How to recognise a deepfake voice call – and what to do in the first 60 seconds
Also available in: العربيةБългарскиČeštinaDanskDeutschΕλληνικάEspañolSuomiFrançaisעבריתहिन्दीHrvatskiMagyarBahasa IndonesiaItaliano日本語한국어NorskNederlandsPolskiPortuguês (Brasil)PortuguêsRomânăSlovenčinaSvenskaไทยTürkçeУкраїнськаTiếng Việt简体中文繁體中文
A familiar voice, a sudden emergency, a request for money – right now. That is the pattern of almost every voice-clone scam, whether it targets grandparents (“Grandma, I had an accident”) or finance teams (“This is the CEO, I need a transfer before the deal closes”).
The uncomfortable truth: you cannot reliably hear a good deepfake. Phone lines compress audio, stress narrows attention, and modern cloning tools reproduce accents and speaking style. Protection therefore has to come from procedures and verification, not from your ears.
Why voice cloning became a phone problem
- Little audio is needed. Research systems such as Microsoft’s VALL-E (2023) demonstrated imitation from a few seconds of speech. Voice notes, videos and podcasts provide plenty.
- Caller ID can be faked. The displayed number is just data. Attackers can show the number of a relative, your bank or your employer.
- Pressure is the real weapon. The script is designed to stop you from pausing: an accident, an arrest, a confidential deal, a deadline.
One of the first publicly reported cases dates back to 2019, when the UK subsidiary of an energy company reportedly transferred around €220,000 after a call imitating the voice of its parent company’s chief executive. Since then the tools have become cheaper and better.
Warning signs during the call
None of these proves a deepfake on its own – together they should trigger your callback rule:
- Urgency plus secrecy: “Don’t tell anyone”, “there’s no time”.
- An unusual payment route: gift cards, crypto, a new bank account, a courier collecting cash.
- Unknown or suppressed number for someone who normally calls from their own phone.
- The caller avoids open questions or steers back to the script when you ask something personal.
- Odd audio: unnatural pauses, flat emotion in a supposed emergency, background noise that does not change.
The 60-second response plan
- Pause. Say: “I’ll call you right back.”
- Hang up – even if the voice protests.
- Call back on a number you already know (from your contacts, not from the call log or the message).
- Ask the safe word if your family or team has one.
- Never send money, codes or passwords during an unverified call.
Set up a family safe word today
Agree on a word or question that only your family knows and that never appears online. Anyone who calls with an emergency must be able to answer it. Write it down for older relatives. It costs nothing and defeats most “grandchild” scripts.
For businesses: stop CEO fraud by design
- Two-channel rule: no payment or change of bank details on the basis of a phone call alone – confirm through a second, known channel.
- Pre-registered callback numbers for executives, suppliers and banks.
- Verified caller identity for internal calls, so finance teams see who is calling, not just a number.
- Training with real examples – people who have heard a cloned voice are much harder to fool.
Where technology helps
Procedures stop most attacks, but they rely on people remembering them under stress. Technology can make the right decision the default:
- Verified contacts show a cryptographic badge when the real person calls – and its absence is a warning.
- Synthetic voice detection analyses call audio and warns while the call is still running.
- Number risk scoring flags spoofed or reported numbers before you pick up.
That is what we are building with Identity Phone – for individuals, families and teams, and as an API for contact centers and banks. It is currently in development; you can join the early-access waitlist.
Frequently asked questions
Can you hear whether a voice is a deepfake?
Not reliably. Modern voice clones can sound convincing, especially over a phone line that already compresses audio. Use procedures – a callback on a known number or a safe word – instead of trusting your ear.
How much audio does a scammer need to clone a voice?
Research systems have shown that a few seconds of speech can be enough for a rough imitation. Voice messages, videos and social media posts are common sources.
What should I do if I think I received a deepfake call?
Hang up, call the person back on a number you already know, do not send money or codes, and report the incident to your bank and the police if money was requested.