A familiar voice is no longer proof of identity: Tom Eston and Scott Wright explain how AI voice-cloning scams use urgency and emotion, and why trusted callbacks, private family code phrases, and independent approval steps are the defenses that actually work.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
One of the things I've learned over the last decade
or two teaching people about social engineering attacks
is attackers can leverage any emotion
that they know you're gonna respond to.
And so if they do a little bit of open source intelligence
on you, you know, look at your Facebook page
or your LinkedIn profile or other things
that may be published about you,
they might be able to guess things
that would be emotional triggers for you.
And if they can do that,
they can create a pretext or a story around it.
Your phone rings, it's your wife,
your boss or your kid, and they sound scared.
The only problem, they might be sitting right next to you.
AI voice cloning scams are churning familiar voices
into social engineering bait,
and I recognize that voice is no longer verification.
So today we are looking at what actually stops it.
Pause, call back on a trusted number,
use a family secret phrase
and put real controls around money and account changes.
And joining me for this conversation
is my co-host, Mr. Scott Wright.
Folks.
Hello, how you doing, Scott?
Not too bad, not too bad.
Good, good.
Is it a turning fall up in Canada?
You know, the air's a little cooler,
but not too many leaves changing yet,
so it's a little later than normal.
You know, it's supposed to be global warming, I guess.
Yeah, I heard that's fake though, Scott.
That doesn't exist.
To you, maybe.
Only fake for us in the US, everywhere else in the world,
it's real.
Yeah, the weather's been very strange around here
in Cincinnati.
We had like 90 degree Fahrenheit heat
for like two weeks straight,
and now all of a sudden it's like 60.
But this week is actually the first week of fall, technically.
So I guess that does make sense.
But yeah, we're here to talk about these scams
that are happening to a lot of people,
and I was inspired to do this episode.
And first of all, just a little history.
We have talked about this topic before on the podcast.
We've talked about deep fakes
when that was starting to be a thing,
and then we've talked about these voice cloning scams,
which I think was starting to happen maybe a year,
almost maybe two years ago.
But this is happening a lot more now
because, well, guess what?
AI is making these things a lot easier.
So cloning somebody's voice has gotten pretty trivial,
I would say, with the tooling that's available
and the technology has really increased.
I would say not just voice cloning,
but video cloning somebody through video or pictures.
And there are all kinds of issues happening
with this right now.
I saw a story on the local news
about some high school kid was nudifying girls
in his class, and he was using an AI tool for that,
and there's all kinds of crazy things happening,
and a lot of this is not good.
They're not good things at all.
Yeah, it is disappointing.
A lot of people are, well, it's not that bad yet,
and it's not really thinking,
and it's not, the AI is not sentient,
it's not super human yet,
but it doesn't really have to be damaging.
And that's one of the things we want to talk about.
Yeah, exactly.
So this LinkedIn post was super interesting
because the scam that happened,
I don't know it was to him or somebody he knew,
but somebody called sounding like this person's wife,
like exactly like his wife,
and his wife was asking for a credit card number
so they could pay for gas because they were out of gas.
Now, what's funny about this
is the gentleman's wife was sitting right next to him
and they have a Tesla, which doesn't require a gas,
and how are you going to use a credit card number
without a physical card at a gas station is beyond me.
So a lot of red flags there,
but the person was kind of taken back by how realistic.
And I would say don't be fooled.
Yeah, don't be fooled by this kind of amateur looking
kind of attack because of those little anomalies, right?
It's going to get better in terms of its capability
or worse in terms of its impact
and its ability to convince people.
So I think we have to be on guard
and telling people to be on guard for it as soon as possible,
even if this stuff sounds wacky,
and how stupid is that that it's asking
for a credit card number.
Next week it won't be, you know.
Yeah, well, it's kind of going back to the same trope
that we've always been talking about
is all of these social engineering scams,
they always start with a pretext of urgency
and it's an emergency.
And even it is someone,
it sounds like somebody you know that you trust,
like your kid or your wife or significant other
or whatever, right?
It should give you some pause
because it's probably going to be out of character for them.
And even in an emergency situation,
which you kind of have to go back to thinking about,
well, how did my family handle
other emergency situations in the past?
And even talking with your family about,
well, what do we do if there is a call like this?
And one of the pieces of advice that we often hear
is having some type of secret code or a phrase
or something that everybody in the family
can share with each other in an emergency situation
to make sure that, yes, this is in fact,
my kid, my wife, whoever that I'm talking to on the phone.
Right, so while we're on that topic,
this is something I've known
and I recommend to people as well,
but I think it's a good idea to maybe walk through
a hypothetical example.
And I don't know if Tom, have you seen situations
where this kind of a secret phrase has been used?
What would that look like to somebody in a family?
I don't know anybody personally that this has happened to,
but I have read and I have heard many, many stories
of this actually happening.
And these calls are often from what I've read
is that they're very automated.
Like this isn't a human obviously on the other end.
I guess it could be because there are voice cloning
technologies that can be used,
but often these things are prerecorded.
They're built in with, you know, pauses
and they wait for a response
and then the other piece of the recording kicks in
and things like that.
But I think the idea around the family's safe phrase
or code word is just something that is discussed
with your family previously,
you know, in a previous conversation about,
hey, what do we do if there is a scam like this
and you call me or my kid calls me and says,
hey, I'm in a car accident, I need help.
It's as simple as, hey, give me the code word
or the code name, right?
If it sounds suspicious.
Right, I think you want to tell the person
why you're asking if it is a real call.
You're gonna say, hey, do you remember
we talked about having, you know,
the chance that somebody might be trying
to impersonate one of us and I just want to make sure
it's not you being impersonated and so yeah,
then you could say, do you remember the phrase?
