AI Voice Cloning Apps Have No Consent Checks. None.
A Hong Kong company wired $25 million to fraudsters in 2024 because an employee trusted a voice. The voice belonged to the company's CFO. Except it didn't. It was a clone, built from audio scraped off the internet, and it was convincing enough to move $25 million in a single transaction.
Part of our Voice Cloning Scams topic guide.
By Jesse Seaver, Co-Founder, Trust Onion
Published September 23, 2026
Filed to the News Desk · AI Voice Cloning Attack
Originally reported by BGR · Read the original article
- Consumer Reports found that ElevenLabs, Speechify, PlayAI, and Lovo have no technical consent verification before cloning a voice.
- Voice cloning requires only 20 to 30 seconds of audio, which scammers can find in voicemails or social media posts.
- Human accuracy at detecting cloned voices is only 55 to 60 percent, making your ears an unreliable defense.
- Hanging up and calling back is a good step, but it does not prove the original caller was legitimate.
- Three rotating codewords that change every 60 seconds give families a verification layer no cloned voice can defeat.
The Apps Are Everywhere. The Safeguards Aren't.
In January 2026, BGR covered a Consumer Reports investigation into the biggest AI voice cloning platforms on the market. The findings were straightforward and alarming. ElevenLabs, Speechify, PlayAI, and Lovo, four of the most widely used voice cloning services, have no technical mechanisms to confirm that the person being cloned has given their consent.
Anyone can upload a few seconds of audio and get a voice back.
These platforms are not fringe tools. They have millions of users, legitimate business customers, and polished interfaces, built for podcasters, marketers, and accessibility applications. But Consumer Reports found the same technology is wide open to anyone who wants to sound like your mom, your boss, or your grandchild.
A Few Seconds Is All It Takes
Voice cloning now requires just 20 to 30 seconds of audio to produce a convincing replica. That audio doesn't have to come from a private conversation. A voicemail, a video posted on social media, a clip from a school play, that's enough.
Scammers have figured this out. The FTC reported that Americans lost $2.7 billion to imposter scams in 2023, and AI voice tools are accelerating the trend. Researchers at McAfee found that 77% of voice cloning scam victims lost money, with 36% losing more than $1,000.
The Hong Kong case is the extreme end, but the same technology scales down to everyday targets: elderly parents who get a tearful call from a "grandchild" in jail, or a spouse who hears a familiar voice asking for a wire transfer.
How the Scam Actually Works
The playbook is simple. Scammers identify a target, usually someone with money or someone emotionally connected to someone with money, then find audio of the person they want to impersonate. That audio is easy to find: voicemails, TikToks, YouTube videos, Instagram reels, even a brief clip from a podcast interview.
They feed that audio into a cloning app. No verification required, no consent check, no flagging system.
Then they call. They use the cloned voice to create urgency: "I'm in trouble," "I need money right now," "Don't tell anyone, just send it." The emotional pressure is designed to short-circuit your judgment. When the voice sounds right, your brain wants to believe it.
Human detection accuracy for cloned voices sits at 55 to 60 percent, barely better than a coin flip, according to researchers at University College London. Your ears are not a reliable defense.
Consent Was Never Part of the Design
The Consumer Reports investigation highlighted something worth stating plainly: these platforms were not designed with consent in mind. They were designed for speed and quality. Getting a realistic clone up and running fast is the product. Who gave permission for that voice to exist is not a field in the upload form.
ElevenLabs has faced public pressure before. In 2023, the platform was used to generate fake audio of public figures, and the company added some restrictions after the backlash. But restrictions are not the same as verification. A policy in a terms-of-service document does not stop someone from uploading 30 seconds of a stranger's voice.
PlayAI, Speechify, and Lovo have similar gaps. The investigation found no consistent, platform-wide technical barrier to cloning someone without their knowledge.
