Global Scam IntelligenceDaily updates on global scam news and tactics
← Back to home
AI Voice ScamsPublished: September 28, 2026🌐

Fighting AI Voice Clone Fraud: A Simple Family Security Word Defense

AI-generated voice clone fraud is becoming increasingly common, with one in four Americans reporting receiving a deepfake voice call in the past year. ESET experts recommend a simple, free defense: establishing a pre-agreed family security word to verify the caller's identity.

The Growing Problem of AI Voice Clone Fraud

AI-generated voice clones have become a standard tool for fraudsters. According to a March 2026 survey by Hiya, one in four Americans reported receiving a deepfake voice call in the past year, and another 24% admitted they cannot distinguish between real and synthetic voices. Alarmingly, twice as many respondents believe scammers are winning against mobile carriers when it comes to voice cloning technology.

Criminals need only a few seconds of audio to create a convincing voice imitation. This material often comes from unrestricted social media posts or work-related audio files that circulate online without proper privacy controls.

How Criminals Use Cloned Voices

One of the most common fraud tactics is "virtual kidnapping." Criminals call a family member and play a fake audio clip to convince them that a loved one has been kidnapped. They add credibility by including personal details harvested from social media accounts and may even monitor victims' profiles to choose the optimal moment to strike—for example, when the supposed victim is traveling and difficult to reach.

The key to pulling off the deception is keeping the family confused and emotionally distressed. That's why scammers typically use the cloned voice for only a few seconds, mixing it with crying and background noise that creates a chaotic, authentic atmosphere.

The Family Security Word Solution

A security word is a pre-agreed word or phrase that any family member can request when they suspect a voice may be fake. Since a scammer has no way of knowing it, they cannot pass verification. The word should be easy to remember but uncommon and not something that can be deduced from social media or other publicly available information. Obvious choices like a pet's name or favorite sports team should be avoided.

How to Introduce the Idea to Your Family

This topic requires careful handling—the goal is not to alarm family members but to ensure everyone understands that technology has advanced and that some people exploit it. It helps to clarify that the security word will probably never need to be used, and to review specific situations when it should be requested, such as unexpected, distressing calls from someone claiming to be a family member asking for money or personal information.

If Someone Forgets the Security Word

Having a backup plan is recommended. The best approach is to hang up and reconnect using a phone number already saved in your contacts, or message through an existing family chat group to confirm whether the person is actually in trouble. You can also ask a question whose answer only the family knows and cannot be found online. Everyone should understand that money should never be sent or personal information shared if anything seems suspicious.

If You've Already Been Victimized

ESET emphasizes there is no shame in falling victim to this scam—the technology is increasingly convincing. The recommended steps are:

  • Immediately cut all contact with the scammer
  • Alert your bank to determine if it's possible to block or recover transferred funds
  • Change any passwords that may have been exposed, activate two-factor authentication (2FA), and use unique, strong passwords stored in a password manager
  • Preserve all available evidence, such as phone numbers or voice recordings
  • Report the incident to relevant authorities

ESET also warns against anyone who promises to recover your money for a fee or offers to "protect" your accounts—they are lying, and paying them only increases your losses.

Frequently Asked Questions

How do scammers get my voice? They need only a few seconds of audio from a work-related recording or audio/video you've shared on social media. For this reason, it's recommended to limit who can access your posts to people you actually know.

Does a security word really stop deepfakes? Nothing is foolproof, and the word doesn't prevent deepfake generation. However, it's a free and highly effective measure for detecting fraud based on fake audio, such as virtual kidnapping, because it dramatically reduces the likelihood the scam will succeed.

What if they guess the security word? It's possible but unlikely if you choose a random, uncommon phrase without obvious meaning outside your family circle. Still, having backup plans—such as agreeing to call back on a known number—is advisable.

Source: Infosertec

Share