IA · 11 October 2026 · 5 min read

The Voice AI Honeypot: 350,000 Bots Pose as Victims to Waste Scammers' Time

In brief: As digital fraudsters automate large-scale phishing campaigns, the cybersecurity sector is responding in kind with an army of conversational voice bots designed to pose as gullible targets. Telecommunications providers and security vendors are deploying hundreds of thousands of autonomous agents capable of keeping criminals entangled in hours-long calls, depleting their resources while logging illicit bank accounts, scripts, and phone numbers in real time.

by Team Mocchi's

The Voice AI Honeypot: 350,000 Bots Pose as Victims to Waste Scammers' Time

Turning the Tables on Phone Scams

For years, fraudulent phone networks have held a massive structural advantage: automated dialers and predictive calling tools enable operators to blast tens of thousands of calls a minute at near-zero marginal cost from offshore hubs well outside the legal reach of Western authorities. Traditional countermeasures have struggled to keep up, relying primarily on public awareness campaigns and reactive blocklists that fail to blunt the daily torrent of impersonation scams and social engineering attempts.

Rather than merely dropping suspect calls, a growing contingent of telecom providers and financial institutions is routing illicit callers into dense webs of AI agents engineered to behave like ideal prey. The core strategy is not confrontation, but resource exhaustion: by absorbing a fraudster's working hours inside convincing, circular dialogues, these conversational honeypots insulate real human targets while driving up the operating expenses of illicit boiler rooms.

The Psychology of the Plausible Target

Sustaining a believable voice trap requires behavioral fidelity that far exceeds generic scripted bots. As reported by Wired, security firm Apate operates a network of approximately 350,000 conversational agents equipped with synthetic personal profiles, regional speech patterns, simulated messaging profiles, and realistic phone mannerisms. Some bots answer hesitantly, others claim to be distracted running errands and ask the caller to hold, while others voice a measured degree of skepticism.

This calibrated hesitation is crucial. If an agent folded immediately, a seasoned scammer would suspect an operational trap; by pushing back gently before exhibiting confusion or mild distress, the AI lures the fraudster into redoubling their persuasive efforts. The resulting calls routinely stretch beyond two hours. Throughout the exchange, the underlying platform silently harvests intelligence: illicit money-mule accounts, wire transfer instructions, and phishing URLs are captured and fed directly into real-time fraud mitigation feeds across banking partners.

The Real-World Test for Full-Duplex Models

This deployment highlights the rapid maturation of interactive speech processing architectures. While industry executives note that conversational voice has yet to achieve its definitive inflection point — as examined by TechCrunch regarding remaining reasoning delays and conversational pacing hurdles in enterprise settings — active defense scenarios provide an environment where speech nuances excel today.

Full-duplex models capable of continuous listening and seamless turn-taking mimic real conversational pauses, verbal fillers, and ambient domestic background noise with startling precision. In an adversarial phone encounter, human conversational slack actually works in the model's favor: every simulated hesitation — such as fumbling for a reading glass or hunting for a misplaced bank card — affords the reasoning stack ample buffer time to decode fraudulent intents and construct the next stalling maneuver.

Mocchi's take

Deploying conversational agents as defensive honeypots signals a major paradigm shift: cybersecurity is moving from passive firewalls toward active, highly persuasive software interactions. For technology teams and digital leaders across Europe, this development proves that conversational AI's true return on investment extends well beyond internal task automation into neutralizing asymmetrical threats. Mastering low-latency full-duplex speech and real-time structured data extraction is no longer merely a user experience pursuit, but a core architectural capability for safeguarding critical digital infrastructure.

Further reading

All articles on the Mocchi's blog