The classic version of this scam used to require an attacker who could do a passable impression, or a victim relaxed enough not to question a slightly-off voice on the phone. Neither is required anymore. Current voice-cloning tools can produce a convincing replica of a specific person's voice from a few seconds of audio — a voicemail greeting, a public video, a clip posted online is enough.

The call that follows is built around the same emotional formula phishing emails use, just with a more convincing delivery: a loved one in trouble — an accident, an arrest, a stranded emergency — asking urgently for money, and asking you not to tell anyone else in the family "to avoid embarrassment" or "because there's no time." The isolation instruction is doing real work: it's specifically designed to stop you from doing the one thing that would expose the scam, which is calling that person or another family member to check.

Why a familiar voice stopped being proof

The uncomfortable truth: if a scammer has three seconds of someone's voice from anywhere public, they can generate new sentences in that voice — words the real person never said. Recognizing the voice is no longer evidence the call is genuine.

The defense that still works: a code word

A pre-agreed verification phrase works precisely because it doesn't depend on recognizing anything about the call itself — not the voice, not the story, not the caller ID. Either the person on the phone knows the word, or they don't.

Other tells worth knowing, even though they're not proof on their own

The takeaway

The old advice — trust the voice, question the story — has effectively inverted. The voice can no longer be trusted on its own, and the story is often airtight by design. A code word sidesteps both problems by relying on something a clone of anyone's voice still can't produce: a fact only your family actually knows.

GOOGLE AD SLOT — IN-ARTICLE (responsive)
GOOGLE AD SLOT — END-OF-ARTICLE (responsive)