Skip links

AI Voice Phone Scam: What’s Real, What’s Not, What to Do

The 20-second version

Try our awesome AI for free

Nation AI
Ask me anything...

No, saying “hello” does not hand your voice to a scammer. The version that went viral in spring 2026 is a remix of the old “Can you hear me?” hoax, amplified by companies that sell anti-fraud products. Years in, consumer watchdogs still have not documented one person who lost money that way.

But AI voice scams are absolutely real, through a different door: a few minutes of audio you already posted (a video, a podcast, a voicemail greeting) is all consumer cloning tools need. The payoff is almost always a relative in trouble or a fake bank fraud department.

The one habit that actually protects you: hang up and call back yourself, on a number you already had. No real bank employee and no real federal agent will ever ask you for a code or a transfer over the phone.

Already caught? Freeze the card, dispute it in writing (Regulation E runs on deadlines you do not want to miss), file a police report, then report it to the FTC. The tool below gives you the exact order for your situation.

An unknown number lights up your screen. You pick up, nobody answers. Since spring 2026, a rumor says those few seconds are enough to steal your voice and make it speak for you. The truth is less cinematic and more serious: the viral scenario does not hold up, but scams built on AI-generated voices are very much happening, with a completely different playbook. Here is what checks out, what does not, and exactly what to do if you already answered, talked, or paid.

No, saying “hello” is not enough to clone your voice

You have seen the post: an unknown number calls, you pick up, you keep saying “hello? hello?”, nobody speaks. Hackers supposedly grab enough of your voice to rebuild it, call your family, and talk them out of money.

This story has a paper trail. It grew out of blog posts published by companies that sell protection against exactly this kind of fraud, and it is the direct descendant of the “Can you hear me?” hoax that police departments and local news have been recycling since 2016. That older version claimed a recorded “yes” could be edited into an authorization for a purchase. The Better Business Bureau’s Scam Tracker still has no report of anyone losing money to it, and fact-checkers who asked the BBB, the FTC and the Consumer Federation of America for a single documented victim never got one. The 2026 remix swapped the recorded “yes” for AI, but the evidence did not improve: no agency has published a single case where a two-second “hello” produced a working voice clone. The FTC’s own warnings about AI-powered family emergency scams describe something else entirely, and that something else is the part worth worrying about.

How much audio does cloning actually take?

The most reliable answer comes from the vendors themselves. ElevenLabs, the reference tool for AI voice cloning, publishes two modes on its product page: instant cloning asks for 1 to 5 minutes of audio, and professional cloning, the one that becomes “nearly indistinguishable” from the original, needs more than 30 minutes of clean recordings, ideally around three hours.

Screenshot of the English ElevenLabs voice cloning page comparing instant cloning (1 to 5 minutes of audio) with professional cloning (30+ minutes of clean audio samples)
In the “Select the cloning mode based on your needs” section of its voice cloning page, ElevenLabs asks for 1 to 5 minutes of audio for an instant clone and 30+ minutes of clean audio samples for a professional one. Screenshot taken July 28, 2026 on elevenlabs.io.

Two seconds of “hello” over a compressed phone line, with background noise, does not fill either bucket. Reporters have run the test repeatedly: feed a cloning tool a few words or a voicemail greeting and the output lands somewhere in the uncanny valley, with flat delivery and wrong rhythm.

Illustration: a scale weighs one tiny sound clip against a much heavier stack of audio recordings
A single “hello” weighs nothing next to the amount of audio a convincing voice clone actually requires.

So why do these silent calls happen at all? Two much duller reasons. First, call centers use predictive dialers that fire dozens of numbers at once to keep agents busy: when too many people answer at the same moment, there is nobody left to take your call. Second, these “ghost calls” confirm that a number pulled from a data breach is still live, so it can be sold and dialed again later.

