Government and authority impersonation · Also called senior US officials impersonation, AI voice message official scam, deepfake official
Senior official AI voice impersonation
Senior official voice impersonation is a campaign where attackers send texts and AI-generated voice messages that sound like a senior government official. The aim is to build rapport with officials and their contacts, then move them to another platform, where a link steals account access or the contact is asked for sensitive information.
How it works
- The attacker researches a senior official and their network, then sends a text or an AI-generated voice message in that official's name.
- The message builds rapport and asks the target to continue the conversation on a different messaging platform.
- The new platform link is malicious and harvests login credentials, or the attacker asks for contact details of other officials.
- Compromised accounts are used to impersonate the victim in turn and reach more contacts.
Red flags
- A text or voice message from a senior official you do not normally hear from this way.
- A request to move the conversation to a different messaging app or to click a link to do so.
- The voice sounds right but the phrasing, timing, or number is unusual.
- Requests for contact details of colleagues, sensitive information, or money.
If you are targeted
- Stop contact: do not click links or reply until you have confirmed who sent the message.
- Verify the sender through a known number or channel, such as their office's official contact details.
- If you entered credentials, change the password, sign out other sessions, and tell your security team.
- Report it. Our Report a scam page lists where to report in your country, such as ic3.gov and ReportFraud.ftc.gov in the US.
Prevention
For individuals
- Verify the identity of anyone who calls or messages claiming to be an official, using contact details you already have.
- Do not click links in texts or emails until you have independently confirmed the sender.
- Turn on multi-factor authentication on every account that allows it, and never share an associate's contact details with someone you have met only online or by phone.
For organisations
- Publish and train staff on an out-of-band verification rule for any request that arrives by text, voice message, or a new messaging app.
- Use phishing-resistant multi-factor authentication for staff accounts so harvested passwords alone cannot be used.
- Give staff an easy way to report suspected impersonation to the security team and warn their contacts.
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Government impersonation losses reported to the FBI IC3 in 2025 | $797.9M | US, 2025, FBI IC3 |
| Losses in FBI IC3 complaints mentioning AI in 2025 (overlaps other categories, never summed) | $893.3M | US, 2025, FBI IC3 |
Real cases
2025-05 · US · Disclosed
FBI warns of AI voice messages impersonating senior US officials, 2025
Delivered through: SMS phishing (smishing), Voice phishing (vishing)
How official datasets classify it
- FBI IC3
- Government Impersonation
- MITRE ATT&CK
- T1566.004, T1684.001
Questions
- Can attackers fake a senior official's voice?
- Yes. The FBI has warned of campaigns using AI-generated voice messages that impersonate senior US officials to build trust before sending malicious links.
- How do I check if a message from an official is real?
- Contact the person through a number or channel you already know, not the one in the message, and do not click any link until you have confirmed it.