DARINORCold Lab

// Writing

Your Voice Is Not a Password Anymore

By
7 min read
Defense engineering#ai-security#threat-modeling

The phone rings and it's your daughter's voice. Live, scared, asking for help with something that has to be paid tonight. It has her accent, her pauses, the way she breathes between words.

It is not her. And nothing you were taught about spotting a fake call works anymore.

Three seconds

On September 14, Spain's national cybersecurity agency, INCIBE, published new guidance on AI voice-clone calls: scams where software rebuilds a person's voice well enough to fool their own family. The number that matters in it is small. Older warnings said a scammer needed about ten seconds of clear audio to work from. INCIBE's updated guide puts it at three — lifted from any video already sitting in public view.

Three seconds is a greeting. It's the top of a birthday video, a voice note, a clip your kids posted years ago and forgot about.

The scale is real, not hypothetical. INCIBE reports more than 135 million suspicious calls blocked in Spain this year, with roughly one in three carrying a cloned or AI-generated voice. The average victim who loses money loses €577 — and fewer than one in three ever reports it, so the true number is higher.

The defense most people were taught died quietly in the same guidance. The old advice was to ask an unexpected personal question, on the theory that a scammer could only play back a recording. INCIBE's finding: the newer tools improvise in real time. They follow the conversation. Your clever question isn't a wall anymore — it's a prompt.

The con is old. The machinery is new.

The emergency scam is one of the oldest cons there is. A panicked relative, an accident abroad, money needed before anyone finds out — your great-grandparents got versions of that letter in the mail. Nobody needed AI to invent it.

What changed is the proof. The scam used to break on its details: a wrong-sounding voice, a weird pause, wording your child would never use. That was the tell, and most people's entire defense lived there. In one study cited by researchers at The Conversation, listeners caught a fake voice only about 60% of the time — a coin flip, tilted toward losing. And the ceiling case isn't a grandparent at all: the engineering firm Arup lost $25 million after a video call staffed by deepfakes of colleagues the victim worked with daily.

So the honest position now is this: you cannot reliably hear a fake. Not you, not your most suspicious relative, not the colleague who "would never fall for it." The voice check is gone, and the scam didn't even have to get clever to kill it — it just had to get cheap.

Panic is the product

Here's the part that should make you uncomfortable. The voice being fake is almost not the scam. The scam is the state it puts you in.

Nobody makes a good financial decision mid-panic. That's not a weakness of character — it's how stress works on attention. Scammers know it, and the scripts are engineered around it: an accident, a lost wallet, legal trouble in another country, a payment needed before you can think. INCIBE's guidance points at urgency as the clearest surviving warning sign — along with a call that conveniently cuts out the moment your questions get hard.

It went viral this past week, in fact: a man got a call from his wife's voice asking him to read out his credit card number for gas. His wife was sitting next to him. The family car is electric. "If she hadn't been sitting next to me," he wrote, "I would have fallen for it." That's not a gullible man. That's the new baseline — the voice passed every listening test he had. Only the facts failed.

The check that lives outside the call

Every defense that happens inside the call — listening carefully, recognizing the voice, springing a surprise question — is now fighting on the scammer's ground. The checks that hold live somewhere else entirely.

Hang up when the pressure starts. Not rudely, not after one more question. The moment urgency arrives, the call is doing its job on you, and the correct move is to end it. Hanging up is the security control. It costs nothing and it works.

Call back on a number you already have. Not the one the caller reads out — a number saved in your phone, from before this call existed. A cloned voice can't answer your daughter's actual phone. This is the whole defense in one move: you've left the line the scammer controls.

Agree on a code word, tonight. One phrase, specific and strange enough that nothing you've ever posted online could guess it — not a pet's name, not a birthplace, not a fact. No code word, no money. No exceptions, because the exceptions are the business model. Zoho's chief scientist spent his weekend telling strangers on the internet the same thing, which tells you how the week has gone.

A voice is a claim made on the scammer's line. The only proof that counts lives somewhere the scammer can't reach — a number you saved before the call, a word agreed before the emergency.

I write about security for a living, mostly for engineers, and this is the same lesson I keep having to relearn in the other direction: a check that lives inside the conversation can be talked around. A ransomware crew spent this spring talking its way past an AI coding agent's refusals the exact same way — new session, plausible cover story, ask again. Your family's callback rule and that agent's environment wall are the same principle wearing different clothes. Trust what's outside the channel, not what's speaking inside it.

What this advice cannot do

An honest version of this post has to say where it stops.

A code word only protects you if it's genuinely unguessable, and most people's first three guesses are guessable. Security experts are already warning that simple family safe-words fail — anything a relative posts about publicly is fair game. Make it a shared memory, not a fact. If you'd rather let a machine handle the entropy, toolsforweb's password tools build strong candidates entirely in your browser — nothing leaves the page — and that's the same bar the code word has to clear: unguessable by anyone who knows you.

Pressure defeats procedure. The scam's real product is the panic, and a caller who can keep you on the line past the point where you'd normally verify has already won half the argument. Rehearse the hang-up. It feels dramatic the first time. It gets easier.

And no single check is enough against a patient attacker. The layers stack — callback, code word, time, a second family member looped in. Every one you add takes something the scam needs: speed, isolation, secrecy. The scam needs you fast and alone. Refuse to be either.

Tonight

Agree on the code word tonight — with the people you'd actually send money to at 2 a.m. Save each other's numbers in your phones, the real ones, under names a stranger wouldn't delete. If your parents are older, start with them: these scams aim at grandparents hardest, and this year's Grandparents' Day warnings from the BBB weren't a coincidence.

You can't hear a fake anymore. You can only verify one — and that happens after you hang up.