Now they'll say, oh, you know what, I forgot.
What do you do that?
Yeah, right.
Personally, I feel like I would know right away, right?
Because I know if my kid's gonna call me
in a panic situation, for example,
we use Life360 to track our kids, right?
And it's, of course, they know that we're doing this, right?
It's not like they don't know,
but I've been in situations where my kid
needs assistance somewhere, right?
For whatever reason and I can look it up on Life360
and I can see that they're in the location
they said they were gonna be at, right?
And they're calling me from that location and, right?
There's things that you can do to verify,
but I think the code word is definitely helpful
for situations that you're not sure, right?
Like the, hey, I just got put in prison, dad.
Yeah, yeah, yeah.
I need bail money and you look up on Life360
and they're at their friend's house
a couple doors down, right?
Like there's things that you can do, right?
To kind of verify location.
So the code word doesn't necessarily have
to be one of those things,
but I think it's more about being aware
that this is happening and it could happen to anybody.
And how do you prepare yourself and your family for this?
And I think it's not always going to be
just an emergency situation.
One of the things I've learned over the last decade
or two teaching people about social engineering attacks
is attackers can leverage any emotion
that they know you're gonna respond to.
And so if they do a little bit
of open source intelligence on you,
like at your Facebook page or your LinkedIn profile
or other things that may be published about you,
they might be able to guess things
that would be emotional triggers for you.
And if they can do that,
they can create a pretext or a story around it
and impersonate somebody and then talk to you
about maybe some opportunity that is just too good to,
you know, if you're addicted at gambling
or other kinds of, you know,
things that you just love to do and you can't resist
and they know that, you know,
they're gonna impersonate somebody
who's got a really compelling story around that
to get you to act in whatever way.
Maybe it's to help them pay for something or whatever.
So I'm just saying,
it's not always going to be an emergency or a problem.
The other advice we tell you too
is you can call that person back
on their known number, right?
So even if that call is spoofed
and it looks like it's coming from a family member
or a trusted person, it's okay to like say,
hey, can I call you back on your number?
And then you actually call them
and you'll probably find out very quickly
if it's a scam or not.
So that's another trick that you can do.
If you don't have that code word, right,
with your family, you can just call them back
at their real number.
This is sort of a situation where as security nerds,
right, we would say,
this is a great example of a situation
where you could use a tabletop exercise
with your family.
So let's pretend, let's pretend I get a call saying,
from my wife, apparently who's trying
to access a bank machine or something
and they're having trouble
and they need something really quickly or whatever.
How do you know what that's gonna look like?
So you have to sort of walk through some scenarios
with the people that you're expecting
to potentially have this happen to.
Yeah, and what I find interesting too,
if I did a little bit of research to kind of see,
what are the typical voice cloning scams
that are out there that have been used in the past
and not surprisingly,
but they all have to do with money
in some way, shape, or form of.
Yeah, there's not much other reason for an attacker to do it
unless they're really trying to kidnap you or something.
Right, right, right.
But there's usually cryptocurrency involved,
gift cards, some type of bank deposits,
or we've seen ones where they want you to change an account,
like go to this link or call me back on this number
and I need to verify some information about you
because of a situation, right?
Yeah, the first couple of times it happens,
it's gonna feel really weird,
but I think we'll all get used
to having those kinds of calls at some point.
Yeah, I mean, it's not ending anytime soon
and I think the phone companies are trying
to do the best they can with weeding out
and preventing a lot of these calls from happening,
but my phone is still like ringing off the hook
with numbers and scams and things.
I pretty much send everything to voicemail these days.
I have unfortunately said,
oh, that's an interesting number
and I end up picking it up
and then you hear that like long pause of-
Long pause, yeah, the auto dialing.
And they're like, oh, no, all right.
That's true.
Almost every time I get a call if I answer it
and I don't know who it's from
and you hear that, give it a second and a half,
two seconds, hang up.
If they really wanna talk to you, they'll call back.
But yeah.
Yeah, exactly.
So the message for everybody is,
be aware that this technology has gotten a lot better.
AI voice cloning is trivial to do these days.
There's tons of tools out there that do this
and it's just getting a little bit more dangerous,
I guess, from that perspective.
So it's good just to be prepared,
have a conversation with your family
to talk about these types of scams that are happening,
create that code word,
make sure that you're calling back numbers
that sound like somebody's trying
to impersonate a family member or a friend.
That's always good advice, right?
Yep, yep.
And I'm not an American,
but I have a sense there could be an opportunity
coming up in the next few weeks to a month
where you might be influenced
by other kinds of imitations that you've seen,
whether it's online or in an email or whatever, right?
People trying to influence how you might vote.
Yeah, there's a lot of that happening
with the midterms is what you were looking to say.
I think that's what I'm trying to say.
Yeah, it's amazing to me the amount
of misinformation and disinformation
that I've already seen on TV commercials
and flyers in the mail about both sides.
All candidates, it's crazy.
And actually impersonating candidates, right?
And saying things that they would never say.
That's right, that's right.
It's a big, big problem
and it's really only getting worse.
And I think it's gonna be harder and harder to detect
if someone was deep faked
or there's a voice cloning situation going on.
And that's why we all have to be much more aware
of these situations.
All right, well, I think that's all we have time
for today, Scott.
But again, I wanted to thank everyone for listening to the show.
Thank you for subscribing to our YouTube channel.
And until next time, stay safe, stay secure and stay private.
Thank you for listening or watching.
If you liked this episode, hit subscribe,
share it with your friends and colleagues
or jump into our community at sharedsecurity.net
slash supporter to keep the conversation going.
Thanks again and we'll see you next week
for another episode of Shared Security.