The voice on the phone sounds familiar: recognising AI-enabled scams
New to AI6 min readAI Safety & Data Privacy

The voice on the phone sounds familiar: recognising AI-enabled scams

A calm, practical guide to voice-clone emergencies, impersonation messages, fake media, and AI-polished scams — with a family verification plan that works even when the fake looks or sounds convincing.

What you should be able to do

Do not try to out-detect a convincing fake. Stop, end the contact, and verify the story through a channel you already trust.

AI Expert TeamPublished: Jul 28, 2026
Saved only in this browser.
In this article

The call sounds like your daughter. She says she has been in an accident, her phone is about to die, and she needs money now. The voice shakes in exactly the way you would expect. You can even hear traffic behind her.

It may still be a scam.

Artificial intelligence did not invent family-emergency fraud, fake invoices, romance scams, or impersonation. It made convincing text, images, and voices cheaper to produce. That matters because many of the clues people were taught to look for — poor spelling, an unfamiliar accent, an obviously edited photo — are no longer dependable.

The answer is not to become an expert deepfake detector. It is to use a verification procedure that remains safe when the message is polished and the voice is familiar.

[!SAFETY] Urgency is a reason to verify, not a reason to skip verification. End the contact and call the person, bank, or organisation using a number you already know or find independently.

Four patterns to recognise

1. The family emergency

Someone who sounds like a relative says they have been arrested, injured, stranded, or kidnapped. A second person may take over as a police officer, lawyer, doctor, or kidnapper. The story creates fear, demands secrecy, and makes delay sound dangerous.

The US Federal Trade Commission’s family-emergency scam guidance warns that scammers can clone a loved one’s voice from a short audio sample and recommends calling the relative on a number you know. The FBI also recommends a private family word or phrase in its impersonation campaign alert. Both sources were rechecked on 28 July 2026.

The defence is not “listen more carefully.” End the call. Contact the relative directly. If they do not answer, contact someone physically near them.

2. The boss, bank, or authority message

A message appears to come from a manager, bank employee, police officer, tax authority, courier, or service provider. It may refer to real names, projects, account details, or recent events. The request is usually one of these:

  • transfer money or change bank details;
  • buy gift cards or cryptocurrency;
  • disclose a password, PIN, or one-time code;
  • install remote-access software;
  • open a link or attachment;
  • keep the request confidential.

AI can make the language natural and adapt it to your role. Caller ID and display names can also be spoofed, so a familiar name on the screen is not proof.

The safe response is the same: do not use the contact details supplied in the message. Find the official number yourself, or use the number already saved in your contacts, and start a new conversation.

3. The convincing relationship

Generative tools help a scammer maintain many long, personalized conversations. The persona may be a romantic interest, recruiter, investment adviser, customer, landlord, or marketplace buyer. Images, documents, and even video calls can be manipulated.

Watch the behaviour rather than trying to judge the media:

  • the relationship moves unusually fast;
  • every attempt to meet or verify ends in a new excuse;
  • money, account access, identity documents, or intimate material enter the conversation;
  • a supposed investment requires moving money to an unfamiliar service;
  • the person asks you to receive or forward money for them.

A real-looking profile does not make a financial request safe. Pause and discuss it with someone outside the conversation.

4. The fake proof

A voice note, screenshot, invoice, photo, or video is presented as proof that something happened. It may show a CEO authorising a payment, a relative in distress, a celebrity promoting an investment, or a bank notice confirming new account details.

Treat media as a claim, not as independent verification. Check the underlying event through a separate trusted channel. A screenshot of a bank screen is not the bank. A video of a manager is not the payment-approval process.

The verification ladder

When a request involves money, credentials, secrecy, or personal safety, climb this ladder until the story is independently confirmed:

  1. Stop. Do not pay, click, install, share a code, or continue under pressure.
  2. End the contact. Hang up or close the message. You need a clean channel.
  3. Call back independently. Use a saved number or an official website you locate yourself.
  4. Ask another person. Contact a family member, colleague, bank, or organisation that can verify the event.
  5. Verify the action, not only the identity. Even if the person is real, confirm the amount, recipient, and reason before acting.

If the caller says that hanging up will make things worse, that is an additional reason to hang up.

Set up one household defence today

Choose a family verification phrase. It should be:

  • memorable to the people who need it;
  • unrelated to facts visible on social media;
  • never used as a banking password or account-recovery answer;
  • changed if it is disclosed outside the family.

