09.01.26 06:00 GMT
Breacher.ai launches AI-driven assessment for voice phishing threats
In a significant shift in cybersecurity threats, Breacher.ai has launched a new assessment aimed at addressing the rise of voice phishing, which has overtaken email as the primary method of social engineering attacks in enterprises. According to Mandiant’s M-Trends 2026 report, based on over 500,000 hours of incident response investigations, voice phishing has become the second most common initial infection vector, a stark contrast to the decline in email phishing.
This shift has prompted Breacher.ai to develop a comprehensive, managed service that replicates the exact sequence of a sophisticated voice phishing attack. The assessment, which can be initiated without any software or integration, autonomously calls employees posing as their internal IT support desk. If the call goes unanswered, it leaves a voicemail with a callback number. Upon the employee’s return call, the AI voice agent responds, engaging in a live conversation.
The service allows for the optional cloning of a named individual’s voice, provided that consent is documented. Additionally, it includes testing of the organization’s own service desk recovery procedures. The assessment covers only initial access, ensuring no remote access tools or customer data are involved in the process.
Found and CEO Jason Thatcher explained, "Email security improved, but human voices didn't get easier to distrust. Attackers moved to the channel where automated controls you bought don't operate." He emphasized the importance of training and procedural verification over relying on individual judgment.
Breacher.ai's assessment uses their proprietary measurement model, OSES™, to score the results. The score is based on the depth and breadth of the employee's engagement, ranging from no action to a consequential escalation. The company also highlights the importance of measuring the entire sequence, including voicemail-and-callback paths, which are often overlooked.
Thatcher noted, "Knowing that 14% of your people complied tells you nothing. What matters is how you compare to your peers and the specific behaviors that put you at risk." The deliverables include detailed risk scores, peer vertical comparisons, named process failures, and procedural recommendations tailored to the organization’s own policies.
The launch of this assessment reflects Breacher.ai's commitment to staying ahead of evolving cybersecurity threats. As the company states, human detection of synthetic media cannot be the sole defense; the enduring layer of protection is robust processes, policies, and procedures combined with comprehensive training.
For organizations looking to ensure they are not the next target, Breacher.ai's AI voice phishing assessment is now available at [https://breacher.ai/services/ai-voice-phishing-assessment/](https://breacher.ai/services/ai-voice-phishing-assessment/).