How AI Voice Scams Work
The call sounds like your daughter. She is upset, there has been an accident, she needs money now and asks you not to tell anyone.
The useful thing to know is not that this happens. It is that your ear cannot settle it, and that a check which takes thirty seconds can.
This article covers how voice cloning works, what the measured evidence says about human detection, what to do during a call like this, what to do afterward, and which verification methods hold up. Lathic's article on deepfakes covers synthetic video and imagery; this one stays on voice. It does not include anything that would help someone run this scam.
How voice cloning works
A voice-cloning system has three conceptual parts.
The first listens to a sample of someone's speech and reduces it to a compact set of numbers describing how that voice sounds. The second converts written text into a sound-shape. The third turns that sound-shape into audio you can hear.
The part that surprises people is the first one. In the canonical research, published at NeurIPS in 2018, the component that captures a voice was trained on a completely different task, telling voices apart, using "noisy speech from thousands of speakers without transcripts." It never heard the person being cloned. It learned what makes voices differ from one another, which is enough.
That is why cloning does not require retraining on a target. The system is given a reference sample at the moment it generates, and produces speech in that voice. The US Federal Trade Commission describes the input requirement in its own consumer material as "a short audio clip or snippet of someone's voice."
Synthetic speech is also produced in more than one way. NIST's guidance on synthetic content describes text-to-speech, speech-to-speech, and imitation-based systems that keep the original words but change who appears to be saying them.
Why you cannot hear the difference
This is the part worth taking seriously, because the instinct is to listen harder and it does not work.
A 2025 study published in Scientific Reports ran two experiments with 604 listeners between them. In the first, judging whether a voice was real or synthetic, 300 participants correctly identified real voices 67.4% of the time and AI-generated voices 60.8% of the time, and 21% performed at or below chance on the AI clips.
The second experiment, with 304 participants, matches what a scam actually asks of you. When listeners compared a real recording of a speaker with an AI clone of the same speaker, they judged the two to be the same person around 80% of the time. That is not a question about whether audio sounds synthetic. It is the question "is this the person I know," and people got it wrong four times in five.
An earlier controlled study of 529 listeners, published in PLOS ONE in 2023, found people classified clips correctly 70.35% of the time when judging them one at a time, which is the condition a phone call puts you in. Given a real and a fake version of the same sentence side by side, accuracy rose to 85.59%. You never get the side-by-side. Two of its results matter more than the headline. Showing participants examples of deepfakes beforehand improved accuracy by only about 3.84 percentage points. Playing the clip more times did not help. The authors concluded that "attempting to improve human detection capabilities is unreliable."
There is a useful counterweight. A separate 2025 UK study found that voice clones were labeled as human 58% to 70% of the time depending on the experiment, statistically comparable to real human voices at 62% to 72%. Clones are about as convincing as real people, not more so. The problem is not that synthetic audio has become uncanny. It is that ordinary voices were never a reliable identifier in the first place, and now anyone can produce one.
Automated detection does not rescue this either. Writing in November 2024, NIST reported that accuracy in the research literature "ranges from 50% to well above 90%, depending on the method and evaluation dataset," and degrades on audio from generators the detector was not trained on, or with background noise.
What these scams actually look like
The FBI's Internet Crime Complaint Center describes two uses of cloned voices in its December 2024 alert on generative AI and financial fraud, and they run in opposite directions.
The first is the one people picture. Criminals "generate short audio clips containing a loved one's voice to impersonate a close relative in a crisis situation, asking for immediate financial assistance or demanding a ransom."
The second is the reverse: criminals use AI-generated audio of you to get into your accounts, obtaining "access to bank accounts using AI-generated audio clips of individuals and impersonating them." Voice authentication is the target, not your relative's ear.
A third pattern shows up in a separate September 2026 alert, where the FBI warned about scammers impersonating law enforcement and government officials, noting that they "often spoof authentic phone numbers, email addresses, employee names, and credentials." A correct-looking number is not evidence of anything.
A fourth is slower and aimed at individuals with access worth having. In 2025 the FBI recorded a campaign in which AI-generated voice messages claiming to come from senior US officials targeted current and former officials and their contacts, building rapport before seeking account access. The goal was not an immediate wire transfer.
The one number worth keeping in proportion: in its 2025 Internet Crime Report the FBI states that victims claimed losses over $5 million to distress scams, the category that includes grandparent scams using voice cloning to mimic a loved one. The same report records 22,364 complaints with an AI nexus and $893 million in adjusted losses, but over $632 million of that is investment fraud. Reports of family-emergency voice scams are a small share of the total, and it is worth saying so rather than borrowing the larger figure.
All of these are reported losses, from complaints people chose to file. The FBI says its own data "is variable and can evolve" and is "an assessment taken at a point in time."
Warning signs
Four things show up across the FTC and FBI guidance.
Urgency. The situation cannot wait and there is no time to check. Manufactured time pressure is the mechanism, because checking is what defeats this.
Secrecy. You are told not to tell anyone else in the family. The FTC's guidance addresses this directly and tells people to call someone else "even if the caller said to keep it a secret."
An unusual payment method. Wire transfer, cryptocurrency, gift cards where you read out the numbers and PIN, or a payment app. The FBI adds that legitimate government and law enforcement agencies never demand payment by prepaid card, cryptocurrency or courier.
A plausible caller ID. Spoofing is routine and is illegal under the Truth in Caller ID Act when done with intent "to defraud, cause harm, or wrongfully obtain anything of value," which tells you it happens. It is not a check.
What to do during the call
The FTC's instruction is short: "Don't trust the voice. Call the person who supposedly contacted you and verify the story. Use a phone number you know is theirs."
That is the whole method. Everything else is a variation on it.
| What you can do | How reliable it is | Why |
|---|---|---|
| Hang up and call back on a number you already have | High | The attacker does not control the number you dial |
| Ask for a family code word agreed in advance | High | Recommended by the FTC, the FBI and multiple state attorneys general |
| Reach the person another way, or reach another family member | High | Works even if the first number is unanswered, and defeats the secrecy tactic |
| Ask a question only the real person could answer | Medium | Useful, but an attacker may have researched the answer online |
| Judge whether the voice sounds right | Low | Listeners matched clones to the real speaker about 80% of the time in controlled testing |
| Trust the caller ID | Low | Spoofing is common and prosecuted |
The FTC's own four steps, from its guidance on fake emergencies: resist the pressure to send money immediately; hang up, or say you will call back; call someone else in your family or circle of friends even if told to keep it secret; and ask a question only the real person would know.
Do the callback even when the call turns out to be genuine. It costs a minute, and the cost of being wrong in the other direction is the point of the article.
Why caller ID does not help
Phone networks in North America use a framework called STIR/SHAKEN, in which the company originating a call digitally signs the caller ID number and the delivering company checks the signature. There are three attestation levels; the highest is asserted only when the originating provider knows the customer and has verified their right to use that number.
It authenticates the number, not the caller. The FCC's December 2025 report to Congress quotes the Commission's own earlier finding that STIR/SHAKEN information "does not provide consumers with robust information about who is calling," and that a top-level attestation indicator "alone does not give consumers enough information to decide whether a call is worth answering." In its own body text the report describes the framework as designed "not as a panacea for combatting all illegal robocalls," notes exemptions for legacy non-IP networks, and records that authentication data is stripped when a call crosses older infrastructure.
There is a concrete illustration. In 2024 the carrier that transmitted deepfaked robocalls of President Biden's voice before the New Hampshire primary agreed to a $1 million civil penalty and a compliance plan requiring it to apply the highest attestation level only to calls where it supplied the number itself. A call can carry the strongest trust marking and still be fraudulent.
Where the law has moved
Two US actions are worth knowing, and one common belief about a third is wrong.
In February 2024 the FCC adopted a unanimous declaratory ruling holding that AI-generated voices are "artificial" under the Telephone Consumer Protection Act, effective immediately. The effect, in the FCC's words, is that this "makes the act of using AI to generate the voice in these robocalls itself illegal." Callers must have prior express consent, and prior express written consent for telemarketing.
In September 2024 the FCC adopted a $6 million fine against the political consultant who directed the New Hampshire robocalls. State criminal proceedings followed; their outcome is outside what this article covers.
The FTC's Government and Business Impersonation Rule took effect on 1 April 2024. It covers impersonation of government entities and of businesses. It does not cover impersonation of private individuals. The FTC proposed extending it to individuals in February 2024, citing voice cloning, and as of September 2026 that extension remains a proposed rule. Coverage of this often implies otherwise.
None of this is a defense at the moment your phone rings. It matters for what happens afterward.
What to do afterward
Move on the money first. The FBI says "time is of the essence": contact your financial institution immediately and ask for a recall of the funds.
Then report it. In the US that means ReportFraud.ftc.gov, ic3.gov regardless of the amount, and your state attorney general. Reporting is worth doing even when recovery is unlikely, because these agencies act on volume.
