Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3% Detection, and Profitable Economics for Attackers
Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) (TL-2026-1431), also tracked as AI Vishing Persuasiveness Study, is a medium-severity tracked intrusion set, first published 2026-07-17. It has no confirmed attribution, affects Meta Llama Full-Duplex (voice mode), maps to 15 MITRE ATT&CK techniques (T1036, T1123, T1199), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-1431
- Threat ID
- TL-2026-1431
- Also known as
- AI Vishing Persuasiveness Study, Harvard-Meta Voice Phishing Study
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-17
- Last reviewed
- 2026-07-17
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, telecoms, consumer general public, government administration, elderly vulnerable populations
- Target regions
- North America, united states of america
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing)
Malware and tooling: ElevenLabs voice cloning, Google Gemini (Ursa voice, mobile app), Llama Full-Duplex, OpenAI Advanced Voice Mode (Sol voice, GPT-4o), Play.AI (Celeste voice), Sesame (Maya voice)
A peer-reviewed study by Harvard Kennedy School, Harvard SEAS, and Meta researchers (arXiv:2607.09970, accepted to Expert Systems with Applications) surveyed 4,100 US adults against recordings from six commercial AI voice systems (Llama Full-Duplex, OpenAI AVM, Gemini, Sesame, Play.AI, ElevenLabs) and human callers performing vishing scenarios. Participants correctly identified synthetic voices only 70.3% of the time, falsely flagged real humans as synthetic 54.2-67.4% of the time, and overall scam compliance averaged 16.5%, reaching 36.1% in an ElevenLabs-cloned 'sister in distress' scenario. Economic modeling shows several AI voice models (Gemini, Sesame, ElevenLabs) are already profitable for attackers per-call, unlike human-operated vishing.
How Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) works
Researchers Fred Heiding, Claudio Mayrink Verdun, Simon Lermen, Andrew Kao, Vitor Albiero, Lauren Deason, Irina-Elena Veliche, and Christine Lehane (affiliations: Harvard Kennedy School, Harvard School of Engineering and Applied Sciences, Meta Platforms Inc., and independent researchers) published 'Evaluating AI Models' Capability to Automate Voice Phishing Attacks' (arXiv:2607.09970), accepted for publication in Expert Systems with Applications and covered by Help Net Security on 2026-07-17.
The study combined a large-scale survey experiment (N=4,100 US adults) with qualitative interviews (N=12). Participants were exposed to audio recordings or transcripts of five vishing scenarios generated by six leading voice-AI systems — Llama Full-Duplex (Meta, experimental mode, April 2025), OpenAI Advanced Voice Mode ('Sol' voice, GPT-4o), Google Gemini ('Ursa' voice, mobile app), Sesame ('Maya' voice, open-source conversational model), Play.AI ('Celeste' voice), and ElevenLabs (voice cloning) — alongside human-caller control recordings, with model refusals, disclaimers, and generation beeps edited out to simulate a competent attacker.
The five scam scenarios were: (1) MasterCard credential phishing impersonating card support (~7-15% compliance), (2) Gmail credential phishing impersonating Google support (~6-13% compliance), (3) a charitable Donation solicitation from an unknown caller (20-32% compliance), (4) a 'Police-Grandma' bail/relative-in-trouble scenario from an unknown caller (24-25% compliance), and (5) a 'Sister-in-Distress' scenario using an ElevenLabs-cloned voice claiming a family emergency requiring immediate funds, which produced the highest compliance at 36.1% (combined 'yes'/'maybe' responses; 6.5% hard 'yes'). Overall compliance across all five scenarios and both AI and human callers averaged 16.5%.
Detection performance varied sharply by model: participants correctly flagged OpenAI AVM as synthetic 93.7% of the time, Llama FD 88.6%, Gemini 88.4%, Play.AI 85.6%, ElevenLabs clones 75.8%, but Sesame only 66.3% — the hardest system to distinguish from a human. Overall voice-AI detection accuracy across all six systems was 70.3%, while real human callers were incorrectly flagged as synthetic between 54.2% and 67.4% of the time, indicating participants applied a strong 'guess AI' bias rather than genuine discrimination ability. Neither self-reported AI familiarity nor voice-assistant usage improved detection (51.2% for frequent AI users vs. 54.4% for non-users, not statistically significant).
