Three seconds. That is how much of your voice a criminal needs.
McAfee’s security researchers demonstrated it: three seconds of audio produced a clone with an 85 per cent match to the original speaker. Feed the model a handful more clips and the match climbed to 95 per cent. That was 2023. The tools have only become cheaper, faster and more convincing since, and most of them now run in a browser tab for the price of a coffee.
Three seconds is a voicemail greeting. It is the opening line of an Instagram reel. It is the “hello? hello?” you say to a silent caller before hanging up, which is precisely why some of those silent calls exist.
I have spent a long career in cyber security watching the gap between attacker capability and family awareness. Voice cloning is the widest that gap has been in years, because it attacks something no security product protects: the instinctive trust you place in a voice you have known your whole life.
The fix is not a product. It is a phrase, agreed at your kitchen table, that costs nothing.
The scam that sounds like your daughter
The family emergency scam is old. Con artists have been ringing grandparents claiming to be a grandchild in trouble for decades. What changed is that the caller no longer has to hope you cannot tell the difference. Now the voice is right.
In December 2024 the FBI’s Internet Crime Complaint Center issued public service announcement I-120324-PSA, setting out how criminals are using generative AI across fraud schemes. On vocal cloning it is blunt: “Criminals generate short audio clips containing a loved one’s voice to impersonate a close relative in a crisis situation, asking for immediate financial assistance or demanding a ransom.”
The same advisory notes a second use that gets far less attention: “Criminals obtain access to bank accounts using AI-generated audio clips of individuals and impersonating them.” If your bank uses voice as a security check, that check is now a liability rather than a protection.
How the attack actually runs
Understanding the sequence matters, because every stage is a chance to break it.
- Harvest. A few seconds of voice from a social post, a voicemail greeting, a school concert video, a work webinar, a podcast appearance, or a deliberate nuisance call recorded at the criminal’s end.
- Clone. Commodity voice synthesis, much of it free or a few dollars a month, with no technical skill required.
- Pretext. A car accident. An arrest and bail money. A hospital. A phone stolen overseas. A kidnapping claim with sobbing in the background.
- Pressure. Extreme urgency, enforced secrecy (“don’t tell Mum, she’ll panic”), and a payment channel you cannot reverse: bank transfer, cryptocurrency, gift cards.
- Cash-out. The money moves offshore in minutes, long before anyone in the family compares notes.
Notice that the technology only carries the first two stages. Stages three, four and five are pure social engineering, and they are where you can win.
The scale, stated honestly
I want to be careful here, because scare numbers are easy and they damage credibility.
Australians reported $2.18 billion in scam losses in 2025 across Scamwatch, ReportCyber, the Australian Financial Crimes Exchange, IDCARE and ASIC, from 274,577 loss-bearing reports out of 481,523 total reports. That is the National Anti-Scam Centre’s Targeting Scams Report figure, and it is up 7.8 per cent on 2024, though still down almost 30 per cent from the 2022 peak of $3.1 billion.
That $2.18 billion is all scam types, not voice cloning. Investment scams accounted for the largest single share at $837.7 million, followed by payment redirection at $166.8 million, romance at $139.9 million, phishing at $97.6 million and remote access at $69.9 million. Nobody publishes a clean “voice clone” line item, because voice cloning is a technique used inside those categories rather than a category of its own. Anyone quoting you a precise dollar figure for voice cloning fraud is guessing.
What the official data does tell us is where the technique fits. ACCC Deputy Chair Catriona Lowe put it plainly: “As Australia and indeed the world faces increasing sophistication in scam activity through Artificial Intelligence (AI) and the industrialisation of criminal syndicates through scam compounds, it is clear more needs to be done, quickly and at scale.”
Two other figures deserve your attention. In the first half of 2025 Scamwatch received 24 per cent fewer reports than the year before, yet losses rose 26 per cent to $173.8 million. Fewer hits, bigger damage: the average reported loss was $12,212. That is the signature of better-crafted attacks, not fewer of them.
