Blog
AI Voice Cloning Attack

AI Voice Cloning Apps Have No Consent Checks. None.

A Hong Kong company wired $25 million to fraudsters in 2024 because an employee trusted a voice. The voice belonged to the company's CFO. Except it didn't. It was a clone, built from audio scraped off the internet, and it was convincing enough to move $25 million in a single transaction.

voice cloning phone scam ai threat consumer protection

Part of our Voice Cloning Scams topic guide.

By Jesse Seaver, Co-Founder, Trust Onion

Published September 23, 2026

Filed to the News Desk · AI Voice Cloning Attack

Originally reported by BGR · Read the original article


Key Takeaways
  • Consumer Reports found that ElevenLabs, Speechify, PlayAI, and Lovo have no technical consent verification before cloning a voice.
  • Voice cloning requires only 20 to 30 seconds of audio, which scammers can find in voicemails or social media posts.
  • Human accuracy at detecting cloned voices is only 55 to 60 percent, making your ears an unreliable defense.
  • Hanging up and calling back is a good step, but it does not prove the original caller was legitimate.
  • Three rotating codewords that change every 60 seconds give families a verification layer no cloned voice can defeat.

The Apps Are Everywhere. The Safeguards Aren't.

In January 2026, BGR covered a Consumer Reports investigation into the biggest AI voice cloning platforms on the market. The findings were straightforward and alarming. ElevenLabs, Speechify, PlayAI, and Lovo, four of the most widely used voice cloning services, have no technical mechanisms to confirm that the person being cloned has given their consent.

Anyone can upload a few seconds of audio and get a voice back.

These platforms are not fringe tools. They have millions of users, legitimate business customers, and polished interfaces, built for podcasters, marketers, and accessibility applications. But Consumer Reports found the same technology is wide open to anyone who wants to sound like your mom, your boss, or your grandchild.

A Few Seconds Is All It Takes

Voice cloning now requires just 20 to 30 seconds of audio to produce a convincing replica. That audio doesn't have to come from a private conversation. A voicemail, a video posted on social media, a clip from a school play, that's enough.

Scammers have figured this out. The FTC reported that Americans lost $2.7 billion to imposter scams in 2023, and AI voice tools are accelerating the trend. Researchers at McAfee found that 77% of voice cloning scam victims lost money, with 36% losing more than $1,000.

The Hong Kong case is the extreme end, but the same technology scales down to everyday targets: elderly parents who get a tearful call from a "grandchild" in jail, or a spouse who hears a familiar voice asking for a wire transfer.

How the Scam Actually Works

The playbook is simple. Scammers identify a target, usually someone with money or someone emotionally connected to someone with money, then find audio of the person they want to impersonate. That audio is easy to find: voicemails, TikToks, YouTube videos, Instagram reels, even a brief clip from a podcast interview.

They feed that audio into a cloning app. No verification required, no consent check, no flagging system.

Then they call. They use the cloned voice to create urgency: "I'm in trouble," "I need money right now," "Don't tell anyone, just send it." The emotional pressure is designed to short-circuit your judgment. When the voice sounds right, your brain wants to believe it.

Human detection accuracy for cloned voices sits at 55 to 60 percent, barely better than a coin flip, according to researchers at University College London. Your ears are not a reliable defense.

Consent Was Never Part of the Design

The Consumer Reports investigation highlighted something worth stating plainly: these platforms were not designed with consent in mind. They were designed for speed and quality. Getting a realistic clone up and running fast is the product. Who gave permission for that voice to exist is not a field in the upload form.

ElevenLabs has faced public pressure before. In 2023, the platform was used to generate fake audio of public figures, and the company added some restrictions after the backlash. But restrictions are not the same as verification. A policy in a terms-of-service document does not stop someone from uploading 30 seconds of a stranger's voice.

PlayAI, Speechify, and Lovo have similar gaps. The investigation found no consistent, platform-wide technical barrier to cloning someone without their knowledge.

What "Hang Up and Call Back" Doesn't Solve

The standard advice when you get a suspicious call is to hang up and call the person back on a number you already have. That advice is worth following. If you get a call from someone claiming to be a family member in distress, hang up and call them directly on their usual number.

