Deepfake and voice-clone scams: household defenses
How AI voice-cloning scams work, and the specific, low-cost defenses — starting with a family safe word — that actually stop them.
How the scam works
The attack follows a consistent pattern: a scammer harvests a short public audio sample of a family member (a social media video, a voicemail greeting, a public livestream), uses it to synthesize a cloned voice, then places an urgent, emotionally charged call — often spoofing the real caller ID — claiming an emergency that requires immediate money or account access.
As little as three seconds of audio is enough to produce a usable voice clone with current tools — far less than most people assume is needed, and easily obtainable from a single public video.
The single most effective defense
Establish a family safe word: a short phrase, agreed on in person or over a channel you’re both certain is secure, that any family member can ask for during an unexpected urgent call. AI voice cloning cannot guess a phrase that was never spoken publicly. This single measure defeats the overwhelming majority of documented cases.
Additional protocol
- Never act on urgency alone. Scam calls are engineered to bypass your normal skepticism through emotional pressure; hanging up and calling back on a known, trusted number is always safe.
- Limit public audio and video of family members, especially elderly relatives and children, who are disproportionately targeted.
- Treat video calls with the same skepticism — real-time deepfake video puppeting has been used in documented corporate fraud cases; a shared safe word works the same way on video as on a phone call.
- Report attempts to the FTC and your local authorities even if no money was lost — pattern data helps regulators and carriers respond faster.
If you’re targeted
Do not engage further, do not provide information, and do not send money under time pressure, no matter how convincing or distressing the call sounds. Verify independently, every time.
Sources
Communications Fraud Control Associationreports that as little as three seconds of audio can clone a person’s voice.
CFCA, Report
Full register of everything this manual cites: source index.