AI voice cloning scams, on the other hand, are very real

Killing the rumor does not mean the risk is zero. It means the risk is somewhere else. Scammers do not need to call you to collect your voice: they already have it. A story, a TikTok or YouTube video, a podcast episode, a recorded webinar, a carefully worded voicemail greeting, a voice note someone forwarded: a few minutes of clean audio is enough for instant cloning.

And you are often not the target. More often, the scammer clones someone you love in order to call you and trigger a panic response before you think.

$3.5Breported lost to imposter scams in 2025, the most-reported fraud category for the fifth year running (FTC, June 2026)
$920Mof that went to government impersonators, up from $789 million in 2024 (same FTC data)
$7.7Blost by victims age 60 and older in 2025, up 37% in one year, average loss above $38,000 (FBI IC3)
70%of adults surveyed say they could not reliably tell a cloned voice from the real one (McAfee, 7,054 respondents)

The FTC logged more than a million imposter scam reports in 2025 alone, and its data points straight at the pattern used here: the costliest schemes open with a fake security alert, usually from a bank, and end with the victim moving money to “protect” it. Losses in those cases are limited only by what the victim has available. AI voice scams are not tracked as their own category, and that is the point: cloning is a coat of paint on fraud that already worked, not a new crime.

Vishing, spoofing, voice deepfake: what is what? Vishing is phishing by phone: someone calls to talk you out of a code or a transfer. Spoofing is faking the caller ID: your screen shows a local number, sometimes your actual bank’s number. A voice deepfake is the synthetic voice itself. A good scam stacks all three, and only the deepfake needs AI at all.

The 4 AI voice scam scenarios you will actually run into

Four colored tiles illustrating the four voice scam scenarios: a relative on the phone, a bank, a government agency and a company
Four different stage sets, one goal: get a code, a transfer or an approval within sixty seconds.

1. The family emergency call

A call comes in, the voice is familiar and frightened: a car wreck, an arrest, a broken phone, a stolen wallet in another country. The ask lands fast, usually a wire, a gift card reload, or a code that just arrived by text. This is the grandparent scam with better production value. The cloned voice only has to get past your first second of doubt; panic does the rest. Nearly eight in ten people who fell for an AI voice scam in McAfee’s survey lost money, most commonly between $500 and $3,000, and many of them sent it even though something about the call felt wrong.

2. The fake bank fraud department

This is the most expensive version in the US. Bank impersonators drove the highest reported losses of any business impersonation category in 2025, inside a nearly $1 billion total. The caller shows your bank’s real number (spoofing), knows your name, sometimes quotes recent transactions pulled from a breach, and announces “suspicious activity on your account.” Then comes the ask: approve the alert in your app, read back the code, or wire the balance to a “safe account” they will open for you. Synthetic speech makes the delivery smoother and lets the operation run at scale. There is no such thing as a safe account, and no bank moves your money for you over the phone.

3. The government impersonator

The IRS, the Social Security Administration, Medicare, a county sheriff, a federal “cyber division”: authority buys compliance. The hook is a refund waiting to be claimed, a fine to settle, a warrant you can make disappear by paying right now. Americans reported about $920 million lost to government impersonators in 2025. No federal agency calls to demand payment, and none accepts gift cards, wire transfers or crypto.

4. Business email compromise, by voice

The workplace version: a controller or an assistant picks up a call from the “CEO,” voice and all, demanding an urgent, confidential wire to a new account. It usually lands after hours, backed up by an email or a text. Business email compromise remains one of the largest single loss categories the FBI tracks, and adding a cloned voice to the follow-up call is now the cheap upgrade.

Red flags that should stop you cold

A good synthetic voice is hard to catch by ear, and the technical tells fade every year. So the warning signs are not in the voice, they are in the script, and that script has not changed in twenty years.

