An AI voice cloning scam call is a fake family emergency: someone who sounds exactly like your child, parent or partner says they are in trouble and need money now, and the voice was cloned by software from a short recording. The defense takes about a minute: hang up, call the person back on a number you already have, and ask for the family code word before any money moves.

How we checked this

This guide draws on AI voice-cloning alerts from the US Federal Trade Commission (2023 and the current fake-emergency page, updated August 13, 2026) and the FBI’s Internet Crime Complaint Center (December 2024 and September 17, 2026), on UK and Spanish bank guidance (Starling Bank’s “Safe Phrases” campaign, September 2024, and CaixaBank’s explainer on voice cloning, October 2025), and on the FTC’s page on what to do after paying a scammer. It is built from official sources. Facts checked on September 24, 2026.

How the scheme works, end to end

The script is old. The FTC has warned about the “family emergency” or “grandparent” scam for years: someone calls pretending to be a relative, and in the FTC’s words, “the scammer will say it’s urgent and that you’re the only one who can help” (FTC). What changed is the voice. In March 2023 the FTC added a warning that the caller may now sound exactly like your grandson or daughter, because “all he needs is a short audio clip of your family member’s voice — which he could get from content posted online — and a voice-cloning program” (FTC consumer alert, March 20, 2023).

The FBI describes the same pattern. Its December 2024 alert on generative AI and fraud says criminals “generate short audio clips containing a loved one’s voice to impersonate a close relative in a crisis situation, asking for immediate financial assistance or demanding a ransom” (FBI IC3, PSA241203).

So the call has three parts, and it helps to see them separately. First, a familiar voice, which lowers your guard. Second, a crisis with a clock on it, which stops you from thinking or checking. Third, a payment request through a channel that is hard to reverse. The voice is the new ingredient, but the second and third parts are what actually take the money, and they are also where the scheme is easiest to break. We cover the wider family of these frauds in AI scams that steal money in 2026: the catalog, with what to do; this guide stays with the phone call.

How much audio is enough to clone a voice?

Less than most people expect. Starling Bank, a UK bank, said in its 2024 campaign that criminals can clone a voice “from as little as three seconds of audio,” which can come from videos posted online or on social media (Starling Bank, September 18, 2024). Spain’s CaixaBank uses the same figure: “bastan tres segundos de audio para conseguir una voz clonada,” roughly “three seconds of audio is enough to get a cloned voice” (CaixaBank, October 20, 2025). The US regulators are less specific and say “a short audio clip” (FTC).

Treat the three-second number as the banks’ warning, not a lab result we have checked. The practical point holds either way: if someone in your family has ever posted a video with their voice in it, you should assume a stranger can produce something that sounds like them. A short, emotional call over a phone line is also the easiest setting for a fake to pass.

That is why “I would recognize my own kid’s voice” is not a defense. The FTC’s advice is blunt: “Don’t trust the voice” (FTC, 2023). CaixaBank lists some audio tells, such as odd pauses, unusual intonation, repetitive phrasing and background noise added to cover flaws (CaixaBank). Those are worth knowing, but we would not rely on them. The technology improves, a bad phone line hides a lot, and you are listening while frightened. Build the defense around checking, not listening.

What these calls ask for, and why those payment methods

The request is almost always for money that is fast to send and slow or impossible to pull back. The FTC’s fake-emergency page names wire transfers through services like Western Union and MoneyGram, cryptocurrency, payment apps and gift cards, and notes that scammers “insist that you can only pay in ways that make it tough to get your money back” (FTC). Its 2023 alert flags requests to wire money, send cryptocurrency, or buy gift cards and read out the numbers and PINs (FTC, 2023).

The reason is simple. A card payment can be disputed. A gift card number read over the phone, a crypto transfer or an instant bank transfer usually cannot be recalled once the recipient has moved the money on. Scammers choose the rail that ends the story fastest.

The same logic shows up in a related scheme. The FBI’s September 17, 2026 alert covers criminals impersonating police and government officials, sometimes using AI “to appear as law enforcement and government officials on video calls with victims.” It counts nearly 61,000 complaints and more than $1.6 billion in reported losses from January 2025 through July 2026 across these impersonation scams, and states that officials “will never request payment via prepaid cards, cryptocurrency, or courier” (FBI IC3, PSA260917). Family emergency calls often borrow this layer too: a second voice claiming to be a lawyer, officer or hospital worker. The rule is the same for both. Nobody legitimate needs you to pay a stranger by gift card, crypto or courier within the hour.

What you hear What it is for What you do
A loved one’s voice, upset Lowers your guard Treat it as unverified
“Don’t tell Mom and Dad” or “keep this quiet” Stops you checking Tell someone anyway
A deadline: bail, a fine, a hospital bill “right now” Stops you thinking Slow down; a real emergency survives a callback
Gift cards, crypto, wire, payment app, instant transfer, courier Money that is hard to recover Do not pay under pressure
A second person (lawyer, officer, doctor) takes over Adds authority Verify through official, public contact details

The one habit that defeats it: the callback rule

If you only remember one thing, remember this: end the call and call the person back on a number you already have saved. The FTC puts it as “Hang up — or tell the person you’ll call them right back,” and “Use a phone number you know is right to call or message the family member or friend” (FTC). If you cannot reach them, contact other family members or their friends to check the story (FTC, 2023). CaixaBank gives the same advice: call back on the number you know, and contact banks only through official channels, not numbers given to you on the call (CaixaBank).

