AI voice scams are no longer as niche as they once were. The technology is both cheap and convincing: a worrying combination that has lowered the barrier to entry for would-be scammers. According to a Hiya report from March, one-in-four Americans say they’ve received a deepfake voice call in the past 12 months. A further quarter (24%) say they can’t tell the difference.

The same study reveals that twice as many Americans think scammers are winning the battle with mobile carriers over voice clones. But it’s not a foregone conclusion. The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

How are deepfakes used by scammers?

We all think we could recognize a loved one’s voice. But cloning technology is advancing at a dizzying rate. All scammers need is a few seconds of audio to create a convincing deepfake. And that can be scraped from our social media posts, if we haven’t restricted access via the privacy settings. Or possibly work-related content that ends up being posted online.

So once they’ve cloned a voice, what do they do with it?

One of the most prominent scams involves cold calling a relative and playing deepfake audio designed to make them think their loved one has been kidnapped. These virtual kidnapping scams may be made to appear more realistic by citing personal details also harvested from the same social accounts. Scammers may also monitor the victim’s social media profile, or those of their relatives, in order to choose the best time to strike. It can be more useful for them if the victim is abroad at the time and therefore not checking their phone for incoming calls.

The key for the fraudsters is to keep the victim’s relatives guessing, and traumatized. To this end they’ll use the cloned voice only for a few seconds at a time, mix it with sobbing noises, and potentially introduce background noise to make the whole thing sound more plausible, and chaotic.

What is a safe word?

In this context, one of the simplest but most effective things you can do to see through a scam is to agree on a safe word with your family members. It should be an easy-to-remember word or phrase that the family member can request if they think that your voice may have been deepfaked. A scammer would have no way of finding out what the safe word is, thus unmasking any plot designed to trick your family into paying a ransom.

Of course, it should be memorable but also unusual. And it shouldn’t be anything that could be gleaned from reading your social media posts or other open source intelligence (OSINT) sources. That should rule out the likes of family pets and favorite sports teams for starters.

How to introduce it without frightening people

There’s a right way and a wrong way to go about agreeing on this kind of approach. You don’t want to alarm your family. But equally, you need them to recognize that technology has advanced, and there are bad people out there ready to capitalize.

It might help to explain that it’s unlikely you’ll ever be called upon to use the word. But suggest some scenarios in which it would be a good idea to request a safe word. An unsettling and unsolicited call in which someone sounding like you tries to elicit money or information from them, for example.

What if someone forgets the safe word?

It’s important to have a backup if someone can’t remember the safe word. The best thing to do is encourage family members to end the call and then ring back on the number they have for you in their address book. Or message you through an existing group you have set up. That will instantly tell them whether you are in trouble, or not.

Alternatively, they could try to ask another question that only someone in the family would know. It can’t be any info which could be researched online. They should also know never to send money or personal information if something feels wrong.

What to do if you've fallen for a deepfake scam

Don’t be embarrassed. Deepfake technology is becoming more convincing by the day. If you or a family member has been scammed:

  • Stop communicating with the scammer immediately
  • Contact your bank to explain what’s happened and ask if there is a recourse to blocking or returning the defrauded funds
  • Change any passwords that may have been disclosed across all relevant accounts. This would be a good time to switch on two-factor authentication (2FA) and update to strong, unique passwords for each account stored in a password manager
  • Preserve any relevant evidence (e.g., phone numbers, recordings)
  • Report the scam to the appropriate authorities (e.g., FTC, FBI IC3)

Remember: scammers are shameless. Be on the lookout for secondary fraudsters who will promise to get your money back for a fee, or to secure your accounts. They’re lying. Paying them will only increase your losses.

FAQs

How can scammers get hold of my voice?

They only need a few seconds of audio to produce a convincing voice clone. It could be something that was posted of you speaking in a work capacity. Or video/audio content that you shared on social media. It’s always a good idea to limit your followers to people you know.

Does a safe word really stop deepfakes?

Nothing’s fool proof. But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings. It doesn’t stop the deepfake being created. But it can reduce the success rate of the scam that follows.

What if scammers guess our safe word?

Anything’s possible. But if you choose a random, unusual word or phrase that has no real significance outside the family, it should be extremely difficult to do so. That said, it’s useful to have back-up plans in the event of such a situation, such as agreeing to call the person back.

What should I do if I’ve been scammed?

Stop all communication with your scammers. Contact your bank to notify them. Preserve as much evidence as you can. Change passwords if relevant, and report the scam to the appropriate authorities.