  • Manufactured urgency. “We have to act now,” “you have two minutes.” No legitimate situation requires a financial decision inside a minute.
  • Enforced secrecy. “Don’t tell anyone,” “don’t mention this to your branch.” A legitimate caller never tries to cut you off from other people.
  • An impossible request. A code from a text, a card PIN, a password, an approval tap in your banking app: nobody is allowed to ask you for those, ever.
  • A payment you cannot claw back. Wire transfers, Zelle, gift cards, crypto, cash handed to a “courier.”
  • A sudden change of channel. They move you to WhatsApp, Telegram or text “so this goes faster.”
  • Odd pauses and unnaturally even pacing. Strange gaps after your questions, flat intonation, perfectly formed sentences with no hesitation: possible signs of a generated voice or a read script.
  • A voice that dodges anything unscripted. An AI, or a scammer working from a sheet, handles an off-topic question badly. Try “what did we eat last Sunday?”
Situation A legitimate caller A scammer
Codes and passwords Never asks, under any pretext Wants them “to verify your identity” or “to cancel the fraud”
Pace Is fine with you calling back, lets you think Refuses a callback, invents a deadline
Verification Points you to the official number or your branch Says customer service “won’t have this on file”
Money Never moves funds for you or through your app Walks you through a wire to a “safe account”
Other people Has no problem with you calling a relative first Demands secrecy, especially from family
Caller ID May well be genuine, which proves nothing Often shows the bank’s or the agency’s real number

Caller ID proves nothing
This is the mistake that costs the most. A scammer can put your bank’s exact number, a sheriff’s office, or your daughter’s cell on your screen, and neighbor spoofing will even match your own area code and prefix. Seeing your bank’s name or “Mom” on the display validates nothing. Only a call you dial yourself counts.

You just got that call: what do you do right now?

Answer the two questions below and the tool builds the action plan that matches your situation, in the right order, with the deadlines and the right places to report. It collects nothing and never leaves your browser.

The voice scam emergency guide

Two questions, one personalized action plan with the real deadlines and where to report.

1. Where exactly do things stand?



2. Who was the caller claiming to be?




Please pick an answer to both questions.

You gave up nothing: lock the door and report it

Your immediate risk is low, but your number is now flagged as “live” on a scammer’s list. More calls are coming.

  1. Never call the displayed number back, especially an unfamiliar area code or an international prefix.
  2. Block the number on your phone, and forward any related text to 7726 (SPAM) so your carrier gets it.
  3. Write down the date, the time and the number. You will want them if a second call follows.
  4. Warn the most exposed people around you, starting with older parents and teenagers.

You gave out personal data: cut off the reuse

That information exists to make the next call believable, or to open an account in your name.

  1. Give nothing more: hang up if the call is still going, and do not pick up when they call back.
  2. Change the passwords on every affected account, plus anywhere you reused the same one. Turn on two-factor authentication, using an app rather than text messages.
  3. Check your bank and card accounts every day for the next few weeks, and freeze your credit files so nobody can open an account in your name.
  4. Report it at ReportFraud.ftc.gov to get a written recovery plan, and forward any related text to 7726.
  5. Keep every piece of evidence (call history, texts, emails) and delete nothing.

You gave a code or approved a transaction: move within the hour

This is the urgent one. Every minute counts to stop a transfer that is still in flight.

  1. Call your bank now, using the number on the back of your card, and ask them to freeze the card and lock the account. Note the time and the case number they give you.
  2. Change your online banking credentials and your email password. Your inbox is the reset path for everything else.
  3. Put the dispute in writing the same day. Under Regulation E, telling your bank within two business days of learning about it caps your liability at $50. Past 60 days from the statement, the cap disappears entirely.
  4. File a police report, then report the fraud at ReportFraud.ftc.gov. If a wire or crypto was involved, file with the FBI at ic3.gov too.
  5. Pull your evidence together: statements, screenshots, call log, app notifications.

Money is gone: recall, dispute, report

A transfer is not always lost. Flagged fast enough, a bank can sometimes halt or recall it before it clears.

