Deepfake Vishing: How to Spot and Prevent These Attacks
- The increasing sophistication of artificial intelligence is fueling a surge in "deepfake" voice scams, also known as "vishing" attacks, where criminals impersonate individuals to defraud victims.
- On Wednesday, security firm Group-IB outlined the steps involved in these attacks, noting they are easily reproducible at scale and difficult to detect.
Deepfake Voice Scams Are on the Rise, and They’re Getting Harder to Spot
The increasing sophistication of artificial intelligence is fueling a surge in “deepfake” voice scams, also known as “vishing” attacks, where criminals impersonate individuals to defraud victims. Government officials have been warning of this threat for years, with the Cybersecurity and Infrastructure Security Agency stating in 2023 that threats from deepfakes and other synthetic media have increased “exponentially.” Last year, Google’s Mandiant security division reported that these attacks are executed with “uncanny precision,” leading to more realistic phishing schemes.
Anatomy of a Deepfake Scam Call
On Wednesday, security firm Group-IB outlined the steps involved in these attacks, noting they are easily reproducible at scale and difficult to detect.

The workflow of a deepfake vishing attack.
Credit: Group-IB
The basic steps are:
- Collecting voice samples: Samples as short as three seconds are sufficient, sourced from videos, meetings, or calls.
- AI-based speech synthesis: Samples are fed into engines like Google’s Tacotron 2, Microsoft’s Vall-E, or services from ElevenLabs and Resemble AI, creating text-to-speech output mimicking the target’s voice.While most services prohibit this use, consumer Reports found in March safeguards are easily bypassed.
- Number spoofing (optional): Attackers may spoof the target’s or association’s phone number.
- Initiating the scam call: The cloned voice follows a script or generates speech in real-time, responding to questions for increased believability.
“Although real-time impersonation has been demonstrated by open source projects and commercial APIs, real-time deepfake vishing in-the-wild remains limited,” Group-IB said. “However, given ongoing advancements in processing speed and model efficiency,
