Concern Grows Over AI-Powered Voice Attacks, Mutare Survey Finds
While organizations have invested heavily in protecting endpoints, identities, cloud infrastructure, applications, and email, cybercriminals have increasingly shifted their attention toward a communications channel that has historically received far less scrutiny: the enterprise voice network, Mutare noted in a new report.
The survey reveals a clear change in industry thinking. Voice is no longer viewed simply as a business communications tool or an operational nuisance plagued by robocalls and voice spam. Instead, organizations increasingly recognize that AI-powered voice attacks, vishing, social engineering, call spoofing, voice spam storms, and other forms of unwanted voice traffic represent a growing cyber risk capable of disrupting operations, compromising employees, and providing initial access into enterprise environments.
"Cybersecurity strategies have evolved dramatically over the past decade, but Voice Security has largely remained a blind spot," said Brian McDonald, chief security officer of Mutare, in a statement. "Our 2026 Voice Threat Survey shows that security leaders and business owners are beginning to recognize voice as a legitimate attack vector that deserves the same strategic attention as email, endpoints, data, identity, and cloud security."
The findings indicate growing awareness that voice has become an increasingly attractive pathway for threat actors and cybercriminals seeking to bypass traditional security controls through direct human interaction. As AI tools continue lowering the barriers to sophisticated social engineering, organizations are recognizing that protecting people begins long before a conversation ever starts.
Among the report's key findings are several important trends shaping the future of enterprise cybersecurity:
- Growing concern over artificial intelligence-enhanced voice attacks and increasingly sophisticated social engineering campaigns.
- Continued expansion of voice phishing (vishing) as a preferred method for gaining initial access to organizations.
- Increasing recognition that voice security belongs within broader cybersecurity and risk management strategies.
- Continued awareness gaps surrounding available voice security technologies and best practices.
- Strong momentum toward implementing proactive, multi-layered voice security strategies that reduce risk before malicious callers reach human endpoints.
As organizations have strengthened traditional attack surfaces through Zero Trust initiatives, endpoint protection, identity management, and advanced email security, threat actors have adapted by targeting people directly. Live voice conversations provide opportunities to build trust, manipulate employees, bypass technical safeguards, and exploit the human element of security. Generative AI has dramatically accelerated this trend by enabling attackers to create highly personalized scripts, create hyper-targeted campaigns, conduct rapid reconnaissance, clone voices, and scale sophisticated campaigns at unprecedented speed.
"The conversation around voice security has fundamentally changed," McDonald added. "Organizations are beginning to understand that awareness training alone is no longer sufficient. A modern cybersecurity strategy must include technical controls that reduce opportunities for malicious callers to ever reach employees, executives, help desks, or contact center agents. That's where voice security becomes a critical layer of defense."