But a successful callback doesn't prove the original caller was legitimate. Sophisticated scammers can spoof numbers, manipulate context, or call back themselves. If you can't reach the person, that doesn't mean the emergency was real. And if you do reach them, the caller who first contacted you could still have been a scammer who got lucky with timing.

For calls involving family members, the callback is a good first step, not a complete answer. Use common sense, and if you genuinely believe someone may be in danger, contact local authorities.

Three Words the Clone Will Never Know

This is exactly the kind of call a family's three rotating codewords stop cold.

Trust Onion gives every family a set of three words that rotate every 60 seconds, calculated locally on each person's phone, with no server and no internet required. When someone calls claiming to be your son, your sister, or your dad, you ask one question: "What are the words?" A clone can sound perfect. It cannot know three private codewords that change every minute and were never said out loud anywhere a microphone could hear them.

The words are never transmitted and never stored anywhere a scammer can reach. They live in your family's phones and nowhere else. AI can clone a voice, but it cannot fake knowing something that only exists in your family's hands, rotating on a timer.

Trust Onion is free. Setup takes a few minutes. Any real family member can answer "What are the words?" instantly.

The Platforms Aren't Going to Fix This

Consumer Reports called on ElevenLabs, Speechify, PlayAI, and Lovo to build consent verification into their products. That is a reasonable ask, and also not something families should wait on.

Regulation moves slowly. Platform policy changes are inconsistent. The scammers using these tools are not waiting for a terms-of-service update.

Your family doesn't need the platforms to fix their consent problem. You need a system that works regardless of what any platform does or doesn't do. Three rotating codewords fit that description. The scam fails the moment the caller can't answer the question.

Frequently Asked Questions

How much audio does it take to clone someone's voice?

As little as 20 to 30 seconds of clear audio is enough for modern AI voice cloning tools to produce a convincing replica. That audio can come from voicemails, social media videos, or any public recording.

Are AI voice cloning apps legal?

Most voice cloning apps operate legally, but using them to impersonate someone for financial gain is fraud. The problem is that platforms like ElevenLabs and Speechify have no technical systems to verify consent before a voice is cloned.

How can I tell if a call is using a cloned voice?

You often can't. Research shows human detection accuracy for AI-cloned voices sits at around 55 to 60 percent. The safest approach is a pre-arranged verification method, like shared family codewords, rather than trusting your ears.

What should I do if I get a suspicious call from a family member?

Hang up and call the family member back on their usual number. If you can't reach them and believe they may be in danger, contact local authorities. Keep in mind that a successful callback does not prove the original call was legitimate.

How do Trust Onion's three rotating codewords stop voice cloning scams?

The codewords change every 60 seconds and are calculated locally on each family member's phone. A scammer using a cloned voice has no way to know the current words, so any caller who can't answer the question immediately is exposed as an impostor.

Give your family a verification system that no cloned voice can beat. Trust Onion's three rotating codewords are free, work offline, and take minutes to set up at trustonion.io.

Protect Your Family Free

Cite this page

AI Voice Cloning Apps Have No Consent Checks. None. — Trust Onion, September 23, 2026. https://trustonion.io/blog/ai-voice-cloning-apps-no-consent-checks-family-scams

RELATED READING

More on this topic

Fake Cop Calls Are Draining Bank Accounts in South Carolina

July 3, 2026

Fake Cop Calls Are Draining Bank Accounts in South Carolina

Beaufort County residents lost thousands to scammers posing as police. Here's how impersonation scam...

Read More
Bay Area Mom Wired $5,400 Before One Call Ended the Scam

May 26, 2026

Bay Area Mom Wired $5,400 Before One Call Ended the Scam

A Bay Area mom wired $5,400 to scammers who cloned her daughter's voice. One call to her daughter en...

Read More
AI Cloned His Daughter's Voice. He Almost Paid.

May 5, 2026

AI Cloned His Daughter's Voice. He Almost Paid.

AI scammers cloned a Vancouver man's daughter's voice to extort him. Here's how the scam works and w...

Read More