Blog
AI Voice Cloning Attack

AI Scam Bots Are Calling Your Family Right Now

A Kotaku writer's family member picked up the phone and heard a Royal Mail worker on the other end. Polite. Helpful. Completely convincing. Also completely fake. The caller was an AI bot, one of thousands making scam calls every hour to people just like your parents and grandparents.

voice cloning phone scam ai threat family safety

August 23, 2026

Originally reported by Kotaku · Read the original article


Key Takeaways
  • AI scam bots now conduct entire phone conversations without a human operator, scaling fraud to thousands of simultaneous calls.
  • Voice cloning requires as little as 20-30 seconds of audio, meaning any family member's voice can be faked.
  • Americans over 60 lost more than $3.4 billion to fraud in 2023, and AI bots specifically exploit voice-based trust.
  • A family's three rotating codewords stop impersonation calls instantly because no AI bot can know words it was never told.
  • Trust Onion's codewords are free, work offline, and rotate automatically so stolen words expire before they can be misused.

The Scam Call Got an Upgrade

For years, phone scams meant a real person reading from a script in a call center. You could sometimes hear background noise. The accent might seem off. You had clues.

That era is ending.

AI-powered scam bots now handle entire phone conversations without a human in the loop. They respond naturally, pivot when challenged, and stay in character under pressure. According to a Kotaku investigation published in August 2026, these bots are already reaching ordinary families, including one family member who received a call from a bot impersonating a Royal Mail worker.

The bot didn't ask for much at first. It just sounded helpful.

How the Bots Work

AI scam bots use large language models to hold real-time conversations. They're given a persona (postal worker, bank fraud department, grandchild in trouble) and a goal (get a payment, get a code, get access). Then they dial.

The technology scales in a way human scammers never could. One server can run hundreds of simultaneous calls. The bot doesn't get tired, doesn't get flustered, and doesn't break character the way a nervous human might.

Deepfake video versions are also on the rise. In February 2024, engineering firm Arup lost $25 million after an employee joined a video call where every participant, including the CFO, was a deepfake. What looked like a fringe capability a few years ago has become a practical tool for fraud at scale.

The Scambaiters Fighting Back

The same Kotaku piece highlights a community of YouTube creators who turn these bots against themselves. Kitboga and Jim Browning are two of the most well-known, spending hours on calls with scammers, exposing tactics, and occasionally triggering what can only be described as a bot breakdown.

Prompt injection is one technique. If a scammer's AI bot processes text from the call, a clever responder can insert hidden instructions that confuse or derail it. The resulting clips, where the AI starts contradicting itself or going off-script, make for genuinely entertaining viewing.

The breakdowns are funny. The underlying problem is not. For every bot that gets baited into a meltdown on YouTube, thousands more complete calls against real targets who don't know what they're dealing with.

Who's Most at Risk

Kotaku calls out older adults as the population most at risk, and that tracks with what researchers have documented for years. The FBI's Internet Crime Complaint Center reported that Americans over 60 lost more than $3.4 billion to fraud in 2023, the highest loss of any age group.

AI bots make this worse for a simple reason: older adults often rely on voice cues to judge whether a caller is legitimate. Does the voice sound right? Is it someone they recognize? Voice cloning now requires as little as 20-30 seconds of audio to generate a convincing replica of a specific person's voice.

That means a bot can call your mom sounding like you. It can call your grandfather sounding like your dad. The voice you trust most can be faked.

What the Bots Can't Fake

An AI scam bot is very good at sounding like a person. It cannot know what it was never told.

If your family uses three rotating codewords shared only among yourselves, an AI bot has no way to answer "What are the words?" Those words aren't in any training data. They're not on any social media profile. They rotate every few hours and are calculated locally on your phone, not stored on a server that could be breached.

The three codewords that Trust Onion generates are exactly the kind of private knowledge that makes impersonation calls fall apart. You pick up a call from someone claiming to be your daughter in trouble. You ask: "What are the words?" If she's your real daughter, she knows. If it's a bot, the call ends there, not after a long suspicious conversation, not after transferring any money, but in three seconds.

The Bigger Picture

The Kotaku piece frames scambaiting videos as a guilty pleasure, and watching a carefully constructed AI persona have a complete meltdown is hard not to enjoy. There's something satisfying about seeing the technology used against itself.

But the trend underneath the entertainment is worth taking seriously. AI scam bots are not a future threat. They're calling people's families right now, at scale. The Royal Mail bot that called the Kotaku writer's family member is one example among millions.

Deepfake video scams are following the same trajectory. Human detection accuracy for AI-generated voices sits around 55-60 percent, barely better than a coin flip. Awareness matters, but awareness alone doesn't stop a convincing AI caller from talking your parent into a gift card purchase before they realize what happened.

A shared family verification system does.

One Question That Changes Everything

You don't need to understand how AI voice cloning works to protect your family from it. You just need a question that only your real family members can answer.

"What are the words?"

Three rotating codewords. Free. No server. Works offline. They change every few hours, so anything stolen expires fast.

Trust Onion built it for exactly this situation, when the voice on the phone can no longer be trusted on its own and families need something simple that actually works.

The scam bots are getting better. The answer to that doesn't have to be complicated.

Frequently Asked Questions

How do AI scam bots make phone calls?

AI scam bots use large language models to hold real-time voice conversations. They're given a persona and a goal, then dial automatically. One server can run hundreds of simultaneous calls without any human involvement.

Can AI really clone a family member's voice?

Yes. Voice cloning technology now requires as little as 20-30 seconds of audio to generate a convincing replica. That audio can come from voicemails, social media videos, or any recording.

What is prompt injection in a scam call?

Prompt injection is a technique where someone inserts hidden instructions into a conversation to confuse or redirect an AI bot. Scambaiters like Kitboga and Jim Browning use it to expose scammer tactics on YouTube.

How do family codewords stop AI scam calls?

Three rotating codewords known only to your family can't be guessed or looked up. When someone calls claiming to be a family member, you ask 'What are the words?' A real family member knows. A scam bot doesn't.

Are AI phone scams getting more common?

Yes. According to reporting from Kotaku in August 2026, AI-powered scam bots are already reaching ordinary families at scale. Deepfake video scams are following the same trend, with cases like the $25 million Arup fraud in February 2024.

Set up your family's three rotating codewords for free at trustonion.io. One question stops the bots cold.

Protect Your Family Free
RELATED READING

More on this topic

AI Voice Cloning Scams Cost Americans $893M Last Year

August 11, 2026

AI Voice Cloning Scams Cost Americans $893M Last Year

A California mom lost thousands to a fake AI call of her daughter. FBI says Americans lost $893M to ...

Read More
She Heard Her Brother's Voice. It Wasn't Him.

August 7, 2026

She Heard Her Brother's Voice. It Wasn't Him.

An Ontario woman lost $12,000 after AI cloned her brother's voice in a fake emergency call. Here's h...

Read More
How AI Voice Scams Work (And What Actually Stops Them)

August 4, 2026

How AI Voice Scams Work (And What Actually Stops Them)

Group-IB research breaks down how deepfake voice scams work in 2025. Learn how AI clones trusted voi...

Read More