The phone rings at 11pm. It is your daughter, and she is crying. There has been an accident, she is at a police station, she needs money for a lawyer immediately and please do not tell Dad because she is embarrassed. The voice is unmistakably hers — the cadence, the way she says your name, the small catch in her breath.
She is asleep at home. The voice was generated from a few seconds of audio scraped from a video she posted last year, and the person speaking has never met her.
This attack works because it bypasses judgement entirely. You are not evaluating a suspicious email; you are hearing your child in distress. The defence cannot be scepticism in the moment, because the moment is engineered to remove it. It has to be a rule you decided on in advance.
What changed in 2026
- Cloning got fast and cheap. A usable voice clone now needs seconds of audio, not minutes, and the tools are widely available. Anyone who has posted a video has provided enough material.
- Real-time video joined voice. Live face-swapping on a video call is convincing enough over typical compression that "get them on video" stopped being reliable verification.
- Targeting got personal. Scripts increasingly reference real names, employers, and recent events pulled from social media, which removes the generic feel that used to give these calls away.
- Business versions scaled up. The same technique aimed at finance staff — a cloned executive authorising an urgent transfer — became a significant category of corporate fraud.
Why detection is the wrong strategy
The instinct is to listen harder. People ask what to listen for: flat emotion, odd pauses, an artificial edge on certain sounds.
Those artefacts exist in poor clones and are absent from good ones, and you cannot know in advance which you are hearing. Worse, the advice creates false confidence in exactly the wrong direction — someone who has been told what to listen for and does not hear it concludes the call is genuine.
The reliable defence does not depend on assessing the content at all. It depends on the channel.
The callback rule
If a call involves money, credentials, or urgency, hang up and call back on a number you already have. Not a number given to you during the call. Not a number in a message that just arrived. A number from your own contacts, or one you look up independently.
That is the entire defence and it defeats essentially every version of this attack, because the attacker controls the inbound channel and not the outbound one. Whoever is impersonating your daughter cannot answer her actual phone.
Two practical notes. Attackers anticipate the callback and may say "my phone is broken, use this number" — that objection is itself the signal. And if you cannot reach the person, call somebody else who would know: a sibling, a colleague, the workplace main line. The secrecy instruction exists precisely to stop you doing that, which is why ignoring it is the right move.
The code phrase
Agree a word or phrase with close family now, before you need it. Requirements: not guessable from anything public, not derivable from your social media, never sent in a message or stored in a note.
The test is simple. "What is the code?" Someone who cannot answer is not who they claim, no matter how they sound.
Choose something absurd rather than meaningful — a nonsense pairing is more memorable and less guessable than a pet's name or a street you lived on, both of which are frequently discoverable. Share it verbally, in person. Include the people most likely to be impersonated and most likely to be targeted, which usually means both the youngest and oldest members of a family.
The same logic works at a company: a verbal callback policy for any payment instruction, no exceptions for seniority or urgency. The corporate version of this scam relies entirely on staff being reluctant to slow down an executive.
Reducing your exposure
You cannot remove your voice from the internet, but you can reduce what is easy to harvest and what is easy to weaponise.
Lock down public video. Public accounts posting video are the raw material. Restricting audience is the single largest reduction available.
Watch what a voicemail greeting gives away. A recorded greeting in your own voice is a clean, high-quality sample anyone can call and collect.
Reduce the personal detail attached to your name. Scripts get convincing when they include specifics. Data broker opt-out covers removing the aggregated profiles these attacks draw on.
Talk to the people who will be targeted. Older relatives are disproportionately hit and often have not heard that this is possible. That conversation is worth more than any technical measure.
Common mistakes
- Trying to verify by asking personal questions. Attackers often have the answers from social media, and a wrong answer gets explained away by stress.
- Treating video as proof. Live face swapping is good enough on a compressed call.
- Honouring the secrecy request. "Do not tell anyone" exists to prevent verification. It is the clearest signal in the whole script.
- Assuming a familiar number is safe. Caller ID is trivially spoofed. An inbound call from a known number proves nothing.
- Paying to end the pressure. Gift cards, wire transfers, and crypto are chosen because they are irreversible.
- Not agreeing a code phrase until after an incident. It takes two minutes and only works if it already exists.
FAQ
What if I have already sent money?
Act immediately. Contact your bank or the payment service — wire recalls are occasionally possible within a short window, and gift card issuers can sometimes freeze unspent balances. Report to law enforcement and, in the US, the FTC. Speed matters more than anything else, and embarrassment is what attackers count on to delay you.
Can any tool detect a deepfake reliably?
Detection tools exist, accuracy varies, and the generation side improves continuously. Treat them as supplementary. Process-based verification does not degrade as the technology improves.
Is this only a risk for older people?
No. Older relatives are heavily targeted in the family-emergency version, but the workplace variant aims squarely at finance and operations staff of any age, and it is often more lucrative.
Should I stop posting videos entirely?
That is a personal call and probably unnecessary. Reducing public exposure helps, but assume some sample of your voice exists regardless — which is exactly why the defence should not depend on preventing cloning.
Where to go next
For the account-security layer that limits what a successful impersonation can reach, read passkeys vs 2FA and the best password managers. For freezing the financial damage, credit freeze vs lock, and for background on the underlying technology, what is an AI voice clone.