Three seconds of audio, pulled from a social media video, is now enough to clone someone’s voice convincingly. This is not a future risk. It is already being used against families, businesses and individuals right now, and understanding how it works is the first real step towards protecting yourself.
What AI Voice Cloning Actually Is
Voice cloning technology analyses a short audio sample to learn a person’s tone, accent, pacing and speech patterns, then generates new audio of that voice saying anything a script asks it to. Legitimate uses exist, such as accessibility tools, dubbing and content creation, but the same technology requires no special access or hacking skill to misuse.
How the Common Scam Works
Most voice cloning scams follow a similar pattern. A scammer gathers a short clip of someone’s voice from a public social media video, then calls a family member or colleague using a spoofed caller ID, often introducing a plausible reason for slight audio imperfections, such as claiming a bad phone connection or an injury. The script typically creates urgency, such as a supposed accident, arrest or emergency, pressuring the target to send money or sensitive information immediately, before they have time to think clearly or verify anything.
Why This Works So Well on Otherwise Careful People
A cloned voice bypasses normal scepticism because it triggers genuine emotional recognition, not just belief. Hearing what sounds exactly like your child or your boss creates urgency that overrides the usual pause-and-think response most people rely on to catch a scam. This is precisely why regulators and researchers flag voice-based fraud as more dangerous than text-based scams.
The Business Risk, Not Just the Family One
This threat extends well beyond family emergency scams. There have been documented cases of cloned executive voices, and even full video deepfakes of company leadership, used to authorise large fraudulent payments during what appeared to be a routine business call. Any business with wire transfer authority should treat this as a genuine operational risk, not a hypothetical one.
Practical Protection That Actually Works
- Set a family or team codeword. Agree privately on a word or phrase that only genuine family members or colleagues would know, to be used specifically to verify identity during an unexpected urgent request.
- Always call back on a known number. If you receive an urgent call, hang up and call the person back on a number you already have saved, rather than continuing the original call or using a number provided during it.
- Slow down deliberately. Scammers rely on urgency to prevent careful thinking. Treat any request for immediate money or sensitive information with more suspicion, not less, the more urgent it feels.
- Limit public audio of your voice where practical. Consider your social media privacy settings for video content, particularly for older or more vulnerable family members who may be specifically targeted.
- Add a verification step for business payments. Require a second, independent confirmation method for any large or unusual payment request, regardless of how convincing the requesting call or video sounds.
Frequently Asked Questions
How much audio does someone need to clone a voice?
Some current voice cloning tools can produce a convincing result from as little as three to five seconds of clear audio, which is often available from a single public social media video.
What is a family codeword and does it actually help?
A family codeword is a private phrase agreed in advance that genuine family members would know, used to verify identity during an unexpected urgent call. It is widely recommended by consumer protection organisations as an effective, simple defence against voice cloning scams.
Can businesses be targeted by voice cloning scams, not just individuals?
Yes. There have been documented cases of cloned executive voices and video used to authorise fraudulent business payments, so businesses with wire transfer authority should treat this as a genuine operational risk requiring independent verification steps.
Is it illegal to clone someone’s voice without permission?
Regulation is evolving, but using a cloned voice for fraud, impersonation or robocalls is already treated as illegal in several jurisdictions, with regulators actively working on broader consent and disclosure rules specific to synthetic voice.
What should I do if I think I am on a call with a cloned voice?
Hang up immediately and call the person back directly on a number you already have saved, rather than a number given during the call. Never send money or sensitive information while still on the original, unverified call.
Want more guidance on protecting your business from AI-related risks? Read our AI cybersecurity guide or browse AI News & Updates.
