« All posts

AI Voice Phishing Rivals Human Scammers—And Costs Far Less

A 4,100-person study finds AI voice phishing matches human scammers in persuasiveness, with 70% detection accuracy and profitable economics at scale.

A large-scale study (N=4,100) tested how susceptible US adults are to AI-generated voice phishing across six leading models—Llama Full Duplex, Sesame, Gemini, OpenAI's Advanced Voice Mode, Play.AI, and ElevenLabs—compared against human callers. Compliance rates reached as high as 36% for emotionally charged scenarios like a cloned "sister in distress," with an overall average of 16.5% across five scam types, despite the dramatically lower cost of automating attacks versus paying human operators.

Sesame and ElevenLabs's voice cloning achieved human-level naturalness ratings in neutral contexts, and participants could correctly identify AI-generated callers only 70.3% of the time—while frequently misidentifying real humans as AI. Crucially, familiarity with AI tools or voice assistants provided no detection advantage, and message persuasiveness, not vocal fidelity, was the strongest predictor of compliance regardless of perceived origin.

The findings indicate AI-powered vishing has crossed an economic threshold: while human-operated scam calls are unprofitable at US wage rates, several AI voice models make automated phishing campaigns financially viable at scale. For engineers building voice AI systems, this underscores the urgency of watermarking, provenance verification, and consent-based cloning safeguards, since current detection methods and user skepticism are insufficient countermeasures.