  1. Call your bank immediately to request a recall and freeze your payment methods. For a wire, the window that matters is the first few hours.
  2. Confirm everything in writing the same day, explicitly asking for reimbursement of the unauthorized transfers.
  3. File a police report and file a complaint at ic3.gov. When a domestic wire is reported quickly, the FBI can work with the receiving bank to try to freeze the funds.
  4. If the bank says no, ask for the denial in writing with its reasoning. Regulation E covers transfers you did not authorize, so if they claim you authorized this one, say in writing that you were deceived into it and keep escalating.
  5. Report it at ReportFraud.ftc.gov. If you paid in gift cards, call that retailer’s fraud line right away: some can freeze the balance before it is drained.

Verify with the relative involved

  • Hang up and call the person back on their usual number, the one in your contacts. If they do not answer, call another family member.
  • Never use the number on your screen or one given to you during the call.
  • Agree on a family safe word, something simple that you never send by text, to ask for during any emergency call.
  • Shrink the family’s public audio: private accounts, a generic voicemail greeting, and some caution with long talking-head videos.

Verify with your bank

  • Hang up, then dial the number on the back of your card or on your statement yourself. Never the number on your screen, never a callback they offer you.
  • Ask them to confirm that an employee actually called you, and have the incident logged on your file.
  • Remember that a bank never asks for a code, a password, or a “protective transfer” to a safe account. No such account exists.
  • Report the call at ReportFraud.ftc.gov and forward any related text to 7726, which sends the number to your carrier.

Verify with the agency itself

  • Click no link and call back no number that was given to you during the call.
  • Log in to your own official account (irs.gov, ssa.gov, medicare.gov) to see whether any request actually exists.
  • No federal agency asks for bank details, a code or an immediate payment by phone, and none threatens you with arrest to collect.
  • Report the attempt at ReportFraud.ftc.gov, and forward the text to 7726.

Verify inside your company

  • Use dual approval: call the executive back on their known number and confirm through a second internal channel.
  • Never change payment details on the strength of a call or an email alone. Confirmation has to come from a contact already on file.
  • Alert finance leadership and your security contact immediately. These campaigns usually hit several employees the same day.
  • Keep any recording, call logs and related emails for the police report and the ic3.gov complaint.

Verify when you have no idea who called

  • Do not call back. Some numbers are premium-rate and the callback is the whole point of the exercise.
  • Search the displayed number if you want, but draw no conclusion from it: caller ID is trivially faked.
  • Block the number, forward related texts to 7726, and turn on “silence unknown callers” on your phone.
  • Check your bank accounts and the last few days of sign-in alerts in your email.

General information
This guide follows the procedures published by US federal consumer agencies as of July 27, 2026. It is not a substitute for professional advice: if you end up in a dispute with your bank or the loss is significant, get help.

How to verify a call in 30 seconds, without being a tech expert

Three-step illustration: hanging up the phone, locking down accounts, then getting a verified confirmation
Hang up, lock down, verify: three moves that defeat almost every voice scam.
  1. Hang up. No explanation required. A legitimate caller will never hold it against you; a scammer will do anything to keep you on the line. That reaction is the tell.
  2. Call back yourself, using a number you already had: the back of your card, your contacts, the agency’s official site. Wait thirty seconds before dialing, or use a different device. On some landlines a caller can stay connected and fake a dial tone.
  3. Ask something off script. A detail only the real person would know, without feeding them the answer. Skip “is that really you?” and ask “where did we see each other last?” A cloned voice improvises badly.
  4. Approve nothing during the call. No codes read aloud, no notification tapped in your banking app, no transfer. Anything legitimate can wait ten minutes.
  5. Set up a family safe word. A short phrase your household knows, never texted, never posted. It is the standard recommendation from consumer protection agencies and it is the one defense that still works against a perfect imitation.

A word on detection tools: AI audio detectors exist, but none is reliable enough to bet on and none works live during a call. The same goes for text: our AI text detector can help you look at a suspicious email or text that arrived after the call, but it tells you nothing about a voice, and as our guide to spotting AI-written text explains, no score is proof of anything. Never let one drive a financial decision.

You gave a code or sent money: the exact procedure

The clock is against you, but US law is on your side, as long as you move fast and put it in writing.

