Voice phishing is emerging as a major initial-access tactic as attackers impersonate employees, help-desk staff, and senior officials to steal credentials, capture one-time passcodes, and transfer MFA enrollment. U.S. government warnings and industry reporting describe malicious messaging and vishing campaigns that use phone calls, SMS, and collaboration platforms such as Microsoft Teams to manipulate targets into granting access to single sign-on and cloud environments. Group-IB and CIS both report that advances in synthetic speech, real-time voice transformation, and voice cloning are lowering the cost and skill barrier for these scams, while incident data cited by defenders shows vishing accounting for a growing share of intrusions.
The technique has been linked to serious downstream compromises, including an alleged ShinyHunters breach at Harvard University in which attackers reportedly used voice phishing to bypass MFA and access Microsoft 365, SharePoint, and Salesforce, exposing roughly 115,000 records tied to alumni and development operations. Security guidance across the referenced reporting urges organizations to harden identity workflows rather than rely on user recognition of suspicious calls, with emphasis on phishing-resistant MFA such as FIDO2, stricter help-desk identity verification, protection of passkey enrollment, and monitoring for anomalous authentication and account-recovery activity.

Get the infrastructure and lures behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Group-IB reported that threat actors were operationalizing AI voice capabilities through synthetic speech from scripts and real-time voice transformation, while noting voice cloning was becoming more accessible.
A breach at Harvard University allegedly occurred on February 4, 2026 and was attributed in the source to ShinyHunters. The incident reportedly exposed about 115,000 records from the Alumni Affairs and Development department.
On May 15, 2025, the FBI's IC3 published a public service announcement warning that malicious actors were impersonating senior U.S. officials in messaging campaigns to compromise accounts and enable further malicious activity.
The FBI said threat actors had impersonated senior U.S. officials using AI-generated voice messages and fraudulent texts since at least April 2025, targeting current and former federal and state officials.
Mandiant's M-Trends 2026 report documented that vishing accounted for 11% of initial access cases in 2025, making it the second most common vector, while email phishing fell to 6% from 14% the prior year.
CrowdStrike reported a 442% increase in vishing between the first and second halves of 2024, indicating rapid growth in voice-based social engineering.
CrowdStrike researchers reported that device code phishing and voice phishing attacks had more than doubled, with attackers increasingly combining phone calls and mobile authentication workflows. The tactic tricks users into approving fraudulent device authentication requests, enabling access to corporate networks through social engineering.
The CIS CTI team said it observed incidents in the first eight months of 2026 in which attackers posing as help desk personnel targeted U.S. state, local, tribal, and territorial organizations to gain unauthorized access to SSO environments.
In April 2026, ShinyHunters reportedly targeted an employee at a widely used physical security firm with a vishing call, accessed the firm's enterprise account, pivoted into Salesforce, and exfiltrated about 5.5 million customer records.
In April 2026, ShinyHunters reportedly used a vishing call to compromise a major telecom company employee's Microsoft Entra account, then pivoted into Salesforce and exfiltrated customer records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcezimperium.com
Open sourcegroup-ib.com
Open sourcehudsonrock.com
Open sourcecisecurity.org
Open sourceic3.gov
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.