AI voice scams - how to tell if a call is really from someone you know
Voice cloning has removed the one thing that made a phone call trustworthy. You can no longer verify a person by how they sound, which means verification has to move to something the caller cannot control - and that turns out to be simple.
The short answer
- Stop trying to judge the voice. Cloned audio is now good enough that listening for flaws is not a reliable test, and treating it as one is the mistake the scam depends on.
- Verify through a channel the caller does not control. Hang up and call the person back on the number you already have saved.
- Agree a family code word in advance. The FBI's own guidance is to create a secret verification phrase with family members.
- The request is the tell. Real emergencies do not require gift cards, cryptocurrency, wire transfers or secrecy from the rest of the family.
- A short voice sample is enough to clone from, so a public voicemail greeting or a video with clear speech is source material.
The question people ask about voice cloning is "how do I tell the difference?" It is the wrong question, and answering it honestly is the most useful thing this page can do.
Quick answer
You cannot reliably identify a cloned voice by listening to it. Modern tools produce convincing imitations from a short sample of clear speech, and the scenarios they are used in — a distressed relative, a bad connection, someone in a hurry — explain away any oddity you might have noticed.
So the answer is not better listening. It is verification through a channel the caller does not control:
- Hang up and call back on the number already saved in your phone.
- Ask for a code word your family agreed in advance.
Both work regardless of how good the audio is, because neither depends on judging it.
What an AI voice scam looks like
The most common version is the family emergency call. It has a fixed shape:
- A call or voice message from a number you do not recognise.
- A familiar voice, distressed. Crying, panicking, or clearly hurt.
- A crisis — an accident, an arrest, a hospital, a stranded trip abroad.
- A handover. A second voice takes over: a lawyer, a police officer, a doctor, a bail bondsman. The relative is "not able to talk right now".
- A payment, needed immediately, in a form that cannot be reversed.
- Secrecy. Do not tell mum. Do not call anyone. This is confidential.
Steps 4, 5 and 6 exist to remove the two things that would end it: talking properly to the person, and talking to anyone else.
Other versions use the same technique:
- A boss or colleague asking for an urgent payment or a document
- A bank's fraud team, calling about a suspicious transaction
- An official, sometimes using AI-generated video as well as audio — the FBI has warned about deepfaked senior officials being used to lend credibility to fraud, including against people who had already been scammed
- A "wrong number" call that is friendly and goes nowhere, whose purpose is to record you speaking
Why the "listen for the tells" advice has expired
You will still find lists of audio flaws to listen for: flat emotion, strange pacing, no breathing sounds, odd word emphasis. These were useful. They are not now, for three reasons:
- The tools improved. Emotion, breath and hesitation are all reproducible.
- The scenario covers the gaps. Someone sobbing on a bad line is expected to sound wrong.
- Recognition is not analysis. Hearing a familiar voice triggers recognition before any conscious assessment starts. By the time you are evaluating, you have already believed it.
The two things that do work
1. Hang up and call back
End the call. Then dial the person yourself, using the contact already in your phone — not a number the caller gave you, not a number that appeared on your screen.
This works because the attacker controls the call they made to you, and controls nothing about a call you originate. Caller ID can be spoofed to show any number; an outbound call cannot be redirected.
If they do not answer, call someone else who would know — a sibling, a partner, their workplace, the place they said they were.
When they say there is no time: there is. A real emergency survives sixty seconds. That objection is not an obstacle to verification; it is a reason for it. Urgency manipulation explains why the pressure is always the first thing to arrive.
2. Use a code word
A short phrase your family agreed in advance, that anyone claiming an emergency can be asked to say.
Setting one up:
- Pick something unguessable — not a pet's name, a street, a birthday, or anything findable on social media. A random pair of unrelated words works well.
- Share it in person or by voice, not in a group chat or a shared document.
- Include everyone who might be called about, or called by: children, parents, grandparents, partners.
- Practise it once. The reason code words fail is embarrassment — people feel rude asking. Using it once as a joke removes that permanently.
- Agree the rule: no code word, no money, no exceptions.
The request is still the strongest signal
Whatever the voice sounds like, some requests are fraudulent by construction. Treat these as automatic stops:
- Gift cards — no court, hospital, lawyer or police force takes them
- Cryptocurrency or a crypto ATM
- A wire transfer to a name you do not recognise
- Cash handed to a courier, or left somewhere
- Payment through an app to a stranger
- A two-factor code read aloud. The FBI's guidance is blunt: never provide a two-factor code to anyone over email, text or a messaging app
- Secrecy from the rest of your family
Real institutions have processes, references and letters. None of them require you to be the only person who knows.
Reduce what can be cloned
You cannot prevent this entirely, and it is not your fault if you are targeted. A few things do reduce the raw material:
- Use the default voicemail greeting rather than one in your own voice.
