Shared Security Podcast

A familiar voice is no longer proof of identity: Tom Eston and Scott Wright explain how AI voice-cloning scams use urgency and emotion, and why trusted callbacks, private family code phrases, and independent approval steps are the defenses that actually work.

Show Notes

A familiar voice is no longer proof of identity. Tom Eston and Scott Wright explain how AI voice-cloning scams turn family emergencies, executive requests, and urgent account changes into social-engineering bait—and why the defenses that work are old-fashioned but essential: pause, call back on a known number, use a private code phrase, and require independent approval before money, data, credentials, or access changes hands.

** Links mentioned on the show **

A scammer can now sound 100% like your wife — LinkedIn post https://www.linkedin.com/posts/saedf_a-scammer-can-now-sound-100-like-your-wife-share-7505586875944853506-TLYq/

FTC — Scammers use AI to enhance their family emergency schemes https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes

FTC — Preventing the harms of AI-enabled voice cloning https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2023/11/preventing-harms-ai-enabled-voice-cloning

National Cybersecurity Alliance — Why your family and coworkers need a safe word in the age of AI https://www.staysafeonline.org/articles/why-your-family-and-coworkers-need-a-safe-word-in-the-age-of-ai

** Watch this episode on YouTube **

https://youtu.be/6sfXD86bKco

** Become a Shared Security Supporter **

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

** Thank you to our sponsors! **

SLNT

Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

** Subscribe and follow the podcast **

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

What is Shared Security Podcast?

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

One of the things I've learned over the last decade

or two teaching people about social engineering attacks

is attackers can leverage any emotion

that they know you're gonna respond to.

And so if they do a little bit of open source intelligence

on you, you know, look at your Facebook page

or your LinkedIn profile or other things

that may be published about you,

they might be able to guess things

that would be emotional triggers for you.

And if they can do that,

they can create a pretext or a story around it.

Your phone rings, it's your wife,

your boss or your kid, and they sound scared.

The only problem, they might be sitting right next to you.

AI voice cloning scams are churning familiar voices

into social engineering bait,

and I recognize that voice is no longer verification.

So today we are looking at what actually stops it.

Pause, call back on a trusted number,

use a family secret phrase

and put real controls around money and account changes.

And joining me for this conversation

is my co-host, Mr. Scott Wright.

Folks.

Hello, how you doing, Scott?

Not too bad, not too bad.

Good, good.

Is it a turning fall up in Canada?

You know, the air's a little cooler,

but not too many leaves changing yet,

so it's a little later than normal.

You know, it's supposed to be global warming, I guess.

Yeah, I heard that's fake though, Scott.

That doesn't exist.

To you, maybe.

Only fake for us in the US, everywhere else in the world,

it's real.

Yeah, the weather's been very strange around here

in Cincinnati.

We had like 90 degree Fahrenheit heat

for like two weeks straight,

and now all of a sudden it's like 60.

But this week is actually the first week of fall, technically.

So I guess that does make sense.

But yeah, we're here to talk about these scams

that are happening to a lot of people,

and I was inspired to do this episode.

And first of all, just a little history.

We have talked about this topic before on the podcast.

We've talked about deep fakes

when that was starting to be a thing,

and then we've talked about these voice cloning scams,

which I think was starting to happen maybe a year,

almost maybe two years ago.

But this is happening a lot more now

because, well, guess what?

AI is making these things a lot easier.

So cloning somebody's voice has gotten pretty trivial,

I would say, with the tooling that's available

and the technology has really increased.

I would say not just voice cloning,

but video cloning somebody through video or pictures.

And there are all kinds of issues happening

with this right now.

I saw a story on the local news

about some high school kid was nudifying girls

in his class, and he was using an AI tool for that,

and there's all kinds of crazy things happening,

and a lot of this is not good.

They're not good things at all.

Yeah, it is disappointing.

A lot of people are, well, it's not that bad yet,

and it's not really thinking,

and it's not, the AI is not sentient,

it's not super human yet,

but it doesn't really have to be damaging.

And that's one of the things we want to talk about.

Yeah, exactly.

So this LinkedIn post was super interesting

because the scam that happened,

I don't know it was to him or somebody he knew,

but somebody called sounding like this person's wife,

like exactly like his wife,

and his wife was asking for a credit card number

so they could pay for gas because they were out of gas.