Recovery depends heavily on how you paid. The FTC states that federal law protects you from unauthorized use of a credit or debit card, and that cryptocurrency payments "don't have the same legal protections as credit and debit cards do, so it can be hard to get your money back."
There is one real recovery figure and it needs its context. In 2025 the FBI's Recovery Asset Team initiated 3,900 financial fraud kill chain incidents covering $1.16 billion in attempted theft and froze $679 million, a 58% success rate. That is 58% of the funds in the 3,900 cases where the process was triggered, out of more than a million complaints. It is not the chance that any given victim gets their money back.
The thing to actually change
The same habit protects you elsewhere. Lathic's guide to using AI safely covers what not to hand over in the first place.
Agree a code word with the people who might call you in an emergency. Write down, for each of them, a number you know is theirs. Then treat any distressing call as unverified until you have called back on that number.
Four agencies recommend the code word, including the FTC, the FBI and state attorneys general in California and Michigan. None has published an evaluation of how well it works, so treat it as recommended practice rather than proven. It is free, and it replaces a judgment your ear cannot make with one it can.
Related AI terms
Frequently Asked Questions
How can I identify an AI voice scam?
Identify the situation, not the voice. The pattern is an urgent problem, a request for money or access, an instruction not to tell anyone, and a payment method that cannot be reversed. Any one of those is worth a pause; together they are the scam. Trying to identify it by how the voice sounds is the approach that fails, because in controlled testing listeners matched a cloned voice to the real speaker about 80% of the time.
How can you tell if someone is using an AI voice?
Usually you cannot, and the research says so directly. In a 2023 study of 529 listeners, showing people examples of synthetic speech beforehand improved their accuracy by under four percentage points, and replaying the audio did not help at all. Detection tools are also unreliable: NIST reports published accuracy ranging from 50% to well above 90% depending on the method and the test set, with performance dropping on audio from generators the detector has not seen.
How do I protect myself from AI voice scams?
Agree a code word with family members in advance, and keep a number for each of them that you know is theirs. When a distressing call comes, hang up and call back on that number. The FTC's guidance is to call someone else in your family even if the caller told you to keep it secret, because secrecy is part of the method. Reducing the amount of your voice posted publicly is also recommended by state consumer-protection offices, though it is not a complete defense.
How do I know if a voice message is real?
Verify through a separate channel you control. Call the person back on a number you already have, message them another way, or contact someone else who would know. Do not call a number the message gave you, and do not treat a familiar-looking caller ID as confirmation, because spoofing is routine. The phone network's caller ID authentication system signs the number, not the person, and the FCC states that this alone does not tell a consumer who is calling.
Does caller ID verification stop this?
No. The STIR/SHAKEN framework used in North America verifies that a caller is entitled to use the number they are displaying. It says nothing about who is speaking, it has exemptions for older network equipment, and its authentication information is stripped when calls cross legacy infrastructure. In 2024 the carrier that transmitted the deepfaked robocalls sent before the New Hampshire primary agreed to a $1 million civil penalty and a compliance plan restricting when it may apply the highest attestation level.
What should I do if I already sent money?
Contact your bank or payment provider immediately and ask them to recall the funds, because the window is short. Then report it to the FTC at ReportFraud.ftc.gov, to the FBI at ic3.gov whatever the amount, and to your state attorney general. What you can recover depends largely on how you paid: the FTC notes that cryptocurrency payments do not have the same legal protections that credit and debit cards do.