Regression analysis identified message persuasiveness as the dominant predictor of victim compliance (odds ratio 2.58, p<.001), followed by caller sentiment (OR=1.64) and a 9-item trustworthiness scale covering expertise, credibility, empathy, urgency, and confidence (OR=1.48, Cronbach's alpha=.927). A separate 6-item Partner Modelling Questionnaire human-likeness scale (alpha=.93) did not independently predict compliance once persuasiveness and trustworthiness were controlled for — meaning voice realism itself was not the primary driver of victim harm; script quality and emotional manipulation were. Participants who cited 'repetitive responses' (OR=1.38, p=.048), 'long-winded responses' (OR=3.80, p<.001), or 'unnatural phrasing' in text transcripts (OR=3.39, p<.001) were more likely to correctly detect AI, but these cues went unnoticed by the majority of participants despite being present in the recordings.
The paper's economic model computed expected hourly attacker profit per voice system using a revenue formula r_j(t,X_i) = m(X_i) x p_j(t,X_i) x q, where m(X_i) is average extractable value per victim (~$450), p_j is per-call success probability, and q is a 0.6% call-to-contact conversion rate calibrated from marketing-industry data. Human operators paid US minimum-adjacent wages ($34.55/hr) were unprofitable at -$27.10/hr expected profit despite a 23% success rate, because human labor cost dominates. Among AI systems, Gemini (12% success rate, $0.13/hr compute cost) yielded +$2.38/hr expected profit, Sesame (15.2% success, $0.33/hr cost) yielded +$1.03/hr, and ElevenLabs (36.9% success rate — driven by the cloned-voice sister scenario — $0.75/hr cost) yielded the highest expected profit at +$2.97/hr; Llama FD, OpenAI AVM, and Play.AI remained unprofitable at current success/cost ratios. The authors estimate a one-time attacker development cost of $16,120 (260 engineering hours at $62/hr), with break-even periods of continuous operation ranging from 226 days (ElevenLabs) to 655 days (Sesame) to recoup that investment — figures the authors expect to shrink further as model costs decline and success rates improve.
The authors conclude that 'the primary risk of present-day AI-enabled vishing thus lies in the economics of automation rather than novel or superhuman persuasive techniques,' and that 'even a 5% success rate across millions of automated calls represents a transformative shift in the economics of fraud.' They recommend consumer education pivot from 'detect the synthetic voice' toward recognizing manipulative conversational strategies and resisting urgency/emotional-pressure tactics, plus out-of-band verification through independently-established channels, developer-side abuse-prevention and provenance tracking for voice-AI platforms, risk-based Know-Your-Customer controls for AI voice service signup, and regulatory frameworks that account for the 'automation dividend' of near-zero marginal-cost attacks.
This finding sits within a broader 2025-2026 vishing/imposter-scam surge documented by federal agencies: the FBI has issued repeated advisories on AI voice-cloning attacks impersonating senior US officials and family members in distress, and the FTC's June 2026 fraud report found Americans reported $3.5 billion in imposter-scam losses in 2025 (up roughly threefold since 2020), with imposter scams the top-reported fraud category for a fifth consecutive year and social media the fastest-growing initial contact vector ($2.1B in 2025 losses, an eightfold increase since 2020). A separate, since-withdrawn arXiv preprint (2602.20061, submitted Feb 2026, withdrawn Mar 2026 pending revision) reported even lower human discrimination ability (37.5% accuracy, below chance) on a smaller 22-participant, 16-clip sample, consistent directionally with the Harvard/Meta findings though not independently verified due to withdrawal.
