Deborah Del Mastro heard her daughter’s voice, frantic, pleading, saying she’d been kidnapped in Mexico. She wired more than $5,000 before she found out her daughter was safe the entire time. The voice on the phone wasn’t real. It was a clone.
“I was totally taken by it,” she told CNN.
Why it matters: Cloning a voice used to take a professional studio and real skill. Now it takes about three seconds of audio, a free app, and no skill at all. Family emergency scams have existed forever. AI just made them nearly impossible to catch by ear.
How little it actually takes
A 2023 McAfee test found that three seconds of someone’s voice was enough to produce a clone with an 85% match. The tools have only gotten better since. A more recent McAfee survey of 7,000 people found that roughly one in four had either been targeted by an AI voice-cloning scam or knew someone who had.
Where do scammers get the three seconds? A birthday video posted publicly. A voicemail greeting. A podcast appearance. Anywhere your real voice exists online, in your own words, is a raw material scammers can use against you.
The regulators are scrambling
Imposter scams, someone posing as a family member, a government official, a bank, are now the single most-reported fraud category tracked by the FTC’s Consumer Sentinel Network. The agency has specifically flagged voice cloning as the reason family emergency scams now work better than they ever did before.
More than 75,000 people have signed a Consumer Reports petition demanding the FTC hold voice-cloning platforms accountable. The FTC ran its own Voice Cloning Challenge, offering more than $35,000 in prize money for workable defenses. Congress has taken notice too: both the Senate Commerce Committee and the House Energy and Commerce Committee have held hearings this year on AI voice fraud, and two bills are circulating that would require consent before cloning someone’s voice and mandate watermarking of AI-generated audio.
A separate law, the TAKE IT DOWN Act, was signed in May 2025 and criminalizes publishing certain nonconsensual AI-generated imagery. As of this May, platforms covered by the law must remove reported content within 48 hours. It already has its first conviction: an Ohio man pleaded guilty in April.
Who’s getting hit hardest
Older Americans absorb the worst of it, largely because these scams are built on fear for a family member’s safety, not a tempting financial pitch. Americans over 60 reported roughly $7.7 billion in total cybercrime losses recently, up 59% year over year, and within romance and confidence scams specifically, people over 60 file nearly three times as many complaints as people in their fifties.
Some banks have started adding friction on purpose: extra verification steps or short delays on large wire transfers requested by older customers, an imperfect fix that fraud specialists say is still better than nothing.
What actually works
Forget trying to spot a fake voice by ear. Security researchers recommend something lower-tech: agree on a family code word nobody outside your household would know, and verify any urgent money request through a separate channel before sending anything. If you get a call like Del Mastro’s, hang up and call the person back on a number you already have saved.
The bottom line: The technology to fake your voice is now free, fast, and good enough to fool the people who love you most. The only defense that actually works is one you set up before you ever need it.
The tools are outrunning the defenses
Part of what makes this so hard to stop is how low the barrier to entry has fallen. Voice-cloning apps are now widely available to anyone with an email address, and cybersecurity researchers describe a growing “fraud-as-a-service” underground economy, where criminal groups sell subscription access to cloning and auto-dialing tools, letting people with zero technical skill run scams that once required real expertise.
A handful of banks and telecom carriers have started piloting real-time tools designed to flag synthetic speech mid-call, but independent testing of those systems remains limited so far. Detection is racing to catch up with generation, and for now, generation is winning. Security advocates increasingly recommend keeping voicemail greetings generic rather than recorded in your own voice, since even that small, everyday convenience can hand a scammer everything they need.