  1. Freeze it immediately. Call your bank using the number on the back of your card and ask them to block the card, lock the account and attempt a recall on anything still pending. Write down the time and the case number.
  2. Dispute in writing. Send your bank the list of unauthorized transactions and demand reimbursement. Under Regulation E, notice within two business days of learning about the loss caps your liability at $50; between then and 60 days after the statement it rises to $500; past 60 days from that statement you can be held responsible for everything.
  3. Reimbursement. Your bank has 10 business days to investigate. If it needs longer, it must credit your account provisionally within those 10 days and can then take up to 45 days, stretched to 90 for a new account, a point-of-sale debit or a transfer initiated abroad.
  4. Police report. Your local department, in person or online, with your evidence. Banks and insurers routinely ask for the report number, so get one even if the officer seems unenthusiastic.
  5. Report the fraud to the FTC at reportfraud.ftc.gov, which feeds the federal database investigators work from and hands you back a written recovery plan. Add an ic3.gov complaint if a wire, an app payment or crypto was involved.
  6. Escalate. Bank refuses? Demand the denial in writing with its reasoning, then take it up the chain. A written, dated paper trail is what makes the difference later.
Screenshot of ReportFraud.ftc.gov, the Federal Trade Commission portal for reporting fraud and scams
ReportFraud.ftc.gov is the front door for scam reports in the US, alongside ic3.gov for anything with an online component. Screenshot taken July 28, 2026 on reportfraud.ftc.gov.
Channel What it does When to use it
Your bank’s fraud line (back of the card) Freezes the card, locks the account, attempts a recall First call, before anything else
FTC consumer advice Plain-English steps, current scam alerts, credit freeze walkthrough The moment you are not sure what to do
ReportFraud.ftc.gov Feeds the federal fraud database and returns a written recovery plan After any scam call, loss or no loss
FBI IC3 Federal complaint for internet-enabled fraud; can trigger a wire freeze attempt Money sent by wire, payment app or crypto
Local police report Opens a criminal case and gives you a report number As soon as there is an actual loss
Forward the text to 7726 (SPAM) Sends the number straight to your carrier’s abuse team After any suspicious text tied to the call
Your carrier’s spam and call filtering Blocks known bad numbers and routes unknown ones to voicemail Repeat calls after the first attempt

Delete nothing
Call history, texts, bank alerts, emails: all of it is evidence. Erasing a message “to move on” weakens your case with the bank and with investigators. Take dated screenshots and back them up somewhere other than the phone involved.

What the law and the carriers already do about spoofed numbers

The decisive part of these scams is not the voice, it is the number on your screen. Congress passed the TRACED Act in December 2019, and the FCC turned it into a mandate with a Report and Order on March 31st, 2020: carriers had to deploy the STIR/SHAKEN framework across the IP portions of their networks. The principle is a chain of trust between carriers, where each one cryptographically signs the calls it originates so the receiving network can check that the number really belongs to the caller.

The compliance deadline was June 30th, 2021, with extensions for small carriers under 100,000 subscribers, and the FCC’s Robocall Mitigation Database now requires providers to certify their implementation or risk having their traffic blocked outright. It works, but only partly: a call that touches a legacy non-IP network loses its signature along the way, and calls originating overseas often arrive unsigned or barely attested. That is exactly the gap spoofed calls walk through, and it is why imposter scams still topped FTC fraud reports in 2025 for the fifth year in a row.

What this means for you
A blocked or unknown number is not automatically fraud, and a clean local number is not automatically legitimate, especially with neighbor spoofing matching your own area code. And if your number gets used to call other people, changing your SIM or your number accomplishes nothing: your line is not compromised, the display is being forged upstream by someone who never touched it.