The callback works because it moves the conversation to a line the scammer does not control. A cloned voice can say anything, and you cannot be sure what the incoming screen proves, but the scammer cannot answer your daughter’s real phone. It also breaks the clock. The caller’s whole plan depends on you staying on the line and acting before you think.

For anyone claiming to be an official, the FBI’s version applies: do not use contact details the caller gives you; look up the agency’s public number yourself (FBI IC3, PSA260917).

The 60-second check

Here is the whole routine, written so you can put it on the fridge or in a family group chat.

  1. Pause (5 seconds). Notice the pressure. Urgency plus secrecy plus an unusual payment method is the pattern, whatever the voice sounds like.
  2. Ask for the code word (10 seconds). If you have one, ask for it. A wrong answer, a dodge or “I don’t have time for that” ends the call.
  3. Hang up (5 seconds). Say you will call right back. You do not need to be polite or to explain.
  4. Call back on a saved number (30 seconds). Use the contact already in your phone, not a number from the call or a message. No answer? Try another relative, a partner or a friend who would know.
  5. Decide (10 seconds). Pay nothing until you have spoken to the person, or someone who is with them, on a line you chose. Nothing about the payment request itself counts as proof.

If it is real, you have lost a minute. If it is a scam, you have lost nothing.

How to set up a family code word without making it weird

The FBI recommends it directly: “Create a secret word or phrase with your family to verify their identity” (FBI IC3, PSA241203). Starling calls it a “Safe Phrase” and asks people to “agree a ‘Safe Phrase’ with their close friends and family that no one else knows” (Starling Bank). CaixaBank suggests the same, plus personal questions only the real person could answer (CaixaBank).

How we would do it:

  • Bring it up as a practical thing, not a fear thing. Something like: “I read that scammers can fake voices now. Let’s pick a word we’d only use if one of us really needed money in a hurry.” Framing it as the same kind of step as a spare house key keeps it ordinary.
  • Agree on it in person or on a live call. Starling’s advice is not to share it by text or messaging. A word that sits in a chat thread can leak with that account.
  • Pick something that is not online. Avoid pet names, street names, school names, birthdays or anything visible on social media. A random pair of words that means something only inside the family works well.
  • Keep it small. Close family and the people who would actually call you in an emergency. The more people who know it, the weaker it is.
  • Use it both ways. Parents should expect to be asked too, including by grown children and by grandparents who get a call “from” you.
  • Change it if it is ever used or exposed.

Two limits worth knowing. A code word only works if you remember to ask, which is why the callback rule comes first. And it does not replace checking: if the person on the phone gets the word right but still wants gift cards within the hour, hang up and call back anyway.

What to watch out for

  • Secrecy requests. “Don’t tell anyone” is there to stop the callback. Tell someone.
  • A second caller. A “lawyer,” “officer” or “hospital” voice that takes over the call is there to add authority. Verify through public, official numbers (FBI IC3).
  • Couriers. Any request to hand cash or cards to a courier is a red flag; the FBI says officials never ask for payment by courier (FBI IC3).
  • Follow-up calls. After a first payment, expect more calls. Be wary of anyone who asks for more money, or who offers to recover what you lost for a fee.
  • Video. The FBI now reports AI being used to fake officials on video calls (FBI IC3). Seeing a face is not proof either.

Starling’s 2024 survey of 3,010 UK adults, run by Mortar Research, found that 28% said they had been targeted by an AI voice-cloning scam in the past year, 46% did not know such scams existed, and 8% said they would send money even if the call seemed strange (Starling Bank). These are self-reported survey answers commissioned by a bank, not crime statistics, but they explain why a two-minute family conversation is worth having.

If money was already sent

Act immediately, and contact the company you paid through before anything else. The FTC’s instructions by payment method (FTC, What to do if you were scammed):

You paid by Contact first What to ask
Gift card The card issuer, using the number on the back of the card Report that the card was used in a scam
Wire transfer (Western Union, MoneyGram and similar) The wire transfer company Tell them a scammer tricked you into sending money
Payment app The app’s support Ask them to reverse the payment and refund you
Cryptocurrency The exchange or crypto ATM operator Tell them it was a fraudulent transaction
Bank transfer Your bank or credit union Ask them to reverse the payment and refund you

In the US, report it at ReportFraud.ftc.gov and to your state attorney general (FTC). In the UK or Spain, call your bank on the number printed on your card and report to the police. Our step-by-step guide, Your money was stolen: what to do in the first hour, covers the order of calls in more detail. Whether you can get the money back depends on your bank, the payment method and local rules; if a large sum is involved, it may be worth speaking to a lawyer or a consumer advice service in your country. This guide is general information, not legal advice.

Then tell the family member who was impersonated, so they can warn others and check their own accounts, and change your code word.

Go deeper