Man holding a fake moustache showing AI deepfakes

Secretary of State Rubio Impersonated With AI Deepfakes Targeting Officials

A threat actor suspected to be based in Russia crafted AI deepfakes of US Secretary of State Marco Rubio and attempted to use them to fool several foreign ministers and US officials, according to an anonymous source speaking with reporters from the Washington Post.

The source says that the AI deepfakes were used to contact three foreign ministers, a US Governor, and a member of Congress around the middle of June via the Signal messaging app. Two of the officials received fake voicemail messages mocked up to use Rubio’s voice, and another received an invite to join a chat that appears to have used AI tools to mimic the Secretary’s writing style.

AI deepfakes made use of inside state department information

The source did not name the officials that were contacted or indicate exactly what the hackers were after, but a State Department comment on the story characterized the communications as “no threat” to US officials and “not very sophisticated” in terms of cyber risk.

The AI deepfakes focused on “vishing” and “smishing” rather than video, using tools to impersonate the Secretary’s voice to leave voicemail messages and his style of writing to send text messages. The most likely intent was to lure targets into a malicious chat or to a phishing site and attempt to gain account login details from there.

A follow-up internal warning cable from the State Department issued on July 3 was shared with Reuters reporters, providing a bit more information about the attack. It noted that a similar attempt to use AI deepfakes to target former State Department officials (along with Eastern European activists and dissidents as well as international think tank employees) was observed in April of this year and linked to a hacker believed to be in Russia. A firm link to Russian state-sponsored activity has yet to be established, but the attacker had inside knowledge of State Department Bureau of Diplomatic Technology logos, branding, naming conventions and internal documentation that was used to add legitimacy to their phishing emails.

AI deepfake threats increasing in sophistication, ease of creation

Though these particular AI deepfakes were described as unsophisticated, the field is becoming increasingly realistic with recent advances in voice and video generation. Newer tools can create voices that are nearly indiscernible from the source and videos that have very few of the telltale artifacts that made it relatively easy to spot older fakes. And the technology still has a great deal of room to grow. Generative AI tools also bolster “vishing” by providing a personality that can make use of the voice in a fluid way, with instant responses to keep pace with a conversation.

This is actually the second attempt to use AI deepfakes to impersonate Rubio, though the first was more of a public propaganda attempt than a targeted cyber attack. In March of this year, a deepfake video began circulating on social media that purported to show Rubio threatening to have Elon Musk turn off Starlink service to Ukraine. The video made use of two pieces of actual footage, including the infamous meeting between Trump and Zelensky at the White House from that time, but laid over deepfake audio of Rubio speaking.

Other similar attempts have been made on high-profile politicians. Perhaps the most noteworthy of these was an early 2024 series of robocalls made to voters in New Hampshire ahead of the state’s Democratic primary election. The calls used AI deepfakes to emulate Joe Biden’s voice, urging voters not to “waste” their vote on the primary and wait for the general election in November. After an investigation by the state attorney general’s office that lasted several months, political consultant Steve Kramer (associated with the Dean Phillips presidential campaign) was indicted for hiring a third party to create the deepfake audio. Kramer had faced potentially decades in prison under an assortment of felony voter suppression charges, but was acquitted by a jury in June. He still faces a $6 million fine from the FTC.

But the biggest and most damaging single incident involving AI deepfakes thus far would have to be a successful scam run on British design firm Arup in January 2024. An employee authorized to approve financial transactions at a Hong Kong office was targeted and convinced to transfer $25 million USD by hackers using fake voices meant to sound like company executives. That scam incorporated a fake video call that made use of prior video of company employees on conference calls, but with AI-generated deepfake audio controlled by the attackers.

Aditya Sood, VP of Security Engineering and AI Strategy at Aryaka, notes that these attempts should be taken very seriously given that video is on the verge of catching up with audio: “The rising trend of AI-generated deepfakes poses a significant and immediate threat to national security, as well as public trust. These scams outpace traditional detection methods, exploiting gaps in platform moderation and regulatory oversight. The proliferation of AI has only exacerbated this issue, with advanced threat actors capitalizing on unprepared organizations. To mitigate these scams, social media platforms are deploying AI-powered detection tools to identify manipulated media and impersonation attempts. However, it’s hard to control the AI generated public media content. Combating deepfakes requires a multi-pronged strategy: proactive media literacy education to empower the public to assess content critically; robust technical solutions, such as real-time detection, content provenance standards (e.g., C2PA), and cryptographic authentication, to verify media authenticity; and strong legal frameworks coupled with rapid platform action for the removal of malicious deepfakes. This collective effort, which combines public awareness with technological defenses and regulatory pressure, is essential to preserving truth and trust in our increasingly synthetic digital landscape. Additionally, proactive security measures should be implemented to deter unauthorized access to sensitive information. Network containment measures such as segmentation, virtual local area networking (VLAN) quarantining, zero-trust network access (ZTNA), and traffic filtering will ensure that an attack can be maintained and localized if it does occur, limiting threat actors’ lateral movement across an organization.”

Steve Cobb, CISO at SecurityScorecard, expands on the likely sources of attacks using AI deepfakes and their approaches: “These operations are suspected to be linked to Russian actors, a finding that’s not entirely surprising, as Eastern Europe continues to be a hub for malicious cyber activity. To avoid falling victim to these schemes, staying vigilant is key. This is not the first time threat actors have impersonated state officials, and it likely won’t be the last. The first and most important step has already been taken: these campaigns have been reported to the FBI’s Internet Crime Complaint Center, which will serve as the primary source of verified information on incidents like this moving forward. Additionally, to verify the authenticity of someone reaching out to engage or meet with you, look for some form of secondary authentication. This could include calling a known, trusted phone number, messaging the person through a verified social media account, or contacting someone who has a personal affiliation with the individual you’re trying to verify. We need to evolve toward a default mindset of healthy skepticism in these interactions and adopt a “trust but verify” approach as our standard practice.”

Alex Quilici, CEO at YouMail, adds: “If AI can fool senators, government officials, and foreign ministers just by mimicking a well-known voice, imagine what it could do to everyday consumers. Tools like Live Voicemail actually open the door wider (risk more) for these scams. What stands out here is that it’s messaging-based, not a live call. Short, AI-generated voice clips are easy to pull off today. Longer back-and-forth conversations are tougher, but increasingly within reach. Fooling someone with short voice messages is fairly easy given the current state of AI, however, keeping up longer interactive conversations is still harder, though it might still be possible.”

And Brian Long, CEO of Adaptive Security, warns that these attacks will not be limited to politicians or public figures: “Scammers often target notable individuals due to their access to classified information, net worth and assets, or ability to influence others — all of which could be possible in this situation with Rubio. His likeness also adds credibility for this fraudster. These government officials are already familiar with Rubio and his voice, so getting a call out of the blue from him wouldn’t immediately raise a red flag. But it’s not just Rubio or other high-profile people that should be worried about bad actors deepfaking their voices. Attackers can find the cell phone number for almost anyone, and with advances in AI, can also clone nearly anyone’s voice if there is publicly available audio of someone speaking online. Even if you have your own voice in your cell phone voicemail greeting, we highly recommend changing it to the default robotic voice instead. This recording – even just three seconds of audio – is all that attackers need in order to create a deepfake. It’s imperative to stay informed on how easy it is nowadays to create and deploy these voice clones, and organizations – from small businesses to even federal governments, in this case – need to properly train individuals on how to spot and flag scams of this nature.”