Sources
- Ye Jia, Yu Zhang, Ron Weiss, Quan Wang, Jonathan Shen, Fei Ren, Zhifeng Chen, Patrick Nguyen, Ruoming Pang, Ignacio Lopez Moreno and Yonghui Wu, "Transfer Learning from Speaker Verification to Multispeaker Text-To-Speech Synthesis," Advances in Neural Information Processing Systems 31, 2018. https://proceedings.neurips.cc/paper/2018/hash/6832a7b24bc06775d02b7406880b93fc-Abstract.html
- NIST, "Reducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content Transparency," NIST AI 100-4, November 2024. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-4.pdf
- Federal Trade Commission Office of Technology, "Approaches to Address AI-enabled Voice Cloning," 8 April 2024. https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/04/approaches-address-ai-enabled-voice-cloning
- Federal Trade Commission, "Announcing the FTC's Voice Cloning Challenge," November 2023. https://consumer.ftc.gov/consumer-alerts/2023/11/announcing-ftcs-voice-cloning-challenge
- Sarah Barrington, Emily A. Cooper and Hany Farid, "People are poorly equipped to detect AI-powered voice clones," Scientific Reports 15, article 11004, 2025. https://www.nature.com/articles/s41598-025-94170-3
- Kimberly T. Mai, Sergi Bray, Toby Davies and Lewis D. Griffin, "Warning: Humans cannot reliably detect speech deepfakes," PLOS ONE 18(8), 2 August 2023. https://journals.plos.org/plosone/article?id=10.1371%2Fjournal.pone.0285333
- Nadine Lavan, Meg Irvine, Victor Rosi and Carolyn McGettigan, "Voice clones sound realistic but not (yet) hyperrealistic," PLOS ONE 20(9), 2025. https://journals.plos.org/plosone/article?id=10.1371%2Fjournal.pone.0332692
- FBI Internet Crime Complaint Center, "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud," Alert I-120324-PSA, 3 December 2024. https://www.ic3.gov/PSA/2024/PSA241203
- FBI Internet Crime Complaint Center, "Senior US Officials Impersonated in Malicious Messaging Campaign," Alert I-051525-PSA, 15 May 2025. https://www.ic3.gov/PSA/2025/PSA250515
- FBI Internet Crime Complaint Center, "Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes," Alert I-091726-PSA, 17 September 2026. https://www.ic3.gov/PSA/2026/PSA260917
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report, 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- Federal Trade Commission, "Scammers use AI to enhance their family emergency schemes," 20 March 2023. https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes
- Federal Trade Commission, "Fighting back against harmful voice cloning," 8 April 2024. https://consumer.ftc.gov/consumer-alerts/2024/04/fighting-back-against-harmful-voice-cloning
- Federal Trade Commission, "Scammers Use Fake Emergencies To Steal Your Money," modified 13 August 2026. https://consumer.ftc.gov/articles/scammers-use-fake-emergencies-steal-your-money
- Federal Trade Commission, "What To Do if You Were Scammed," modified 21 August 2026. https://consumer.ftc.gov/articles/what-do-if-you-were-scammed
- Federal Trade Commission, "FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025," 15 June 2026. https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
- Federal Trade Commission, "FTC Announces Impersonation Rule Goes into Effect Today," 1 April 2024. https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-announces-impersonation-rule-goes-effect-today
- 16 CFR Part 461, Rule on Impersonation of Government and Businesses, current text as of 17 September 2026. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-D/part-461
- Federal Trade Commission, "FTC Proposes New Protections to Combat AI Impersonation of Individuals," 15 February 2024. https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-proposes-new-protections-combat-ai-impersonation-individuals
- Federal Communications Commission, Declaratory Ruling, CG Docket No. 23-362, FCC 24-17, adopted 2 February 2024, released 8 February 2024. https://docs.fcc.gov/public/attachments/FCC-24-17A1.txt
- Federal Communications Commission, "FCC Makes AI-Generated Voices in Robocalls Illegal," 8 February 2024. https://docs.fcc.gov/public/attachments/DOC-400393A1.pdf
- Federal Communications Commission Wireline Competition Bureau, "Triennial Report on the Efficacy of the Technologies Used in the STIR/SHAKEN Caller ID Authentication Framework," DA-25-1100, 19 December 2025. https://docs.fcc.gov/public/attachments/DOC-416732A1.pdf
- Federal Communications Commission, Forfeiture Order FCC 24-104, 26 September 2024. https://docs.fcc.gov/public/attachments/DOC-405811A1.pdf
- Federal Communications Commission, "FCC Settles Case Against Provider That Transmitted Spoofed AI-Generated Robocalls for Election Interference in New Hampshire," 21 August 2024. https://docs.fcc.gov/public/attachments/DOC-404951A1.pdf
- NSA, FBI and CISA, "Contextualizing Deepfake Threats to Organizations," Cybersecurity Information Sheet, September 2023. https://media.defense.gov/2023/Sep/12/2003298925/-1/-1/0/CSI-DEEPFAKE-THREATS.PDF
- California Attorney General, "Attorney General Bonta Warns Californians: AI-Generated Scams are Widespread and Tricky to Spot," 30 May 2024. https://oag.ca.gov/news/press-releases/attorney-general-bonta-warns-californians-ai-generated-scams-are-widespread-and
- Michigan Attorney General, Consumer Alert: "Artificial Intelligence and Scams." https://www.michigan.gov/consumerprotection/protect-yourself/consumer-alerts/scams/artificial-intelligence-and-scams