Lock it down for good with a few settings

  • Cut your public audio. Social accounts set to private, a neutral voicemail greeting (the carrier default is perfect), and some restraint with long videos where you talk to camera.
  • Turn on call filtering from your carrier or your phone, so unknown numbers go to voicemail and you call back if it actually mattered.
  • Harden the bank side. Two-factor authentication, low default transfer limits, alerts on every transaction, and payees added ahead of time rather than in a hurry.
  • Set the family safe word and explain it to the people most at risk, older parents and teenagers first.
  • Talk about it. People who know the scam resist it, and most people still say they could not tell a cloned voice from the real thing.
  • Connect the dots between channels. A suspicious call is usually followed by a text or an email. Our guide to the AI-powered package delivery scam covers the written half, and our piece on “dark GPTs” explains how scammers bend AI models to their purposes.

Frequently asked questions

Is a phone call from an AI always a scam?

No. Synthetic voices are used legally all over the place: appointment reminders, phone menus, delivery notifications, surveys. What marks a scam is not the nature of the voice, it is the ask: a code, a transfer, an approval in your app, urgency paired with secrecy. A legitimate automated call will never want any of that.

How can you tell if an AI is calling you?

A few clues still help: an unusual lag between your question and the answer, very even pacing with no hesitation and no background noise, trouble handling an off-topic question or an interruption. But those clues shrink every year. The only reliable method is behavioral: ask something unpredictable, or hang up and dial the official number yourself.

Can someone clone my voice just because I said “hello”?

No, not with current technology. Instant cloning needs 1 to 5 minutes of clean audio according to ElevenLabs, and more than 30 minutes for anything genuinely convincing. The “Can you hear me?” version of this rumor has circulated in the US since 2016 and consumer watchdogs have never documented a victim. The audio you publish online, on the other hand, is entirely usable.

What can someone do with just my phone number?

Display it instead of their own to call other people (spoofing), sign you up for services to intercept verification codes, target you with scam texts, or attempt a SIM swap with your carrier to capture your authentication codes. Which is exactly why app-based two-factor authentication beats text-message codes whenever you have the choice.

How do I stop scam calls for good?

Block the number, turn on your carrier’s call filtering and your phone’s “silence unknown callers,” and forward every scam text to 7726 (SPAM) so your carrier can act on it. Registering on the National Do Not Call Registry stops legitimate telemarketers, though not criminals. And never call an unknown number back, especially a premium-rate or international one.

Can my bank refuse to reimburse me?

Yes, and the whole fight turns on one word: authorized. Regulation E protects transfers you did not authorize, with liability capped at $50 if you report within two business days and $500 within 60 days of the statement. If the scammer talked you into sending the money yourself, the bank may argue the transfer was authorized and decline. Demand the denial in writing with its reasoning, state clearly and in writing that you were deceived, and keep escalating.

Should I report an attempt even if I lost nothing?

Yes. A report at ReportFraud.ftc.gov takes a few minutes and feeds the database investigators use to spot patterns and build cases. Once there is an actual loss, however small, a police report becomes essential too: your bank and your insurer will ask for it, and clustered complaints are how these operations get traced back to their source.

The bottom line

The “just say hello” panic made far more noise than victims. The real danger is duller: a spoofed number, a familiar voice built from content you posted yourself, and an urgent request designed to short-circuit your judgment. The defense fits in one sentence: you never verify an identity on the incoming call, you hang up and you dial. And when money is on the table, no decision has to be made in the next sixty seconds.

Legal questions after a scam call?

Disputing with your bank, filing a police report, Regulation E deadlines, what you can actually demand in writing: Nation AI’s legal assistant, trained on US law, helps you frame your situation and draft your letters. Free, no signup.

Ask the legal AI my question

Main sources: Federal Trade Commission, “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025,” June 15, 2026 · FBI Internet Crime Complaint Center, 2025 Internet Crime Report (1,008,597 complaints, $20.9 billion in losses) · Consumer Financial Protection Bureau, Regulation E, 12 CFR 1005.6 and 1005.11 · FCC, caller ID authentication and TRACED Act implementation · ElevenLabs, Voice Cloning product page · McAfee, “Beware the Artificial Impostor,” survey of 7,054 adults. Data verified July 27, 2026.