What "Hang Up and Call Back" Doesn't Solve
The standard advice when you get a suspicious call is to hang up and call the person back on a number you already have. That advice is worth following. If you get a call from someone claiming to be a family member in distress, hang up and call them directly on their usual number.
But a successful callback doesn't prove the original caller was legitimate. Sophisticated scammers can spoof numbers, manipulate context, or call back themselves. If you can't reach the person, that doesn't mean the emergency was real. And if you do reach them, the caller who first contacted you could still have been a scammer who got lucky with timing.
For calls involving family members, the callback is a good first step, not a complete answer. Use common sense, and if you genuinely believe someone may be in danger, contact local authorities.
Three Words the Clone Will Never Know
This is exactly the kind of call a family's three rotating codewords stop cold.
Trust Onion gives every family a set of three words that rotate every 60 seconds, calculated locally on each person's phone, with no server and no internet required. When someone calls claiming to be your son, your sister, or your dad, you ask one question: "What are the words?" A clone can sound perfect. It cannot know three private codewords that change every minute and were never said out loud anywhere a microphone could hear them.
The words are never transmitted and never stored anywhere a scammer can reach. They live in your family's phones and nowhere else. AI can clone a voice, but it cannot fake knowing something that only exists in your family's hands, rotating on a timer.
Trust Onion is free. Setup takes a few minutes. Any real family member can answer "What are the words?" instantly.
The Platforms Aren't Going to Fix This
Consumer Reports called on ElevenLabs, Speechify, PlayAI, and Lovo to build consent verification into their products. That is a reasonable ask, and also not something families should wait on.
Regulation moves slowly. Platform policy changes are inconsistent. The scammers using these tools are not waiting for a terms-of-service update.
Your family doesn't need the platforms to fix their consent problem. You need a system that works regardless of what any platform does or doesn't do. Three rotating codewords fit that description. The scam fails the moment the caller can't answer the question.
Frequently Asked Questions
How much audio does it take to clone someone's voice?
As little as 20 to 30 seconds of clear audio is enough for modern AI voice cloning tools to produce a convincing replica. That audio can come from voicemails, social media videos, or any public recording.
Are AI voice cloning apps legal?
Most voice cloning apps operate legally, but using them to impersonate someone for financial gain is fraud. The problem is that platforms like ElevenLabs and Speechify have no technical systems to verify consent before a voice is cloned.
How can I tell if a call is using a cloned voice?
You often can't. Research shows human detection accuracy for AI-cloned voices sits at around 55 to 60 percent. The safest approach is a pre-arranged verification method, like shared family codewords, rather than trusting your ears.
What should I do if I get a suspicious call from a family member?
Hang up and call the family member back on their usual number. If you can't reach them and believe they may be in danger, contact local authorities. Keep in mind that a successful callback does not prove the original call was legitimate.
How do Trust Onion's three rotating codewords stop voice cloning scams?
The codewords change every 60 seconds and are calculated locally on each family member's phone. A scammer using a cloned voice has no way to know the current words, so any caller who can't answer the question immediately is exposed as an impostor.
Give your family a verification system that no cloned voice can beat. Trust Onion's three rotating codewords are free, work offline, and take minutes to set up at trustonion.io.
Protect Your Family FreeCite this page
AI Voice Cloning Apps Have No Consent Checks. None. — Trust Onion, September 23, 2026. https://trustonion.io/blog/ai-voice-cloning-apps-no-consent-checks-family-scams
July 3, 2026
Fake Cop Calls Are Draining Bank Accounts in South Carolina
Beaufort County residents lost thousands to scammers posing as police. Here's how impersonation scam...
May 26, 2026
Bay Area Mom Wired $5,400 Before One Call Ended the Scam
A Bay Area mom wired $5,400 to scammers who cloned her daughter's voice. One call to her daughter en...
May 5, 2026
AI Cloned His Daughter's Voice. He Almost Paid.
AI scammers cloned a Vancouver man's daughter's voice to extort him. Here's how the scam works and w...


