A familiar voice asking for money is not proof of anything. Pause, call a number you already have saved, and never pay on the same thread that made the request, especially with gift cards, crypto, or a payment handle you have never seen before.
Imagine you are in the middle of cooking dinner when your phone lights up with a WhatsApp message from a number that is not in your contacts. The profile photo is your son at his graduation, the same crop he still uses on Instagram. The message is a 22-second voice note, and it sounds exactly like him.
Six warning signs that matter more than a familiar voice

The clip sounded like your son, and that is exactly what a voice clone is built to do. The Federal Trade Commission (FTC) has warned since 2023 that a scammer can copy a voice from a short public clip, then call and pretend to be family. The Federal Communications Commission (FCC) later said the same about cloned robocalls and deepfake video links. You do not win by studying the sound of the voice. You win by reading what the message asks you to do.
Your 22 seconds of audio carried six warning signs. The first was urgency: he needs $800 now, before a shift the next morning, at a repair shop that can take the car the same day. The second was secrecy, because the message said not to tell Dad. The third was a new way to pay, an Apple Cash handle that never appeared in five years of family Venmo. The fourth was a refusal to video-call, worked into the story (it was a friend’s phone, and the camera was “whatever”). The fifth was slightly off phrasing, since your son says “the shop on Morse” and never “the mechanic shop.” The sixth was the classic cover for a new number: “I dropped my phone.”
Now compare those signs with the FTC’s four scam signals, and the picture gets dull in a useful way. Scammers pretend to be someone you know. They invent a problem. They pressure you to act immediately, and they tell you to pay in a specific way, such as cryptocurrency, a wire, a payment app, or a gift card with the numbers read off the back. Your voice note hit all four at once, and the clone only supplied the raspy voice. You do not need all six signs to stop, because one honest pause is enough. A message from a “CEO” on Slack that only has urgency and a gift-card request is still a reason to stop.
Rule of thumb: A new payment handle plus a 20-minute deadline is a stop sign. Call the known number before you open Apple Cash.
Call back on a number you already have

The FTC’s advice on family-emergency clones is blunt. Do not trust the voice. Call the person who supposedly contacted you, on a phone number you already know is theirs, and if you cannot reach them, try another family member or a friend. In our story you would do that in under four minutes, your son would pick up, and the $800 would stay in your checking account.
The safe channel is one you owned before the request arrived, which security people call reaching the person “out of band.” That means your Favorites list, your work directory, or the number printed on the back of your debit card. It also means searching for your colleague in the company’s real Slack, not answering the direct message that just arrived, and finding a job on the company’s own careers page, not the listing that emailed you. The incoming thread is not safe territory, because caller ID lies, WhatsApp profile photos get lifted, email display names get forged, and a FaceTime thumbnail can be a still image.
The same move works on a fake executive. Say a Teams chat arrives in your accounts payable inbox (the team that pays the company’s bills) from someone calling himself the CFO. He asks you to buy eight Google Play cards for a client lunch because the corporate card declined. The real CFO sits two floors up, so you walk the stairs and find him in a vendor meeting with his own laptop open. The chat account was a lookalike, and the $200 of cards never leaves the drugstore rack. If the person does not pick up, you still do not pay. Call a second relative and wait. A real tow truck driver can hold for one extra ring, but a clone cannot survive a call to a known number.
Video and photos can be fake too
Audio is the loud version of this problem, while video is the version people still treat as proof. A 12-second clip of your son in a parking lot, lips moving, is still just a file. Deepfakes, which are generated video or audio made to look like a real person, are now good enough that hunting for glitches is a weak habit. Odd blinking used to be a party trick, and today it is not a reliable check. The FCC’s consumer guide puts celebrity deepfake ads and cloned family calls in the same group, and the advice is the same for both: reach the real person or the real company before you send money.
