The perception problem

AI voice cloning advanced substantially between 2022-2026. The state of the art:

  • 3 seconds of source audio sufficient for 85%+ voice match (McAfee Labs, 2024 research)
  • Real-time synthesis — the criminal speaks; their words come out in the cloned voice within milliseconds
  • Emotion control — calm, panicked, crying, urgent — the criminal selects the emotional tone
  • Multi-language — same voice cloned across English, Spanish, Mandarin, etc.
  • Phone-quality artifacts deliberately added (compression, slight static) to match what you'd expect from a phone call

Close family members report being unable to tell their loved ones' cloned voice from real audio. Subtle artefacts that existed in 2022-2023 cloning are largely fixed. The defence cannot be "does it sound like them?" — it has to be process-based.

Layer 1 — Callback verification

The single most reliable defence. Used for ANY urgent or unusual phone contact.

The protocol

  1. Tell the caller you'll call back. "I'll need to call you back to verify." Don't justify; don't apologise.
  2. Hang up.
  3. Wait 5 minutes. Criminals sometimes hold the line open to intercept your callback — when you go to dial, you're still connected to them. Wait 5 minutes to ensure the line clears.
  4. Call the person on a number you trust. For family: the number in your contacts, NOT the number the call came from. For institutions: the number on the back of the card, on gov.uk for HMRC, or via dialing 159 for banks.
  5. If they answer normally: the original call was a scam. End all engagement with the caller.
  6. If you can't reach them: try an alternative known contact (their spouse, parent, colleague). Don't act until you've spoken to someone you can independently verify.

Why this defeats voice cloning

The criminal controls the channel of the original call. They don't control the channel of your callback. They might intercept incoming calls to a number they're spoofing, but they can't reach the real person's actual number. The callback either reaches the real person (proving the original was a scam) or doesn't reach anyone (in which case you wait and don't send money).

Layer 2 — Unscripted prompts

For when callback verification isn't immediately practical (e.g., you're in a noisy environment, the caller is pressuring time):

Family / friends

  • "What did we have for dinner when we last met?"
  • "What's the name of your first pet?"
  • "Hum the song I always play in the car."
  • "What did Aunt Pat say at the wedding?"
  • "Where did we go on holiday in 2019?"

Colleagues / work

  • "What was the topic of our last meeting?"
  • "What's the name of [intern / contractor / specific colleague]?"
  • "What did [boss / CEO] say about [recent project] in last week's stand-up?"

The criminal has a script optimised for the scam scenario; anything outside the script trips them up. Real people answer naturally; criminals deflect ("connection issue", "I'm in a rush", "I'll explain later").

Layer 3 — Family safe word

A pre-agreed word or phrase known only to your family that proves identity during urgent contact.

How to set one up

  1. Choose a word specific to your family — a shared memory, an in-joke, a childhood pet's name. NOT a maiden name or anything findable on social media.
  2. Share verbally in person at a family gathering — never by text or email.
  3. Use it: "If anyone says they're in trouble and needs money urgently, ask the word. If they can't provide it, end the call."
  4. Update annually.

Full walkthrough at family safe-word setup. The single best protection for over-65 family members against grandparent / "Hi Nan" voice-cloning scams.

Layer 4 — UK 159 for bank verification

The UK cross-bank fraud-verification short code. Free from any UK landline or mobile.

How to use

  1. If you receive a call/text/email claiming to be from your bank with anything urgent — dial 159.
  2. The voice menu asks you to select your bank.
  3. You're connected directly to your bank's fraud team via the carrier-level UK number system.
  4. Ask the fraud team whether the original contact was genuine.

Participating banks

Bank of Scotland, Barclays, Co-op Bank, Halifax, HSBC, Lloyds, Metro Bank, Monzo, Nationwide, NatWest, RBS, Santander, Starling, TSB, Tide, Virgin Money. Most major UK banks participate. If your bank isn't on the list, call the number on the back of your card directly.

159 cannot be intercepted by the criminal because it routes through the carrier-level system, not through the call you just received. It's specifically designed to defeat caller-ID spoofing + voice cloning attacks.

