The short version: Pindrop® research on high-cost AI attacks maps five patterns doing the most damage right now. Here’s what each one looks like in a health plan’s world: bots on member services lines; fake job candidates; executive impersonations; fake claims and invoices; IT helpdesk credential resets
Five AI-Powered Attacks Every Payer Needs to Know
Health plans have a blind spot: AI-backed attacks working the voice and video channels members, providers, and staff already trust. Here are five ways attackers are using AI to threaten health plans:
1. Attackers use AI bots to attack the member services line
Fraudulent contact center conversations are not new, but the rapidly growing use of AI to automate call line reconnaissance and account takeovers fundamentally changes the stakes.
The chain is simple: a caller claims to be a patient or member, clears a knowledge-based authentication question built on data that’s already for sale, and either walks off with PHI or sets up an account takeover. Stolen identity packages sell for as little as $8 to $35 on dark web markets, and nearly 60% of organizations report fraudsters using that data to get past knowledge-based authentication (KBA). Fraudsters bypass KBA in more than half of attempts and clear OTP challenges roughly 25% of the time.
AI transformed that attack into a volume business. AI-driven attacks grew 1,390% over six quarters.1 At the customer level, that’s an average of 287 AI attacks a day, a 6,400% jump from the year before.2 Automated bot calls now account for more than half of all fraud at some major healthcare organizations. And many of these calls are not overtly malicious, at least not at first. A bot often conducts initial reconnaissance, mapping out the IVR and validating the data it has. Once it has identified a clear path and potentially collected additional information about the patient, it can prepare for a more direct attack, like an account takeover.
Listen to this real example of a bot call:
When these attacks work, the damage hits fast: PHI and sensitive data are released, payments are rerouted, funds are drained from accounts. Perhaps most costly of all is the loss of trust and reputation, especially in an industry where trust is increasingly difficult to preserve.
2. Fake job candidates apply for open roles
Health plans hire remote workers by the thousands: IT and engineering roles, care management staff, member services reps, etc. Remote hiring is a prime space where deepfake candidates thrive.
In 2025, the FBI released an official public service announcement warning about North Korean operatives trying to get hired at U.S.-based companies. Related reports affirm that healthcare is increasingly targeted by these attacks. These operatives and other bad actors use stolen identities and real-time face-swap tools to build a resume, a LinkedIn® profile, and an interview performance convincing enough to clear a screen.
The exposure for health plans is direct. A fraudulent hire in claims, IT, or member services receives legitimate day-one access to PHI, member data, and claims and payment platforms. And the volume of exposure continues to rise. Pindrop’s own 2026 hiring pipeline analysis measured 1 in 47 applicants as having ties to North Korea, a 630% increase from the year before.
If you haven’t detected a North Korean or deepfake candidate, it’s probably because you haven’t been looking.
3. Executive impersonators authorize wire transfers
Payers collect and move large sums constantly: provider reimbursements, capitation payments, vendor payments, etc. That makes finance and executive teams a direct target for impersonation.
A finance employee at Arup joined a video call with who looked and sounded like the company’s CFO and wired $25 million before anyone realized the call was a deepfake. WPP’s CEO was impersonated over WhatsApp with a cloned voice and deepfake video in an attempt to pressure an executive into releasing funds. Attackers exploit the instinct to move fast and trust the person who outranks you, putting all healthcare organizations, including health plans, at risk.
We deepfaked our CFO
Watch this video to see how easily attackers can join meetings as a fake executive
The damage from an executive impersonator goes beyond manipulated employees. Fake videos of leaders making statements about financials or product updates can do serious damage to brand reputation, too. Leaders have access, influence, and trust. AI lets scammers mimic all three.
4. Fake providers or vendors submit fake claims and invoices
Payers work closely with a web of third parties: TPAs, PBMs, provider networks, claims clearinghouses. Every one of those relationships runs on emails, calls, and invoices that are increasingly easy to fake. Fraudulent activity in these relationships is not new, but as with the other attacks in this article, AI has elevated the risk at hand.
The U.S. Department of Justice released a report describing charges against 324 defendants connected with over $14.6 billion in alleged fraud. The report describes charges against several defendants who allegedly “used artificial intelligence to create fake recordings of Medicare beneficiaries purportedly consenting to receive certain products.” The beneficiaries’ confidential information was then used to fuel $703 million in fraudulent claims to Medicare, of which $428 million was paid.
One cybersecurity firm reported attackers using AI to build realistic email threads and fake invoices that looked legitimate enough to get approved and paid before anyone caught the vendor wasn’t real. This playbook is industry agnostic and, thanks to AI, can easily scale. Humans catch AI-manipulated content correctly only about half the time, no better than a coin flip.
Statistically, enterprises cannot rely dependably on staff ears or eyes alone to detect fraudulent activity. An attacker posing as a trusted supplier just needs to send a realistic email, a cloned voice message, or a fake invoice to break through defenses.
5. Bad actors target IT helpdesks to reset credentials and access critical systems
Using stolen information, including employee ID numbers, names, and department information, attackers social engineer IT helpdesks, with or without the help of AI, to access PHI, financial information, and more.
MGM Resorts is the case every security team already knows. Attackers found an employee’s LinkedIn profile, called the help desk pretending to be that employee, and talked their way into a password reset. One convincing phone call led to unauthorized access across MGM’s systems and a multi-day outage. Microsoft recently warned users about a similar tactic spreading through Teams, with attackers posing as IT staff to request remote access before moving through internal systems.
Securing employee credentials and access, while also offering quick support to legitimate staff, is difficult to balance. As the pool of stolen information grows, and as generative AI tools make it easier to look and sound trustworthy, the risk of data and financial exposure through helpdesk manipulation continues to expand.
How can health plans protect against these attacks?
Three critical questions help health plans evaluate every voice and video interaction in a world of fabricated identity. Consider if your organization is prepared to answer these questions:
- Is this a machine? Synthetic voice detection analyzes a live call and flags synthetic audio in roughly two seconds, at up to 99% accuracy with a false positive rate under 1% in Pindrop’s internal testing.4 Either the voice passed or it didn’t, and a clear and documented risk signal exists.
- Is this a bad actor? Risk scoring should look at more than just the voice itself; it should consider the device, behavior, caller ID, and known fraud-consortium data, flagging anomalous call metadata or bad-actor associations for escalation before any privileged action is taken.
- Is this the right human? Passive authentication matches the caller against device and behavioral signals built up over prior interactions, so a legitimate, recognized caller moves through with less friction while an unrecognized or mismatched one gets flagged, regardless of whether they sound convincing or know the right answers.
The future of healthcare security isn’t a guessing game about who is on the other line. Real security means verifying, with confidence, the legitimate identity of the caller. AI has lowered the barrier for entry for bad actors, but it has also created powerful new tools for defense.
Don’t wait for a breach to find the gaps in your own trust models. Talk to a real human to see how the Pindrop® platform can help you secure your voice and video channels.
Sources
-
- Based on Pindrop customer data from Q4 2024-Q1 2026. Derived from a study of over 700M calls.
- Based on Pindrop customer data analysis from Q1 2026 in comparison to the previous five quarters.
- Pindrop customer case study, “90% Drop in Fraud and a Smoother CX: How HealthEquity Did It,” February 23, 2026
- Pindrop, internal dataset and testing analysis, as of May 2026.
- Microsoft Teams is a trademark of the Microsoft group of companies.
- LinkedIn is a registered trademark of LinkedIn Corporation and its affiliates in the United States and/or other countries.