Understanding AI
AI scams: cloned voices, fake images and what to do about them
The same technology that makes AI useful has made a particular kind of scam much more effective. This is worth understanding before it arrives, because the defence is simple and it only works if arranged in advance.
What has changed
Voices can be copied from a few seconds of audio. Software that once needed hours of recordings now needs a short clip. A voicemail greeting, a video posted online, or a few words answering an unexpected call is enough.
Written scams no longer read as scams. The clumsy grammar that used to give them away is gone. Scam emails and texts are now fluent, correctly spelled and convincingly personalised.
Images and video can be fabricated convincingly. Photographs of events that never happened, and video of people saying things they never said.
None of this creates a new type of crime. It makes the existing ones more persuasive.
The one to know about
A relative rings, distressed. It sounds exactly like them, because it is their voice. There has been an accident, or an arrest, or they are stranded. They need money now and they cannot talk long.
Sometimes another person takes over the call: a police officer, a lawyer, a hospital administrator. They are calm and authoritative and they explain what needs to happen.
It is very effective, because it bypasses judgement entirely. You are not evaluating a story, you are hearing somebody you love in trouble.
The defence
Agree a family password now.
Choose a word or phrase that every member of your family knows and that appears nowhere online. Not a pet’s name, not a birthday, not a street you lived on, because all of those are discoverable. Something arbitrary: blue teapot, Nan's caravan.
The rule is simple. If anybody rings claiming to be family and asking for money or urgent action, ask for the password. Somebody who cannot produce it is not who they claim to be, whatever they sound like.
Tell every member of your family this week. It takes one conversation and it defeats the entire category of scam.
If you have not arranged one, the fallback still works: hang up and ring them back on the number you already have. Do not use a number they give you. If they say their phone is broken, ring another family member and check.
Other things worth knowing
Urgency and secrecy remain the giveaways. The technology got better; the psychology did not change. Any call pushing you to act immediately and to avoid telling anybody else is a scam, however convincing the voice.
No payment method changed. Gift cards, cryptocurrency and transfers to unfamiliar accounts are still the tell. No genuine emergency has ever been resolved with iTunes vouchers.
Video calls can be faked too, though it is harder and less common. Do not treat seeing someone as proof, particularly on a poor connection where oddness is easy to explain away.
Reduce what is publicly available. Voice cloning needs a sample. Public social media videos, public voicemail greetings and public posts all supply one. Setting family accounts to private is worth doing anyway.
Spotting fake images
Less critical for household scams, but worth knowing since fabricated images spread constantly.
The old tells like extra fingers are largely fixed. What tends to remain:
- Text in the image, on signs or clothing, is often subtly wrong
- Backgrounds that do not quite make sense on close inspection
- Jewellery, glasses and patterns that do not stay consistent
- Skin and lighting that look slightly too smooth or too even
But the honest position is that you increasingly cannot tell by looking, and you should not rely on being able to.
Check the source instead. Where did it come from? Is a news organisation reporting it? Does a search for the same image show it appearing elsewhere first? Provenance is the reliable test now, not appearance.
What this does not mean
It does not mean everything is fake and nothing can be trusted. That reaction is as unhelpful as being credulous, and a fair amount of coverage encourages it.
The practical position is unchanged from before any of this existed:
- Verify through a channel you chose, not one somebody handed you
- Slow down when something is urgent
- Confirm with a second person before money moves
Those three habits handled every scam that came before, and they handle these too.
Tell the older people in your family
The people most likely to be targeted by a cloned-voice call are grandparents, and they are the least likely to have heard that it is possible.
One conversation this week, agreeing a family password, is genuinely one of the more valuable things you can do. The broader scam guide is worth passing on at the same time.
If you would rather somebody went through all of this properly with an older relative, that is a standard part of lessons for seniors, and the Staying Safe Online class covers it in a group on Wednesday afternoons.