Now, what's funny about this

is the gentleman's wife was sitting right next to him

and they have a Tesla, which doesn't require a gas,

and how are you going to use a credit card number

without a physical card at a gas station is beyond me.

So a lot of red flags there,

but the person was kind of taken back by how realistic.

And I would say don't be fooled.

Yeah, don't be fooled by this kind of amateur looking

kind of attack because of those little anomalies, right?

It's going to get better in terms of its capability

or worse in terms of its impact

and its ability to convince people.

So I think we have to be on guard

and telling people to be on guard for it as soon as possible,

even if this stuff sounds wacky,

and how stupid is that that it's asking

for a credit card number.

Next week it won't be, you know.

Yeah, well, it's kind of going back to the same trope

that we've always been talking about

is all of these social engineering scams,

they always start with a pretext of urgency

and it's an emergency.

And even it is someone,

it sounds like somebody you know that you trust,

like your kid or your wife or significant other

or whatever, right?

It should give you some pause

because it's probably going to be out of character for them.

And even in an emergency situation,

which you kind of have to go back to thinking about,

well, how did my family handle

other emergency situations in the past?

And even talking with your family about,

well, what do we do if there is a call like this?

And one of the pieces of advice that we often hear

is having some type of secret code or a phrase

or something that everybody in the family

can share with each other in an emergency situation

to make sure that, yes, this is in fact,

my kid, my wife, whoever that I'm talking to on the phone.

Right, so while we're on that topic,

this is something I've known

and I recommend to people as well,

but I think it's a good idea to maybe walk through

a hypothetical example.

And I don't know if Tom, have you seen situations

where this kind of a secret phrase has been used?

What would that look like to somebody in a family?

I don't know anybody personally that this has happened to,

but I have read and I have heard many, many stories

of this actually happening.

And these calls are often from what I've read

is that they're very automated.

Like this isn't a human obviously on the other end.

I guess it could be because there are voice cloning

technologies that can be used,

but often these things are prerecorded.

They're built in with, you know, pauses

and they wait for a response

and then the other piece of the recording kicks in

and things like that.

But I think the idea around the family's safe phrase

or code word is just something that is discussed

with your family previously,

you know, in a previous conversation about,

hey, what do we do if there is a scam like this

and you call me or my kid calls me and says,

hey, I'm in a car accident, I need help.

It's as simple as, hey, give me the code word

or the code name, right?

If it sounds suspicious.

Right, I think you want to tell the person

why you're asking if it is a real call.

You're gonna say, hey, do you remember

we talked about having, you know,

the chance that somebody might be trying

to impersonate one of us and I just want to make sure

it's not you being impersonated and so yeah,

then you could say, do you remember the phrase?

Now they'll say, oh, you know what, I forgot.

What do you do that?

Yeah, right.

Personally, I feel like I would know right away, right?

Because I know if my kid's gonna call me

in a panic situation, for example,

we use Life360 to track our kids, right?

And it's, of course, they know that we're doing this, right?

It's not like they don't know,

but I've been in situations where my kid

needs assistance somewhere, right?

For whatever reason and I can look it up on Life360

and I can see that they're in the location

they said they were gonna be at, right?

And they're calling me from that location and, right?

There's things that you can do to verify,

but I think the code word is definitely helpful

for situations that you're not sure, right?

Like the, hey, I just got put in prison, dad.

Yeah, yeah, yeah.

I need bail money and you look up on Life360

and they're at their friend's house

a couple doors down, right?

Like there's things that you can do, right?

To kind of verify location.

So the code word doesn't necessarily have

to be one of those things,

but I think it's more about being aware

that this is happening and it could happen to anybody.

And how do you prepare yourself and your family for this?

And I think it's not always going to be

just an emergency situation.

One of the things I've learned over the last decade

or two teaching people about social engineering attacks

is attackers can leverage any emotion

that they know you're gonna respond to.

And so if they do a little bit

of open source intelligence on you,

like at your Facebook page or your LinkedIn profile

or other things that may be published about you,

they might be able to guess things

that would be emotional triggers for you.

