An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles.
Social Engineering Examples·8 sources
In May 2025, an unidentified individual gained access to the contacts stored on White House Chief of Staff Susie Wiles's personal cellphone and used that access to impersonate her, sending text messages and placing phone calls to senators, governors, top U.S. business executives, and other prominent Republicans and well-known figures. Some of the calls used a voice that recipients said sounded like Wiles, which government officials believed was generated using AI voice-cloning technology.
The messages and calls did not originate from Wiles's actual phone number. Content included a request to one lawmaker to compile a list of people who could be pardoned by President Trump, and at least one request for a cash transfer. Some recipients were asked to move the conversation to Telegram. The scheme was first reported by the Wall Street Journal on May 29, 2025, and confirmed as under investigation by the FBI and the White House the same week; it followed a May 15, 2025 FBI public service announcement warning of a broader campaign, active since roughly April 2025, in which malicious actors used smishing and vishing (including AI-generated voice messages) to impersonate senior U.S. officials and their contacts.
President Trump publicly confirmed on May 30, 2025 that Wiles's phone had been "breached."
Reporting (primarily the Wall Street Journal, corroborated by Reuters, AP, CNN, CBS, ABC, Washington Post, The Guardian, Fox News, The Hill) indicates an unidentified individual gained access to the personal cellphone contacts of Susie Wiles (her private phone, not her government-issued device) and used that contact list to reach senators, governors, top U.S. business executives, members of Congress, and other prominent Republicans and well-known figures.
The impersonator sent text messages and placed phone calls that appeared, at least initially, to be from Wiles; some calls used a synthesized/AI-generated voice that recipients described as sounding like her. The messages and calls did not originate from Wiles's actual phone number. Content included requests recipients initially believed were legitimate, including one lawmaker being asked to assemble a list of individuals who could be pardoned by the president, and at least one instance where the impersonator asked for a cash transfer.
Some recipients were also reportedly asked to continue the conversation on Telegram, a common social-engineering tactic to move victims off a monitored/traceable channel. The White House, FBI, and U.S. intelligence agencies were notified and began investigating; FBI officials reportedly told the White House they did not believe a foreign nation was behind the effort, though this remained unconfirmed in public reporting.
It was not the first cybersecurity incident tied to Wiles: WSJ noted that during the 2024 campaign, Iranian operatives had hacked into her email account and accessed a research dossier on then-vice-presidential candidate JD Vance, though no link between that earlier intrusion and the 2025 impersonation was established.
The lure: messages and calls appeared to come from a trusted, high-authority contact, Trump's own White House Chief of Staff, reaching out personally via a channel (personal cellphone contacts) that implied legitimacy and urgency, with an AI-cloned voice reinforcing the illusion on calls. The tell: broken grammar and phrasing more formal than Wiles's actual communication style; the impersonator asking Trump-related questions Wiles herself would already have known the answers to; the number not matching Wiles's known phone number; and, in some cases, an odd pivot request to continue on Telegram.
As of the most recent public reporting reviewed, the matter remained an open FBI investigation with no arrest, indictment, or public attribution announced. The White House confirmed the investigation and stated it "takes the cybersecurity of all staff very seriously" and that "this matter continues to be investigated." FBI Director Kash Patel stated the FBI "takes all threats against the president, his staff, and our cybersecurity with the utmost seriousness" and called safeguarding administration officials' secure communications "a top priority." President Trump publicly confirmed Wiles's phone had been "breached" and that an impersonator had tried to pose as her, while downplaying concern, saying Wiles "can handle it." Some of the people contacted engaged with the impersonator before realizing the deception; others contacted Wiles directly to verify before responding.
No public reporting confirms actual financial loss, and the identity, nationality, or motive of the impersonator had not been publicly disclosed in the sources reviewed.
This incident is one of the most prominent documented cases of AI voice-cloning used to impersonate a sitting senior U.S. government official for social engineering targeting other high-value figures (sitting senators, governors, and business executives), rather than the more commonly reported deepfake-CEO-fraud pattern against corporate finance staff.
It illustrates how compromising a single high-value individual's personal device and contact list can cascade into a multi-target social-engineering campaign leveraging that person's implicit trust network, and how AI voice synthesis is now sophisticated enough to fool recipients who personally know the person being impersonated, at least initially.
It also demonstrates that non-technical tells (grammar, tone, knowledge gaps, unfamiliar numbers) remain a critical last line of defense even against advanced synthetic-voice attacks, and that securing officials' personal devices, not just government-issued ones, is now a national security concern.