A live video call on a number you already have is a better check than a file someone sent you. Ask something unscripted, such as “What did you burn at dinner on Sunday?” or “What color is the chipped kettle?” Your kettle is blue and ugly. A clone trained on Instagram has the graduation photo, but it does not have the kettle. If the caller stalls, refuses the camera, or keeps returning to the $800, hang up and use the known number anyway.
Still images lie in quieter ways. Romance scams described on the FTC’s consumer pages often start with a handsome profile and a job that keeps the person overseas, and then a plane ticket or a medical bill appears. Generated photos made that cheaper to run. The giveaway is still the request, because the person will not meet you and wants money on a payment method you cannot reverse. The FTC’s crypto page has one sentence worth taping to your monitor: only scammers demand payment in cryptocurrency.
Too-good jobs, crypto chats, and cloned ads
Voice clones steal trust you already have. Too-good offers steal trust you wish you had, such as a job, a return on your money, or a famous face saying “buy.” The defense is the same test of payment method and channel, and only the costume changes.
Fake hiring tests go after your documents. A listing for a “remote AI evaluator, $45 an hour, 20-minute unpaid test, then upload your driver’s license and a voided check for payroll” is a data harvest with a job title on it. Real employers do not collect a Social Security card through a Google Form in the first email. In December 2024, FTC staff wrote that reported job-scam losses were more than $220 million in the first six months of that year. Task scams, where you do tiny “app boosting” jobs and then put in your own money to reach the next tier, were a large share of those reports. Treat that number as reported harm, not a full count of every victim, and reject any listing that asks you to pay to get paid.
Now picture a younger relative, 24, who almost funds a different costume. A TikTok shows a chat window that looks like ChatGPT, branded as an “investment agent,” and promises that a $250 deposit in USDT (a cryptocurrency pegged to the US dollar) will start trades. The web address is a lookalike, and OpenAI does not take your USDT to run a secret money bot. ChatGPT, Claude, Gemini, and Grok will draft a grocery list for you, but they do not hold your coins. He closes the tab once someone makes him read the real help center instead of the ad. A video that looks like a celebrity selling pans or a trading bot is an ad file too, and the FCC flagged deepfake celebrity cookware pushes for that reason, so open the real brand site yourself. Gift cards follow the same pattern, and the FTC repeats that they are for gifts. No government office, no “HR portal,” and no family emergency is paid in Google Play or Apple codes.
What chat products are and are not
ChatGPT, Claude, Gemini, and Grok are writing tools with a search-shaped memory of the public web. They are not your bank. They cannot see your son in the break room, they cannot see your CFO two floors up, and they cannot see the Apple Cash handle on your screen. If you paste a transcript into a chat and ask “does this sound like a scam,” you may get a decent essay back. That essay is not verification, because verification is the second ring on the known number.
People try the chat anyway. After the voice note, you might be tempted to drop the transcript into ChatGPT because the tab is already open from a work draft. You type three words, delete them, and call your son instead. A lookalike site wearing a ChatGPT costume may happily cheer on the deposit, and you cannot tell which one you opened from how confident the writing sounds. Do not paste routing numbers, ID scans, or the voice file into a consumer chat to “double-check.” Use the chat later to draft the fridge script below, and do not treat it as the control that releases $800.
Vendor usage policies (OpenAI, Anthropic, and the others) already forbid using their products to run scams. That rule protects their terms, not your checking account, so your own rule has to be smaller and simpler. A chat box does not approve wires.
Channel, verify step, never-do
This grid covers the voice-note story and the costumes around it. The numbers come from the story ($800, eight gift cards) or from the FTC’s reported job-scam figure above, and nothing else here is a national crime rate.
| Channel | Verify step | Never-do |
|---|---|---|
| Voice note or call | Hang up. Call the number already in Favorites. Ask the family word. | Pay on that thread. New Apple Cash, Zelle, wire, crypto, gift cards. |
| Video clip or live request | Call back on the known number. Demand a live, unscripted question. | Trust a file they sent. Treat a still as FaceTime. |
| Email, Slack, or “CEO” text | Walk upstairs, or search the real company directory. Confirm in a channel you already use. | Buy gift cards because the display name matches. |
| Job listing, dating chat, or ad | Open the real careers page or brand site yourself. Reverse-search the recruiter. | Upload ID and a voided check to a “hiring test.” Send crypto to an “investment agent.” |
The table separates the costume from the control. The costume is the voice, the logo, or the job title, and the control is a channel you owned before the request came in. If the control is missing, the money stays put.