And if they can do that,

they can create a pretext or a story around it

and impersonate somebody and then talk to you

about maybe some opportunity that is just too good to,

you know, if you're addicted at gambling

or other kinds of, you know,

things that you just love to do and you can't resist

and they know that, you know,

they're gonna impersonate somebody

who's got a really compelling story around that

to get you to act in whatever way.

Maybe it's to help them pay for something or whatever.

So I'm just saying,

it's not always going to be an emergency or a problem.

The other advice we tell you too

is you can call that person back

on their known number, right?

So even if that call is spoofed

and it looks like it's coming from a family member

or a trusted person, it's okay to like say,

hey, can I call you back on your number?

And then you actually call them

and you'll probably find out very quickly

if it's a scam or not.

So that's another trick that you can do.

If you don't have that code word, right,

with your family, you can just call them back

at their real number.

This is sort of a situation where as security nerds,

right, we would say,

this is a great example of a situation

where you could use a tabletop exercise

with your family.

So let's pretend, let's pretend I get a call saying,

from my wife, apparently who's trying

to access a bank machine or something

and they're having trouble

and they need something really quickly or whatever.

How do you know what that's gonna look like?

So you have to sort of walk through some scenarios

with the people that you're expecting

to potentially have this happen to.

Yeah, and what I find interesting too,

if I did a little bit of research to kind of see,

what are the typical voice cloning scams

that are out there that have been used in the past

and not surprisingly,

but they all have to do with money

in some way, shape, or form of.

Yeah, there's not much other reason for an attacker to do it

unless they're really trying to kidnap you or something.

Right, right, right.

But there's usually cryptocurrency involved,

gift cards, some type of bank deposits,

or we've seen ones where they want you to change an account,

like go to this link or call me back on this number

and I need to verify some information about you

because of a situation, right?

Yeah, the first couple of times it happens,

it's gonna feel really weird,

but I think we'll all get used

to having those kinds of calls at some point.

Yeah, I mean, it's not ending anytime soon

and I think the phone companies are trying

to do the best they can with weeding out

and preventing a lot of these calls from happening,

but my phone is still like ringing off the hook

with numbers and scams and things.

I pretty much send everything to voicemail these days.

I have unfortunately said,

oh, that's an interesting number

and I end up picking it up

and then you hear that like long pause of-

Long pause, yeah, the auto dialing.

And they're like, oh, no, all right.

That's true.

Almost every time I get a call if I answer it

and I don't know who it's from

and you hear that, give it a second and a half,

two seconds, hang up.

If they really wanna talk to you, they'll call back.

But yeah.

Yeah, exactly.

So the message for everybody is,

be aware that this technology has gotten a lot better.

AI voice cloning is trivial to do these days.

There's tons of tools out there that do this

and it's just getting a little bit more dangerous,

I guess, from that perspective.

So it's good just to be prepared,

have a conversation with your family

to talk about these types of scams that are happening,

create that code word,

make sure that you're calling back numbers

that sound like somebody's trying

to impersonate a family member or a friend.

That's always good advice, right?

Yep, yep.

And I'm not an American,

but I have a sense there could be an opportunity

coming up in the next few weeks to a month

where you might be influenced

by other kinds of imitations that you've seen,

whether it's online or in an email or whatever, right?

People trying to influence how you might vote.

Yeah, there's a lot of that happening

with the midterms is what you were looking to say.

I think that's what I'm trying to say.

Yeah, it's amazing to me the amount

of misinformation and disinformation

that I've already seen on TV commercials

and flyers in the mail about both sides.

All candidates, it's crazy.

And actually impersonating candidates, right?

And saying things that they would never say.

That's right, that's right.

It's a big, big problem

and it's really only getting worse.

And I think it's gonna be harder and harder to detect

if someone was deep faked

or there's a voice cloning situation going on.

And that's why we all have to be much more aware

of these situations.

All right, well, I think that's all we have time

for today, Scott.

But again, I wanted to thank everyone for listening to the show.

Thank you for subscribing to our YouTube channel.

And until next time, stay safe, stay secure and stay private.

Thank you for listening or watching.

If you liked this episode, hit subscribe,

share it with your friends and colleagues

or jump into our community at sharedsecurity.net

slash supporter to keep the conversation going.

Thanks again and we'll see you next week

for another episode of Shared Security.