Simulate AI Voice Phishing Calls

Test employees with lifelike phone calls modeled on real-world scams, including cloned voices, delivered with strict double opt-in consent.

Included with Enterprise subscriptions
Voice Phishing video preview 2:39

Prepare Employees For
The Calls Attackers Are Making

Screenshot of the CanIPhish Voice Phishing Library with ready-to-run vishing templates
Real-Time AI Phone Conversations
Deepfake Familiar Voices
Opt-In Consent Built In
Illustration of a simulated vishing call, where an AI caller posing as a colleague asks an employee to fix an error with her Slack account

Calls That Feel Real

  • Real-Time Dialogue - The AI listens and responds live, using social engineering tactics, so every call is a unique conversation.
  • Prebuilt Templates, Custom Personas - Start from a voice phishing template and customize how the AI persona engages your employees.
  • Context-Aware Personalization - Details like an employee's name or company are woven into the call to increase realism.
  • Credible Under Pressure - Add an AI Knowledge Source so the caller can answer challenges and follow-up questions with relevant context.
Screenshot of the Upload Custom Voice dialog, recording a voice sample from a microphone for voice cloning

Clone A Trusted Voice

  • Upload Or Record - Add an MP3 or WAV file, or record directly with your microphone in the AI Voice Library.
  • Recording Script Provided - Read our script to capture a clear, natural sample that gives the AI more to work with.
  • Assign To Any Scenario - Select your cloned voice in any voice phishing template and save.
  • Train For Deepfake Attacks - Show employees how convincing an impersonated executive, co-worker or vendor can sound.

Realistic Simulations Delivered At Scale

Double Opt-In Consent

Every Number Is Consented To Twice

Employees confirm by email, then again by SMS, tying consent to the exact phone number that will receive the call. Once both steps are complete, they can be included in simulations for up to two years without asking again.

Phone number verification with double opt-in consent status
Outcome Tracking

Results In The Same Dashboard

Every call is tracked, including whether it was answered, whether the employee engaged and what the outcome was. Results feed straight into your CanIPhish dashboard and campaign reporting, alongside your email phishing data.

Voice phishing campaign results and statistics
Privacy By Design

Evidence Without Recording Your People

Employee audio is never recorded. Instead, every call is evidenced by a redacted transcript that shows how the conversation played out and how many back-and-forths took place, alongside the call time, who was called and the outcome.

Redacted call transcript used as evidence for a voice phishing simulation

Stop Training For Checkboxes. Train For Real Attacks.

Compliant Delivery

Calls follow local spam and telecommunications laws, and are only available in regions where compliance can be ensured.

Unique Every Time

Every response is generated in real time, reflecting the unpredictability of real attackers.

Train Beyond The Inbox

Voice simulations sit alongside email phishing, closing the gap attackers use when they pick up the phone.

Internal Caller Identity

Calls appear to come from the employee's own organization, keeping them realistic and transparent.

Stays On Script

The AI operates within the boundaries of the scenario you choose, and can't escalate outside it.

Practice Under Pressure

Employees face urgency and manipulation in a safe setting, so a real scam call is never the first one they've heard.

Included With Enterprise. Go Beyond Email.

Voice Phishing comes with Enterprise subscriptions as an added benefit, so you can add a new attack channel to your program without buying a separate vishing tool.

Create a free account
  • Consent Handled For You
    Email and SMS opt-in is collected automatically before anyone is called.
  • Let AI Make The Calls
    Lifelike, two-way conversations with no human callers to schedule or script.
  • Consolidate Your Security Tools
    Run voice and email phishing from one platform, instead of paying for another.

Frequently Asked Voice Phishing Questions

Voice Phishing is only available to Enterprise subscribers. It isn't on by default. Once you're on Enterprise, an activation notice appears on the Voice Phishing page under Phishing Content.

Employees receive an email with a link to a consent form. After clicking "I Consent", they receive a text message asking them to confirm again, which ties consent to that phone number. Consent then lasts for up to two years.

No. Employee audio is never recorded. Audio is only processed during an active call to decide how the AI responds and whether the employee fell for the simulation. Administrators see a redacted transcript as evidence, along with call metadata and the outcome.

Voice phishing simulations are available in select regions where CanIPhish can ensure compliance with local spam and telecommunications laws. Organizations operating globally should check availability by region.

They can reply STOP or UNSUBSCRIBE to the consent SMS, say "stop calling me" during a simulated call, ask their IT or security team, or email support@caniphish.com with their phone number.

Use clear, natural source audio that's at least a minute long, with a good range of tone and pacing. Then match the scenario's AI persona and tone to the voice, and add an AI Knowledge Source for extra context. Read the full guide.

Top