Procedural guide for conducting organizational resilience testing against AI-assisted voice phishing. This document covers attacker playbooks for constructing realistic scenarios, defender playbooks for response procedures, and healthcare-specific controls.
Scope note: This is written scenario material for organizational exercises. It contains no voice synthesis capabilities, no telephony integration, and no live audio generation. All attack simulation in tabletop exercises uses human actors reading from scripts — not AI-generated voice.
Test whether an organization's people, processes, and controls would detect and block a vishing attack before it causes harm. The goal is to identify specific gaps in:
- Identity verification procedures
- Escalation and approval workflows
- Helpdesk training and script adherence
- Financial authorization controls
This is not a penetration test — it is a decision-tree exercise to map how your organization would respond to a realistic scenario.
Before the attack call, the threat actor builds a target persona using open sources. This phase takes 30–120 minutes for a motivated attacker.
LinkedIn: The primary source. Provides:
- Employee name, title, tenure, manager name, team members
- Profile photo (for deepfake video, if needed)
- Work history and professional background (for social engineering context)
- Connections that can be cross-referenced for organizational structure
Company website: Org chart, leadership bios, press releases, investor relations content. Executive voices are often available in earnings call recordings, conference presentations, and media interviews.
Social media: Twitter/X, Facebook (less common for professionals), Instagram. Personal details that make the caller sound authentic: "I just got back from the cardiology conference in Chicago" requires knowing the executive attended that event.
SEC filings / press releases: For financial targeting, know the fiscal quarter, current vendor relationships, ongoing capital projects, and recent acquisitions.
Audio source collection: For voice cloning, collect 3+ seconds of the target's voice from earnings calls, YouTube, podcast appearances, company videos, or social media. Higher-quality and longer duration improves clone fidelity.
Reconnaissance output: A persona brief with:
- Target's full name, title, direct reports, manager
- Plausible reason for the call (current business context)
- Details the attacker can "know" to establish authenticity
- Available voice samples (for AI clone, if used)
Select a pretext appropriate to the target and goal:
IT helpdesk pretexts:
- "I'm locked out of my account and I have a critical patient case" — urgency + healthcare framing
- "I'm traveling and my authenticator app got wiped when my phone fell" — plausible, creates sympathy
- "IT is pushing a new device policy and asked me to re-enroll my MFA today" — pretends to be a proactive enrollment
Financial pretexts:
- "We're closing a vendor contract today and I need to wire the first payment before 3pm" — time pressure
- "Finance sent me a change of banking details form to sign — can you process the updated account?" — procedural framing
- "The CEO has asked me to handle this payment personally and keep it confidential" — executive override
HR / Payroll pretexts:
- "I changed banks last week and need to update my direct deposit before Friday" — routine + personal
- "My department is onboarding a contractor and we need a temporary system account" — account creation
Success criteria definition:
- What does the attacker need from this call to succeed? (TAP, password reset, wire initiated, account created)
- What is the fallback if the first pretext is rejected?
Standard structure:
-
Establish rapport (30 seconds): Use personal details gathered from reconnaissance. "Hi, this is [Name] from the cardiology department — I think we spoke briefly at the all-hands last month?"
-
State the problem (30 seconds): Describe the situation that requires help. Keep it plausible and specific.
-
Create urgency (if needed): Escalate time pressure if the first approach doesn't produce compliance. "I have a patient in pre-op and I need this in the next five minutes."
-
Overcome objections: Prepare responses to common resistance:
- "I need to verify your identity first" → Provide the pre-gathered personal details
- "I need to get my supervisor to approve this" → "Dr. [Name] already approved it, can you check with them?"
- "I'll need to call you back on a verified number" → See Phase 4
-
Close: Obtain the objective (MFA reset confirmation, TAP code, wire transfer confirmation number).
A trained helpdesk will attempt to call back on a verified number. Attacker responses:
- "Call me on my cell — I'm not at my desk": tries to route the callback to an attacker-controlled number
- Caller ID spoofing: some attackers spoof the caller ID to show the target executive's known number (making the callback to the "verified" number go to the attacker)
- Email pre-seeding: send a spoofed email from the target's lookalike domain before the call: "I'll be calling your helpdesk shortly about an urgent issue — please help them right away." The email makes the caller seem more legitimate.
Every inbound call requesting account changes, access resets, or financial transactions must go through a verification step before any action is taken.
Standard verification procedure:
- Ask the caller to state their employee ID (not their name — they already gave their name).
- Look up the employee ID in the directory independently (do not rely on information the caller provides).
- Ask one "knowledge question" that is not available from public sources:
- "What is your department cost center code?"
- "What was the subject of the last ticket we worked for you?" (requires prior ticket history)
- NOT: "What is your date of birth?" (available from HR records and social media)
- Confirm the callback: "I'm going to call you back on the number we have on file for you before I make any changes."
Critical rule: The verification step cannot be skipped for any reason, regardless of urgency claimed by the caller.
Never action a request based solely on an inbound call.
- Tell the caller: "I need to call you back on the number we have on file."
- Look up the employee's phone number in the official directory (Active Directory, HR system) — do not use any number provided by the caller.
