Case Library / Smishing (SMS Phishing) / Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff Susie Wiles, texting and calling senators, governors and business leaders with requests including a pardon list and a cash transfer, triggering an FBI investigation.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In May 2025, an unidentified individual gained access to the contacts stored on White House Chief of Staff Susie Wiles's personal cellphone and used that access to impersonate her, sending text messages and placing phone calls to senators, governors, top U.S. business executives, and other prominent Republicans and well-known figures. Some of the calls used a voice that recipients said sounded like Wiles, which government officials believed was generated using AI voice-cloning technology. The messages and calls did not originate from Wiles's actual phone number. Content included a request to one lawmaker to compile a list of people who could be pardoned by President Trump, and at least one request for a cash transfer. Some recipients were asked to move the conversation to Telegram. The scheme was first reported by the Wall Street Journal on May 29, 2025, and confirmed as under investigation by the FBI and the White House the same week; it followed a May 15, 2025 FBI public service announcement warning of a broader campaign, active since roughly April 2025, in which malicious actors used smishing and vishing (including AI-generated voice messages) to impersonate senior U.S. officials and their contacts. President Trump publicly confirmed on May 30, 2025 that Wiles's phone had been "breached."

How the Attack Worked

Reporting (primarily the Wall Street Journal, corroborated by Reuters, AP, CNN, CBS, ABC, Washington Post, The Guardian, Fox News, The Hill) indicates an unidentified individual gained access to the personal cellphone contacts of Susie Wiles (her private phone, not her government-issued device) and used that contact list to reach senators, governors, top U.S. business executives, members of Congress, and other prominent Republicans and well-known figures. The impersonator sent text messages and placed phone calls that appeared, at least initially, to be from Wiles; some calls used a synthesized/AI-generated voice that recipients described as sounding like her. The messages and calls did not originate from Wiles's actual phone number. Content included requests recipients initially believed were legitimate, including one lawmaker being asked to assemble a list of individuals who could be pardoned by the president, and at least one instance where the impersonator asked for a cash transfer. Some recipients were also reportedly asked to continue the conversation on Telegram, a common social-engineering tactic to move victims off a monitored/traceable channel. The White House, FBI, and U.S. intelligence agencies were notified and began investigating; FBI officials reportedly told the White House they did not believe a foreign nation was behind the effort, though this remained unconfirmed in public reporting. It was not the first cybersecurity incident tied to Wiles: WSJ noted that during the 2024 campaign, Iranian operatives had hacked into her email account and accessed a research dossier on then-vice-presidential candidate JD Vance, though no link between that earlier intrusion and the 2025 impersonation was established.

The Lure & the Tell

The lure: messages and calls appeared to come from a trusted, high-authority contact, Trump's own White House Chief of Staff, reaching out personally via a channel (personal cellphone contacts) that implied legitimacy and urgency, with an AI-cloned voice reinforcing the illusion on calls. The tell: broken grammar and phrasing more formal than Wiles's actual communication style; the impersonator asking Trump-related questions Wiles herself would already have known the answers to; the number not matching Wiles's known phone number; and, in some cases, an odd pivot request to continue on Telegram.

Outcome

As of the most recent public reporting reviewed, the matter remained an open FBI investigation with no arrest, indictment, or public attribution announced. The White House confirmed the investigation and stated it "takes the cybersecurity of all staff very seriously" and that "this matter continues to be investigated." FBI Director Kash Patel stated the FBI "takes all threats against the president, his staff, and our cybersecurity with the utmost seriousness" and called safeguarding administration officials' secure communications "a top priority." President Trump publicly confirmed Wiles's phone had been "breached" and that an impersonator had tried to pose as her, while downplaying concern, saying Wiles "can handle it." Some of the people contacted engaged with the impersonator before realizing the deception; others contacted Wiles directly to verify before responding. No public reporting confirms actual financial loss, and the identity, nationality, or motive of the impersonator had not been publicly disclosed in the sources reviewed.

Why It Matters

This incident is one of the most prominent documented cases of AI voice-cloning used to impersonate a sitting senior U.S. government official for social engineering targeting other high-value figures (sitting senators, governors, and business executives), rather than the more commonly reported deepfake-CEO-fraud pattern against corporate finance staff. It illustrates how compromising a single high-value individual's personal device and contact list can cascade into a multi-target social-engineering campaign leveraging that person's implicit trust network, and how AI voice synthesis is now sophisticated enough to fool recipients who personally know the person being impersonated, at least initially. It also demonstrates that non-technical tells (grammar, tone, knowledge gaps, unfamiliar numbers) remain a critical last line of defense even against advanced synthetic-voice attacks, and that securing officials' personal devices, not just government-issued ones, is now a national security concern.

