What Are AI Phone Scams and Why Are They Targeting Businesses in 2026?

As of July 2026, AI phone scams are fraudulent voice calls that use artificial intelligence to clone voices, impersonate trusted contacts, and bypass traditional call authentication systems like STIR/SHAKEN. According to the TNS 2026 Half-Year Robocall Investigation Report released on July 28, 2026, these AI-powered attacks are surging across the US voice network and outpacing the defenses carriers built over the past five years, creating urgent risks for small businesses that depend on phone communication.

Scale of the problem: TNS analyzed 1.9 billion daily call events across more than 150 carriers and nearly 300 million subscribers. The data confirms that AI-driven fraud tactics are escalating faster than compliance measures can contain them.

Trust gap widening: 77% of US adults say they are very concerned about AI voice impersonation, and 54% personally know someone who lost money to an imposter scam. That level of distrust means your legitimate business calls are less likely to be answered.

Regulatory response accelerating: The FCC released a proposed rulemaking on July 23, 2026 to expand and strengthen the Robocall Mitigation Database, and a coalition of 49 state attorneys general has urged the FCC to adopt even stricter measures.

What the TNS 2026 Report Found

Transaction Network Services published its 2026 Half-Year Robocall Investigation Report on July 28, 2026. The report draws on data from more than 1.9 billion daily call events, collected across more than 150 communications service providers and nearly 300 million subscribers. The core finding is blunt: STIR/SHAKEN authentication has driven meaningful progress among leading carriers, but authentication alone is no longer sufficient to stop the current wave of voice fraud.

Among Tier-1 carriers like Verizon, T-Mobile, AT&T, Comcast, Charter, Lumen, and UScellular, 85% of exchanged voice traffic was signed and verified with STIR/SHAKEN protocols in 2025, with 93% of those signed calls receiving A-level attestation. That sounds reassuring until you look at the other side. Among smaller and rural carriers, only 17.5% of call traffic was signed. That gap creates a seam in the system that scammers are actively exploiting.

The report highlights a technique called SIM boxing, which allows fraudsters to originate calls from within a carrier’s trusted network. Because the call appears to come from inside the network, it receives A-level attestation even though the call is fraudulent. TNS data shows that over 50% of scam calls tracked through honeypot monitoring carried A-level attestation, and 43% of spam traffic in production networks was A-level attested. In plain terms, the verification that was supposed to mean “this call is legitimate” can no longer be trusted on its own.

The scams themselves have grown more sophisticated. TNS tracked AI-powered voice scams targeting seniors with cloned family member voices, AI-scripted IRS impersonation calls offering phantom refunds in exchange for banking credentials, and coordinated robocall and text campaigns launched in the aftermath of cyberattacks on healthcare systems. For businesses already navigating the challenge of choosing the right business phone system, understanding how these threats affect daily call operations is now just as important as evaluating features and pricing.

Who Is Most at Risk From AI Phone Scams?

AI phone scams are not limited to one industry or business size, but certain businesses carry more exposure because of how heavily they rely on phone communication. If your team makes or receives a high volume of calls daily, or if your staff regularly handles sensitive information over the phone, you operate in the highest-risk zone.

Medical practices and healthcare offices are frequent targets because their staff are trained to be responsive and their patients expect callbacks. Scammers exploit that responsiveness by posing as insurance companies, EHR vendors, or even patients. Law firms face similar risks because attorneys and staff routinely discuss confidential matters over the phone, and a single successful impersonation call can expose privileged information. Home service businesses and contractors are vulnerable because their teams often answer calls from unknown numbers throughout the day, making it harder to distinguish a real customer inquiry from a scam.

Real estate teams and staffing firms round out the high-risk group. Real estate transactions involve wire transfers and sensitive financial data, which makes agents prime targets for impersonation scams. Staffing and recruiting firms process personal data from job candidates and handle payroll information, both of which are high-value targets for AI-powered social engineering.

In our experience helping businesses set up their phone systems, the pattern we see most often is that small teams simply do not have time to screen every inbound call carefully. When every call could be a customer, the instinct is to answer first and evaluate later. Scammers count on that instinct.

Why STIR/SHAKEN Alone Is No Longer Enough

STIR/SHAKEN was designed to solve a specific problem: caller ID spoofing. When a scammer disguises their number to look like a local business or a government agency, STIR/SHAKEN gives the receiving carrier a way to check whether the calling number is legitimate. Calls that pass verification receive A-level attestation. Calls from numbers the originating carrier cannot fully verify receive B or C-level attestation.

The system works as intended among major carriers. But scammers have adapted. The TNS report identifies three structural weaknesses that AI-powered fraud campaigns are now exploiting.