The second: Australians aged 65 and over make up roughly 17.1 per cent of the population but accounted for 26.5 per cent of losses reported to Scamwatch. The distressed-grandchild call is not a theoretical risk for that group. It is the main event.
You will also see McAfee’s “1 in 4 adults has experienced an AI voice scam” quoted widely. Read the fine print: that figure includes people who knew someone affected, not only direct targets. The more useful number from the same research is that 77 per cent of people who fell for a voice scam lost money, and even that skews high because people who lose nothing rarely bother reporting.
Why “I’ll just be able to tell” is no longer true
The advice given for years was to listen for tells: flat delivery, odd pacing, robotic edges, unnatural breathing. That advice has quietly expired.
Modern synthesis reproduces breath, hesitation, laughter and regional accent. More importantly, the scam deliberately degrades the evidence. A distressed call is meant to sound wrong. Sobbing, background noise, a bad line, a stranger explaining that your son is too upset to talk properly: every artefact of synthesis has a ready-made emotional excuse. The pretext does the covering-up for the technology.
Then there is the state you are in. Adrenaline narrows attention onto the perceived threat and away from analysis. You are being asked to make your most sceptical judgement of the year at the exact moment you are least capable of it. That is not a personal failing. It is human physiology, and the criminals have built their entire script around it.
Which is why the whole strategy needs to change. Stop trying to detect the fake. Start verifying the real.
The family safe phrase
A safe phrase is a short string of words that every member of your family knows, that has never been written down, texted, emailed or spoken online. When a call comes in claiming to be a relative in crisis, you ask for it.
This is not fringe advice. It is the first item on the FBI’s own protection list in that December 2024 advisory: “Create a secret word or phrase with your family to verify their identity.” The National Cybersecurity Alliance runs an entire public campaign on it.
The reason it works is worth understanding, because it tells you how not to break it. A criminal running a voice clone controls a great deal: the voice, the caller ID, the emotional script, the timing, the payment channel. There is exactly one thing they cannot control, which is a fact that was never spoken aloud anywhere they could reach. The phrase is out-of-band. It sits outside the channel the attacker owns.
How to choose one that holds up
- Make it meaningless. Four to six concrete words with no connection to your lives. “Purple wheelbarrow, seven o’clock” is good. Your dog’s name, your street, your football team, a birthdate or a wedding anniversary is not, because all of it is already on somebody’s social media.
- Beware the charming inside joke. A family in-joke feels perfectly secret, but if it originated in a story told on Facebook in 2019, it is not. If you cannot be certain it was never posted, discard it.
- Make it easy to say under pressure. Short, common words that survive a bad phone line and a crying voice. Clever wordplay fails exactly when you need it.
- Agree it in person. Never over text, email, a shared note, a password manager entry you tell people about, or a family group chat. If a member lives away, use a video call and confirm something only they could know first.
- Say it out loud once a year. A phrase nobody can recall is a phrase you do not have. Bring it up at Christmas.
The honest weaknesses
I would rather you knew where this control fails than have you trust it blindly.
A genuinely frightened teenager may not remember the phrase. A real emergency call from an unfamiliar hospital number will not include it. If you treat a missing phrase as proof of fraud, you will one day hang up on someone who needed you. A failed phrase means verify harder, never abandon.
The opposite error is more dangerous. If the phrase is ever spoken on a call that later looks suspicious, assume it is burned and change it. Worse, a correct phrase can breed false confidence: it confirms the person knew a shared secret, not that the money request is legitimate, and not that they are not being coerced. The phrase is a filter, not an authorisation.
For households with genuine risk of coercion, agree a second phrase that means the opposite: “I am being made to say this, do not comply.” It costs nothing to have and it has saved people.
The rule that matters even more
If your family adopts only one thing from this article, make it this rather than the phrase.
No money, no account details, no gift cards, no cryptocurrency ever move on the strength of an inbound call. Hang up. Call the person back on the number already saved in your contacts.
