How to spot and avoid AI voice scams.
The four scams we see most. What attackers say, what they ask for, and the verification habits that defeat them.
An AI voice scam uses a cloned or synthetic voice to impersonate someone you trust, a relative, an executive, or IT support, and pressure you into an urgent, irreversible payment or disclosure. Defeat it by slowing down, hanging up, and calling back on a number you already trust, then verifying the audio with a detector before you act.
The four common patterns
1. The family emergency
You receive a call (or voice note) from someone who sounds exactly like a relative. They are in distress. They have been kidnapped, arrested, in an accident. They need money now and they cannot talk long. They name a payment method that cannot be reversed: wire transfer, gift cards, crypto.
2. The CEO wire transfer
You work in finance. You receive a call from someone who sounds like a senior executive (CEO, CFO, controller). They need you to wire a payment immediately to close a deal that "cannot wait until tomorrow." They ask you to bypass the normal approval process. They are confident, in a hurry, and they know enough about the business to sound legitimate.
3. The IT support callback
An attacker who has done their homework calls posing as your IT department. The voice sounds familiar (cloned from internal town-hall recordings posted online). They claim to have detected suspicious activity on your account and need you to "verify" your credentials.
4. The recruiter or vendor
Less dramatic. An attacker uses a cloned voice to set up an inbound call (fake job offer, fake vendor opportunity, fake investor inquiry) that ends with an attempt to extract information or money. Usually pairs with a fake email and a fake LinkedIn profile.
| Scam | Pretext | Who it targets | First defense |
|---|---|---|---|
| Bank fraud dept | "Move your money to a safe account" | Account holders | Hang up, call the number on your card |
| Executive (CEO) | Urgent, confidential wire | Finance teams | Dual approval, callback |
| Family emergency | Accident or arrest | Older relatives | A family code word |
| Tech support | "Your device is infected" | Anyone | Never grant remote access |
Two of these deserve their own playbooks: CEO fraud aimed at finance teams, and the grandparent scam aimed at older relatives.
Why AI voice scams work
Two things changed at once. The cost of cloning a convincing voice collapsed to seconds of sample audio and a free trial, and the volume of imposter fraud kept climbing. The US Federal Trade Commission reports that imposter scams were the most-reported fraud category in 2023, and the FBI's Internet Crime Complaint Center continues to log large losses from business-email and executive-impersonation fraud, which voice cloning makes more convincing.
The mechanism is psychological, not technical. A familiar voice short-circuits the part of your judgment that would normally pause. Add urgency and secrecy and the target acts before verifying. The defense is a habit, not a gadget: verify through a channel you already trust, every time, no exceptions for "just this once."
What strikes me most, having listened to a lot of these, is how little the voice has to do. The clone buys three or four seconds of trust, and the script does the rest. That is why I stopped treating scam defense as a listening problem. You will not reliably hear the seam, and neither will I. The move that actually works is procedural: slow the moment down, break the channel the attacker chose, and verify on one you control. Everything else, the code words, the callbacks, the detector pass on a saved clip, is a variation on that one idea. Once you internalise it, the specific script stops mattering, and you stop trying to out-listen a technology that is designed to be believed.
Red flags they all share
- Urgency. The decision must be made now. No time to think.
- Process bypass. The normal verification steps are inconvenient and the caller suggests skipping them this once.
- Irreversible payment. Wire, crypto, gift cards. Not credit cards. Not anything chargeback-able.
- Secrecy. "Do not tell anyone yet" or "this is confidential" or "the lawyer said not to discuss".
- Off-channel. The call or voice note arrives through a less-verified channel (WhatsApp, SMS, Telegram) rather than the channel where you would expect to hear from this person.
How to verify before you act
- Hang up. Then call back on a verified number (the one in your contacts, not the one that called you).
- Use a code word. Families and finance teams should have a code word agreed in advance. Real family members and real executives will know it.
- Run the audio through the detector. Save the voice note, drop it at /is-this-ai. A verdict in half a second is faster than the attacker expects you to be.
- Ask a question only the real person knows. Not generic ("what is my dog's name", which might be on Instagram), but specific ("what did we eat together last Sunday").
None of these steps take long, and that is the point. A cloned voice is convincing, but it cannot survive a callback to a number you already trust or a question that is not searchable online. If you want to know which system likely produced a clip after the fact, the detector names the source model where it recognizes one, which is useful when you file a report. For the acoustic tells worth listening for, see how to verify AI audio. Most of these calls are vishing, voice phishing built to rush you.
If you run a fraud or security team, see how this fits a review workflow in our voice fraud detection use case.
If it happens to you
Save the audio. Note the time, the number, and exactly what was said. Report it: to your bank if money moved or nearly did, to local police, and to the FTC at reportfraud.ftc.gov (US) or your national equivalent. The saved audio and a citable verdict give investigators something concrete to work with, and you can identify the likely generator if that helps the report.
Frequently asked questions
What is an AI voice scam?
A scam that uses a cloned or synthetic voice to impersonate someone you trust and pressure you into sending money or sharing access. The voice may be built from seconds of public audio, and the ask is almost always urgent and irreversible.
How do I know if a call is an AI voice?
By ear, listen for too-even pacing, missing background noise, and identical prosody. The reliable check is to hang up, call back on a trusted number, and run any saved audio through a detector, which returns a probability and confidence in about half a second.
What should I do if I get an AI voice scam call?
Do not act on the call. Hang up and call the person or company back on a number you already have. Never send wire transfers, gift cards, or crypto on the strength of a phone call, and use a family or team code word to confirm identity.
Can AI voice scams be detected?
The audio can. Save the voice note and run it through a detector; it reads the synthesis signature even when the clip sounds convincing. Confidence drops on short or compressed audio, and the detector says so rather than guessing.
Who do I report an AI voice scam to?
In the US, report to the FTC at reportfraud.ftc.gov and, for financial loss, the FBI's IC3 at ic3.gov, plus your bank and local police. Other countries have equivalent fraud-reporting bodies.
Slow down. Hang up. Call back on a number you trust. If you are still not sure, run the audio.