Published on 22 Jun 2026

PhonEthic: advancing AI-powered defence against voice-based phishing

Voice-based phishing (vhishing) attacks, one of the most effective social engineering methods in modern cybercrime, have become increasingly widespread. In simple terms, vhishing is a type of attack in which scammers attempt to gain access to personal information through voice communication by impersonating a trustworthy person or organisation. These attacks can be carried out through phone calls, automated calls, voice messages, or malicious software. The primary motivation behind such attacks is financial gain. Scammers seek to prevent victims from making rational decisions and try to achieve their goal by creating a sense of urgency and pressure.

PhonEthic: advancing AI-powered defence against voice-based phishing
PhonEthic: advancing AI-powered defence against voice-based phishing

As one of the four use cases within the ITEA project VESTA, Turkish project partner Orion Innovation is developing a library and tool called PhonEthic. This is an audio analysis system designed to process audio files sent via email, voicemail, and other communication channels, and to perform various AI-based analyses to prevent voice-based phishing attacks. This work is being carried out in collaboration with Kocaeli University and Istanbul Technical University, and the results have been published in nine conference papers and a blueprint article: RansomTrack: A Hybrid Behavioral Analysis Framework for Ransomware Detection.

PhonEthic technology

PhonEthic processes incoming audio streams, recorded calls, or audio files through a multi-stage AI workflow. First, audio inputs from sources such as voicemails, email attachments, or live call streams are pre-processed and segmented. These segments are then analysed across four complementary research dimensions:

Finally, PhonEthic combines the information obtained from these four dimensions to generate a comprehensive risk assessment score, enabling the early detection of voice-based phishing attempts and providing actionable alerts to users or security systems.

PhonEthic library

Voice-based phishing is a highly complex problem, involving many different areas of analysis. In this context, the PhonEthic library was created in which relevant studies are grouped into four dimensions:

The PhonEthic library and tool will be released as an open-source project and will continue to evolve through the development of new methods and technologies. The rapid advancement of generative AI is making both the offensive and defensive sides of voice-based phishing more complex, making the continuously development and implementation of new approaches essential.

This development of the Orion Innovation in the ITEA project VESTA is supported by TÜBİTAK.

Related projects

ITEA Call 2021

VESTA

Proactive protection against phishing-based ransomware