Scams

AI Voice Cloning Scams and the "Family Password" Method

Your child's voice on the phone: crying, saying they are in trouble and asking for money right away. But it is not them calling. AI can imitate someone's voice from a recording just a few seconds long. This guide explains this new scam and the simplest defence against it: a family password.

It is eleven at night. The phone rings and the voice is her daughter's: "Mum, I've had an accident, I'm so scared, please help me!" Then someone else takes the phone and says her daughter is in trouble and things will get worse unless money is sent right away. The voice is so real that it is almost impossible for a mother to doubt it.

But it is not her daughter calling. It is a voice copy created with AI.

Voice cloning technology has developed at an incredible speed in the last few years and is now available to anyone. That makes the old "your relative has had an accident" scam much more convincing. In this guide we explain how this threat works, how it can be spotted, and the simplest and most effective defence a family can use against it: a family password.

How voice cloning works

Voice cloning software analyses a short recording of a person and produces an artificial voice that imitates their tone, accent and way of speaking. For some tools, a recording of just a few seconds can be enough.

Where do scammers find these recordings?

  • Videos shared on social media (Instagram, TikTok, YouTube)
  • Voice messages
  • Public speeches and interviews
  • Even a short phone call made on the pretext of a "wrong number"

Once the voice has been copied, the scammer can have any sentence they write read out in that person's voice or, with some advanced tools, talk in real time.

Typical scenarios

  • Emergency: A child or grandchild says they have had an accident, been arrested or been kidnapped, and urgently needs money.
  • Fake ransom: A voice saying "We have your daughter" with a child crying in the background. In reality the child is at school or at home.
  • Workplace fraud: A company director's voice is imitated to request an urgent transfer from the finance team.
  • A familiar favour: "My phone broke, I'm calling from this number, you need to make an urgent payment."

What all these scenarios have in common are the old scam tactics: panic, urgency and secrecy. The technology just makes the voice more convincing.

How to spot a fake call

Even if the voice is perfect, some signs can catch your attention:

  • Extreme urgency: You are given no chance to think or to call anyone.
  • A request for secrecy: "Don't tell Dad", "Don't tell anyone."
  • Unusual payment methods: Crypto, gift cards, a transfer to an account you do not know, or a "courier" coming to collect money or gold from your home.
  • Short, broken speech: The voice uses short sentences, does not answer questions directly and hands the call over to someone else (a fake police officer, a lawyer, "the other party").
  • An unknown number: "My phone broke, I'm calling from a friend's phone."
  • Vagueness about personal details: Changing the subject when you ask something only that person would know.

But let's be honest: in a moment of panic, noticing these signs is very hard. That is why you need a simple method agreed in advance.

What is a family password?

A family password is a word or short phrase that the family agrees on in advance and that only they know. When someone on the phone claims to be a family member and asks for urgent help, you ask for the password. If they do not know it, however convincing the voice is, you do nothing until you have verified the situation.

The strength of this method is its simplicity: no AI can know a word that no one has written down and that has never been shared online.

How to choose a family password

What makes a good family password

  • It should be unguessable: Not information that can be found on social media, such as a pet's name, birthdays or a street name.
  • It should be memorable: Simple enough to remember even in a panic. For example, "orange elephant" or "lemon cake".
  • It should never be written down: Not shared by message, email or social media. It is best agreed face to face.
  • Everyone should know it: Children, older relatives, partners and, if necessary, close relatives who may pick the children up from school.

Putting the password into practice as a family

  1. Bring the subject up at dinner one evening and explain why it is needed.
  2. Choose the password together.
  3. Role-play it: "What would you do if someone called you saying they were me?"
  4. Remind children and older relatives again a few weeks later.
  5. If the password is exposed in any way (for example, someone sends it by message by mistake), change it immediately.

Step by step when a suspicious call comes

  1. Try to stay calm. Scammers rely on panic.
  2. Ask for the family password. "OK, I'll help you. But first, tell me our password."
  3. If there is no password, or it is wrong, hang up.
  4. Call your relative yourself on the number you know. Do not call back the number that called you.
  5. If you cannot reach them, verify another way: Call their partner, school, workplace or friends. If they share their location, check it.
  6. Never send money without verifying.
  7. If you suspect real danger, call your local emergency number.

Protecting voice recordings

It is not possible to prevent voice cloning completely, but you can reduce the risk:

  • Set social media accounts to private: Make sure, in particular, that videos with children's voices are not public.
  • Be careful with calls from unknown numbers: Calls where no one speaks, or where someone repeatedly asks "Can you hear me?", may be aimed at collecting your voice.
  • Keep your voicemail greeting simple: Use the phone's standard greeting instead of a long recording with your name and personal details.

It's not just voices

The same technology is used for images: fake videos created with AI (deepfakes) and even face imitation in real-time video calls. So the thought "they video-called me, so it must have been them" is no longer completely safe either. The family password still works here.

Protecting older relatives

Older people are among the main targets of this scam. A grandmother who hears her grandchild's voice wants to help without a second thought. When you talk to your older relatives:

  • Explain simply that technology can now imitate voices.
  • Always share the family password with them, and have them repeat it a few times rather than writing it on paper.
  • Give them the rule: "Anyone who asks for money on the phone must be verified first, even if their voice sounds familiar."
  • Ask them to call you when they get a suspicious call.

For more, see our article on scams targeting older adults.

Koriva has a dedicated tool against this scam: Verify family. When you get a suspicious call or message, you send your family member a "Is this really you?" verification request through the app, and they confirm it on their own phone. Because the confirmation is signed with a key stored only on that phone, it cannot be faked from another phone. And if family members share their location, during a call claiming "I've had an accident" you can quickly check on the map that your relative is actually at home or at school.

Conclusion

AI voice cloning is one of the most frightening new faces of fraud. But the most effective defence against it is extremely simple and completely free: a family password you agree on together over dinner. Choose your password today and share it with everyone in the family.

For general scam scenarios, see also our guide to phone scams.

Frequently asked questions

What is a voice cloning scam?

It is when scammers use AI to copy a person's voice and, speaking as that person, ask their relatives for money. The recording is usually taken from social media videos, voice messages or short phone calls.

How much recording does AI need to copy a voice?

It depends on the technology, but some tools can produce a convincing copy from a recording of just a few seconds. Longer recordings give more realistic results.

What is a family password and how do you choose one?

A family password is a word or short phrase that only family members know and that is asked for to confirm identity when a suspicious call comes in. Choose a memorable phrase that cannot be guessed from social media, agree on it face to face and never write it down.

What should I do if someone calls with my relative's voice and asks for money?

Ask for the family password; if they do not know it, hang up. Then call your relative yourself on the number you know, or verify another way. Never send money without verifying, and call the emergency number if you suspect real danger.

Could the person I see on a video call be fake too?

Yes. AI-generated fake videos and real-time face imitation technologies are improving. That is why, on video calls too, you should use a method agreed in advance, such as the family password, when money or information is requested.

  • voice cloning
  • AI scams
  • deepfake
  • family password
  • phone scams

This article is for general information and is not a substitute for medical, legal or other professional advice. In an emergency, call your local emergency number right away (112 in Europe, 911 in the US and Canada).