First, the small-carrier gap. Only 17.5% of call traffic between smaller carriers was signed in 2025. Many of these carriers still run legacy TDM networks that do not support STIR/SHAKEN at all. Scammers route traffic through these carriers specifically because the calls bypass authentication entirely.

Second, SIM boxing. By placing SIM cards inside a carrier’s own network, fraudsters originate calls that the carrier’s systems treat as legitimate. The call receives full A-level attestation because it technically originates from within the trusted network. This means businesses cannot rely on attestation level alone to judge call safety.

Third, AI voice cloning. STIR/SHAKEN verifies the number, not the voice. An AI-cloned call from a verified number passes every authentication check. The voice sounds like someone the recipient trusts, and the number checks out. This combination makes AI-powered impersonation calls far more dangerous than traditional robocalls.

The FCC is moving to close some of these gaps. On July 23, 2026, the Commission released a proposed rulemaking (FNPRM FCC-26-49A1) that would expand the Robocall Mitigation Database to cover VoIP resellers, cloud service providers, call centers, and other entities that touch the voice call chain. The proposal also introduces one-step removal for egregious violations and requires providers to implement “affirmative, effective measures” rather than just “reasonable steps” in their robocall mitigation plans. These rules are proposed, not yet finalized as of July 2026, but they signal where the regulatory environment is heading.

How Do AI Scams Affect Your Business Phone Operations?

The damage from AI phone scams hits small businesses in two directions. The direct threat is an inbound scam call that tricks your staff into revealing sensitive information, authorizing a fraudulent payment, or exposing client data. The indirect threat is less obvious but often more expensive: consumer distrust of phone calls in general is reducing answer rates for legitimate business outreach.

When 77% of adults are concerned about AI voice impersonation and more than half personally know a scam victim, the default behavior shifts. People stop answering calls from numbers they do not recognize. For a medical practice calling to confirm appointments, a law firm following up on a consultation request, or a home service company returning a missed call, that means fewer connections and more voicemails that never get returned.

The table below shows how scam tactics have shifted from traditional robocalls to the AI-powered methods described in the TNS 2026 report.

FactorTraditional Robocalls (Pre-2024)AI-Powered Scams (2026)
Voice qualityRobotic, pre-recorded scriptsCloned voices of real people, natural speech
Caller ID displaySpoofed number, often randomVerified number with A-level attestation
TargetingMass dialing, untargetedData-driven, personalized to the recipient
Response to questionsPlays next script segmentAnswers in real time using AI
Detection difficultyModerate, recognizable patternsHigh, mimics trusted contacts
Typical victim actionHangs up quicklyEngages, shares information, follows instructions

One question we hear constantly from business owners is whether their outbound calls are being flagged as spam. The answer depends almost entirely on their VoIP provider. If the provider handles STIR/SHAKEN authentication properly and signs outbound calls with A-level attestation, those calls have the best chance of reaching recipients without a “Spam Likely” label. If the provider cuts corners on authentication, or if they operate on infrastructure that only supports B or C-level attestation, every outbound call starts at a disadvantage. For businesses evaluating their options, comparing providers on authentication capabilities is now as important as comparing them on affordable VoIP phone service pricing.

Your phone system should protect your calls, not work against them. If you are not sure whether your current provider handles STIR/SHAKEN authentication at the A-level, it is worth finding out before your answer rates drop any further.

How to Protect Your Business Phone System Right Now

Protecting your business phone operations in the current threat environment requires action on two fronts: making sure your outbound calls get answered, and making sure your team can identify inbound scams before any damage is done. These steps apply to any small business using a VoIP or cloud-based phone system as of July 2026.

  1. Confirm your VoIP provider’s STIR/SHAKEN attestation level. Ask your provider directly whether your outbound calls are signed with A-level attestation. If they cannot confirm this, or if they only support B or C-level, your calls are more likely to be flagged or blocked by recipient carriers.
  2. Verify your provider’s Robocall Mitigation Database status. Every voice service provider is required to file in the FCC’s Robocall Mitigation Database. If your provider’s filing is inactive, suspended, or removed, carriers may block calls originating from their network entirely. You can check the database at the FCC’s RMD portal.
  3. Register your business texting through 10DLC. If your business sends text messages from a local phone number, registration with The Campaign Registry is mandatory. As of 2025, all major carriers block 100% of unregistered A2P business text traffic. If your messages are not arriving, unregistered 10DLC is almost certainly the reason.
  4. Enable enhanced caller ID on your phone system. Features like enhanced caller ID help your team identify inbound callers before picking up. This does not stop every scam, but it gives your staff an additional layer of information before engaging with an unknown caller.
  5. Train your team on AI voice scam red flags. AI-cloned calls can sound like a real person, but they often share specific behavioral patterns: urgency that discourages verification, requests for payment outside normal channels, reluctance to hang up and call back on a known number. Build a simple verification protocol: if any caller requests sensitive information or a payment, your team hangs up and calls back on a verified number.
  6. Use call recording to document suspicious interactions. Call recording is not just a training tool. If your team encounters a suspected scam call, having a recording provides evidence for reporting to the FCC or your state attorney general. Many VoIP plans, including those that offer 30-day or unlimited recording, make this straightforward to implement.

