SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Deepfake-Assisted Phishing

Deepfake-assisted phishing is a digital con where scammers use AI to create fake videos or audio recordings that sound and look exactly like someone you trust, such as your boss or a family member. By pretending to be these people, they trick you into doing things you wouldn't normally do, like sending money or sharing private passwords, because you believe you are talking to a real person you know.

Deepfake-assisted phishing is a social engineering technique where adversaries leverage generative AI to synthesize high-fidelity audio or video impersonations of trusted individuals or executives. These synthetic assets are deployed across communication channels like vishing, video conferencing, or messaging to bypass traditional verification methods. By exploiting the target's inherent trust in familiar voices or faces, attackers manipulate victims into performing unauthorized actions, such as credential disclosure or fraudulent financial transfers.

Deepfake-assisted phishing is an advanced social engineering attack vector characterized by the integration of generative AI-based synthetic media—specifically voice cloning and facial reenactment—into traditional phishing workflows. Adversaries utilize publicly available biometric data to train models that generate convincing, real-time or pre-recorded impersonations. These attacks exploit human cognitive biases regarding identity verification to facilitate unauthorized access, financial fraud, or credential harvesting. The technique often functions as a multi-stage operation involving the acquisition of generative capabilities, the synthesis of high-fidelity artifacts, and the orchestration of cross-channel social engineering campaigns to maximize psychological manipulation and operational success.


← all terms