AI Voice Message Impersonation: How to Verify a Familiar Contact
Treat the message as an unverified request
A familiar voice can make an unexpected message feel safe. The FBI warned in May 2025 that malicious actors had been sending text messages and AI-generated voice messages while impersonating senior US officials. The campaign described in the notice had operated since April 2025 and targeted officials, former officials, and their contacts. The warning documents this particular campaign. It does not classify every suspicious voice message.
The notice says the actors tried to build rapport before seeking access to personal accounts. One route was a malicious link presented as a way to move the conversation to another messaging platform. Stolen contact information could then help the actors impersonate trusted contacts and seek information or money.
That sequence warrants verification before any action. Pause when an unexpected contact asks you to change channels, open a link, disclose information, or act on money. Keep the message, sender details, time, and requested action. Do not let recognition of the voice complete the identity check.
Verify through a path the message did not provide
Start a separate conversation. Use a phone number, official directory, company switchboard, or existing chat thread that you already trusted before the message arrived. Do not call a number or follow a link supplied in the suspicious message. Ask the person to confirm the specific request and the channel change. This guide proposes the method; the FBI notice does not prescribe it.
Separate identity from authority. Confirming that a colleague sent a message does not automatically approve a payment, password reset, document release, or account change. Run the request through the approval process that would apply without the voice message. If the claimed sender is a public official or an organization, use a published contact route rather than contact details inside the message.
A reply from the same account is weak confirmation when account access is the issue. The FBI notice explains that access to personal or official accounts can expose trusted contact information and support further impersonation. A second channel should therefore be independent of the account that initiated the request.
Check the link and platform change as a separate risk
The FBI describes smishing as malicious targeting through SMS or MMS and vishing as malicious targeting through voice memos, which may use AI-generated voices. It also says these methods can move a target to a second platform where malware or links to an actor-controlled credential-stealing site may appear.
The destination platform and a familiar profile there are inconclusive on their own. Record the destination without opening it on the device or account you are protecting. If the request involves work, money, credentials, or sensitive records, send the link to the responsible security team using the organization's approved reporting path.
If you already entered credentials, stop interacting with the message and use the legitimate service address to secure the account. Preserve the original message and report the incident through the relevant security channel. The FBI asks victims of the campaign it described to contact appropriate security officials and report detailed information to a local FBI field office or IC3.
Use audio analysis within its limits
When you have a saved audio file, DeepFakeCheck can provide a probabilistic risk signal about possible synthetic or manipulated characteristics. It cannot establish who sent the message, whether the linked account was compromised, whether the request is authorized, or whether the speaker intended the words. Keep identity and authorization checks separate.
Automated analysis can produce false positives and false negatives. A false positive may flag authentic audio, while a false negative may miss generated or altered audio. A high-risk result supports further review; a low-risk result does not authenticate the speaker. The analysis may still leave questions unresolved, so label unknowns rather than filling them with assumptions.
Save the file you actually analyzed, the result, and the time of analysis. Do not substitute a recording made from another device without noting that it is a copy. The purpose of the record is to let another reviewer see which file produced which signal.
Decide from the request, identity, and evidence together
A defensible decision keeps three questions separate: who controls the contact channel, whether the request is authorized, and what the media analysis suggests. Confirm the first through an independent route, the second through the normal approval process, and the third with a clearly bounded result.
If any high-risk step remains unverified, do not send money, credentials, sensitive files, or account access. Escalate the preserved message and your verification notes. This workflow does not promise that every impersonation will be caught. It reduces reliance on a familiar-sounding voice as the only identity check.
Sources
- FBI Internet Crime Complaint Center, “Senior US Officials Impersonated in Malicious Messaging Campaign”: https://www.ic3.gov/PSA/2025/PSA250515
Suspect an image might be AI-generated?
Use our advanced deepfake detection tool to analyze images with high precision.
Analyze Image Now