Common Mistakes About Phone Scam Protection

The most common mistake we see businesses make is assuming their phone provider handles everything. STIR/SHAKEN is a provider-level obligation, but choosing a provider that actually meets that obligation is a business decision. Not every VoIP company invests in full authentication infrastructure, and some smaller or budget providers rely on upstream carriers whose compliance status changes. Checking once is not enough. The FCC’s proposed rules would require providers to update their RMD filings within 10 business days of any change, and downstream providers would need to verify RMD status on an ongoing basis.

A second common mistake is confusing STIR/SHAKEN with branded calling. STIR/SHAKEN verifies the phone number. Branded calling displays your business name and logo on the recipient’s screen. They are two different systems. Having one does not give you the other. As of July 2026, branded calling support is still fragmented across carriers and devices. STIR/SHAKEN A-level attestation is the non-negotiable foundation. Branded calling is a useful addition where available, but it is not a substitute.

A third mistake is ignoring inbound scam risk entirely because “we are a small business, nobody would target us.” The TNS data shows the opposite. Scammers use automated AI tools that can target thousands of small businesses simultaneously with personalized calls. A medical practice receiving a call from someone claiming to be their EHR vendor, or a law firm getting a call from someone posing as a client, does not need to be specifically selected. These campaigns run at scale. The businesses that have a verification protocol in place, along with the right office phone hardware and software tools, are the ones that catch the scam before it succeeds.

Finally, some businesses avoid switching phone providers because they assume the transition will be disruptive. In reality, most modern VoIP providers can set up a new business phone system within one business day. Number porting typically takes 5 to 10 business days, and you can use a temporary local number in the meantime. If your current provider cannot confirm A-level STIR/SHAKEN attestation or their RMD filing is not current, staying put carries more risk than switching.

Frequently Asked Questions

What is STIR/SHAKEN and why does it matter for my business?

STIR/SHAKEN is a federally mandated framework that verifies caller ID information to prevent spoofing. When your VoIP provider signs your outbound calls with A-level attestation, recipient carriers are less likely to flag those calls as spam. Without proper attestation, your legitimate business calls may not reach customers.

How can I tell if my VoIP provider is compliant with FCC robocall rules?

Check the FCC’s Robocall Mitigation Database for your provider’s filing. An active filing with current certification means the provider is in compliance. If the filing is missing, inactive, or has been removed by enforcement action, carriers may block calls from that provider’s network.

Can AI voice scams really clone someone’s voice convincingly?

Yes. Modern AI voice cloning tools can replicate a person’s voice from just a few seconds of audio. The TNS 2026 report documents cases of cloned family member voices used to target seniors and AI-scripted impersonation calls that respond to questions in real time. These calls are significantly harder to detect than traditional robocalls.

What is the Robocall Mitigation Database and why is the FCC changing it?

The Robocall Mitigation Database is an FCC registry where voice service providers certify their robocall prevention practices. On July 23, 2026, the FCC proposed expanding filing requirements to cover VoIP resellers, cloud providers, and call centers. The goal is to close gaps that allow bad actors to enter or abuse the voice network.

Does HIPAA compliance protect my phone system from scams?

HIPAA compliance protects patient data handled over your phone system, but it does not prevent scam calls from reaching your team. However, a provider that meets HIPAA standards typically invests in stronger security infrastructure overall, which can include better call authentication and encrypted communications.

How quickly can I switch to a VoIP provider with better scam protection?

Most modern VoIP providers can have your business phone system live within one business day of signup. Number porting from your existing provider typically takes 5 to 10 business days. Month-to-month plans with no contracts make switching straightforward and low risk.

Next Steps

Review your current VoIP provider’s STIR/SHAKEN attestation level and RMD filing status to confirm your outbound calls are properly authenticated.

For more context on selecting the right system, read our guide to business phone systems in 2026.

Compare your current provider against the most affordable VoIP phone service options for small business to see how your plan stacks up on both price and protection.

Ready to make sure your business phone system is protected? Talk to our team.

AI phone scams are not slowing down, and your phone system should not be the weak link. Phone Service Now provides HIPAA-compliant VoIP phone service with no contracts and full setup in one business day, starting at $18.99 per user per month.