AI Voice Cloning and Deepfake Scams
For as long as telephones have existed, the test for whether a caller is who they say they are has been whether they sound like it. That test has stopped working, and most people have not updated their behaviour to match.
Cloning a voice convincingly now requires seconds of audio, and that audio is freely available from a social media video, a voicemail greeting, or a podcast appearance.
The three things to remember
Recognising the voice proves nothing. Urgency and secrecy are the real signals. And the only reliable defence is a channel switch, not a judgement call.
The three patterns in circulation
| Pattern | How it runs |
|---|---|
| The family emergency | A relative's voice, distressed, needing money immediately and privately |
| Business payment fraud | A senior person's voice authorising an urgent transfer outside normal process |
| Deepfake endorsement | A recognisable public figure appearing to promote an investment scheme |
All three exploit the same thing, which is not gullibility. They exploit the fact that voice and face recognition are automatic and feel like knowledge. You do not decide that your daughter sounds like your daughter. You simply know it, and that certainty is now unreliable.
People try to catch these out by asking questions only the real person would know. Against a prepared attacker that often fails, because the answers are frequently discoverable from the same social media that supplied the voice. Worse, it keeps you in the conversation, which is where the pressure is applied. The defence is not to interrogate better. It is to leave the channel entirely.
The channel switch
This is the whole defence, and it works because it does not require you to judge anything. You do not have to decide whether the voice is real. You simply stop using the channel the caller chose and use one you control.
That last line is worth keeping, because it answers the objection people raise. The scenario is engineered so that pausing feels like abandoning someone. In reality, if the call was genuine, five minutes changes nothing. If it was not, five minutes ends it.
A family safe word
Agree a word or a question with the people who would plausibly ring you in trouble, and agree it now rather than during an incident. It must be something never posted anywhere and never used elsewhere.
This scam is aimed disproportionately at grandparents, using a grandchild's voice, because the emotional leverage is strongest and the technology is least familiar. Having the conversation before it happens is worth more than any amount of advice afterwards. Frame it as a family agreement rather than a warning about being fooled, which lands better and is more likely to be remembered.
The signals that still work
The voice cannot be trusted, but the shape of the request can. These three appear in almost every case and are far harder for an attacker to avoid, because the scam does not function without them.
| Signal | Why it has to be there |
|---|---|
| Urgency | Time to think is time to verify, so it must be removed |
| Secrecy | A second opinion breaks the scam, so it must be discouraged |
| Unusual payment method | Transfers that can be reversed are useless to the attacker |
The third is the most reliable of the three. Requests to pay by transfer to a new account, by cryptocurrency, or by gift cards exist because those routes are hard or impossible to reverse. A genuine organisation asking for money has ordinary ways of taking it.
If you are tricked into making a payment yourself, that is legally different from a payment made without your involvement, and getting it back is considerably harder. New Zealand banks have introduced account name checking so you are warned when the account name does not match what you typed, which helps. It is a warning rather than a block, and it only helps if you stop when it appears.
Deepfake investment promotions
The third pattern differs from the other two because there is no call. A video circulates in which a well-known figure appears to endorse a trading platform or a cryptocurrency scheme. The face and voice are synthetic, the endorsement never happened, and the person often has no idea it exists.
The defence here is structural rather than perceptual, and it is a New Zealand-specific one. Anyone providing financial services here should be on the Financial Service Providers Register, and licensed providers are listed by the Financial Markets Authority, which also publishes warnings about entities to avoid. Check the register and the FMA warning list, and treat a celebrity endorsement as evidence of nothing at all.
If it has already happened
People who have been caught often do not report it, and the reason is embarrassment rather than indifference. That silence is useful to the attacker, because it delays warnings reaching other people and it delays the bank action that might recover the money. Being deceived by a convincing synthetic recording of someone you love is not a failure of intelligence. It is the technology working as designed.
What this guide does not cover
Detection tools for synthetic media are unreliable and improve on both sides continuously, so none is recommended here. Responsibility for cyber incident reporting in New Zealand has moved between agencies, so confirm the current route rather than relying on any name in this guide. Business payment controls, which are the real answer for organisations, require specific advice. This is general information rather than legal or security advice.
Related guides and tools
- Avoiding scams guide, for the broader set of approaches in circulation.
- Identity theft protection guide, for what an attacker gathers before making contact.
- Investment scams guide, for the deepfake endorsement pattern specifically.
- Digital wallets guide, for the one-time code attack that works the same way.
Test Your Knowledge
Ten questions on synthetic media scams and how to verify.
Sources: Netsafe on online scams and harm reporting; New Zealand Police on fraud reporting; and the New Zealand banking industry's introduction of account name checking on payments. Responsibility for cyber incident reporting has moved between agencies in recent years, so check the current reporting route before relying on any single agency name. This is general information rather than legal or security advice.