Skip to content

Security1 publisher2 min readPublished

To counter voice clones built from a few seconds of scraped audio, experts suggest agreeing on a family safe word

Hiya's March report puts deepfake voice calls at one in four Americans, with 24 percent saying they cannot tell a clone from the real voice. WeLiveSecurity's recommended control is a secret agreed before any call.

The Watch · Security desk

Illustration accompanying To counter voice clones built from a few seconds of scraped audio, experts suggest agreeing on a family safe word

What happened

  • A Hiya report from March found one in four Americans say they received a deepfake voice call in the previous 12 months, according to WeLiveSecurity's account of the study.
  • A few seconds of audio is enough to build a convincing clone, and those seconds come from social posts left unrestricted by privacy settings or from work content that ends up online.
  • The prominent version of the scam is a cold call to a relative playing deepfake audio suggesting a loved one has been kidnapped, dressed up with personal details taken from the same accounts.
  • The recommended control is a pre-agreed safe word that is memorable but unusual and derivable from no social post or open source, which rules out family pets and favourite sports teams.
  • If the word is forgotten, the advice is to end the call and ring back on the number already in the address book, or send a message through a family group that already exists.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability The entry requirement for this fraud is seconds of public audio, so an unrestricted account supplies the attacker's only technical input and nothing needs to be breached first.
  • constraint A secret agreed off the phone holds at any level of clone quality, so a better cloning model still runs into that one check.
  • exposure Publicly posted travel plans hand the caller the timing, because a relative who cannot reach the supposed victim by phone is the condition the script wants.
  • decision Whether the same pre-agreed challenge belongs in help-desk resets and payment approvals is a call this guidance does not make, and no effectiveness figure exists in it to make the case with.

The kidnap script keeps the audio sample short on purpose. The cloned voice plays for a few seconds at a time, mixed with sobbing and, where it helps, background noise [7]. The caller picks the moment by watching the supposed victim's social accounts, and the best moment is while that person is abroad and not answering their phone [6]. The check a family makes therefore has to work in the first minute and under pressure. There is no clean recording to examine.

An attacker working this way holds two inputs: the scraped audio, and whatever the accounts gave up about names, places and plans [4][5]. A word agreed in advance is in neither. WeLiveSecurity puts it as a scammer having no way of finding the word out [9]. The same guidance rules out pets and favourite teams, because those are researchable [8].

The failure mode is recall. Someone hearing a relative sob down the line may not retrieve an agreed phrase at all, so the fallback carries more weight than the phrase: end the call, dial the number already stored in the address book, or message through the group that already exists [10].

The two survey figures sit one point apart, 25 percent reporting a deepfake call in the past twelve months and 24 percent saying they cannot distinguish one [13]. Hiya's report as cited does not say whether those are the same people, and the line about twice as many Americans thinking scammers are beating the mobile carriers arrives as a ratio with no absolute numbers behind it [3][14].

The guidance is written for families, and it stops there. It does not extend the pre-agreed phrase to help-desk password resets or payment approvals, and it puts no number on how often a safe word has stopped a call [15]. What transfers is the structure: a secret agreed before the call, verified on a channel the caller does not choose. For the aftermath the article lists steps a fraud desk would recognise, which are to stop communicating with the scammer, contact the bank about blocking or returning the funds, change any passwords disclosed, and switch on two-factor authentication [12].

What to watch

  • Whether Hiya's next report moves the 24 percent who say they cannot distinguish a cloned voice.
  • Whether any carrier, bank or employer publishes a pre-agreed phrase as written procedure with a stop rate attached, rather than as consumer advice.
  • Whether kidnap-script callers begin prompting for a safe word themselves to learn what a family agreed.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories