Quick answer: AI can now clone a voice from as little as three seconds of audio, so listening for robotic pauses or vocal glitches is no longer a reliable way to spot a fake. The checks that still work are behavioural: unexpected urgency, a request to keep the situation secret, pressure to send money or gift cards, and any request you cannot verify through a second, independently known contact method. Setting up a family or team “safe phrase” is the single most effective defence.
A grandparent hears their actual grandchild’s voice say they have been in an accident and need bail money urgently, and not to tell anyone. The voice is real, cloned from a TikTok video, and the emergency is not. This is the shape of the fastest-growing phone scam of 2026, and the old advice for spotting it no longer works.
Why the Old Advice Stopped Working
For years, the standard guidance was to listen for strange pauses, a slightly robotic tone, or vocal fluctuations that gave away a synthetic voice. That advice is now outdated. As AI voice technology has advanced, those tell-tale glitches have largely disappeared. A voice cloned today from a few seconds of audio, scraped from a social media video, a voicemail greeting, or a video call, can be convincing enough that relying on how the voice sounds is no longer a safe way to confirm who you are actually speaking to.
Security researchers now advise shifting the focus entirely, away from analysing the voice itself and toward the behaviour and structure of the call.
The Behavioural Red Flags That Still Work
Unusual Urgency
Almost every voice cloning scam leans heavily on urgency. The caller has been arrested, is in an accident, urgently needs medical help, or claims an account is in immediate danger. This pressure is deliberate: it gives you less time to think clearly or verify the story independently. A genuine emergency involving someone you know rarely requires an instant, unverified financial decision made over the phone.
Pressure to Keep It Secret
Be especially cautious if the caller asks you not to tell anyone else about the situation. Scammers isolate the moment deliberately, since a second person, a spouse, a colleague, another family member, is often the one who would catch the story falling apart.
Requests for Money Through Hard-to-Trace Methods
Wire transfers, cryptocurrency, gift cards, or payment apps are the preferred methods in these scams specifically because they are difficult or impossible to reverse once sent. A request to move money quickly through one of these channels, especially paired with urgency, is a serious warning sign regardless of how familiar the voice sounds.
Inconsistencies in the Story
Ask a follow-up question a scammer would not expect, something specific only the real person would know. Voice clones can mimic tone and cadence convincingly, but the underlying script often cannot adapt naturally to unexpected, specific questions the same way a genuine conversation would.
Never Trust Caller ID
Spoofing a phone number to display a trusted contact’s name costs almost nothing and works against most carriers. Seeing a familiar name or number on your screen is not confirmation of who is actually calling. If a call feels wrong, the number displayed should not be treated as reassurance.
Set Up a Family or Team Safe Phrase
This is the single most effective defence security experts recommend, and it works because of a simple limitation: AI can clone a voice, but it cannot know a private, pre-agreed word it was never trained on. Agree on a short phrase with close family members or, for businesses, with your finance team, that must be provided before you act on any urgent request involving money or sensitive information. If the caller cannot provide it, treat the call as fraudulent.
Always Verify Through a Second, Known Channel
If you cannot immediately confirm a safe phrase, hang up and call the person back using a phone number you already know is correct, not the number that just called you and not a number the caller provides. This single habit defeats the overwhelming majority of voice cloning scams, because it removes the attacker’s control over the conversation entirely. Most victims who avoided losing money did so by taking exactly this step before acting.
This Is Not Just a Family Scam
Businesses face a version of the same attack, sometimes called vishing, where a cloned executive’s voice contacts a finance team requesting an urgent wire transfer. This is not a hypothetical risk: in one widely reported 2024 case, a finance worker wired over 25 million US dollars after a video call where every face and voice present, including the “CFO,” was AI-generated. Security researchers report AI-powered scam activity surged over 1,200 percent in a recent year, with voice cloning specifically flagged as a top emerging threat by law enforcement.
Organisations should apply the same core defence at scale: a verification protocol for any unusual financial request, regardless of how convincing the voice or video on the call appears, and a clear escalation process for employees who suspect a call is fraudulent.
What to Do During a Suspicious Call
- Stay calm and resist the pressure to act immediately.
- Ask for your pre-agreed safe phrase, or a specific detail only the real person would know.
- Do not send money or provide sensitive information while still on the call.
- Hang up and call the person back on a number you already know is theirs, never the number that called you.
- If you cannot reach them directly, contact another trusted family member or colleague to verify the situation before doing anything else.
If You Have Already Sent Money
- Contact your bank or payment provider immediately to report the transaction and ask about reversal options, particularly for wire transfers reported within the same day.
- Report the incident to your local law enforcement and, in the United States, the FTC or FBI’s Internet Crime Complaint Center.
- Change passwords for any account you may have discussed or referenced during the call.
- Warn the person whose voice was cloned, so they can alert others who might also be targeted using the same cloned audio.
Common Questions
Can you still tell an AI voice clone by how it sounds?
Not reliably anymore. Robotic pauses and vocal glitches that used to give away a synthetic voice have largely disappeared as the technology has improved. Focus on behavioural red flags and verification instead of the voice quality itself.
How much audio does it take to clone someone’s voice?
As little as three seconds, scraped from something as ordinary as a social media video, voicemail greeting, or video call clip.
What is a safe phrase and how do I set one up?
A short, private word or phrase agreed in advance with family members or a work team, which a genuine caller must be able to provide before you act on an urgent request. Since it was never shared publicly, an AI voice clone cannot know it.
Should I trust a call if the caller ID shows a number I recognise?
No. Caller ID can be spoofed cheaply and easily, and a familiar number or name displayed on your screen is not proof of who is actually calling.
What should I do if I already sent money to a voice cloning scammer?
Contact your bank or payment provider immediately to report the transaction, report the incident to law enforcement, and warn the person whose voice was used so others are not targeted with the same recording.
The Bottom Line
AI voice cloning has made listening for a fake voice an unreliable defence. The checks that still work focus on behaviour, not sound: unusual urgency, pressure for secrecy, requests for money through hard-to-trace methods, and any request you cannot verify through a channel you already trust. A pre-agreed safe phrase and a habit of calling back on a known number close off the vast majority of these scams, regardless of how convincing the cloned voice on the other end sounds.
