A scammer needs about three seconds of your grandchild's voice — a voicemail greeting is enough. What the FBI's first-ever AI fraud numbers actually show, how the cloning works, the three scripts scammers use, and the one-minute habit that stops it.
The phone rings. It's your grandson. He's crying — there's been an accident, and he needs money now. You know that voice. You've known it his whole life. It isn't him. This is a fact-checked look at how that call gets made, what it actually costs to fake a voice convincingly, the three scripts scammers lean on to keep you from checking, and the specific, low-effort habits that stop it cold.
What the FBI just started counting
For the first time in its nearly 25-year history, the FBI's Internet Crime Complaint Center (IC3) gave artificial intelligence its own section in the annual Internet Crime Report. In its 2025 report, that section covers 22,364 complaints, costing Americans nearly $893 million. It sits inside a much larger total: cyber-enabled crime overall defrauded Americans of almost $21 billion that year, with AI-related and cryptocurrency schemes among the costliest categories. More than a third of a billion dollars of that AI-related total — $352.5 million — came from people over 60.
It's worth being precise about what that $893 million actually measures, because the video says so on screen and it matters: it covers every kind of AI-related complaint the FBI logged that year — fake social profiles, deepfake videos of public figures, voice clones, fabricated ID documents — not voice-cloning scams alone. There's no official breakout of how much of it was specifically a cloned-voice call to a family member. What the number does establish is that the FBI now considers AI-enabled fraud significant enough to track as its own category, in a report that's tracked internet crime since 2000.
The three-second test
In 2023, McAfee's own security researchers ran an internal test: could they clone a colleague's voice, and how little audio would it take? Three to four seconds of audio was enough to produce a clone the researchers rated an 85% match to the original — worth flagging that this was McAfee's own benchmarking, not an independent listening panel, but it shows how little raw material one commercial tool needed to get most of the way there. When McAfee's researchers paid for a higher tier of the same tool and added emotional inflection, their own assessment of the result was "almost indistinguishable" from the source voice. With more training data, they estimated a 95% match was achievable.
Three to four seconds isn't a special recording — it's a voicemail greeting, a birthday video, a few seconds of a video call, or literally any clip where your grandchild says hello on a public platform. McAfee's two-week investigation into the tooling itself found more than a dozen voice-cloning tools freely available online, and concluded they required only "a basic level of experience and expertise to use." This isn't lab equipment. It's consumer software.
Why the voice is the cheap part
Here's the part that matters more than the cloning technology itself: the voice buys the scammer maybe ten seconds of belief. What does the actual work is the script — and there are three that show up again and again, all built around the same principle, stopping you from thinking clearly enough to verify.
Arrest and bail. The story hands you a built-in reason to keep quiet: he's ashamed, don't tell his mother. The one move that would end the call instantly — phoning another family member to check — gets reframed as a betrayal of the person supposedly in trouble.
The accident. Noise, urgency, and then someone claiming to be a police officer or a tow-truck driver takes over the call, pulling your "grandchild" away before you can ask anything that would reveal the story doesn't hold up.
The hospital emergency. This one runs entirely on a clock. Every question you ask costs time, and time is exactly what the caller claims your loved one doesn't have.
These aren't guesses about what scammers might do — the Canadian Anti-Fraud Centre names arrest-and-bail, car-accident, and hospital/ambulance stories as the specific, recurring patterns behind what's broadly called the "grandparent scam," and notes it's tracking further variations that arrive by text message and social media too. None of the three scripts ask you to believe anything technically strange. They only ask you to move before you think — and the cloned voice only has to hold up for the first few seconds, before adrenaline takes over.
The three things that actually work
A family word. Agree on a word or phrase, out loud, with the people it matters for — something that's never been posted, texted, or said anywhere public. If a call claims there's an emergency, ask for it. Important caveat the video is upfront about: a word can still leak eventually, so treat it as a filter, not a guarantee.
