Privacy & Security 8 min readBy Mehadi ShawonPublished Updated

Can You Trust a Voice on the Phone Anymore? AI Voice Cloning Scams Explained

AI voice cloning scams copy a familiar voice from seconds of audio. How the calls work, what the FCC ruled in 2024, and how to verify any caller safely.

Glowing blue audio waveform morphing into a synthetic face outline on a dark background, representing an AI voice cloning scam call
Quick answer

Can You Trust a Voice on the Phone Anymore? AI Voice Cloning Scams Explained

An AI voice cloning scam uses a synthetic copy of someone's voice — built from a short audio sample — to make a phone call you believe is from a relative, colleague or executive. On 8 February 2024 the US FCC released a declaratory ruling (FCC 24-17) confirming AI-generated voices in robocalls are illegal under the existing Telephone Consumer Protection Act.

A voice on the phone is no longer proof of who is speaking. Synthetic speech generated from a short recording now sounds convincing enough to carry a whole conversation — including the pauses, breathing and regional accent that used to make a voice feel authentic.

That single change breaks a trust assumption most people have used their entire lives. It is why the classic emergency call from a relative in trouble has become dramatically more effective, and why finance teams are being drilled to distrust an instruction from a boss they can hear perfectly clearly.

How AI voice cloning scam calls are built

The workflow has three stages, none of which require unusual technical skill.

  1. Sample collection. A few seconds of clean speech is enough for modern voice models. Social video, podcast appearances, voicemail greetings, conference recordings and company webinars all supply it.
  2. Model generation. The sample is fed to a voice synthesis service that produces a reusable voice profile, which can then read any typed text — sometimes in real time during a live call.
  3. Delivery with pretext. The caller adds urgency and secrecy: an accident, an arrest, a bail payment, an urgent supplier transfer that must not be discussed with anyone else.

Caller ID is spoofed to match, and public details harvested from social profiles fill in the specifics — a school name, a partner's name, a recent holiday. The combination of a correct voice, a correct number and correct family trivia is what pushes people past their own doubts.

Telephone handset connected to a neural network sphere by glowing sound waves, illustrating deepfake voice fraud on a phone call

The incident that changed corporate policy

The clearest documented case is engineering consultancy Arup. The company confirmed in 2024 that an employee in its Hong Kong office was tricked into making a series of transfers totalling roughly $25 million (about HK$200 million) after joining a video call in which colleagues, including the chief financial officer, were AI-generated recreations. Hong Kong police investigated; the transfers had already been made across fifteen transactions.

What makes that case instructive is that the employee did everything a cautious person is supposed to do — including seeing and hearing the people giving the instruction. Visual and audio confirmation simply stopped being a control.

What regulators have done about AI voices

On 8 February 2024 the US Federal Communications Commission released a declaratory ruling, FCC 24-17, confirming that AI-generated voices count as 'artificial' voices under the Telephone Consumer Protection Act. In practice that means calls using cloned or synthetic voices without prior consent are illegal under the same law long used against traditional robocalls, and state attorneys general can pursue them directly.

The Federal Trade Commission has pushed in the same direction, running a public Voice Cloning Challenge to encourage detection and authentication technology rather than relying purely on enforcement after the fact.

None of this stops a call reaching you. Enforcement addresses the callers who can be found; the defence you control is verification.

How to verify a caller when the voice sounds right

  • Hang up and call back on a number you already have — from your own contacts, a bank card or an official website. Never a number the caller supplies.
  • Agree a family code phrase in advance. A short, unguessable phrase that only relatives know defeats a clone instantly, because the model cannot answer what it has never heard.
  • Ask something contextual and recent that is not online: what we ate last Sunday, what the dog did yesterday.
  • Refuse pressure and secrecy outright. 'Do not tell anyone' and 'this must happen in the next ten minutes' are the operating requirements of the scam, not of real emergencies.
  • Treat any payment method that cannot be reversed — crypto, gift cards, wire transfers to a new account — as an automatic red flag regardless of who is asking.
  • At work, require a second channel and a second person for any payment instruction, and make it explicit that a video or voice call alone is never sufficient authorisation.

Reduce your own voice exposure

You cannot remove your voice from the internet, but you can reduce easy sampling: keep voice notes and video out of public profiles, drop your voice from your voicemail greeting in favour of the default recording, and think twice before posting long unedited clips of yourself or your children speaking.

The same reasoning applies to written material you feed into AI systems. If you have ever pasted sensitive data into a chatbot, our guide on whether it is safe to paste your data into ChatGPT explains what retention actually looks like.

How voice cloning fits the wider fraud picture

Voice cloning is one part of a broader shift where attackers automate the persuasive parts of fraud. We covered the arms race in detail in how attackers and defenders are both using AI, and the pattern repeats in text and in printed material — the same social pressure appears in the QR code scams now spreading in 2026.

The practical conclusion is narrow but firm: identity now has to be proven by something the caller must possess or know independently, not by how they sound. Once your family and your finance team both operate that way, a cloned voice becomes a wasted effort.

Why the caller ID and the voice both look right

Two separate weaknesses stack in these calls. Caller ID was never designed as an authentication mechanism — the displayed number is supplied by the calling party, which is why spoofing a familiar number is routine. Voice was, informally, treated as authentication for decades, and synthesis has removed that assumption.

When both signals are forged at once, every cue most people rely on is gone. What remains reliable is the structure of the request: urgency, secrecy, and an irreversible payment or code. Those three together are the actual signature of the fraud, independent of how convincing the audio is.

A verification routine worth agreeing in advance

  1. Agree a spoken passphrase with close family that is never written down or posted, and use it whenever money or a code is requested.
  2. Hang up and call back on the number you already have stored, never a number offered during the call.
  3. For any workplace request involving payment, confirm through a second channel that you initiated — a message in your internal system, not a reply to the call.
  4. Treat a refusal to be verified as the answer. A genuine relative or colleague will wait two minutes.
  5. Ask something only the real person could answer from shared history, and be prepared for a plausible deflection.

Reducing your own exposure helps too: long public recordings of your voice are the raw material, so consider who can access voice notes, livestreams and video posts of you and your family.

Frequently Asked Questions

How much audio does an AI need to clone a voice?+

Modern voice synthesis services can produce a usable clone from only a few seconds of clear speech. Publicly posted videos, podcast clips, webinars and voicemail greetings all provide more than enough material.

Are AI voice scam calls illegal?+

In the United States, yes. The FCC's declaratory ruling of 8 February 2024 (FCC 24-17) confirmed that AI-generated voices are 'artificial' voices under the Telephone Consumer Protection Act, making unconsented AI-voice robocalls illegal under existing law.

Has an AI voice or video scam caused a real financial loss?+

Yes. Engineering firm Arup confirmed in 2024 that an employee was deceived by a deepfake video call impersonating company executives and made transfers totalling roughly $25 million before the fraud was discovered.

How can I tell if a voice on the phone is fake?+

Do not rely on listening. Hang up and call back on a number you already trust, ask a question only the real person could answer, or use a code phrase agreed in advance. Clones fail on knowledge, not on sound.

Can caller ID confirm who is calling me?+

No. Caller ID information can be spoofed, so a familiar number displayed on screen is not evidence of identity. Treat the number and the voice together as a claim to be verified rather than a confirmation.

Ad Space

Try the related free tools

Hands-on utilities from DigiMetrics Hub that go with this guide.

All tools