Blog

No Deepfake Needed: The Basic Impersonation That Reached the Prime Minister

Jack Corbett4 min read

  • impersonation
  • identity
  • government

In cybersecurity, we spend a lot of time preparing for complex threats like autonomous agents, deepfake video calls and perfectly cloned audio. But sometimes, all it takes to reach the highest levels of global leadership is a simple text message.

On 17 August 2026, Politico broke a concerning story, subsequently confirmed by the BBC: UK Prime Minister Andy Burnham had been targeted in an impersonation scam. Sometime after he took office on 20 July, Burnham exchanged messages with an unidentified person posing as Susie Wiles, the White House Chief of Staff.

The most critical detail of this incident? There was no verbal conversation. No synthetic media, no voice cloning and no deepfakes. It was a basic, low-tech text exchange.

What happened

Burnham addressed the incident with reporters on 18 August, making it clear he felt he handled the situation correctly and that no damage was done.

No, I’m not [embarrassed], because there was a minimal exchange, nothing of consequence, and actually, quickly, I realised that this needed to be reported, and I did so.

Downing Street, meanwhile, declined to comment further on national security matters.

Why chasing the technology is a losing move

This is not the first time Susie Wiles’ identity has been weaponised. She has been the target of high-profile impersonation twice in just fifteen months, once with AI and once without.

Around May 2025, federal authorities investigated an impersonator reaching out to Republican senators, members of Congress, and business executives while posing as Wiles. Recipients noted that the voice on the phone sounded exactly like hers, leading officials to suspect AI voice cloning. By July of that year, the threat evolved again when an attacker used AI to mimic Senator Marco Rubio’s voice to target foreign ministers.

Comparing these incidents reveals the reality of the threat landscape. The sophisticated, AI-driven voice clone reached senators and executives. The incredibly simple, text-only impersonation managed to reach the Prime Minister. A firm that builds defences exclusively against the sophisticated version remains wide open to the low-tech one.

Why existing defences fail

“We have deepfake detection.” Detection tools inspect content for synthetic anomalies. But plain text carries no artefacts to inspect. Deepfake detection would have been completely ineffective here, proving that impersonation cannot be solved by detection software alone.

“Our systems are secure.” The White House confirmed no devices were compromised. Every perimeter control was perfectly intact, and not a single one was relevant. The attacker did not need a breach to impersonate the Chief of Staff; they only needed a phone number and a plausible premise.

The risk and compliance reality

Crucially, no damage was done. This was just a diplomatic contact where nothing was lost or stolen, and Burnham’s instincts kicked in quickly. For risk and compliance teams though, that is the flaw in the system: security was dictated by gut feeling, not a technical control.

This is exactly how Ferrari dodged a massive deepfake scam in 2024, when an executive’s gut feeling prompted them to ask the impersonator a question about a book recommendation he had made. Instinct saved both Downing Street and Ferrari.

But instinct cannot be evidenced in an audit. Compliance demands controls that can be evidenced, and this incident demonstrates the risk of operating without them.

Where verification changes the game

When an unexpected message arrives, you cannot assume the sender is who they claim to be. Relying on the platform itself, like iMessage or WhatsApp, leaves you completely unprotected.

This is exactly where HonestID comes in. We verify the human behind any communication.

If a cryptographic, human-to-human verification control had been in place, the outcome would have looked very different. One simple challenge to the real Susie Wiles, delivered securely to her actual device, would have ended the attack before the first reply was ever sent.

You can no longer trust the channel. You have to verify the person.