If a call is happening right now
Say you will call back. Hang up. Call the person on a number you already have for them, not the number that just called you. If you cannot reach them, call another family member or a friend of theirs. Do not send money, gift cards, or cryptocurrency to anyone until the person is confirmed. That is the FTC's and the FBI's guidance in one paragraph; everything below explains why it works and how to prepare so you follow it under pressure.
How voice cloning scams actually play out
A voice cloning scam is an old confidence trick with a new prop. The scammer still needs urgency, secrecy, and a payment channel that cannot be reversed. What the cloned voice adds is the emotional shortcut: a familiar voice in distress makes people skip the step where they would normally ask questions. The voice does not have to be perfect. A phone line, a bad connection, crying, and a "lawyer" who takes over the call cover a lot of imperfection.
For the scale of the problem, including FBI complaint and loss figures, see our sourced AI voice cloning scam statistics roundup. This article is about the moment the phone rings.
| Pattern | How it runs | The tell |
|---|---|---|
| Family emergency (the “grandparent scam”) | A cloned voice of a child or grandchild calls in distress: an accident, an arrest, a hospital abroad. A second voice, the “lawyer” or “officer”, takes over and asks for bail, fees, or fines by gift card, wire, or cryptocurrency. | Urgency plus secrecy (“don’t tell mom”), an unusual payment method, and a reason you cannot call the person back. |
| Executive or vendor impersonation (business email compromise with a voice) | An employee receives a voicemail or call in the voice of a CEO, CFO, or supplier authorising an urgent transfer or a change of bank details, often timed to travel or end-of-quarter pressure. | A request that bypasses the normal approval path, pressure to act before a deadline, and reluctance to be reached on the executive’s known number. |
| Official or public-figure impersonation | The FBI has warned that malicious actors use AI-generated voice messages impersonating senior officials to build rapport and then move the target to another platform or extract information and credentials. | An unexpected contact from someone important, a request to continue on a different app, and links or attachments arriving soon after. |
What the FTC, FBI, and FCC say
Three US agencies have published guidance or rules on AI voice cloning, and their advice converges on one behaviour: independent verification through a channel the scammer does not control.
FTC: call back on a number you know
In its April 8, 2024 consumer alert "Fighting back against harmful voice cloning", the FTC's core advice is to call the person who supposedly contacted you using a phone number you know is theirs and verify the story. If you cannot reach them, try to get in touch through another family member or their friends. Scams should be reported to the FTC at ReportFraud.ftc.gov.
FBI: research, verify independently, use a secret phrase
The FBI's Internet Crime Complaint Center issued a public service announcement on May 15, 2025, "Senior US Officials Impersonated in Malicious Messaging Campaign", warning that malicious actors were using AI-generated voice messages (vishing) alongside text messages (smishing) to impersonate senior officials, and noting that AI-generated audio is increasingly used to impersonate both public figures and personal relations. Its recommendations apply to any suspicious call:
- Before responding, research the originating number, organisation, or person, then independently identify a phone number for that person and call to verify their authenticity.
- Create a secret word or phrase with your family members to verify their identities.
- Listen closely to tone and word choice to distinguish a legitimate call or voice message from a known contact from AI-generated voice cloning.
- Do not send money, gift cards, cryptocurrency, or other assets to people you do not know or have met only online or over the phone.
- Report incidents to the Internet Crime Complaint Center at ic3.gov.
FCC: AI voices in robocalls are "artificial" under the TCPA
On February 8, 2024 the FCC announced the unanimous adoption of a Declaratory Ruling recognising that calls made with AI-generated voices are "artificial" under the Telephone Consumer Protection Act, effective immediately. The practical effect is that using AI to generate the voice in an unsolicited robocall is itself illegal, giving state attorneys general additional tools against the people behind voice cloning scams. It does not make the calls stop, which is why the personal routine below still matters.
Verify a caller in 60 seconds
- 0–10 s: Slow the call down. Say "I'm going to call you right back." A real relative in trouble will accept that; a script built on urgency will resist it. Resistance is itself information.