Putting it together — when someone calls in 2026

The decision tree:

  1. Is the call urgent + asking for money or sensitive data? If yes, proceed to step 2. If no, normal protocols apply.
  2. Tell the caller you'll call back. Hang up.
  3. Wait 5 minutes.
  4. Choose verification route:
    • Bank: dial 159, OR call the number on the back of your card
    • HMRC: call 0300 200 3300 (verified at gov.uk)
    • Family: call them on their known mobile number; if unreachable, try alternative known contact
    • Colleague: call via your company directory or known mobile
  5. Confirm or refute the original call's claim.
  6. If refuted: file Report Fraud report at reportfraud.police.uk; forward to 7726 if SMS; report to bank if banking-related.

Frequently asked questions

Can I tell a cloned voice from a real one?

In 2026, no — not reliably by ear alone. Current AI voice cloning tools produce 85%+ similarity from 3 seconds of audio (McAfee research). Close family members report inability to distinguish their loved ones' cloned voice from real audio. Subtle artefacts (slight robotic timbre, unnatural pause patterns) existed in 2022-2023 cloning but are largely fixed in 2024-2026 models. Perception-based detection has failed; the only reliable defence is process-based: callback verification, unscripted prompts, pre-agreed safe words. Don't try to listen for fakeness — use the protocol instead.

What's the callback verification protocol?

When someone calls claiming to be a family member, friend, colleague, or trusted institution: (1) Tell them you'll call back. (2) Hang up. (3) Wait 5 minutes (criminals sometimes hold the line open to intercept). (4) Call the person on their known number — the one in your contacts, not the one the call came from. If they answer normally, the original call was a scam. (5) For institutions (banks, HMRC, etc.): use the number on the back of your card or on the official website. The original caller's claimed identity is irrelevant; verification happens through a channel you can independently establish.

What's an unscripted prompt?

A spontaneous question or request that's hard for a criminal to handle. The criminal has a script optimised for the scam scenario; anything outside the script trips them up. Examples: 'What did we have for dinner when we last met?' / 'Hum the song I always play in the car.' / 'What's the name of your first pet?' / 'What did Auntie Pat tell you at Christmas?' For business calls: 'What was the topic of our last meeting?' / 'What's the name of [colleague]?'. The criminal can't research everything; specific shared memory is the test.

How do family safe words work?

A pre-agreed word or phrase known only to your family, used to verify identity during urgent or unusual contact. If 'grandchild' calls asking for emergency money, you ask 'what's our safe word?' — real family member knows; criminal doesn't. The word must be: (1) Shared verbally in person — never written in messages or emails that might be intercepted. (2) Specific to your family — not findable on social media. (3) Updated annually to prevent leakage. (4) Known by all family members the protocol applies to. Full guide at /scamsupport/protect/family-safe-word-setup.

What about UK 159 for bank verification?

159 is the UK's cross-bank fraud-verification short code. Free from any UK landline or mobile. Dial 159, follow the prompts to select your bank — connects directly to your bank's fraud team. Use it when: (1) Someone calls claiming to be from your bank. (2) You receive a text or email about suspicious activity. (3) You're unsure whether bank contact is genuine. The criminal can't intercept 159 because it routes through the carrier-level UK number system, not through the call you just received. 159 is participating in: Bank of Scotland, Barclays, Co-op Bank, Halifax, HSBC, Lloyds, Metro Bank, Monzo, Nationwide, NatWest, RBS, Santander, Starling, TSB, Tide, Virgin Money.

What if someone says they're calling from the bank?

Apply callback verification 100% of the time. Real bank fraud-team callers EXPECT you to verify them, not the other way around. A genuine call ends with 'if you want to check this is real, please call us back on the number on the back of your card or dial 159'. A scam call resists this — 'we don't have time' / 'the fraud is happening right now' / 'we'll be back to you in a moment'. Hang up immediately on any caller who resists callback verification, regardless of how legitimate they sound. Real banks understand and respect the protocol.

Related scam guides

Just had a call like this? Use our free Cold-Call Checker to find out in a minute whether it was legal under the 2026 UK rules, who to report it to (ICO, Ofcom or Action Fraud), and get a ready-to-send complaint — or browse the “who called me?” number guide.