ISJ hears exclusively from Javvid Malik, Lead CISO Advisor at KnowBe4 about the use of AI voice phishing within global organisations.
For decades, the human voice was a cornerstone of trusted and reliable authentication, providing a layer of certainty that digital systems often lacked.
While email filters, secure web gateways and multi-factor authentication (MFA) protected digital perimeters, a quick phone call served as the final trusted check for organisational decision-making.
Hearing a familiar voice or an authoritative executive on the line was usually enough to provide the green light to move forward.
But with the evolution of voice phishing, or ‘vishing’, that call can no longer be trusted.
What was once a niche vector operated by low-grade phone scammers reading scripts from call centres, has transformed into a high-precision, scalable enterprise threat.
Driven by breakthroughs in AI voice cloning and social engineering, vishing is now a primary method for breach, extortion and ransomware deployment across major global organisations.
The AI catalyst
According to Mandiant’s M-Trends 2026 report, interactive vishing attacks have climbed to become the second most commonly observed initial infection vector, jumping ahead of email phishing.
The catalyst behind this rise is the availability of AI voice cloning.
Threat actors no longer need hours of pristine studio recordings to replicate a target’s voice.
Modern AI models require as little as 30 seconds of clear audio — easily harvested from public webinars, podcasts, earnings calls, or video keynotes — to create an ultra-realistic synthetic clone.
When combined with real-time text-to-speech engines and natural language processing, attackers can easily execute dynamic, two-way telephone conversations.
Unlike email, where employees have time to inspect headers or hover over links, live phone calls create a sense of urgency where decision-making error rates can increase under pressure.
Furthermore, mobile network compression and occasional background noise naturally mask minor AI imperfections, making synthetic voices more likely to sound authentic over the phone.
From helpdesks to the c-suite
Recent high-profile breaches demonstrate that vishing attacks target two distinct pressure points within the enterprise: frontline support desks and executives.
- Exploiting the Helpdesk: Frontline IT support staff are hired to solve problems quickly, making them ideal targets for manipulative social engineering. In the high-profile MGM Resorts ransomware outbreak, attackers from the ALPHV/BlackCat ransomware group reportedly gathered information from LinkedIn, impersonated an MGM employee and called the internal IT helpdesk. By tricking support personnel into issuing new credentials and resetting MFA devices, the attackers took down hotel management and casino systems for days, incurring millions in operational losses
- Executive Deepfakes: When attackers elevate their targets to senior leadership or high-value organisations, the potential payouts increase exponentially. In early 2026, the ShinyHunters group used a targeted vishing campaign against Charter Communications, culminating in the unauthorised access of nearly 42 million customer records
In another instance, fraudsters generated a voice clone of Italian Defence Minister Guido Crosetto to execute high-urgency calls to prominent business figures, including former Inter Milan owner Massimo Moratti.
Claiming emergency funds were needed to release kidnapped journalists in the Middle East, the scam successfully coaxed over €1 million from victims before law enforcement intervened.
Building a vishing-resilient organisation
Traditional endpoint security, antivirus software and email security gateways are unable to protect organisations from vishing.
Defending against modern voice attacks requires an evolution in processes, operational culture and technical guardrails.
- Enforce strict verification: Under no circumstances should credential resets, MFA re-enrolment, or financial transfers be authorised solely on an inbound phone call. Organisations must implement mandatory callbacks using pre-verified phone numbers listed in an official corporate directory. Additionally, two-person authorisation controls should be enforced for high-risk operations, such as bank transfers or privileged account changes
- Harden the service desk: IT helpdesks must be treated as a critical security risk point. Teams need to transition away from information-based authentication such as employee ID numbers or birthdates that can easily be scraped online. Mandating video verification with active employee managers or push-notification identity checks via secure enterprise portals prior to resetting access provides a crucial additional layer of protection
- Deploy zero-trust technical controls: By assuming a worst-case scenario is inevitable, technical controls can limit the blast radius of a successful vishing call. Application allowlisting and ringfencing ensure that even if a user is coerced into downloading remote access software, unapproved executables are blocked by default. Furthermore, organisations should replace voice- or SMS-based MFA codes with hardware security keys
- Modernise Security Awareness Training: Most training programmes still focus largely on identifying phishy emails, leaving a major gap in phone-based defense. Organisations must update their training to conduct realistic, vishing simulations that build employee defensive awareness. Crucially, leadership must establish a corporate culture where questioning authority or delaying an urgent request to perform mandatory identity checks is praised rather than penalised
As generative voice tools become cheaper, faster and more accessible, AI-driven vishing will continue to escalate in frequency and sophistication.
To protect critical infrastructure, sensitive data and financial assets, security leaders must accept that the human voice can no longer be trusted.
Operational resilience requires pairing zero-trust technical measures with unyielding human verification processes, so your organisation is ready to pause and verify whenever a suspicious request arrives.