- 10–20 s: Ask for the code word. If your family has one (see below), ask for it. A wrong answer, a deflection, or "I can't remember, just hurry" ends the call.
- 20–30 s: Ask one question only the real person can answer. Not their birthday or their pet's name, which are on social media, but something recent and private: what you talked about last weekend, what they borrowed from you.
- 30–45 s: Hang up and call back on a known number. Use the number saved in your phone or written down at home, never the number that called you and never a number the caller gives you. Caller ID can be spoofed.
- 45–60 s: If unreachable, call someone next to them. A spouse, roommate, sibling, or friend. The FTC recommends this second route explicitly.
- Any time: refuse unusual payment. Gift cards, wire transfers, cryptocurrency, payment apps to a stranger, or cash handed to a courier are the scam's signature. No genuine emergency is settled that way.
Notice that none of these steps require deciding whether the voice is real. They work because they move the decision to a channel the scammer does not control. That is the whole design, and it is why official guidance leads with call-back rather than with detection.
Setting up a family code word
The FBI recommends a secret word or phrase with family members; the FTC's call-back advice assumes you know who to call. Combining them takes ten minutes at a family dinner.
- Pick something that has never been online. Not a pet, a street, a team, or a maiden name. An inside joke, a made-up word, or a phrase from a family story works better because it cannot be scraped from a profile.
- Share it face to face or by a channel you already trust, and never in the same message thread a stranger could read later.
- Include the people most likely to be targeted: grandparents, teenagers with public accounts, and anyone who handles money for the family.
- Agree the rule, not just the word: "If anyone calls asking for money, we ask for the word, then we hang up and call back." Rehearse it once so it is muscle memory under stress.
- Extend it to work. Teams that approve payments can adopt the same idea: a verbal request from an executive is confirmed on the executive's known number or in person, every time, with no exceptions for urgency.
What a voice detector can and cannot do during a live call
People searching for an AI voice detector in the middle of a scam are usually hoping for a live verdict. Free consumer tools do not offer one. The EyeSift AI voice detector analyzes a saved file in your browser; it cannot listen to a call. Real-time detection exists, but as enterprise products aimed at banks, contact centers, and meeting platforms, not as an app on a personal phone.
| Task | EyeSift (free, browser) | Other tools |
|---|---|---|
| Screen a saved voicemail or voice note for synthetic-audio signals | Yes, after you save the file | Yes (file-based) |
| Analyze a call while it is happening | No | Only enterprise real-time systems (for example Pindrop Pulse in contact centers, Resemble Detect on meeting platforms) |
| Attribute a voice to a specific generator | No | Only that vendor’s own classifier, for its own output |
| Prove the caller is who they claim | No | No tool does; verification through a known channel does |
| Decide whether to send money | No | No |
Where a detector does help is afterwards. If the scammer left a voicemail or sent a voice note, save the file and screen it. EyeSift reports waveform and file-quality signals (duration, bitrate, silence, clipping, dynamic range, micro-variation) with a reliability label, and never uploads the audio. It is a heuristic screen, not a spectral classifier, and it can miss a good clone or flag a badly compressed real message, so treat the result as one note in your report rather than a verdict. For how to listen critically yourself, see how to tell if a voice is AI-generated; for the free tools compared honestly, see free AI voice detectors in 2026.
If money has already been sent
- Contact the bank, card issuer, or payment provider immediately and ask them to stop, recall, or dispute the transaction. Speed matters more than anything else at this stage; do not wait to gather evidence first.
- If gift cards were used, contact the card issuer with the card numbers and receipts and ask whether the balance can be frozen.
- Report to the FBI at ic3.gov and to the FTC at ReportFraud.ftc.gov. Include the phone numbers, the times, any voicemail file, and the payment details.
- Preserve everything: the voicemail or voice note as an unmodified file, screenshots of messages, call logs, and receipts. Do not re-record audio from a speaker; forward or export the original.
- Warn the person who was impersonated and the rest of the family. Scammers who succeed once often try the same voice on other relatives.