Hang up and call back. This is the one that actually settles it. Hang up, and call the person back yourself — on a number you already have saved, never the number that just called you. This is also the FTC's own consumer guidance verbatim: "Don't trust the voice. Call the person who supposedly contacted you and verify the story. Use a phone number you know is theirs. If you can't reach your loved one, try to get in touch with them through another family member or their friends."
Decide it in advance. The habit families skip. Agree now, today, out loud, that hanging up to verify is always the right move — before anyone is scared enough to hesitate over hanging up on someone they love. Fear is what these scripts are built to produce, and a decision made calmly in advance is much harder to talk someone out of in the moment than a decision made mid-call.
Lowering what's public
You can't un-post a voice that's already online, but you can reduce how much new material is out there and see what already exists under a family member's name — private accounts, and a quick look at what's public now. Treat this as lowering the odds, not as protection on its own; it doesn't substitute for the hang-up-and-call-back habit.
Having the conversation without it feeling like an accusation
The most useful framing, if you're the one raising this with your own parents: don't make it about what they might fall for. Start by picking the family word together, as a shared precaution rather than a warning aimed at them.
On the financial side, two concrete steps: turn on transaction alerts for their bank accounts, and ask their brokerage about naming a trusted contact. A FINRA rule already requires brokerages to make a reasonable effort to obtain a trusted-contact name for every account — that person can be notified if the firm suspects exploitation, but critically, a trusted contact has no authority to trade or withdraw funds. It's a notification channel, not a handover of control.
If it happens: where to report it
In the United States: ReportFraud.ftc.gov and ic3.gov. In Canada: your local police and the Canadian Anti-Fraud Centre (1-888-495-8501) — CAFC data shows the emergency-scam variant alone has resulted in more than $23 million in reported losses across Canada, and police have arrested more than 70 people acting as money mules, collecting cash in person at victims' homes, in every province since 2021. AARP also runs a Fraud Watch Helpline (1-877-908-3360) that's free to anyone who calls, whether or not you're a member.
Both the U.S. and Canadian figures above are only what got formally reported — fraud of this kind is widely under-reported, particularly by older victims who feel embarrassed rather than deceived. Neither number is the actual size of the problem; both are a floor.
The bottom line
The technology genuinely is this cheap: three to four seconds of audio, a dozen-plus freely available tools, and a result McAfee's own researchers called almost indistinguishable once they paid for the better tier. But the clone alone doesn't move money — the script does, by design, and all three common scripts work the same way: they get you to act before you verify. The fix isn't more suspicion of every call forever. It's three specific, low-effort habits, decided calmly before you ever need them: a family word, hanging up to call back on a number you already have, and agreeing in advance that checking is always allowed. Pick the word tonight, before the phone rings.
Sources
FBI — 2025 Internet Crime Report press release — https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
McAfee Labs — "Artificial Imposters: Cybercriminals Turn to AI Voice Cloning for a New Breed of Scam" (2023) — https://www.mcafee.com/blogs/privacy-identity-protection/artificial-imposters-cybercriminals-turn-to-ai-voice-cloning-for-a-new-breed-of-scam/
FTC Consumer Alert — "Scammers Use AI to Enhance Their Family Emergency Schemes" (March 2023) — https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes
FINRA — "Protecting Older Investors from Financial Exploitation" — https://www.finra.org/investors/insights/older-investors-financial-exploitation
Canadian Anti-Fraud Centre — emergency scam advisory (April 2024) — https://antifraudcentre-centreantifraude.ca/news-nouvelles/2024/2024-04-18-eng.htm
This article is general safety guidance and is not legal or financial advice. Some scenes in the accompanying video are AI-illustrated and labeled on screen — no real person's voice was cloned to make this video. Disclosure: AI by Age is run by people who work in AI and build AI-related products. We take no AI-vendor sponsorships or affiliate payments. Full disclosure on our About page.