Breacher.ai launches IT support impersonation assessment as voice phishing overtakes email as the way into the Enterprise
Press Release August 31, 2026
Most voice testing measures the outbound call. Breacher.ai measures the voicemail and the callback, where the most consequential outcomes occur, and returns an OSES™ risk score benchmarked against the organization's peer vertical.
img img
Most people don't answer, so the voicemail goes out and a portion of them ring the number back. That callback is where the worst outcomes happen, and the reason we built OSES™

ORLANDO, FL, August 31, 2026 /24-7PressRelease/ -- Breacher.ai today announced a fixed-price deepfake and AI voice phishing assessment, built around the vector that has displaced email as the leading social engineering route into enterprises.

Mandiant's M-Trends 2026, drawn from more than 500,000 hours of incident response investigations found highly interactive voice phishing had risen to one of the top initial infection vectors, the second most common overall, while email phishing fell overall.

The 2026 breach record has followed the data. A telecommunications operator, an identity protection provider and a networking vendor each disclosed large-scale customer data exposure originating from voice phishing calls.

Breacher.ai's assessment replicates that sequence. An autonomous AI voice agent calls employees as their internal IT support desk. Where a call goes unanswered it leaves a voicemail with a callback number, and when the employee rings back the agent answers and holds the conversation live.

Voice cloning of a named individual is available where the customer wants it tested and consent for the likeness is documented. Testing of the organization's own service desk recovery procedure is available as well.

The assessment is offered as a managed service, with no subscription and no commitment. It originates entirely outside the customer's environment and requires no software, integration or access to internal systems. It covers initial access only; no remote access tooling is deployed, no lateral movement is attempted and no customer data is touched.

Why the pretext works
"Email security got better. Human voices did not get easier to distrust," said Jason Thatcher, founder and chief executive of Breacher.ai. "Attackers moved to the channel where the automated controls you bought don't operate."

Breacher.ai also reports that the technique does not require synthetic media to succeed. Among the most effective campaigns in the company's engagement book are runs using a conversational AI voice agent with no cloned voice at all.

"Training matters and every organization should be running it. What it can't do is carry this on its own," Thatcher said. "Detection ability decays as generation quality improves. Procedural verification doesn't. The question isn't whether your people can hear that a voice is synthetic, it's whether your process holds when they can't, and that's a question you answer with testing rather than with a course."

Measuring the full sequence: Breacher.ai's data indicates that measuring only the outbound call discards the majority of the sample. Because most targets do not answer, the voicemail-and-callback path is the dominant route through a population rather than an edge case, and the inbound callback is where the company observes the most consequential results: a structural effect, since the employee initiated the contact and therefore has no cold open and no reason for suspicion.

Results are scored using OSES™ (Orchestrated Social Engineering Simulation), Breacher.ai's proprietary measurement model. Scoring is based on an escalation ladder at the deepest point they campaign reached across all legs and both directions: no action, small engagement, click, conversational engagement, action taken, or a consequential escalation downstream.

Scores are banded Low, Medium, High or Critical.
Small groups within a roster are reported as events rather than rates. "One person handing over an identity is the finding," Thatcher said. "It doesn't need a denominator, and putting a percentage on three people would be dishonest."

Thatcher also points to the speed at which a single phone call becomes an incident. Mandiant measured the median hand-off between initial access and a second threat actor collapsing from roughly eight hours in 2022 to 22 seconds. "There is no realistic window in which somebody reports the call in time," he said. "That's why the control has to be the process, not the person noticing afterwards."

Benchmarking against peers
The company positions the peer vertical comparison, not the raw score, as the primary deliverable, and notes that it matters more for this technique than most, because the crews running it work one sector at a time.

"Knowing that 14% of your people complied tells you nothing on its own," Thatcher said. "It doesn't tell you whether you're the soft target in a sector someone is about to work through. That's the report that matters: you scored X, your peer vertical scores Y, and here's the specific behavior that moved you off the median."

Deliverables include the OSES risk score with DEPTH and SPREAD reported separately, the peer vertical position, named process failures identifying the verification step that should have interrupted the call, a per-leg breakdown carrying its own denominators, and procedural recommendations written against the customer's own policy.

The assessment is available immediately at https://breacher.ai/services/ai-voice-phishing-assessment/.

Breacher.ai builds and operates OSES™, an orchestrated social engineering simulation platform used by major organizations, to test how organizations behave under AI-driven voice, video and messaging. Founded and run by security practitioners, the company was among the first entrants in deepfake social engineering simulation and maintains one of the field's larger independent benchmark datasets.

Breacher.ai's position is that human detection of synthetic media cannot carry the defense, and that the durable, measurable layer is process, policy and procedure alongside training.

The company is based in Orlando, Florida.

# # #

Contact Information

Jason Thatcher

Breacher.ai

Orlando, FL

United States of America

Telephone: 4079000799

Email: Email Us Here

Website: Visit Our Website

Blog: Visit Our Blog

Follow Us: in