Defenses

Multiple recipients caught the fraud through classic social-engineering tells rather than technical controls: broken grammar and unusually formal phrasing inconsistent with Wiles's normal communication style; the impersonator asking questions about Trump that the real Wiles would already have known the answer to; and the calls/texts originating from a phone number not associated with Wiles. Wiles herself proactively warned her contacts to disregard messages/calls not coming from her known number and apologized for the inconvenience, functioning as an informal out-of-band verification signal. The FBI's May 15, 2025 public service announcement (PSA) had already warned senior officials and their contacts about the broader smishing/vishing/AI-voice campaign, providing some advance awareness. The episode underscores standard recommended defenses that were largely absent beforehand: callback verification via an independently known number, a pre-agreed verbal/code-word challenge for high-value requests (pardon lists, fund transfers), skepticism toward any request to move a conversation to an unofficial channel like Telegram, and treating personal (non-government) devices of senior officials as high-value targets requiring the same hardening as official devices.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: The attacker likely identified Susie Wiles as a high-value target given her role as White House Chief of Staff and her personal phone's role as a trust hub connecting senators, governors, and business executives; this kind of targeting is consistent with the FBI's May 15, 2025 PSA describing malicious actors impersonating senior U.S. officials specifically to reach their well-connected contacts.
Countering Stage 1: Public visibility of senior officials and their networks is unavoidable and cannot be eliminated; the realistic control is treating well-connected officials' personal devices as high-value targets requiring proactive hardening, rather than trying to suppress the fact that they are targets.
2
Personal device/contact-list compromise: The attacker gained access to the contacts stored on Wiles's personal (non-government) cellphone through a method not publicly disclosed, likely consistent with common consumer-device compromise vectors such as SIM-swapping, phishing of device or cloud-account credentials, or a malicious app or link, none of which sources confirm specifically in this case.
Countering Stage 2: Personal devices belonging to senior officials should receive the same security posture as government-issued devices, including mobile threat defense, carrier-level SIM-swap protections, phishing-resistant multi-factor authentication on cloud/contact-sync accounts, and periodic review of connected apps and account access.
3
Voice-cloning preparation: To generate a synthetic voice that recipients described as sounding like Wiles, the impersonator likely used a commercial or open AI voice-cloning tool trained on samples of her public speech, such as televised interviews, press appearances, or other publicly available audio, a technique consistent with the vishing tactics described in the FBI's PSA.
Countering Stage 3: There is no practical way to prevent an attacker from collecting a public figure's existing recorded speech to train a voice clone; the realistic control sits downstream, at Stage 4, where callback verification through an independently known number defeats a cloned voice regardless of its quality.
4
Spoofed outreach via text and voice: Using a phone number not associated with Wiles, the impersonator sent text messages and placed AI-voice phone calls to senators, governors, business executives, and other prominent contacts drawn from the hacked list, opening with rapport-building messages designed to appear as routine, legitimate outreach from the Chief of Staff.
Countering Stage 4: Recipients of unsolicited high-authority requests should independently verify the sender through a previously known number or channel rather than trusting caller ID or a message's apparent origin, exactly the behavior the FBI's PSA recommended and that some Wiles contacts practiced by calling her directly.
5
Elicitation of sensitive information and funds: Once initial trust was established, the impersonator escalated to specific asks, including requesting one lawmaker compile a list of individuals eligible for a presidential pardon and, in at least one case, requesting a cash transfer, exploiting the assumed authority and urgency of a Chief of Staff-level request.
Countering Stage 5: High-value or sensitive requests (pardon lists, fund transfers, confidential data) should require a pre-agreed out-of-band verification step, such as a callback to a known number or an internal verbal/code-word challenge, before being acted on, regardless of the apparent seniority of the requester.
6
Platform pivot to Telegram: In some interactions the impersonator asked recipients to continue the conversation on Telegram, a tactic the FBI's PSA describes as a means to move targets to a secondary platform, likely to reduce traceability, avoid carrier/telecom fraud controls, and potentially stage follow-on phishing links or malware.
Countering Stage 6: Any request to move a sensitive conversation to an unofficial or unmonitored platform like Telegram should itself be treated as a red flag; organizations and officials' staff can train contacts to recognize platform-pivot requests as a common social-engineering tactic rather than a legitimate operational need.
7
Objective completion or detection: The scheme's ultimate objective was not achieved before detection in the reported instances; recipients caught the deception through tells (broken grammar, unfamiliar number, knowledge gaps) and either disengaged or contacted Wiles directly to verify, at which point the White House and FBI were notified and an investigation was opened.
Countering Stage 7: Since technical prevention failed to stop outreach from occurring, the last line of defense was recipient skepticism toward inconsistencies (grammar, tone, knowledge gaps) and prompt reporting to the impersonated official and authorities, which is what ultimately triggered the FBI investigation and limited further harm.
Quick Facts
Victim
Susie Wiles, White House Chief of Staff, and by extension the senators, governors, business executives, and other prominent Republicans/well-known figures in her personal contact list who received the fraudulent texts and calls
Location
United States (Washington, D.C. and nationwide, targeting officials and executives across the country)
Date
2025-05 (campaign active weeks before public disclosure on 2025-05-29/30, FBI PSA on broader related campaign issued 2025-05-15)
Impact
No financial loss has been publicly confirmed. WSJ reported that in at least one instance the impersonator asked a recipient for a cash transfer, but no source confirms any funds were actually sent or any monetary loss occurred. The primary confirmed harms are reputational/operational: disruption to Wiles's network of contacts, engagement by some recipients before they realized the deception, and the launch of an FBI investigation.
Status
Confirmed
Case Type
Real-World Incident
Sector
Cross-Sector / Multiple Industries, Government & Public Sector
Related

Related Cases

PG&E Utility Shutoff Barcode/QR Payment Scam

Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection, then text or email a barcode/QR code and…

Incident 2025Read →

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it…

Incident 2025Read →

GTIG Discloses PROMPTFLUX: First "Just-in-Time" Self-Obfuscating AI Malware Using the Gemini API

Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite…

Incident 2025Read →