FBI warns: cybercriminals are using AI to attack hospitals with cloned CEO voices
Executive Summary
The FBI has issued a specific alert to the healthcare sector about the growing use of artificial intelligence by cybercriminals, including executive voice cloning (CEO fraud with deepfake audio) and automated personalized phishing generation. The alert was shared by John Riggi, national cybersecurity advisor for the American Hospital Association (AHA), following a meeting with FBI leaders.
Attacks observed in Q1-Q2 2026 include cloned voice calls from a hospital system CEO requesting urgent bank transfers, spear phishing emails generated with AI imitating the writing style of specific doctors, and deepfakes in video conferencing where the “participant” was actually an attacker.
Key Points
- Vishing with AI: voice cloning with only 3-5 seconds of public audio (from YouTube, podcasts, social media)
- Automated spear phishing: generative AI tools allow personalized emails at scale with data scraped from LinkedIn, ResearchGate, hospital websites
- Deepfakes in video conferencing: incidents in Zoom/Teams meetings where the “boss” requests urgent actions
- Nation-state + cybercriminals: growing collaboration where APT actors provide AI tools to ransomware groups
- Most affected sectors: large hospital systems, academic medical centers, insurers
Regulatory Implications
HIPAA: AI voice cloning vishing attacks can be used to obtain EHR system credentials. If an attacker gains access to PHI through social engineering, it remains a HIPAA breach with notification obligation.
NIS2: Hospitals must implement robust multifactor verification for financial and administrative actions.
Recommendation
- “Callback verification” protocol: any urgent request for transfer, credential change, or access to sensitive data must be verified through an independent channel (callback to the known number, not the one appearing in the email/call).
- Specific deepfake training: employees must know that the CEO’s voice on a call is NOT proof of identity. Implement “security words” for critical actions.
- Limit executive voice exposure: restrict public audio of leadership, especially in formats used to train AI (YouTube, podcasts, presentations).
- Real-time detection: tools exist (Pindrop, Hive AI) that analyze incoming audio to detect voice synthesis. Consider for hospital call centers.
- Process hardening: no financial or PHI access decision should be made by a single call, email, or message. Always 2 people + out-of-band verification.
- Report to FBI/INCIBE: detected attempts must be reported to FBI (US) or INCIBE 017 (Spain). Aggregated intelligence protects everyone.
Source: AHA News - FBI intel on healthcare cyberthreats
This analysis is part of HealthSec, the weekly briefing on healthcare cybersecurity.