Sign in Book demo
coming up
Prepping for October Cybersecurity Awareness Month? We've got you covered. Get your kit today.

AI Social Engineering, Vishing, Deepfakes and the Evolution of the Secure Workforce

Would your help desk reset MFA for a cloned voice? Learn how Fable tests vishing, deepfake, and AI social engineering risk before attackers do.

I’m excited! It’s been about six months since I joined Fable and in that time alone the threat landscape seems to have shifted dramatically and we at Fable are right in the middle of helping customers respond.

Just at the end of last year, video and voice generation was becoming commonplace for attackers’ initial access vector. But in the last few months the volume of attacks have risen rapidly. We have been working closely to consult with organizations on the best way to prepare their workforce for this changing era from helping implement processes that have more control verification channels to simulations, emulations, and training.

Threat actors are no longer constrained by the time required to draft believable emails, conduct persuasive phone calls, or generate plausible video content.

Artificial intelligence grants adversaries unprecedented speed, scale, and sophistication when impersonating trusted personnel.

According to Microsoft, threat actors increasingly utilize AI to scale phishing campaigns and generate synthetic media. Furthermore, the FBI has warned against campaigns leveraging AI-generated voice messages to impersonate corporate leadership, while Google Mandiant has documented how voice spoofing and deepfakes significantly enhance the credibility of social engineering attacks.

Consequently, the methods of security programs must evolve. While employees must maintain vigilance regarding suspicious email communications, they must also be equipped to respond when an apparent executive joins a video conference, when a familiar voice requests an access reset from a help desk, or when an urgent request transitions across communication channels. The core capability required is not merely identifying visual or auditory anomalies, but rather exercising caution, transitioning to verified channels, and adhering strictly to authentication protocols regardless of media realism.

This is where human risk management platforms come into play. Security teams need a new set of capabilities that don’t focus on content libraries. Fable takes a different approach. For instance, we run live, authorized calls against the phone lines attackers go after, capture evidence of what happens when employees face attack scenarios, and turn those findings into targeted interventions for the specific people and teams who need them, all on one platform. We are already seeing success with our early adopters and excited to expand access today to help organizations stand strong in the face of the latest threats.  

What we are launching

Our engineering team has been working on how to put the latest generative text, voice, and video models to work in a way that keeps defenders in control. Today, I’m excited to share three updates to the Fable Platform that work together to build a workforce ready for the current generation of AI threats. 

  1. AI vishing with deepfake voices to test high-risk phone workflows (early access now, broader availability coming soon)
  2. Deepfake video training for the moments when employees have to make a tough decision
  3. Human-led red-team engagements for the complex scenarios that represent how advanced threat actors operate 

Voice testing for high-target workflows

Fable’s AI vishing capability provides security teams with a controlled framework to evaluate shared phone workflows. Organizations can configure authorized deepfake voices, establish realistic scenarios, preview the experience, and conduct targeted testing on shared lines such as IT help desks.

Each engagement generates detailed call evidence, enabling security leaders to assess operational resilience under pressure and determine necessary policy adjustments.

Initial deployments focus on critical shared workflows. Organizations can preview simulations, validate telephony environments, review transcripts and evidence, and translate findings into concrete policy, training, and operational enhancements with Fable’s Secure Behavior Management Platform.

AI vishing is available today to early-access customers, and we’ll share more when it becomes broadly available in the coming weeks. If you’d like to be one of the first to try it, request early access. 

Deepfake video training for decision-making moments

Significant updates to Fable AI Studio enable security teams to deploy highly credible deepfake video training assets. The platform offers industry learning visual quality, streamlined content creation, and accelerated preview and update cycles.

Authorized custom voices and avatars can be seamlessly integrated into scenarios that replicate typical corporate meeting environments.

The primary objective is operational readiness. For example, finance personnel can rehearse responding to an apparent executive requesting an urgent wire transfer during a video call, executive assistants can practice out-of-band verification procedures for sensitive requests, and help desk analysts can experience the pressure of familiar visual or voice impersonations seeking policy exceptions.

Through repeated exposure, employees establish verification habits that remain effective even against advanced synthetic media.

Human expertise for complex scenarios

Some scenarios need expert judgment. Our human red-team engagements adapt to each organization’s context and run multi-channel scenarios that test real behavioral and procedural responses. Fable pairs that expertise with the scale and repeatability of a platform-driven testing environment.

See it in action

Together, these capabilities cover the full picture. AI vishing tests high-risk voice workflows, deepfake video training prepares the workforce for synthetic impersonation, and human-led assessments handle the scenarios that call for an expert. Because all three capabilities run on one platform, organizations can prepare, test, analyze, and strengthen security across the entire human attack surface without adding another point tool.

Join the security teams at Genesys, Pennymac, Sisense, Mount Sinai, Sandisk, and Dayton Children’s Hospital who already use Fable to prepare their people for what attackers will try next.

If your organization is concerned about how AI-driven impersonation could reach your help desk, finance team, or executive staff, dealing with complex deep fakes, or being targeted by some of the most challenging and persistent threats, we’d love to help.

  • Join our upcoming webinar. Hear how attackers are using AI-generated voice and video today, and which verification habits hold up when the impersonation looks and sounds real. Register here.
  • Talk with our experts. Book time with Fable’s security team to walk through the social engineering risks you’re facing right now, whether that’s help desk resets, executive impersonation, or wire fraud attempts, and how you could test those workflows safely. Request time with our team here.