The Rise of AI Voice Cloning Scams
Criminals are increasingly using generative artificial intelligence to mimic the voices of loved ones. This technology, often referred to as deepfake audio, allows a scammer to record a small sample of a person's speech and then recreate it perfectly using software. These scammers often use these realistic voices to commit fraud through high-pressure tactics. For example, a scammer might use a deepfake of a teenager's voice to falsely claim a friend has died, demanding a large sum of money like $7,500 to prevent further harm. These schemes rely on the emotional distress of the victim to bypass logical thinking, making it very difficult to spot the fraud through sound alone.
What is a Secret Code Word?
A secret code word is a unique, agreed-upon phrase or word used exclusively among trusted individuals, such as family members or close friends. It serves as a manual verification tool to confirm that the person on the other end of a phone call or message is actually who they claim to be. Instead of relying on the sound of a voice, which can now be convincingly faked by AI, you rely on a shared piece of private information that a computer cannot guess. This simple human-to-human verification method can act as a vital defense against vishing, which is voice phishing, and other deepfake impersonation scams.
Why Traditional Verification is No Longer Enough
In the past, you could trust a voice because it sounded familiar. You knew your child's inflection, their tone, and the way they pronounced certain words. However, the current state of generative AI has changed this reality. Malicious actors can now bypass these auditory cues with high accuracy. Because AI can replicate the subtle nuances of human speech, listening to a voice is no longer a reliable way to ensure safety. The FBI has even highlighted this risk, noting that AI can create realistic messages and emails that make it harder for victims to identify fraud. This shift makes it necessary to move from sensory-based trust to information-based trust.
How to Choose the Best Secret Word
When selecting a secret code word, you want something that is meaningful but not obvious to outsiders. Experts recommend using phrases that hold personal significance to your specific group. This could include the name of a distant family ancestor, a specific shared childhood reference, or a word that relates to a funny private joke. The ideal word should be simple enough to remember during an emergency but unique enough that a stranger could not guess it. You should avoid using common words like "password" or "security," as these are too easy for criminals to anticipate during a social engineering attack.
Storing Your Secret Code Safely
Once you have chosen a code word, you must treat it with the same level of security as a bank PIN or a digital password. Do not write it down on a sticky note near your phone, and do not share it with anyone outside of your trusted circle. Cybersecurity experts recommend storing the code word in a password manager. A password manager provides an encrypted way to keep your sensitive data safe, ensuring that even if your phone is lost, the secret word remains protected. If a person calls claiming to be in trouble and cannot provide the code, you must treat the call as a potential scam until the identity is confirmed.
Practical Steps for Implementation
To make this system effective, you must communicate the plan to your family before a crisis occurs. Sit down with your loved ones and explain the threat of deepfake technology and the purpose of the code word. The Federal Trade Commission (FTC) has even launched a Voice Cloning Challenge to encourage people to take these preventative steps. Make sure everyone understands the protocol: if an emergency call involves a request for money, urgent verification codes, or sensitive information, the caller must provide the secret word immediately. If they hesitate or cannot provide it, hang up and call the person back on a trusted number to verify the situation.
Communication Security and Encryption
While a secret code word is a powerful tool, it is also important to be mindful of the platforms you use for communication. The FBI advises against using Rich Communication Services (RCS) for cross-platform texting because these messages may lack end-to-end encryption. End-to-end encryption ensures that only the sender and the receiver can read the contents of a message. If you are communicating sensitive information or discussing the code word itself, using encrypted messaging apps can provide an extra layer of protection against interception by hackers or malicious actors.
Defeating Emergency Scams and Fraud
The most dangerous use of deepfake audio is the family emergency scheme. In these scenarios, the criminal creates a sense of extreme urgency to prevent you from thinking clearly. By implementing a code word, you create a pause in the emotional momentum of the scam. Even if the voice sounds exactly like your spouse or your child, the inability to provide the secret word provides the logical evidence needed to realize you are being targeted. This simple countermeasure allows you to stay calm and act according to your security training rather than acting on fear, which is exactly what the scammer is counting on.