MITRE ATT&CK techniques used in TL-2026-1431
Defense Evasion
Collection
T1123 Audio Capture; T1213 Data from Information Repositories
Initial Access
T1199 Trusted Relationship; T1566.004 Spearphishing Voice
Execution
Credential Access
T1539 Steal Web Session Cookie; T1621 Multi-Factor Authentication Request Generation
Resource Development
T1583.006 Web Services; T1585 Establish Accounts; T1587.001 Malware
Reconnaissance
T1589 Gather Victim Identity Information; T1593.001 Social Media
Impact
stealth
Affected products and versions in Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing)
- Meta — Llama Full-Duplex (voice mode)
Vulnerable versions: experimental, April 2025 build - OpenAI — Advanced Voice Mode (GPT-4o, 'Sol' voice)
Vulnerable versions: GPT-4o Advanced Voice Mode - Google — Gemini ('Ursa' voice, mobile app)
Vulnerable versions: Gemini mobile app voice mode - Sesame — Sesame conversational voice AI ('Maya' voice)
Vulnerable versions: open-source conversational model - Play.AI — Play.AI voice platform ('Celeste' voice)
Vulnerable versions: current platform - ElevenLabs — ElevenLabs voice cloning platform
Vulnerable versions: current platform
Remediation for Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing)
Immediate actions
- Establish and communicate a family/team 'safe word' or code phrase for verifying identity in distress calls that an AI voice clone cannot know
- Mandate out-of-band verification for any inbound call requesting funds transfer, credential reset, or urgent account action — hang up and call back a previously known/verified number
- Train staff and family members to focus on resisting urgency and emotional-pressure tactics rather than trying to 'detect' a synthetic voice
- Prohibit single inbound phone calls from triggering password resets, MFA bypass, or financial transactions without a secondary independent approval channel
Workarounds
- Financial institutions and support desks should require multi-factor, multi-channel identity verification (not voice alone) before processing account changes or fund transfers requested by phone
- Encourage reporting of suspected AI vishing attempts to ReportFraud.ftc.gov and the FBI IC3 (ic3.gov) to improve situational awareness and victim recovery support
Longer-term hardening
- Deploy risk-based Know Your Customer (KYC) verification for users of voice-cloning/voice-synthesis platforms to raise the cost of abuse
- Implement deployment-level monitoring, abuse detection, and content provenance/watermarking on voice-AI platforms (Llama, OpenAI AVM, Gemini, Sesame, Play.AI, ElevenLabs and peers)
- Build consumer and employee security-awareness programs around persuasion-tactic recognition (urgency, authority, empathy exploitation) rather than voice-authenticity detection, since detection accuracy plateaus near 70% and does not improve with AI familiarity
- Advocate for and track emerging regulatory frameworks addressing the 'automation dividend' of near-zero-marginal-cost AI-enabled fraud
Timeline of Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing)
- FBI publishes advisory 'Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign,' warning of AI voice/text impersonation targeting government officials and their contacts — precursor evidence of the same automation-driven impersonation trend the study later quantifies.
- Meta's Llama Full-Duplex experimental voice mode, one of six systems later benchmarked in the study, becomes available for testing.
- A separate, smaller-scale arXiv preprint (2602.20061, 22 participants, 16 clips) on human perception of synthetic vishing voices is submitted to arXiv.
- arXiv preprint 2602.20061 is withdrawn by its authors pending revision, leaving its below-chance (37.5%) human-detection finding unverified though directionally consistent with the later Harvard/Meta results.
- FTC publishes 'New trends in reports of imposter scams' consumer alert documenting a surge in AI-enabled impersonation fraud.
- Local/national press (Click2Houston) reports on FBI warning about AI voice-cloning scams mimicking loved ones in distress.
- FTC releases 2025 fraud data showing $3.5 billion in reported imposter-scam losses, the fifth consecutive year imposter scams top the fraud-report category, with social media the fastest-growing initial contact vector.
- Heiding et al., 'Evaluating AI Models' Capability to Automate Voice Phishing Attacks,' submitted/posted to arXiv as 2607.09970, accepted for publication in Expert Systems with Applications.
- Help Net Security publishes coverage of the Harvard Kennedy School/Meta study, summarizing the 4,100-participant survey results, 70.3% detection rate, 66% false-positive rate, and 16.5%/36.1% compliance figures.
Sources cited for Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing)
- Research: AI voice phishing
- Evaluating AI Models' Capability to Automate Voice Phishing Attacks (arXiv:2607.09970)
- Evaluating AI Models' Capability to Automate Voice Phishing Attacks (HTML full text)
- Can You Tell It's AI? Human Perception of Synthetic Voices in Vishing Scenarios (withdrawn preprint, arXiv:2602.20061)
- FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025
- New trends in reports of imposter scams
- FBI warns of AI voice-cloning scam that mimics loved ones in distress
- Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign
- FTC warns of record $3.5 billion losses to imposter scams in 2025
Threats related to Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing)
Detection coverage for TL-2026-1431
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1431 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.