MITRE ATLAS 2026.09 / technique reference
AML.T0052.001
Deepfake-Assisted Phishing
MITRE source definition
Adversaries may use deepfakes (AI-generated synthetic images, audio, or video) in phishing campaigns to impersonate trusted individuals, executives, or organizations. These attacks exploit human trust by presenting fraudulent voice or video communications as legitimate, enabling adversaries to manipulate targets into disclosing credentials, transferring funds, or granting access to systems.
Voice deepfakes (AI-cloned voices) are used in vishing [[vishing]] (voice phishing) attacks over telephone or VoIP. Adversaries can clone a target's voice using a few seconds [[valle]] of publicly available audio from speeches, earnings calls, podcasts, or social media [[voice]]. These cloned voices are then used in pre-recorded voicemail messages or live phone calls. Video deepfakes can impersonate a trusted individual's face and voice. Adversaries use publicly available video from company meetings, earnings calls, or social media to create convincing AI-generated video of target individuals. They are used in live video conference calls or recorded video messages. AI-generated content has advanced to the point that it is often difficult to identify as synthetic [[fbi]].
Adversaries may first perform [Obtain Capabilities](/techniques/AML.T0016): [Generative AI](/techniques/AML.T0016.002) followed by [Generate Deepfakes](/techniques/AML.T0088) in preparation for their [Phishing](/techniques/AML.T0052) campaign. Deepfake phishing campaigns often utilize other communication channels (such as email, SMS, or instant messaging) for layered social engineering attacks [[aiid839]].
These attacks span a wide range of victims and attack types, demonstrating the breadth of deepfake-enabled fraud. Adversaries have conducted extensive deepfake-assisted phishing campaigns against the individuals, including targeted scams [[aiid564]] [[oecd1]] [[aiid1280]] [[aiid1285]], as well as large-scale credential harvesting campaigns targeting billions of users [[aiid839]] [[aiid941]]. Adversaries have used deepfakes to impersonate executives [[aiid1100]], causing business entities to suffer significant financial losses from [[aiid634]] [[aiid147]]. There are also reports of government officials being targeted in widespread campaigns [[fbi]] [[aiid927]].
The attacks span communication channels including voice deepfakes for vishing [[aiid567]] and video deepfakes in conference calls [[aiid634]], as well as multi-channel campaigns combining phone, email, and messaging platforms [[aiid839]].
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
Source-backed defensive context
MITRE mitigations
MITRE case studies
No explicit relationship in this pinned source.
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
- AI Incident Database - LastPass CEO Voice Deepfake Attempt
- Reported Use of AI Voice and Identity Manipulation in the 'Phantom Hacker' Fraud Scheme
- Purportedly AI-Generated Jason Momoa Deepfake Used in Romance Scam
- Reported AI-Cloned Voice Used to Deceive Hong Kong Bank Manager in Purported $35 Million Fraud Scheme
- Voice deepfake targets bank in failed transfer scam
- Deepfake Voice Exploit Compromises Retool's Cloud Services
- Alleged Deepfake CFO Scam Reportedly Costs Multinational Engineering Firm Arup $25 Million
- Purportedly AI-Driven Phishing Scam Uses Spoofed Google Call to Attempt Gmail Breach
- Italian Defense Minister Voice Clone
- AI-Driven Phishing Scam Uses Deepfake Robocalls to Target Gmail Users
- FBI Public Service Advisory: Scammers are deepfaking voices of senior US government officials
- AI-Generated Voice Used in Scam Targeting Drica Moraes' Contacts
- VALL-E Family: Neural codec language models for speech synthesis
- Vishing - Social-Engineer Framework
- AI-powered voice spoofing: Understanding and defending against vishing attacks