A family call-back script
Print this and put it on the fridge. Fill in the brackets in person, not in the family WhatsApp after something has already happened. Pick a silly word on purpose (here it is blue kettle), because Instagram does not know your kettle.
FAMILY CALLBACK (fridge copy)
Word we picked in person: [blue kettle]
Known numbers: Son or daughter [Favorites], Partner [Favorites], Parent [landline]
If anyone asks for money by voice, video, text, or chat:
1. Do not reply on that same thread.
2. Call the person on a number already in contacts.
3. If they do not pick up, call a second family member.
4. Ask for the family word. Hang up if they stall or refuse video on the known number.
5. Never send Apple Cash, Zelle, Venmo, wire, crypto, or gift cards on an urgent ask.
6. New handle, new URL, or "I dropped my phone" means stop.
7. After you are safe, report at ReportFraud.ftc.govThis script turns your four minutes of careful thinking into a default. The word is a cheap second check, and the list of known numbers is the real one. Change the word if it ever leaks, and do not post a photo of the fridge sheet.
Common mistakes
- Trusting the raspy voice because it sounded like Sunday dinner, when clones copy rasp.
- Calling back the incoming WhatsApp number or the caller ID, which is still the scammer’s thread.
- Sending a “small test” of $50 to see if the handle is real, when small tests get cashed out too.
- Pasting the transcript into ChatGPT and treating the answer as if it were a callback.
- Uploading a license and a voided check to a 20-minute hiring test.
- Keeping the secret because the clip said not to tell Dad, when secrecy is the whole trick.
How to practice this week
Pick the family word at dinner, on paper, with phones face down. Fill in the fridge script, and then run one fake drill for 10 minutes using the $800 voice note or the gift-card chat from the CFO. The next post in this series covers honesty at school and work, and how to cite AI properly. You can find the whole series at AI safety for everyday life. If you still need to tidy up your accounts before the next scare, the earlier post on free versus paid AI accounts is the place to start, and a fourth payment app is not.
Quick recap
- Treat a familiar voice as untrusted until a known number picks up.
- Call a number you already own, and never the incoming thread.
- Video files and celebrity ads can be fake, and a live, unscripted call to a known number is the check.
- Too-good jobs, crypto “agents,” and cloned ads fail the same payment-method test.
- ChatGPT is a place to draft, and it does not confirm wires.
Series notes
This is Part 1 of AI safety for everyday life. Next: School, work honesty, and citations.
Sources
- FTC Consumer Advice: How To Avoid a Scam (four signs: pretend, problem or prize, pressure, specific payment rail)
- FTC: Scammers use AI to enhance their family emergency schemes (voice clones from a short public clip; call a number you know)
- FTC: Fighting back against harmful voice cloning (boss or family voice asking for money or account numbers)
- FCC: Deep-fake audio and video links (cloned voices, celebrity deepfake ads, call the real person before you send money)
- FTC: Job scams and the FTC staff press note on reported job-scam losses, including more than $220 million in the first half of 2024 (December 2024 release)
- FTC: What To Know About Cryptocurrency and Scams (only scammers demand payment in cryptocurrency)
- FTC: Avoiding and Reporting Gift Card Scams (gift cards are for gifts, not payments)
- ReportFraud.ftc.gov (where to tell the FTC after you are safe)
- OpenAI usage policies and Anthropic usage policy (vendor rules; they are not a substitute for a callback)
- Analytics Made Simple: AI safety for everyday life (this series)
Keep going
Same lessons in your feed
Short diagrams, hooks, and weekly tutorials on Substack, Instagram, X, and Facebook.
