High-level U.S. government officials, including White House Chief of Staff Susie Wiles and Secretary of State Marco [PERSON_001], were targeted by sophisticated impersonation campaigns. Attackers used AI-generated voice and text messages to pose as these officials, aiming to gain access to sensitive information and accounts. The FBI has linked these incidents to broader malicious campaigns targeting government officials and their contacts, highlighting significant vulnerabilities in national security communications.
President Trump announced that White House Chief of Staff Susie Wiles had been impersonated via a phone breach involving AI-generated voice messages and spoofed texts. The attacker reportedly contacted high-profile individuals in her network while posing as Wiles. The incident is linked to a campaign identified by the FBI in April 2025, involving malicious actors using social engineering and AI to impersonate senior U.S. officials and gain access to sensitive information. See Incident 1077.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation
The attackers used AI voice cloning to impersonate trusted high-level officials in targeted social engineering attempts to gain unauthorized access or solicit funds.
Additional risk subdomains
- 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information: The attackers compromised the privacy of senior officials by accessing and exploiting their private contact lists to facilitate the targeted impersonation.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by malicious human actors intentionally deploying AI voice-cloning tools to execute targeted impersonation and social engineering campaigns.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The technology used involves AI-generated content such as deepfakes (voice cloning), which falls under Risk Level 3 due to transparency and disclosure obligations.
AI system and alleged parties
- AI system: None named
- AI purpose: Voice Generation; Text Style Replication
- Behaviour type: Tool
- Alleged developer: Unknown voice cloning technology developers, Unknown deepfake technology developers
- Alleged deployer: Unknown scammers
- Alleged harmed parties: Susie Wiles's network, Susie Wiles
Harm severity
Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Minor
- Privacy: direct Minor, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Minor, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Malicious content
Reported: Yes, synthetic voicemails and texts were created to deceive targets.
Directly caused: Attackers generated synthetic voicemails and text messages impersonating Marco [PERSON_001] and Susie Wiles to deceive their contacts.
Indirectly caused: N/A
Inferred additional harm: N/A
Democracy
Reported: Yes, the reports describe infiltration attempts at the highest levels of U.S. diplomacy and administration.
Directly caused: N/A
Indirectly caused: The impersonation of the Secretary of State and the White House Chief of Staff targeted foreign ministers, senators, and governors, threatening diplomatic communications and national security protocols.
Inferred additional harm: Continued sophisticated impersonation of high-ranking officials could severely undermine trust in government communications, disrupt diplomatic relations, and compromise sensitive state secrets.
Privacy
Reported: Yes, the breach of personal contacts.
Directly caused: The impersonator breached Susie Wiles's phone or contacts list, obtaining private contact information of high-profile individuals.
Indirectly caused: N/A
Inferred additional harm: The compromise of contact lists likely exposed the private phone numbers and communication channels of numerous other high-ranking government and business leaders to malicious actors.
Epistemic
Reported: Yes, the use of deepfake voices to fabricate communications.
Directly caused: The creation of highly convincing synthetic voices fabricated statements from Susie Wiles and Marco [PERSON_001], misleading their contacts into believing they were communicating with the actual officials.
Indirectly caused: N/A
Inferred additional harm: The proliferation of high-quality voice clones erodes the ability of officials to verify the authenticity of voice communications, leading to a broader loss of trust in digital interactions.
People affected
- Occurrences reported: 2
- People reportedly harmed: 15
- People reportedly exposed: 50
Potential causes
Management
- Dismissive Incident Response: Minimizing security breaches delayed the implementation of systemic fixes.
- Reduced Cybersecurity Funding: Staff cuts at CISA weakened national capabilities to detect deepfake threats.
Technology
- AI Voice Cloning Technology: Enabled highly convincing synthetic audio generation of senior officials.
- Exploitation of Auto-Synced Contacts: Allowed attackers to map and target trusted networks of high-profile users.
Data Inputs
- Compromised Contact Directories: Leaked private numbers provided the essential inputs for targeting campaigns.
Human Factors
- Overreliance on Voice Verification: Targets trusted the voice identity without performing out-of-band validation.
Process and Methods
- Inadequate Identity Verification: Lack of standard protocols to verify the source of urgent communications.
Regulatory Environment
- Insufficient IT Access Controls: Broad access permissions to federal databases increased the attack surface.
Information quality
- Classification confidence: High
- Reason for confidence: The reports provide clear, consistent details about the impersonation of Susie Wiles and Marco [PERSON_001] using AI voice cloning. The involvement of the FBI and official statements from government sources ground the facts well, leaving little ambiguity about the nature of the AI's role as a tool for impersonation.
- Ambiguities identified: The exact AI voice-cloning platforms or models used by the attackers are not specified.
- Alternative interpretations: None. The reports consistently describe these events as targeted cyber-espionage and social engineering campaigns leveraging synthetic media.
Russian SVR-affiliated cyber actors utilized sophisticated AI voice cloning to impersonate high-level U.S. officials, including the Secretary of State and White House Chief of Staff, in a targeted espionage campaign. By contacting foreign ministers and members of Congress, the operation directly threatened the integrity of sovereign diplomatic communications and national security protocols, representing a severe information warfare and government function compromise.
- Overall national security impact: Severe
- Response level: Severe
- Scope: Multiple nations
- Primary target: United States
- Other affected: Unnamed foreign nations
- Alleged perpetrator: Russian Foreign Intelligence Service (SVR) affiliated actors
Threat characteristics
- Imminence: Near-term. The FBI has issued warnings regarding an active, ongoing campaign that continues to target government officials, requiring continuous monitoring and defense adjustment.
- Autonomy: Human-controlled. The AI voice-cloning technology was directly controlled and deployed by human threat actors to generate specific messages for targeted social engineering.
- Novelty: Evolved capability. While voice cloning is an established threat, its highly sophisticated application targeting the highest levels of U.S. national security and foreign diplomacy represents a significant evolution in capability.
Impact by dimension
- Physical security: Negligible. No physical systems, critical infrastructure, or human safety were directly threatened or damaged in this incident.
- Information security: Severe. Russian SVR-affiliated actors used sophisticated AI voice cloning to impersonate the Secretary of State and Chief of Staff, targeting foreign ministers and lawmakers to compromise sensitive diplomatic and national security communications.
- Sovereignty: Severe. The impersonation of the Secretary of State in communications with foreign ministers and of the Chief of Staff with members of Congress directly threatens the integrity of sovereign diplomatic relations and core executive branch communications.
- Economic security: Minor. While business executives were targeted and funds were solicited, the primary impact was focused on political and diplomatic espionage rather than systemic economic or technological disruption.
- Societal stability: Minor. The campaign targeted specific high-profile political and business figures rather than the general public, resulting in limited direct impact on overall societal stability.