an executive or IT support, then creates time pressure so the target acts before verifying. Help desk impersonation and caller ID spoofing are also frequently used.

    How can a company defend against voice AI vishing?

    Harden help desk verification, require out-of-band confirmation for money and access requests, limit unnecessary public audio exposure, and run regular vishing simulations to measure and reduce employee susceptibility over time.

    Sources

    Frequently asked questions

    Ready to find what attackers would find?

    AI-powered, hybrid, or fully manual penetration testing with audit-ready reports for SOC 2, PCI DSS, HIPAA, and CMMC. Most engagements can start within 24 hours.

    Share this article