The Federal Bureau of Investigation says the smishing and voice-scam messages fooling the most people right now are not generic prize notifications or delivery alerts, but texts and calls that claim to come from senior U.S. officials. The agency’s Internet Crime Complaint Center has now issued more than one public warning about the campaign, describing messages convincing enough that recipients have handed over access to personal accounts believing they were responding to a real government contact.
How the Impersonation Campaign Works
According to the FBI’s Internet Crime Complaint Center, malicious actors have been sending text messages, known as smishing, and AI-generated voice messages, known as vishing, that pose as communications from senior U.S. officials, including White House and Cabinet-level figures and members of Congress. The messages typically try to establish rapport first, presenting themselves as a familiar or important contact, before steering the recipient toward a separate platform or a link designed to harvest login credentials or take over an account entirely.
IC3 has said the targets have largely been current or former federal and state officials and, notably, the people already saved in those officials’ address books, meaning the scam spreads through networks of family members, colleagues and acquaintances rather than through random mass texting. That targeting pattern is part of why the messages land as more convincing than an ordinary scam text: they often arrive from a contact the recipient has genuine reason to expect a message from.
AI Voice Cloning Raises the Stakes
What sets this campaign apart from older impersonation scams is the pairing of text messages with AI-generated voice messages designed to sound like a specific real person. Recipients who received a text and then a follow-up voice message reinforcing the same false identity described the combination as considerably harder to dismiss than a text alone, since a familiar-sounding voice can override the skepticism a suspicious link might otherwise trigger.
The FBI has not detailed exactly which voice-cloning tools the campaign relies on, but the bureau’s warning fits a broader pattern security researchers have flagged: as consumer-grade voice-generation tools have become more accessible, the cost of producing a convincing fake voice message has dropped sharply, making this kind of layered text-plus-voice deception increasingly available to less sophisticated scammers, not just well-resourced operations.
The Campaign Has Continued, Not Faded
The bureau’s initial public service announcement flagged the scheme as active since roughly April of the year it was issued, but IC3 later published a follow-up advisory reiterating that senior U.S. officials continued to be impersonated in the same style of campaign, indicating the tactic did not disappear once it drew public attention. That persistence is consistent with how phishing and smishing campaigns generally behave: once a script proves effective at converting targets, it tends to get reused and adapted rather than retired.
Security researchers tracking the campaign have noted that its cross-channel approach, blending smishing, vishing and platform redirection, makes it more resilient to takedowns than a single-channel scam, since blocking one delivery method, such as a specific phone number sending texts, does little to stop the voice-message side of the operation. That resilience is also why the bureau has treated the pattern as a recurring template rather than a single incident, reissuing guidance as new variations of the same core deception surface across different regions and target lists.
Multi-Factor Authentication as the Practical Backstop
IC3’s guidance centers on a small number of concrete steps rather than broad caution. The bureau advises verifying any unsolicited message claiming to come from an official by independently calling a known, previously verified phone number rather than one supplied in the suspicious message itself, and inspecting sender information and links closely for subtle alterations, such as a phone number or domain that looks almost, but not quite, correct.
The other central recommendation is enabling multi-factor authentication on personal and work accounts, since the campaign’s ultimate goal in most cases is account takeover rather than a one-time financial transaction. Even when a scam message succeeds in extracting a password, a second authentication step tied to a separate device can still block the takeover, which is why IC3 treats broad multi-factor adoption as one of the more effective defenses against this specific style of attack.
Why Officials’ Networks Make an Attractive Target
Beyond the immediate financial or account-access motive common to most scams, impersonating a senior official carries a secondary benefit for attackers: access to the kind of contact network, from congressional staff to federal agency personnel, that could be leveraged for further social-engineering attempts or intelligence-gathering down the line. That dual incentive is one reason the bureau has continued to treat the campaign as a standing security concern rather than a single incident to be resolved and closed, and why the underlying advice, verify independently and use multi-factor authentication, applies just as directly to anyone who receives a message claiming to be from a public figure, official or otherwise.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Automakers are quietly dropping the stop-start feature many drivers love to hate
- A granite sarcophagus surfaced in Egypt with its original lid still sealed
- The FBI tells phone owners to delete these toll-payment texts draining accounts nationwide
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn