Man talking on phone showing AI-generated deepfake audio

U.S. Officials Targeted Via AI-Generated Text and Deepfake Audio Impersonating Public Figures

The Federal Bureau of Investigation (FBI) warns about AI-generated phishing text or deepfake audio messages impersonating senior U.S. officials targeting current and former state and federal officials and their contacts.

“Since April 2025, malicious actors have impersonated senior US officials to target individuals, many of whom are current or former senior US federal or state government officials and their contacts,” the agency stated.

The attackers behind the smishing and vishing campaign usually assume the identities of well-known, public figures or personal relations to make their phishing lures more believable.

U.S. officials targeted in AI-powered phishing campaign

The agency warned that the attackers begin by attempting to “establish rapport before gaining access to personal accounts” of the targeted individuals.

They then send malicious links under the guise of transitioning to a separate messaging platform, a common tactic employed by state-sponsored and financially motivated attackers.

They use the secondary communication platforms to send credential- and log-stealing malware (info-stealers) or malicious links directing victims to attacker-controlled domains.

The exploitation of secondary communication platforms is especially concerning amid allegations that Pentagon officials in the Trump and Biden administrations communicated using third-party encrypted apps like Signal to coordinate government activities.

In text-based phishing (smishing), the attackers use software to create ghost numbers that are not associated with any mobile phone or subscriber to impersonate an associate or family member.

“While the IC3 alert does say “malicious actors typically use software to generate phone numbers that are not attributed to a specific mobile phone or subscriber,” it is important to note that threat actors can also spoof known phone numbers of trusted organizations or people, adding an extra layer of deception to the attack,” warned Max Gannon, Intelligence Manager at Cofense.

For voice-based phishing (vishing), they use AI-generated audio to impersonate well-known pubic figures or family members.

The FBI warned that attackers could use compromised accounts to impersonate other U.S. officials and their contacts to obtain sensitive information or funds, using the trusted information they collect.

“Contact information acquired through social engineering schemes could also be used to impersonate contacts to elicit information or funds,” the FBI said.

In December 2024, the FBI had warned that attackers were exploiting generative AI to commit large-scale financial fraud.

Back then, the FBI explained that generative AI helped bad actors make their scams believable. It also synthesized known information into “something entirely new” while removing obvious errors that would raise suspicions.

Europol and the U.S. Department of Health and Human Services (HHS) also warned about AI-generated materials being used for organized crime, including deepfake explicit content and voice cloning.

“Threat actors are increasingly turning to AI to execute phishing attacks, making these scams more convincing and nearly indistinguishable from legitimate communication,” added Gannon. “For traditional phishing alone, Cofense has observed a 70% increase in BEC attacks from 2023 to 2024, which can be attributed to the increasing use of AI.”

Meanwhile, the FBI has not disclosed the number of victims impacted and has not attributed the cyber campaign to any threat actor. Nonetheless, government officials are frequently targeted by state-linked hackers for cyberespionage.

The agency also did not disclose the secondary communication platform that the attackers use to target U.S. officials in the seemingly ongoing campaign.

Undoubtedly, deepfake technology has become increasingly accessible via mainstream apps and is frequently leveraged for political, geopolitical, and financial purposes.

“Deepfake voice attacks are part of an increasing trend, having been used successfully to demonstrate social engineering using AI, with increasing levels of success and impact,” noted Steve Povolny, Senior Director of Security Research at Exabeam. “There is small risk and high reward given the nature of the medium; recorded voices are simply very simple to fake and equally harder to detect.”

During the 2024 Democratic primaries, Steve Kramer oversaw the creation of a deepfake audio impersonating then-primaries candidate Joe Biden, dissuading New Hampshire voters from casting their ballots.

Crypto scammers also frequently use deepfakes to impersonate Tesla and SpaceX CEO Elon Musk on his X platform to promote investment scams.

Protecting against AI-generated phishing texts and audio

The FBI published a list of recommendations to help U.S. officials avoid falling victim to the AI-generated text and audio phishing campaign.

It advised U.S. officials to verify the identity of the person calling or sending messages and independently confirm the phone number of the person purporting to be calling.

“If you receive a message claiming to be from a senior US official, do not assume it is authentic,” the FBI warned.

The agency also recommended verifying email addresses, URLs, and messaging account details when engaging with someone purporting to be a government official.

Targeted U.S. officials should also remain vigilant for AI-generated images and videos by checking for distorted or irregular body features, such as distorted hands and feet.

Unrealistic accessories such as glasses and jewelry, watermarks, mismatching shadows, call lag times, unusual movements, and mismatching voices are telltale signs of AI-generated profiles.

Similarly, paying attention to the speaker’s choice of words and tone could help the victim differentiate between an AI-generated voice and normal speech.

Targeted U.S. officials are also advised to contact their relevant security officials when they doubt the caller’s identity.

The FBI also discouraged sharing personal information or their associates’ contacts, sending money, gift cards, or cryptocurrency.

State and federal officials should also avoid clicking on suspicious links in emails or downloading attachments and applications when requested by someone whose identity they cannot confirm.

They should also enable multi-factor authentication and avoid disclosing 2FA codes over any communication channel. U.S. officials should also set secret words or phrases that only family members know to verify identity.