- Do not pay anyone who offers to recover the money for a fee. Recovery scams target recent victims.
Reduce the raw material
Cloning needs a voice sample, and the easiest samples are public: video posts, voicemail greetings, podcast appearances, and answering unknown numbers with a few full sentences. You do not need to disappear from the internet, but it is reasonable to make voicemail greetings short and generic, to let unknown numbers go to voicemail, and to talk with teenagers and older relatives about why a stranger might want them to keep talking. For organisations, the same logic applies to executives whose voices are on every earnings call: assume the voice is clonable and build approval processes that do not depend on recognising it. Our guide for teachers, podcasters, and HR teams covers policy language for exactly that.
Provenance tools are slowly making some synthetic audio identifiable: ElevenLabs says it embeds imperceptible watermarks in audio it generates and offers a classifier for its own output, and Google's SynthID marks audio from Lyria and NotebookLM. Scammers do not use tools that label their output, so those signals help journalists and platforms more than families. We explain what they cover and do not cover in Does ElevenLabs watermark its audio?
Frequently Asked Questions
How do I verify a caller who sounds like a family member?
Hang up and call the person back on a phone number you already know is theirs. That is the FTC's core advice for voice cloning scams. If you cannot reach them, contact another family member or one of their friends. Do not call back the number that just called you, and do not rely on caller ID, which can be spoofed.
What is a family code word and how do I set one up?
A family code word is a private word or phrase agreed in person that a real relative can produce during an emergency call and a scammer cannot. The FBI recommends creating a secret word or phrase with family members to verify their identities. Pick something that never appears on social media, share it only face to face or by a trusted channel, and rehearse asking for it before anyone sends money.
Can an AI voice detector stop a scam call while it is happening?
Consumer file-based tools cannot analyze a live call. EyeSift and similar browser tools screen a saved voice note or recording after the fact. Real-time detection exists in enterprise products such as Pindrop Pulse and Resemble Detect, which are aimed at contact centers and meeting platforms, not personal phones. During a live call, the defense is behavioral: pause, hang up, and verify through a known number.
Are AI voice robocalls illegal in the United States?
Yes. On February 8, 2024 the FCC unanimously adopted a Declaratory Ruling recognizing that calls made with AI-generated voices are "artificial" under the Telephone Consumer Protection Act, effective immediately. That gives state attorneys general additional tools against voice cloning robocall scams, but it does not stop scammers from placing calls, so personal verification still matters.
What should I do if I already sent money to a voice cloning scammer?
Contact your bank, card issuer, or payment provider immediately and ask them to stop or reverse the transaction. Then report the incident to the FBI Internet Crime Complaint Center at ic3.gov and to the FTC at ReportFraud.ftc.gov. Keep the voicemail, messages, numbers, and receipts, because they help investigators and any dispute process.
Where can I check a suspicious voicemail for AI signals?
Save the voicemail or voice note as a file and run it through the free EyeSift AI voice detector, which analyzes it in your browser without uploading it. The result is a triage signal only. Whatever the score says, verify the person through a separate trusted channel before sending money or sharing account details.
Official sources checked September 17, 2026
- FTC: Fighting back against harmful voice cloning (April 8, 2024)
- FBI IC3 PSA: Senior US Officials Impersonated in Malicious Messaging Campaign (May 15, 2025)
- FCC: AI-generated voices in robocalls are artificial under the TCPA (February 8, 2024)
Received a Suspicious Voicemail? Screen It Free
Save the voice note and run it through EyeSift's browser-side AI voice detector. No signup, no upload. Then verify the person on a number you already trust.
Open the AI Voice DetectorRelated Articles
AI Voice Cloning Scam Statistics 2026
FBI, FTC, and industry data on voice-clone fraud losses.
Voice DetectionHow to Tell If a Voice Is AI-Generated
Eight manual checks and what a free detector can and cannot flag.
ComparisonBest AI Voice Detectors 2026
Free browser tools, provider classifiers, and enterprise platforms compared.