AI voice-cloning can now convincingly imitate a family member's voice from just a few seconds of audio. A simple secret check-word — agreed on in advance — is one of the few defenses that still works.
An AI voice clone can copy how someone sounds, but it can't guess a private phrase your family agreed on ahead of time. This is exactly the kind of low-tech defense that current security researchers recommend against the newest generation of voice-cloning scam calls.
A real emergency call from family can wait 30 seconds for you to hang up and call them back directly. If someone is pressuring you not to verify, that pressure is the scam.
Scammers research their targets. They know your children’s names, your street, your dog — all of it from social media. Knowledge-based questions (“what’s your mother’s maiden name?”) are no longer security, because the answers are public. A check-word is different: it is never written down, never posted, and never used anywhere else, so there is nothing for an attacker to find.
Real emergencies sound chaotic — that is exactly when scammers strike, because stress shuts down careful thinking. The rule is simple: if a caller can’t give the check-word, hang up and call your family member directly on the number you already have. A genuine emergency survives a two-minute delay. A scam does not.
A family check word is a shared secret, agreed in advance, used to verify that an urgent request really came from the person it claims to. It costs nothing, needs no technology, and defeats an entire category of fraud that is otherwise very difficult to defend against.
It matters now because voice cloning has made "it sounded exactly like her" meaningless as evidence. The old assumption — that recognising a voice confirms identity — no longer holds, and nothing has replaced it except deliberate verification.
The rule to agree on is simple: any urgent request for money, card details, or personal information must be confirmed with the check word. If the person cannot produce it, the conversation ends and you call them back on the number you already have.
Ask for it plainly. "What's our word?" Do not offer a hint, do not accept "you know it's me", and do not accept an explanation for why they cannot remember it under stress. A real family member who forgets will happily take a call-back instead.
Agree also that nobody will ever be annoyed at being asked. That agreement is what makes people actually use it, because the usual reason verification fails is social awkwardness rather than ignorance.
The approach that works is to frame it as something the family is doing together, not as a warning about their vulnerability. "We've all agreed a word so nobody gets caught out by these fake calls" lands very differently from "you need to be careful". Give a concrete example of the scam so the reason is obvious.
Then practise once. Ring them and ask for the word, so the mechanics are familiar. A step you have rehearsed once is far more likely to be used under pressure than one you only discussed.
Change it if it has been spoken where it could be overheard, if it was ever written in a message, if a family device has been compromised, or if somebody outside the group has learned it. Changing it is easy, so do it whenever you are uncertain rather than hoping.
Review it once a year. A quick conversation at a family gathering is enough, and it also brings anyone new into the arrangement.
Two unrelated, unguessable words that are easy to picture and say. Avoid anything connected to pets, places, dates or schools, since those are discoverable from social media and security questions.
Better not to. If any family phone or messaging account is compromised, the attacker reads the history. Agree it in person or on a phone call, and do not store it in writing on a device.
Then you hang up and call them back on the number already in your phone. That verifies them just as well. The point is to have a step that does not depend on recognising a voice.
No. Keep it separate. A password can end up in a breach list, and a check word that appears in leaked data is no longer secret.
Present it as something the whole family is adopting together rather than a caution aimed at them. Give one concrete example of a fake emergency call, then practise it once so the step feels routine.