The FBI says hackers are using AI voice clones to impersonate US government officials
The campaign uses AI voice generation to send messages pretending to be from high-ranking figures


Had a call from a senior US official? It probably wasn't real. The FBI has issued a warning about an ongoing malicious text and voice messaging campaign in which scammers use AI-generated voices to target victims.
As part of the campaign, threats actors claim to be a senior US official in a bid to access personal accounts. The campaign began in April, according to the law enforcement agency, and it hasn't said which senior US officials are being impersonated.
AI-generated voice calls have been used in a few high profile attacks. Last year, an executive at Ferrari stymied a similar attack by asking about a book recommended by the person being impersonated.
Similarly, British engineering company Arup paid out $25 million to scammers who set up a false video call meeting to trick an employee while back in 2019 a British energy firm was targeted using AI-generated calls to a cost of more than £200,000.
In its advisory, the FBI said the "smishing" or "vishing" attacks, as the American policing agency called them, may be using AI tools to generate the voices.
"One way the actors gain such access is by sending targeted individuals a malicious link under the guise of transitioning to a separate messaging platform," the FBI said in a statement.
Once the account of one person is compromised, it can be used in future attacks.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Access to personal or official accounts operated by US officials could be used to target other government officials, or their associates and contacts, by using trusted contact information they obtain," the FBI added.
"Contact information acquired through social engineering schemes could also be used to impersonate contacts to elicit information or funds."
The warning comes as 68% of businesses have said they've developed a "deepfake" response plan amid the rise in social engineering attacks, with separate research saying nearly two-thirds of finance professionals had been targeted by deepfake fraud.
Avoiding AI scams
The FBI warning noted that the scammers are using software to generate a phone number that isn't attributed to a specific phone. As such, anyone unsure of a message should verify the identity of the person calling with a bit of research, independently verify their correct number, and check that any information shared is correct.
However, Max Gannon, intelligence manager at Cofense, noted that threat actors can also spoof known phone numbers of trusted individuals or organizations. This, he said, adds another layer of risk for potential victims.
“Phone filtering does not typically detect when the number is being spoofed, giving a false sense of security to users who rely on their phones to tell them when something is a scam call,” he said.
When examining a video or image for signs of AI, the FBI suggested looking for subtle imperfections such as distorted hands or feet, indistinct faces, inaccurate shadows, voices matching facial movements, and other unnatural movements.
These practices could be the difference between swerving a disaster or falling victim, the agency added. However, it warned that AI-generated content has now “advanced to the point that it is often difficult to identify”.
As such, the FBI suggested people create a secret word or phrase to prove their identity, as well as the usual security advice of not trusting links or email attachments that haven't been verified. Additionally, individuals and enterprises should never send money, gift cards, or cryptocurrency to someone via the internet or phone.
"Both smishing and vishing techniques rely on social engineering to manipulate recipients, often by instilling a sense of urgency or fear," Gannon added.
"Threat actors are increasingly turning to AI to execute phishing attacks, making these scams more convincing and nearly indistinguishable from legitimate communication. For traditional phishing alone, Cofense has observed a 70% increase in BEC attacks from 2023 to 2024, which can be attributed to the increasing use of AI."
MORE FROM ITPRO
- Ransomware attacks are rising — but quiet payouts could mean there's more than actually reported
- Preventing deepfake attacks: How businesses can stay protected
- FBI issues guidance for enterprises as fake North Korean IT workers wreak havoc
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Using DeepSeek at work is like ‘printing out and handing over your confidential information’
News Thinking of using DeepSeek at work? Think again. Cybersecurity experts have warned you're putting your enterprise at huge risk.
-
Can cyber group takedowns last?
ITPro Podcast Threat groups can recover from website takeovers or rebrand for new activity – but each successful sting provides researchers with valuable data
-
Using DeepSeek at work is like ‘printing out and handing over your confidential information’
News Thinking of using DeepSeek at work? Think again. Cybersecurity experts have warned you're putting your enterprise at huge risk.
-
Passwords are a problem: why device-bound passkeys can be the future of secure authentication
Industry insights AI-driven cyberthreats demand a passwordless future…
-
Microsoft patched a critical vulnerability in its NLWeb AI search tool – but there's no CVE (yet)
News Researchers found an unauthenticated path traversal bug in the tool debuted at Microsoft Build in May
-
AI breaches aren’t just a scare story any more – they’re happening in real life
News IBM research shows proper AI access controls are leading to costly data leaks
-
The rise of GhostGPT – Why cybercriminals are turning to generative AI
Industry Insights GhostGPT is not an AI tool - It has been explicitly repurposed for criminal activity
-
Think DDoS attacks are bad now? Wait until hackers start using AI assistants to coordinate attacks, researchers warn
News The use of AI in DDoS attacks would change the game for hackers and force security teams to overhaul existing defenses
-
Okta and Palo Alto Networks are teaming up to ‘fight AI with AI’
News The expanded partnership aims to help shore up identity security as attackers increasingly target user credentials
-
Despite the hype, cybersecurity teams are still taking a cautious approach to using AI tools
News Research from ISC2 shows the appetite for AI tools in cybersecurity is growing, but professionals are taking a far more cautious approach than other industries.