> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/simulations/deepfake-phishing-simulations.md).

# Deepfake Phishing Simulations

## Overview

Attackers can now clone a voice from just a few seconds of audio and use it to impersonate an executive or coworker over the phone. The most effective way to build resistance is to let people experience it safely — hearing their **own** voice cloned by AI is far more memorable than reading about the threat.

Herd delivers this as a **Voice Deepfake step** inside a training. Rather than a standalone campaign, you drop the exercise into any training you build, alongside info, quiz, and phishing steps.

## How the exercise works

When a user reaches a Voice Deepfake step in a training:

1. They're asked to record a short voice message (5–10 seconds) using Slack's built-in audio recording.
2. Herd clones the recording with AI voice-cloning technology.
3. The user is played both samples — their original recording and the AI clone — and asked to identify which is which.
4. Whatever they choose, the step closes with the lesson: AI can clone a voice from seconds of audio, so when a call feels off, verify through a trusted channel.

## Adding a Voice Deepfake step to a training

In the training step editor, add a step and choose **Voice Deepfake** ("Clone the user's voice with AI"). You can customize the instruction, processing, comparison, and follow-up messages, as well as the text the cloned voice speaks. See [Creating Trainings](/herd-security-docs/trainings/getting-started-with-trainings/creating-trainings.md) for the full training builder walkthrough.

### Choosing an attack vector

The step editor's **Attack Vector** selector picks the scenario the exercise dramatizes, prefilling all the step messages with matching copy (which you can then edit):

* **IT help desk password reset** (the default) — an attacker impersonates IT support and pressures the target into revealing their credentials.
* **CEO fraudulent payment (finance / accounts receivable)** — an attacker deepfakes the CEO's voice to pressure a financial controller or AR team member into approving an urgent, confidential wire transfer. The closing lesson: always verify urgent payment requests through a separate, trusted channel.

{% hint style="info" %}
Voice Deepfake steps are delivered through **Slack**, so your workspace needs the [Slack integration](/herd-security-docs/getting-started/slack-training-setup.md) connected. They're also a plan-gated feature — if you don't see the option in the step editor, contact your Herd representative.
{% endhint %}

## Related

* [Make Simulations Challenging but Fair](/herd-security-docs/how-to-documentation/make-simulations-challenging-but-fair.md) — guidance on running higher-pressure simulations responsibly.
