Comserv Connect
← Back to Blog
Cybersecurity

Criminals Are Renting AI Voice Agents

By Comserv Connect TeamReviewed by Chris Ferrera

For the better part of a year, mostly in Brazil, the same call kept landing. The woman on the line said she was Alice from Apple Support, that the call was recorded for quality assurance, and that she was calling about a stolen iPhone. She asked for the device passcode. Then the Apple ID. Then the two-factor code, live, while the person was still on the phone.

Alice is software, rented by the call.

We build voice AI for businesses. Ours answers the phone, takes messages, and books work, and it sounds like a person because that is the product. This story is about the same technology used the other way.

The Rental Economy Behind the Call

On August 24, 2026, SOCRadar's Threat Research Unit published its analysis of AnonyMousKIT, a phishing platform that sells by the credit. An email lure costs 1.50 credits. A recorded voice call costs 1. The live AI agent costs 2. SOCRadar published Alice's opening line verbatim:

"Hello , this is Alice from Apple Support. This call is being recorded for quality assurance and security purposes."

The researchers also traced what one operator actually spent: 200 AI voice calls, $19.24 in total, roughly 9.6 cents each. That is a receipt from the operator's own account, not a price list.

A live scam call has always needed a person who can hold a script, speak the language, and stay calm when the target gets suspicious. At these prices, the person is optional.

Where the Calls Went

Of the 200 calls SOCRadar documented, 179 went to Brazil. Two went to Chile. One reached the United States. Eighteen could not be resolved. This was a Brazilian campaign, and it already happened: the calls ran from August 2025 through May 2026. The platform behind them is still running. SOCRadar tracked active operations through August 2026.

What We See on Our Own Phones

Our own cell numbers, and the ones across our own clients, take more scam calls than they did a year ago, including calls that sound automated. Business loans. Offers to buy the business. Nothing ties any of it to AnonyMousKIT. What the report adds is detail: how one of these operations actually worked, and what it cost to run.

More Than a Hundred Companies Signed the Same Warning

On August 27, three days after the report, more than 100 companies and organizations, including OpenAI, Anthropic, Google and Microsoft, published an open letter on collective cyber defense, organized by OpenAI:

"In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable."

The letter names four audiences and puts "Every organization" first, ahead of the security industry, governments, and the frontier AI companies themselves. Its first ask is to make cyber defense an immediate leadership priority. It also singles out the defenders with the least to spend, "especially for critical infrastructure organizations with limited budgets."

The Question to Ask About Your Logins

The Alice script works because a person can read a code out loud. Multi-factor authentication did not fail on those calls. It did its job, produced a code, and the attack asked a human to hand it over.

So sort your logins with one test: can this login be completed by somebody reading digits into a phone? CISA and NIST both classify SMS codes, voice codes, and authenticator app one-time codes as not phishing resistant, because a code you type by hand is a code you can be talked into saying. NIST puts it plainly: manual entry "does not bind the authenticator output to the specific session being authenticated." Push notifications with number matching do not clear the bar either. CISA describes number matching as a fix for push bombing, which is a different attack.

What passes the test: FIDO2 and WebAuthn security keys and passkeys, and certificate-based methods like PIV and CAC smart cards. Signing in with one of those produces a signature scoped to the real site rather than a number a caller can collect. There is nothing to read out loud, and it will not release to a lookalike domain.

That protects against this one trick and nothing else. Help desk resets and account recovery can still hand over an account, and across our own clients the recovery route is rarely the one anyone has looked at.

Then give your staff one sentence that requires no judgment: nobody from your IT provider, from Apple, or from this company will ever call and ask you to read out a passcode, a password, or a one-time code. That rule holds no matter how convincing the caller sounds.

Let Your Team Hear One First

When a scam call lands on a business we work with, the failure is rarely a careless person under pressure. More often, across our own clients, it is that nobody ever heard an example before the real one arrived.

The fix is rarely a training course. It is letting your team hear what one of these calls sounds like before a real call reaches them. If you want to do that, or work out which of your logins could be handed over on a phone call, book a free strategy call and we will tell you what we would look at first.

Sources

  1. SOCRadar Threat Research Unit: AnonyMousKIT AI PhaaS supply chain
  2. OpenAI: an open letter on collective cyber defense

Want the Checklist We Actually Use?

The same checks we run for the businesses we protect, in plain language. Free PDF, no vendor pitch.