The phone rang at Brinks Home's help desk, and the voice on the other end sounded like anyone who should have access. Patient. Official. Routine. It wasn't. Before that call ended, 4.9 million records were quietly walked out of the building. Mandiant's 2025 incident response data confirms what security teams have feared: vishing โ voice phishing โ has surpassed email as the number one initial access vector. CrowdStrike logs a 442% year-over-year spike. And the strangest part? The technology that made this possible is the same one we're being asked to welcome into our daily lives.
I've spent decades reading transaction receipts, not phone logs. But tracing the ghost in the call receipts feels eerily familiar. The anatomy is the same as every smart contract exploit I've dissected since my 2017 audit sprint: trust, placed in the wrong layer, exploited by someone who read the system better than its builders did.
Context: The Productized Mask
Google's "Let Google Call" is the productized version of Duplex โ the 2018 I/O demo where an AI booked a hair salon appointment and the human on the other end never suspected a thing. Seven years later, the engineering is mature. ASR, TTS, conversational state tracking, real-time intent recognition: all integrated, all scalable, all boringly reliable. This is a productization decision, not an architecture breakthrough.
The product decision, though, is not boring. When the AI calls a business, it states plainly that it is automated. It expects the human on the other end to proceed anyway. Google is systematically conditioning real businesses to accept AI callers as legitimate participants in commerce. Every completed call is a data point in an unstated, large-scale social experiment. The experiment isn't about whether the AI works. It's about whether humans keep saying yes.
I saw this dynamic before. In June 2022, when Celsius froze withdrawals, I spent weeks tracking the 6,000 BTC treasury movement while interviewing depositors who had never once checked a wallet address. The numbers told one story; the trust breakdown told another. When people stop verifying, they start losing.
Core: The Identical Trust Stack
Lay the two scripts side by side, and the overlap is uncomfortable.
A legitimate Google AI call: natural voice synthesis, contextually appropriate dialogue, routine framing, a specific request. A vishing attack: natural voice synthesis โ increasingly AI-generated โ contextually appropriate dialogue, urgency or routine framing, a specific request. Same stack. Same receiver psychology. Same outcome: compliance.
The evidence chain is well documented:
- Mandiant ranks vishing as the number one initial access vector in 2025.
- CrowdStrike reports a 442% increase in vishing attempts year over year.
- Microsoft attributes the ShinyHunters group โ responsible for the Brinks breach โ to campaigns against more than 1,000 organizations, involving 1.5 billion records.
- Brinks Home's breach started with a phone call, escalated to OAuth token abuse, and ended in a compromised Salesforce environment. 4.9 million records. One spoken "yes."
This isn't isolated. ADT and EY entered the same way: vishing first, legitimate credentials second. Attackers aren't breaking in anymore. They're being let in by humans who were conditioned to answer.
Now the paradox. The "I'm an automated agent" disclosure is supposed to be transparency. In practice, it's an unverifiable text-level claim. There is no protocol-level attestation, no cryptographic signature binding the call to a registered entity. An attacker can simply claim to be an AI agent. We are normalizing the mask.
The half-truth is the liar's best disguise. Once society absorbs "AI callers are normal," that disclosure stops being a safety mechanism and becomes a legitimate identity cover for anyone who wants to sound automated. The signature is in the silent transfer โ in crypto, we verify the signer before we settle. In voice, the receiver is asked to trust the sound of the call. And we're being trained to say yes. Audit trails don't lie โ but only if they exist, and voice has none yet.
Contrarian: Listening Harder Is Not the Fix
The reflexive industry answer is better detection: AI voice cloning detectors, real-time social-engineering pattern recognition, risk scoring on every inbound call. I'm deeply skeptical. In 2017, I spent six weeks auditing fifteen ERC-20 tokens for a private firm and found critical reentrancy vulnerabilities in three of them. The market wanted to believe the whitepapers; the code said otherwise. The same pattern repeats here: once AI-generated voice is indistinguishable from a human voice โ and it already is โ the receiver has nothing left to authenticate except the protocol layer.
The fix is not more sensitive microphones. It's infrastructure: extending STIR/SHAKEN to AI agents, digitally signed caller identities, verifiable attestations of who deployed the agent and under what authority. Think of it as the voice equivalent of DKIM and DMARC for email. Without it, detection is a cat-and-mouse game where the attacker only needs to win once.
There's a second, uglier dimension. Google isn't just training model parameters; it's training human conditioned reflexes: pick up, respond, comply. Every legitimate AI call lowers the suspicion threshold that vishing depends on. The Klaviyo 2026 consumer data backs this up โ only 13% of people fully trust AI, while 64% of Americans already distrust major platforms. The trust deficit isn't causing people to hang up. It's causing selective numbness. Attackers know exactly which calls still get answered.
The insurance industry is quietly repricing this risk in real time. Vishing relies on human error, which underwriters classify as operational risk โ historically underpriced. After ShinyHunters' campaign against 1,000+ organizations, network policies are being rewritten with vishing-specific exclusions and verification requirements. That repricing is the market's admission that this problem is structural, not patchable.
Takeaway: Watch for the Signature
The market is tracking the wrong metric. News cycles count breached records; I'm watching whether any AI agent vendor ships a verifiable identity protocol. The next-week signal: if Google โ or any major player โ announces authenticated agent calls with cryptographic attestation, the trust paradox gets an exit ramp. If they stay silent, then the vishing curve and the AI adoption curve are the same chart, and the ghost in the call receipts is only getting started.
Volatility is just data waiting to be tamed โ and so is trust. The question is whether the industry builds the verification layer before the attackers finish building theirs. The phone is ringing. Are you going to answer?