Conference Call Phishing Simulation - Breacher.ai

Conference Call Phishing Simulation

Your people were trained to distrust the email. Nobody trained them to distrust the meeting.

We run live social engineering simulations on Microsoft Teams, Zoom, and Google Meet. A meeting invite arrives, someone joins, and the person on camera is synthetic: generated video, cloned voice, responding in real time. You find out whether the request gets verified or gets actioned. Fully managed and external, with no integrations, no tenant admin consent, and nothing installed.

Microsoft Teams Zoom Google Meet Deepfake Video Voice Cloning No Integrations

Built for security, GRC, fraud, and finance teams.

The meeting has become the most trusted channel you never test

$25M
Moved in a single fraudulent video call where every other participant was synthetic
Source: Hong Kong Police, reported February 2024
3
Platforms simulated end to end: Teams, Zoom, and Google Meet
Guest, external, and dial-in join paths included
0
Integrations, admin consents, or installs required to run it
Fully managed and external

Why the invite works when the email does not

Years of phishing training taught people to hesitate over links. It taught them nothing about a face on a screen.

The calendar carries the trust

A meeting invite does not ask to be clicked. It asks to be attended. It lands inside the workflow people already accept dozens of times a week, from a colleague, a client, or a partner, with a subject line that matches something genuinely in flight.

Seeing and hearing is the verification

On a call, identity feels confirmed the moment the camera turns on. That instinct is the whole attack. A face that responds and a voice that sounds right replace the step where someone would have picked up the phone to check.

Your controls do not attend meetings

Mail gateways inspect headers, links, and attachments. None of them are present for the twenty minutes where a request is made, pressure is applied, and an approval is given verbally.

Nothing to install, nothing to approve, nothing to maintain

Most simulation platforms need to live inside your environment before they can run. This one never enters it.

The usual path
What other platforms need first
Tenant admin consent in Microsoft 365 or Google Workspace
An app registration or connector in your identity provider
Allowlisting rules that quietly guarantee delivery
An agent or browser extension pushed to endpoints
A change window and a security review before anything runs
Ongoing configuration owned by a team that has other work
Every one of these is a reason the simulation slips a quarter, and every allowlist is a reason the result reads better than reality.
Breacher.ai
What we need from you
Signed authorization and an agreed scope
The roles and teams in scope for the exercise
A window to run in and a named approver to call
Written consent for any likeness we are authorized to use
Thirty minutes of your time at scoping and again at debrief
Nothing else
We reach people the way an attacker would, from outside, with no privileged position inside your tenant. That is exactly why the number you get back is real.

Six surfaces, one meeting

Run the full set for a complete picture, or scope down to the platform and pretext your organization actually lives in.

Microsoft Teams

Invites and chat lures that follow the shape of your internal Teams traffic, including external and guest access join paths. The pretext arrives where people already coordinate work, so nobody stops to reread it.

Guest AccessTeams Chat LureExternal Join
Zoom

Scheduled and ad hoc Zoom sessions, waiting rooms, and reused meeting links, run the way vendors and clients actually send them. Covers the rescheduled call, the forwarded link, and the urgent bridge that appears an hour before.

Meeting LinksWaiting RoomClient Pretext
Google Meet

Calendar-first lures built for Workspace organizations, where the invite lands on the schedule before anyone reads a word of it. Includes the auto-accept behaviour that puts an attacker on the calendar without a single reply.

Calendar InviteWorkspaceAuto Accept
Deepfake Video Participant

A synthetic executive or colleague on camera, generated from authorized likeness and driven live. It answers questions, reacts to interruptions, and stays in the conversation. A recording cannot be asked to repeat itself. This can.

Live AvatarExecutive ImpersonationReal-Time Response
Cloned Voice and Dial-In

Camera off, voice only, which is how most calls actually run. A cloned voiceprint built from publicly available audio joins the bridge or calls directly, and tests whether anyone asks for a second factor before acting on what they heard.

Voice CloneAudio BridgeCallback Verification
In-Meeting Payload and Follow-Up

The link dropped in chat mid-call, the file shared on screen, the credential prompt that appears while everyone is watching, and the message that arrives afterwards referencing the meeting by name. The call builds the trust. The follow-up spends it.