- Call that number. Confirm identity again.
- Only then take the requested action.
Healthcare-specific: If the caller claims they cannot wait for a callback due to patient emergency, escalate to the helpdesk supervisor. The supervisor decides whether to invoke the emergency exception procedure. Individual helpdesk staff should not have unilateral authority to skip verification.
Wire transfers and payment account changes require dual confirmation through a second channel:
- Phone request received.
- Email confirmation required from the requesting executive's corporate email address (not their personal email, not a lookalike domain).
- Second approval from a different officer (e.g., CFO request requires Controller approval, Controller request requires CFO approval).
- No exceptions for urgency claims.
This control alone would have prevented the Arup $25.6M wire fraud — the finance team had no dual-authorization requirement.
Build a list of questions that only a real employee could answer, distinct from public-record information:
Good questions (not publicly available):
- "What project were you working on last week that required IT support?"
- "What is your manager's employee ID?"
- "What's the internal code name for your current quarter initiative?"
- "What was the last application you submitted a ticket for?"
Bad questions (available from public sources or social engineering):
- Name, department, job title (all on LinkedIn)
- Date of birth (available in HR records, sometimes social media)
- Manager's name (LinkedIn)
- Office location (company website)
Define a clear path for staff who feel something is wrong:
- "I need to put you on hold while I consult with my supervisor."
- Supervisor reviews the request independently.
- If still uncertain: decline the request and log the call details.
- Report suspicious calls to the security team within 1 hour.
Make it explicitly safe for helpdesk staff to refuse requests. In hierarchical organizations (especially healthcare), staff may feel social pressure to comply with apparent senior-executive requests. Training must address this directly: "You will never be disciplined for following the verification procedure, even if the call turns out to be legitimate."
Some staff believe that asking for identifying information over the phone could violate HIPAA. This is a misunderstanding — HIPAA governs patient health information, not employee identity verification. Explicitly address this in training: identity verification of an employee calling the helpdesk is not a HIPAA issue.
Implement policy-level dual authorization for:
- Wire transfers over $X (set threshold appropriate to organization size)
- Vendor banking detail changes
- New vendor onboarding (first payment)
- Payroll account changes
The authorization must come through official corporate channels (ticketing system, authenticated email), not over the phone.
New vendor relationships, especially for medical device or pharmaceutical contracts, should include a call-back protocol:
- Receive new vendor contact information.
- Look up the vendor's main corporate phone number independently (not from the information provided).
- Call the vendor's main number and ask to be connected to the account representative.
- Confirm banking details through the vendor's verified main phone line, not from an inbound call.
Conduct a tabletop exercise using the scripts in
tools/phishing/vishing/tabletop-exercise-scripts/ before any training
interventions. Record:
- What percentage of participants correctly invoked the verification procedure?
- What percentage initiated a callback (rather than acting on the inbound call)?
- What percentage escalated to a supervisor?
- What percentage completed the attacker's objective (reset MFA, initiated wire)?
Repeat the tabletop 30 and 90 days after training. Target metrics:
- Verification procedure invoked: >95%
- Callback completed before action: >90%
- Attacker objective achieved: <5%
- Suspicious call reported to security team: >80%
Simulated vishing calls (using human actors, not AI, under explicit scope authorization) conducted quarterly. Results reported to security leadership. Individuals who comply with the attack are retrained, not disciplined (punitive approaches reduce reporting).
- IT helpdesk staff (primary target)
- Finance / accounts payable (for wire fraud scenarios)
- HR / payroll
- Security team (as observers and debriefers)
- Briefing (15 min): Explain that participants will hear a scenario read aloud. They should respond as they would on a real call. No forewarning of specific content.
- Scenario playthrough (15–20 min per scenario): Facilitator reads the attacker script. Participant responds. Facilitator follows the decision tree.
- Immediate debrief (10 min per scenario): Walk through the decision points. Where did the participant deviate from procedure? What would have happened?
- Group discussion (20 min): What process changes would have made the correct behavior easier? What is unclear in the current procedure?
See scenario scripts:
tools/phishing/vishing/tabletop-exercise-scripts/healthcare_cfo_impersonation.mdtools/phishing/vishing/tabletop-exercise-scripts/it_help_desk_scattered_spider.md
- Right-Hand Cybersecurity — "The Rise of Deepfake Vishing" (Q1 2025 report).
- SQ Magazine — AI voice-cloning fraud market analysis.
- FBI IC3 — Business Email Compromise / vishing impersonation advisories.
- Microsoft Threat Intelligence — Scattered Spider / ShinyHunters help-desk vishing reporting.
- Arup — public statements on the $25.6M deepfake CFO wire transfer incident.
- FS-ISAC — sector guidance on voice impersonation fraud controls.
- NIST — IR (Identity and Recovery) guidance for call-center verification.
Related in-repo:
tools/phishing/vishing/— tabletop scenarios (no live-call simulation).docs/analysis/vishing-2026-market.md— scale and economics of deepfake vishing.docs/methodology/phish-resistance-testing.md— complementary phish-resistance bench.