Then agree on a procedure:

Any unexpected request for money, credentials, or secrecy gets a callback on a known number. If direct contact is impossible, we check with a second family member. The family phrase helps, but it never replaces the callback.

A phrase can itself be overheard or extracted from compromised messages. It is one layer, not magic. The callback procedure is the stronger control.

Print the procedure for relatives who are not comfortable with technology. Put the known family numbers beside it. Rehearse it once: “If I called crying and asked for money, what would you do?”

What not to rely on

A familiar voice. Cloned and edited audio can sound convincing, and an attacker may mix synthetic audio with a real recording.

A familiar number. Caller ID can be spoofed.

Secret personal facts. Names, birthdays, workplaces, travel, pets, and family connections may be public or stolen. Prefer a deliberately agreed phrase and a callback.

A video call. Video raises the cost of an attack but does not turn the conversation into verified identity. Keep the payment procedure.

An AI detector. Detection tools can be useful signals, but no detector can guarantee that a particular voice, image, or message is genuine. A procedure works without making that guess.

If money or access has already been given

Act quickly and preserve evidence:

  1. Contact your bank or payment provider immediately and ask whether the payment can be stopped or recalled.
  2. If you disclosed credentials, use a clean device to change passwords and revoke sessions. Contact the affected service.
  3. Do not delete the messages. Save phone numbers, account details, transaction references, timestamps, screenshots, audio, and the story used.
  4. In Estonia, report cybercrime through the Police and Border Guard Board at cyber.politsei.ee. RIA points victims to that channel in its current internet-safety guidance.
  5. If somebody may be in immediate physical danger, call 112.

Do not pay a second person who promises to recover the money. Recovery scams target people who have already been defrauded.

A two-minute family briefing

Use this wording:

“Voices, photos, and messages can now be convincingly faked. If any of us unexpectedly asks for money, a code, or secrecy, end the call and ring back on the number you already have. Our family phrase is ____. It helps confirm us, but we still call back. Nobody will be angry with you for checking.”

That final sentence matters. A useful control has social permission behind it. People skip verification when they fear insulting a manager or failing a relative.

The honest limit

You cannot make every incoming contact trustworthy. You cannot keep all family information private, and you cannot reliably identify every synthetic voice or image by eye or ear.

You can make an urgent story wait for independent confirmation.

The technology in the attack will keep changing. The procedure does not need to: stop, leave the channel, call back using trusted details, and involve another person before money or access moves.

Read next

Continue through the same learning path with the next practical articles.

Take it further

Hand-picked external courses that go deeper on this topic.

AWS Skill Builder

AWS Security: Securing Generative AI on AWS

AWS Training and Certification

A cloud-vendor-specific complement to the Macquarie specialization: AWS's own Generative AI Security Scoping Matrix, OWASP Top 10 for LLMs, and MITRE ATLAS, walked through governance, legal, and compliance controls for five different AI deployment scopes — from consumer apps to self-trained models. Not GDPR-specific, but a genuinely practical advanced pick for teams whose AI workloads actually run on AWS and need concrete data-governance and compliance controls, not just theory.

Advanced~2 hours · self-paced (9 modules)
Coursera · Macquarie University

Cyber Security: Data, Privacy and AI Security

Macquarie University Cyber Security Hub faculty

The advanced, most explicitly on-target answer to our GDPR × AI gap: a three-course specialization from Macquarie University's Cyber Security Hub that goes from GDPR/CCPA fundamentals and privacy-by-design, through privacy impact assessments, to a dedicated third course on securing AI systems against adversarial attacks and model leakage. Genuinely bridges 'GDPR compliance' and 'AI security' rather than treating them as separate topics.

Advanced~47 hours · self-paced (3-course specialization)
EU Digital Skills & Jobs Platform · CyberSuite

Secure AI Adoption for SMEs: Cybersecurity and the EU AI Act

CyberSuite

The rare AI Act course written for the companies the Act actually reaches: SMEs adopting AI, not the labs building it. Hosted on the European Commission's own skills platform, it pairs the legal side — roles, obligations, risk classification — with the security side (prompt injection, data leakage, supplier due diligence) that most compliance courses skip. For an Estonian SME deploying AI, this is the practical starting point.

Advanced~15 hours · self-paced

See all courses for AI Safety & Data Privacy