Blog
Phone/Text Scam (General)

AI Voices Are Robbing Companies Blind. Your Family Is Next.

A finance director in Singapore wired $499,000 to criminals she never met. She thought she was on a video call with her CEO and colleagues. Every person on that call was fake, generated by AI in real time. The call looked right. It sounded right. It wasn't.

voice cloning phone scam ai threat family safety

July 31, 2026

Originally reported by BleepingComputer · Read the original article


Key Takeaways
  • Deepfake voice incidents rose 680% year-over-year, according to Adaptive Security researcher Marshall Bennett.
  • A Singapore finance director lost $499,000 on a video call where every participant was AI-generated.
  • Voice cloning requires as little as 20 to 30 seconds of audio to produce a convincing fake.
  • Technical security tools don't monitor conversations, so the human layer is both the vulnerability and the fix.
  • Three rotating codewords that change every few hours give families a simple, offline way to verify any caller instantly.

The Numbers Are Not Abstract

Deepfake voice incidents rose 680% year-over-year, according to research published on BleepingComputer in April 2026 by Adaptive Security researcher Marshall Bennett. That's not a rounding error. That's a technology moving faster than the defenses built to stop it.

Two cases show exactly how bad this has gotten.

In Singapore, a finance director joined what she believed was a routine video call. Her CEO was there. Her colleagues were there. Everyone looked and sounded familiar. She approved a wire transfer of $499,000. Every participant on that call was AI-generated.

At engineering firm Arup, an employee did the same thing in February 2024. The loss: $25.6 million, wired to Hong Kong accounts. Same method. Bigger number.

Why Technical Defenses Keep Failing

Security software scans files, flags emails, and blocks known malware. It wasn't built to watch a video call and ask whether that's actually your CFO.

Bennett's research makes this point clearly: deepfake voice and video attacks exploit human trust through phone and video channels that most security stacks don't monitor. The attack is a conversation, and conversations happen outside the firewall.

So the attacker doesn't need to hack your systems. They just need to sound like someone you trust.

Voice cloning now requires as little as 20 to 30 seconds of audio. A LinkedIn video, a conference recording, a voicemail greeting. That's enough. The cloned voice can then call anyone, say anything, and apply the kind of urgency that short-circuits careful thinking.

"I need you to wire funds before end of day."

"Don't tell anyone yet, it's sensitive."

"I'm at the airport, just handle it for me."

The Human Layer Is the Weak Link, and Also the Fix

Bennett's primary recommendation is to train employees to pause and verify before acting on any urgent financial request. That's genuinely good advice. The problem is that "pause and verify" is vague. Verify how? Call them back on what number? Using what method that an attacker couldn't also intercept or spoof?

This is where most guidance falls short. It tells you to be skeptical but doesn't give you a tool.

In business settings, verification usually means a second channel: a follow-up call on a known number, a confirmation email, a callback through the company directory. That works sometimes, but it's slow, easy to forget under pressure, and still relies on technology an attacker can potentially manipulate.

For families, the challenge is harder. There's no IT department, no security training, no protocol. Just a phone call from someone who sounds exactly like your mom, your son, or your spouse.

What Families Are Up Against

The same AI that fooled a trained finance professional can fool anyone.

Grandparent scams now routinely use cloned voices. A grandparent hears their grandchild's voice, panicked, saying they've been arrested and need bail money wired immediately. The voice is real enough to cause real fear, and real fear causes real money transfers.

The FBI reported that Americans lost more than $10 billion to phone and online fraud in 2023. Elder fraud alone accounted for $3.4 billion of that, according to the FBI's Internet Crime Complaint Center. The figures for 2024 and 2025 are expected to be higher.

These aren't unsophisticated targets falling for crude tricks. These are careful, loving people being deceived by technology that didn't exist five years ago.

The Simplest Defense Is Also the Strongest

Here's what the Singapore finance director didn't have, and what your grandmother probably doesn't have either: a shared secret that only the real person could know.

Not a password stored on a server. Not a security question an attacker could research. Three rotating codewords, calculated locally on your phone, that change every few hours.

That's Trust Onion. It's free, works offline, and requires no technical knowledge to use.

When someone calls claiming to be your daughter, you ask: "What are the words?" If she's really your daughter, she opens the app and reads them. If she can't answer, the call ends.

AI can clone a voice. It cannot fake knowing three codewords that rotate on a schedule and never touch a server. There's nothing to steal, nothing to intercept, nothing to spoof. The words live only on the phones of the people who share them.

For deeper verification, Trust Onion offers Proofies: a selfie with the current three words overlaid, signed in a way the recipient can verify. It combines what you look like, what you know, where you are, and when, all four together in one simple image.

A fake voice can sound like your son. It cannot know what your son's phone showed him at 3pm today.

What You Can Do Right Now

If you work in finance or operations, forward Bennett's research to your team. "Pause and verify" is the right instinct, but build a specific process around it so urgency can't override it.

If you're thinking about your family, talk to them this week. You don't need to explain AI or deepfakes in detail. You just need to agree on a system.

"If anyone calls claiming to be me and needs something urgent, ask them for the words."

That conversation takes two minutes. The app takes two minutes to set up. And the protection works every time someone calls pretending to be someone they're not.

Deepfake voice attacks rose 680% in a year. The technology will keep improving. The codewords work either way.

Frequently Asked Questions

How do deepfake voice scams work?

Scammers clone a real person's voice using as little as 20 to 30 seconds of audio from social media or voicemail. They then call a target, impersonate the real person, and create urgency around a financial request. The voice sounds genuine because it is a real clone, not an actor.

How much money have businesses lost to deepfake video calls?

A Singapore finance director lost $499,000 in a single AI-generated video call. Engineering firm Arup lost $25.6 million in February 2024 using the same method. Deepfake voice incidents rose 680% year-over-year as of April 2026.

How can families protect themselves from AI voice cloning scams?

The most reliable defense is a shared verification system your family agrees on before a scam call happens. Trust Onion uses three rotating codewords that change every few hours. If a caller can't say the words, they're not who they claim to be.

Can AI fake a family member's voice well enough to fool someone?

Yes. Voice cloning technology has advanced to the point that trained professionals have been deceived, including a finance director who lost $499,000. Family members with no security training are at least as vulnerable.

What is Trust Onion and how does it stop voice scams?

Trust Onion is a free app that gives families three rotating codewords calculated locally on their phones. When someone calls claiming to be a family member, you ask for the words. AI can clone a voice but cannot know a codeword that changes every few hours and never touches a server.

Protect your family with three rotating codewords that AI can't clone or fake. Trust Onion is free and takes two minutes to set up at trustonion.io.

Protect Your Family Free
RELATED READING

More on this topic

Bell Canada's AI Flags Spoofed Calls. But Can It Stop Voice Clones?

July 30, 2026

Bell Canada's AI Flags Spoofed Calls. But Can It Stop Voice Clones?

Bell Canada's AI has analyzed 4.4 billion calls and blocked 540 million suspicious ones. Here's what...

Read More
Fake FPL Calls Are Offering $4,000 Rebates. They're AI.

July 25, 2026

Fake FPL Calls Are Offering $4,000 Rebates. They're AI.

AI-generated calls are impersonating FPL reps and promising $4,000 energy rebates. Here's how the sc...

Read More
Fake Walmart Calls Are Using AI Voices to Steal Your Identity

July 21, 2026

Fake Walmart Calls Are Using AI Voices to Steal Your Identity

A nationwide robocall scam uses AI voices posing as Walmart to steal Social Security numbers. Here's...

Read More