The call-back rule is stronger than the safe phrase because it does not rely on your memory, your composure, or your ability to judge audio. It removes the attacker’s control of the channel entirely. A criminal can spoof the number appearing on your screen; they cannot answer the phone when you dial your son directly.
If they do not pick up, that is not confirmation of the emergency. Call a second family member. Call the workplace. Call the hospital’s published switchboard number, not the one you were given. Real crises survive ten minutes of checking. The criminal’s entire advantage is speed, and a deliberate pause is the one thing their business model cannot absorb.
Pair it with a household money pause: any urgent request to move funds requires a second adult to agree before anything is sent. Two people are far harder to panic than one.
Starve the machine of raw material
You cannot remove your voice from the world, and you should not try to live as though you could. You can reduce the easy supply.
- Replace personalised voicemail greetings with the carrier default. Your greeting is a clean, high-quality sample of your voice, available to anyone who rings you.
- Set social accounts to private, particularly for children and teenagers, and think twice about long talking-to-camera videos.
- Do not fill silence on unknown calls. If nobody speaks, hang up rather than repeating “hello, who is this”. Treat any unexpected “can you hear me?” as a harvesting attempt.
- Remember that podcasts, webinars, school events, community radio and conference recordings all publish your voice, often at studio quality. If you speak publicly for a living, as I do, assume a usable clone of you already exists and protect the verification layer instead.
Who needs this conversation this week
Some people in your life carry far more of this risk than others.
- Grandparents and older relatives. Over-represented in loss data and the primary target of the distressed-grandchild pretext. Have the conversation in person, and be careful not to make them feel foolish for being targeted. Shame is why victims stay quiet.
- Young adults away from home or travelling. They are the most plausible source of a genuine emergency call, which makes them the most plausible voice to fake.
- Carers and aged care staff. The safe phrase should belong to the care team, not only the bloodline. A cloned “daughter” ringing a care home is the same attack with a softer target.
- Small business owners and anyone who approves payments. Same technique, different pretext: a cloned director authorising an urgent transfer, or a supplier changing bank details by phone. Payment instructions should never be actioned on voice alone, and a verbal challenge on any change of banking details is basic hygiene.
- Anyone who has ever appeared on a podcast, a panel or the news. Your raw material is already public. Your verification cannot be.
If it has already happened
- Contact your bank immediately and ask them to attempt a recall. Same-day contact materially improves the odds of getting funds back.
- Report it to Scamwatch at scamwatch.gov.au. In the United States, report to ic3.gov. Reporting is what produces the data that drives disruption, which is exactly the point the ACCC keeps making.
- Contact IDCARE if personal information was handed over, not just money.
- Tell the rest of the family what the pretext was, in detail. The same script gets recycled across a household within days.
- Change the safe phrase if it was spoken during the call.
- Do not let anyone carry this alone or in silence. These attacks are engineered by professionals to defeat exactly the instincts that make someone a good parent or grandparent. Being fooled by a cloned voice is not a character flaw.
Have the conversation tonight
This takes about five minutes over dinner. Agree the phrase. Agree the call-back rule. Agree that nobody in the family will ever be annoyed at being asked to verify, because the alternative is worse. Then ring your parents and do it again with them.
Every serious control has a cost, in money, in convenience, in maintenance. This one has none. It requires no app, no subscription, no software update, no technical skill and no ongoing effort. It is the highest-leverage security measure available to an ordinary household in 2026, and almost nobody has it.
The technology can now fake any voice you love. It cannot fake a secret you agreed at your own kitchen table, and it cannot answer when you hang up and ring back. Verification beats detection, every time.
Sources
- FBI Internet Crime Complaint Center, public service announcement I-120324-PSA, “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud”, 3 December 2024.
- ACCC and National Anti-Scam Centre, Targeting Scams Report on scams data and activity 2025.
- National Anti-Scam Centre, Scams Awareness Week media release, 25 August 2025.
- McAfee, “Beware the Artificial Impostor” voice cloning research, May 2023.
- National Cybersecurity Alliance, “Why Your Family and Coworkers Need a Safe Word in the Age of AI”, March 2025.