Multiple recipients caught the fraud through classic social-engineering tells rather than technical controls: broken grammar and unusually formal phrasing inconsistent with Wiles's normal communication style; the impersonator asking questions about Trump that the real Wiles would already have known the answer to; and the calls/texts originating from a phone number not associated with Wiles.
Wiles herself proactively warned her contacts to disregard messages/calls not coming from her known number and apologized for the inconvenience, functioning as an informal out-of-band verification signal. The FBI's May 15, 2025 public service announcement (PSA) had already warned senior officials and their contacts about the broader smishing/vishing/AI-voice campaign, providing some advance awareness.
The episode underscores standard recommended defenses that were largely absent beforehand: callback verification via an independently known number, a pre-agreed verbal/code-word challenge for high-value requests (pardon lists, fund transfers), skepticism toward any request to move a conversation to an unofficial channel like Telegram, and treating personal (non-government) devices of senior officials as high-value targets requiring the same hardening as official devices.
Social Engineering Examples. “Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)”. Accessed 19 September 2026. https://socialengineeringexamples.com/susie-wiles-ai-voice-impersonation-2025
The attacker likely identified Susie Wiles as a high-value target given her role as White House Chief of Staff and her personal phone's role as a trust hub connecting senators, governors, and business executives; this kind of targeting is consistent with the FBI's May 15, 2025 PSA describing malicious actors impersonating senior U.S. officials specifically to reach their well-connected contacts.
Public visibility of senior officials and their networks is unavoidable and cannot be eliminated; the realistic control is treating well-connected officials' personal devices as high-value targets requiring proactive hardening, rather than trying to suppress the fact that they are targets.
The attacker gained access to the contacts stored on Wiles's personal (non-government) cellphone through a method not publicly disclosed, likely consistent with common consumer-device compromise vectors such as SIM-swapping, phishing of device or cloud-account credentials, or a malicious app or link, none of which sources confirm specifically in this case.
Personal devices belonging to senior officials should receive the same security posture as government-issued devices, including mobile threat defense, carrier-level SIM-swap protections, phishing-resistant multi-factor authentication on cloud/contact-sync accounts, and periodic review of connected apps and account access.
To generate a synthetic voice that recipients described as sounding like Wiles, the impersonator likely used a commercial or open AI voice-cloning tool trained on samples of her public speech, such as televised interviews, press appearances, or other publicly available audio, a technique consistent with the vishing tactics described in the FBI's PSA.
There is no practical way to prevent an attacker from collecting a public figure's existing recorded speech to train a voice clone; the realistic control sits downstream, at Stage 4, where callback verification through an independently known number defeats a cloned voice regardless of its quality.
Using a phone number not associated with Wiles, the impersonator sent text messages and placed AI-voice phone calls to senators, governors, business executives, and other prominent contacts drawn from the hacked list, opening with rapport-building messages designed to appear as routine, legitimate outreach from the Chief of Staff.
Recipients of unsolicited high-authority requests should independently verify the sender through a previously known number or channel rather than trusting caller ID or a message's apparent origin, exactly the behavior the FBI's PSA recommended and that some Wiles contacts practiced by calling her directly.
Once initial trust was established, the impersonator escalated to specific asks, including requesting one lawmaker compile a list of individuals eligible for a presidential pardon and, in at least one case, requesting a cash transfer, exploiting the assumed authority and urgency of a Chief of Staff-level request.
High-value or sensitive requests (pardon lists, fund transfers, confidential data) should require a pre-agreed out-of-band verification step, such as a callback to a known number or an internal verbal/code-word challenge, before being acted on, regardless of the apparent seniority of the requester.
In some interactions the impersonator asked recipients to continue the conversation on Telegram, a tactic the FBI's PSA describes as a means to move targets to a secondary platform, likely to reduce traceability, avoid carrier/telecom fraud controls, and potentially stage follow-on phishing links or malware.
Any request to move a sensitive conversation to an unofficial or unmonitored platform like Telegram should itself be treated as a red flag; organizations and officials' staff can train contacts to recognize platform-pivot requests as a common social-engineering tactic rather than a legitimate operational need.
The scheme's ultimate objective was not achieved before detection in the reported instances; recipients caught the deception through tells (broken grammar, unfamiliar number, knowledge gaps) and either disengaged or contacted Wiles directly to verify, at which point the White House and FBI were notified and an investigation was opened.
Since technical prevention failed to stop outreach from occurring, the last line of defense was recipient skepticism toward inconsistencies (grammar, tone, knowledge gaps) and prompt reporting to the impersonated official and authorities, which is what ultimately triggered the FBI investigation and limited further harm.
Browse by what this case has in common with others in the library.
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes…
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…
California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.