[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86456-en":3,"doc-seo-86456-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86456,8796095462418,"Noah","https://ap-avatar.wpscdn.com/avatar/80000253c1241d02b47?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778826106357471780",8,"Research & Report","Evaluating AI Models’ Capability to Automate Voice Phishing Attacks","Voice phishing (vishing) has historically depended on human call operators, constraining scalability. High-quality AI voice synthesis and large language models (LLMs) reduce this bottleneck, enabling automated, large-scale scams. A large survey experiment (N=4100) and qualitative interviews (N=12) evaluate U.S. adults’ susceptibility to AI-powered vishing. Results show high compliance, with 16.5% overall across five categories and caller persuasiveness as the strongest predictor.","Evaluating AI Models’ Capability to Automate Voice Phishing Attacks  \nFred Heidinga , Claudio Mayrink Verdunb , Simon Lermenc , Andrew Kaoa , Vitor Albierod , Lauren  \nDeasond , Irina-Elena Veliched , Christine Lehaned  \na Harvard Kennedy School, 79 John F. Kennedy St, Cambridge, MA, 02138, USb Harvard School of Engineering and Applied Sciences, 150 Western Ave, Allston, MA, 02134, US  \ncIndependent Researcher  \nd Meta Platforms, Inc. , 1 Hacker Wy, Menlo Park, CA 94025, US  \nAbstract  \nVoice phishing (vishing) attacks have traditionally been limited by the need for human operators. The rapid emergence of high-quality AI voice synthesis and large language models (LLMs) reduces this bottleneck and enables scalable, automated scams. In this paper, we conduct a large-scale survey experiment (N=4100) and qualitative interviews (N=12) to assess U.S. adults’ susceptibility to AI-powered voice phishing attacks. Participants were exposed to audio recordings or transcripts of scam scenarios generated using leading voice models such as Llama Full Duplex (Llama FD), Sesame, Gemini, OAI AVM, Play.AI, and ElevenLabs and the corresponding human baselines. The results show high compliance rates. Up to 36% of participants would or might comply with phishing requests in the “relative-in-distress” category. Overall compliance rate across all five scam categories was 16.5%, a striking figure given the low cost and high scalability of AI-automated voice phishing. Caller persuasiveness was the strongest predictor of compliance and certain models (most notably Sesame) achieved ratings comparable to human voices, or sometimes even slightly surpassing them. Our economic analysis suggests that while human-operated vishing is unprofitable at US wages, AI-powered vishing appears to be economically viable for several models. The primary risk of present-day AI-enabled vishing thus lies in the economics of automation rather than novel or “superhuman” persuasive techniques, though these cannot be ruled out for future systems. This raises significant concerns for the design of AI systems, consumer protection, and model release policies.  \nKeywords: vishing, AI voice synthesis, social engineering, voice phishing, large language models  \n1. Introduction  \nThe human voice carries a unique persuasive power that is difficult to replicate with text alone. When listening to speech, individuals automatically process vocal cues such as prosody, intensity, timing, and emotional coloration, which play a central role in rapid social inference and judgments of  \nauthenticity and trustworthiness (Belin et al., 2017; McAleer et al., 2014) . In contrast, text-based channels omit many of the nonverbal signals that support credibility assessment in spoken interaction (Kiesler et al., 1984) . Our qualitative interviews further support this asymmetry, as several participants reported that vocal cues in AI-generated calls made them more suspicious of voice-based  \narXiv :2607 .09970v 1 [ cs .CR] 10 Jul 2026  \nThis paper has been accepted for publication in Expert Systems with Applications. © 2026. This manuscript version is made available under the CC-BY-NC-ND 4.0 license [https://creativecommons](https://creativecommons.org/licenses/by-nc)[.](https://creativecommons.org/licenses/by-nc)[org/licenses/by-nc](https://creativecommons.org/licenses/by-nc)nd/4 .0/  \nscams, whereas the same conversational content presented as text appeared less overtly artificial and therefore less suspicious. This asymmetry makes voice a particularly powerful medium for social engineering. Scammers have long exploited  \nthis vulnerability through voice phishing, or vishing, a form of social engineering that leverages real-time conversations to extract sensitive information or make the recipient take other harmful actions. Unlike email phishing (Tabassum et al. , 2024), which can be automated and distributed to millions at negligible cost, vishing has historically required a human operator for each call","cbCaiaZXDlURl0nO","https://ap.wps.com/l/cbCaiaZXDlURl0nO","pdf",1002618,2,1,31,"English","en",105,"# Introduction\n# Method\n# Results\n# Economic Analysis\n# Implications for AI Design and Policy","[{\"question\":\"What problem does the paper address about voice phishing?\",\"answer\":\"The paper examines how AI voice synthesis and LLMs can remove the human-operator bottleneck that traditionally limited the scale of voice phishing attacks.\"},{\"question\":\"How was susceptibility to AI-powered vishing measured?\",\"answer\":\"The study used a large-scale survey experiment (N=4100) exposing participants to audio recordings or transcripts of AI-generated scam scenarios, plus qualitative interviews (N=12).\"},{\"question\":\"What factors most strongly predict whether people comply with vishing requests?\",\"answer\":\"Caller persuasiveness is identified as the strongest predictor of compliance, and some AI models—especially Sesame—achieved ratings comparable to human voices, occasionally slightly exceeding them.\"}]",1784211846,78,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"evaluating-ai-models-capability-to-automate-voice-phishing-attacks","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/evaluating-ai-models-capability-to-automate-voice-phishing-attacks/86456/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address about voice phishing?","Question",{"text":75,"@type":76},"The paper examines how AI voice synthesis and LLMs can remove the human-operator bottleneck that traditionally limited the scale of voice phishing attacks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How was susceptibility to AI-powered vishing measured?",{"text":80,"@type":76},"The study used a large-scale survey experiment (N=4100) exposing participants to audio recordings or transcripts of AI-generated scam scenarios, plus qualitative interviews (N=12).",{"name":82,"@type":73,"acceptedAnswer":83},"What factors most strongly predict whether people comply with vishing requests?",{"text":84,"@type":76},"Caller persuasiveness is identified as the strongest predictor of compliance, and some AI models—especially Sesame—achieved ratings comparable to human voices, occasionally slightly exceeding them.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]