Chat PayloadCredential CapturePost-Call Pretext

How the simulation runs

Conference call phishing is run as an OSES™ engagement, our orchestrated social engineering simulation framework. Same spine as everything else we run: measure risk, train for what you find, prove it changed, on one dataset.

01
Scope & Authorization
Roles in scope, platforms, likeness consent, run window, named approvers, and abort conditions agreed and signed
02
OSINT Research
The public footprint an attacker would use: reporting lines, vendors, deals in flight, meeting habits, available audio and video
03
Lure & Meeting Build
The invite, the pretext, the platform, and the synthetic participants, built to match how your organization actually meets
04
Live Call
The call runs, the request is made, and every verification attempt, escalation, and approval is captured as it happens
05
Debrief & Training
Findings, process gaps, and training assigned from what actually happened rather than a generic module

Every engagement runs under signed authorization, with likeness consent documented before any media is generated and all generated media destroyed at the end. No payment is ever moved and no real credential is ever used. For testing the verification systems themselves rather than the people using them, see deepfake penetration testing.

The seats an attacker books a meeting with

Anyone who can move money, grant access, or change a record, and who does it over a call because that is faster.

Finance & Treasury
Payment approval under time pressure
Executive Offices
Impersonated leadership and assistants
IT & Service Desk
Reset and access requests made on camera
HR & Payroll
Direct deposit and record changes
Legal & Deal Teams
Confidential transaction pretexts

What makes this different

It runs from outside, like the attack

No allowlist, no admin consent, no privileged position in your tenant. The simulation has to get through the same controls a real attacker faces, which is the only way the result means anything.

Live and interactive, not a recording

The synthetic participant responds in real time and holds a conversation under pressure. Playback tests attention. Interaction tests judgement, and judgement is what fails on these calls.

Reported as an organization

Findings cover where verification was attempted, where it was skipped, and which process allowed the request through. No named individuals and no department leaderboards, so people report what happened instead of hiding it.

Common questions

What is conference call phishing?

A social engineering attack that moves the pretext out of the inbox and onto a video or voice call. The target receives a meeting invite that looks routine, joins, and finds someone they recognize on camera making a request. Because the face and voice appear to confirm identity, the usual verification step never happens.

Which platforms do you simulate?

Microsoft Teams, Zoom, and Google Meet, including guest and external join paths, dial-in bridges, and the follow-up messages that arrive after a call ends. If your organization standardizes on one platform, we run the simulation entirely on that one.

Do you need access to our Teams, Zoom, or Google Workspace tenant?

No. There is no app registration, no admin consent, no connector, and no agent on any endpoint. The simulation runs externally on the same paths an attacker would use, which is what makes the result a measurement rather than a rehearsal.

Is there really a deepfake on the call?

Yes. A synthetic participant joins the meeting with generated video and a cloned voice, responds in real time, and holds the conversation. It is not a recording played back, because a recording cannot be asked a question.

Whose likeness gets used?

Only likenesses your organization authorizes in writing during scoping, typically an executive or internal role that a real attacker would impersonate. Consent is documented before any media is generated, and all generated media is destroyed at the end of the engagement.

What happens to someone who joins and gets caught?

They get a short debrief and training on what the call was and what to look for next time. Reporting is organizational: no named individuals and no department leaderboards. The point is to fix the process that let the request through, not to single anyone out.

Is this authorized, and how is scope controlled?

Every engagement runs under signed authorization within an agreed scope, window, and set of roles, with named approvers and documented abort conditions. No real payment is ever moved and no real credential is ever used. The simulation stops at the point where the action would be taken.

What do we receive at the end?

A report covering which lures got people into the meeting, what happened once they joined, where verification was attempted and where it was skipped, how the request was escalated or approved, and the process changes worth making. Training is assigned from the findings.

How long does an engagement take?

Two to three weeks from scoping call to final report, with the live call window itself usually a few days inside that.

Find out who stays on the call

Thirty minutes. We will walk through how your teams meet, approve, and verify, and pick the first pretext worth running.

No integrations Nothing installed Findings in 2 to 3 weeks
Book a Free Demo

Or see the full deepfake simulation range.