- Consider who can see videos where you speak clearly at length.
- Do not engage with unexpected "wrong number" calls. A polite few sentences is a usable sample. Hang up.
- Think about children's accounts, where public video is common and the emotional leverage of a cloned child's voice is highest.
- Be careful what your family shares about travel — a scam is far more credible when the caller knows someone is genuinely abroad.
If you get one of these calls
- Say you will call back, and hang up. You do not need a reason or an apology.
- Call the person on the number you have saved.
- If you cannot reach them, call someone else who would know. Do not treat an unanswered phone as confirmation.
- Ask for the code word if you are still talking to them.
- Do not send anything until you have spoken to the real person.
If you already sent money
Move quickly, and do not spend time on self-blame — these calls are built to work on people who love someone.
- Contact whoever moved the money immediately — bank, card issuer, wire company, gift card issuer, crypto exchange. Speed is the main variable.
- Report it at IC3.gov and ReportFraud.ftc.gov, or your country's equivalent. How to report an online scam covers what each does.
- Warn the family, including the person who was impersonated. The same number often calls other relatives.
- Expect a follow-up offering to recover the money. That is the second scam.
- Set up the code word now, while everyone is paying attention.
Key takeaways
- Cloned voices are good enough that listening is not a test.
- Verify through a channel you control — hang up and call back on a saved number.
- Agree a family code word in advance, and practise using it once.
- Urgency and secrecy are the two features every version shares.
- Gift cards, crypto, wire transfers and cash couriers are fraudulent requests regardless of who appears to be asking.
The wider category — what AI has and has not changed about fraud — is covered in AI scams, and the phone channel itself in vishing and voice phishing. For verifying people you have never met, see how to verify someone's identity online.
Set the code word tonight
SafeSurf IQ helps families put verification habits in place before they are needed, with scripts for the awkward conversations.
Try it freeFrequently asked questions
- How can I tell if a phone call is really from someone I know?
- Not by listening. Hang up and call them back on the number already saved in your phone, or reach them another way - a message on an app you both use, or a call to someone who is with them. Verification has to run through a channel the caller does not control. If the voice is genuine, calling back costs a minute; if it is not, calling back is the whole defence.
- Can AI really clone someone's voice?
- Yes, and it no longer takes much source audio. Publicly available tools can produce a convincing imitation of someone's voice from a short clip of clear speech - a voicemail greeting, a social media video, or a few sentences spoken on a call. The FBI has warned about AI-generated voice messages being used to impersonate people in order to build trust with targets.
- What is a family code word and how do I set one up?
- A family code word is a short phrase everyone in your household agrees on in advance, so anyone claiming an emergency can be asked to say it. The FBI recommends creating a secret verification phrase with family members. Choose something not guessable from social media, tell everyone in person or by voice, do not write it in a shared document, and practise using it once so nobody feels awkward asking.
- What if the caller says there is no time to call back?
- That sentence is the scam. Urgency exists to prevent verification, which is precisely why verification is the right response to it. No real emergency is made worse by one minute spent confirming who you are talking to, and no genuine hospital, lawyer or police officer objects to you calling back on a published number.
- Can I hear the difference between a real voice and a cloned one?
- Sometimes, and not reliably enough to depend on. Older clones had flat emotion, odd pacing or clipped breathing. Current ones often do not, and a distressed caller with a poor phone line explains away any oddity you notice. Treat any tell you spot as a bonus, never as your test - and never treat a voice that sounds right as proof.
- Does this happen on video calls too?
- Yes. The FBI has warned about AI-generated video being used to impersonate senior officials, including in schemes aimed at people who had already lost money to fraud. The same rule applies - a face on a screen is not identification. Verify through a separate channel you initiated, and be especially careful with any video call that ends in a payment request.
Sources
- Senior US Officials Impersonated in Malicious Messaging Campaign — FBI Internet Crime Complaint Center, 2025
- Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign — FBI Internet Crime Complaint Center, 2025
- 2025 Internet Crime Report — FBI Internet Crime Complaint Center, 2026
- How To Avoid Impostor Scams — Federal Trade Commission, 2026
- FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025 — Federal Trade Commission, 2026
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Phishing
Someone called claiming to be my bank — is it real?
A call that says it's your bank, the police or tech support can feel completely convincing in the moment. Here is how to check without staying on the line - and why hanging up and calling back yourself is the only test that works.
- Online Scams
AI scams: voice clones, deepfakes and synthetic identities
The FBI's 2025 report included artificial intelligence for the first time in the IC3's near-25-year history — 22,364 complaints and roughly $893 million. AI has not invented new scams; it has removed the tells that used to expose the old ones.
- Social Engineering
Urgency manipulation: why deadlines are the scammer's best tool
Almost every scam contains a deadline, and the deadline is rarely about the story. It is there to remove the interval in which you would have checked — which is the only interval that matters.