10 ms·
The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
- imoverclocked 2mo agoSo, you answer your phone to the scam and… now they have your voice too. Talking on the phone is now an unmitigated liability.
- gilleain 2mo agoThe only solution? Answer the phone in an over the top comedy accent, such as Simpsons characters, or just whatever comes to mind.
- andrepd 2mo agoI actually fucking do this, and have done for a year or two. Sad state of affairs.
- matltc 2mo agoA terse, altered "Hello" is all I say. Sometimes I don't say anything. Most humans would wait a few seconds then prompt with "...Hello?", whereas bots tend to hang up after ~2s silence
- lowbloodsugar 2mo agoDon’t you guys have phones that screen calls?
- dredmorbius 2mo agoBecause Reasons I'm looking at several feature-phone / dumbphone options. One feature that's conspicuously missing from many of these is "unknown call block" or equivalent. Which is completely staggering to me. I'm looking at other options, including VOIP / SIP Trunking, where it should in theory be possible to incorporate any arbitrarily complex call-screening feature(s), though Further Research is Needed. Android / iOS phones typically have several available options for call screening. Unfortunately they include numerous other issues and negatives. Sigh.
- rationalist 2mo agoYep, if the number is not in my comtacts, it goes straight to voicemail.
- Symbiote 2mo agoMy colleagues regularly get calls from nurseries, daycare, parents at the after school club, friends of their children or their parents and so on. They can probably ignore international calls, although only probably.
- matltc 2mo agoYes, but false negatives fall through. I don't pay for the call screening; maybe a paid version would be more successful. Mostly ignore unknown numbers, but if I'm expecting a call, I will pick up.
- zelphirkalt 2mo agoWhen it is a human scam caller, what I sometimes do is to say "Hello" and then, when they start talking, and I can already guess they are full of shit, I act as if I am not hearing them properly and say "Hello?? Heeellooo? Hello?" Then they hang up lol.
- deepspace 2mo agoThat's my experience too. I mostly don't pick up calls from numbers that I don't recognize. On the very rare occasion that I am expecting such a call, I always stay silent after picking up. A real human will without fail start talking after a second or two.
- amanaplanacanal 2mo agoI just don't answer the phone. If it's important, they can leave a message.
- abirch 2mo agoA few years back, I would talk with scammers for a while to waste their time. Now I don't. LPT: Please have a codeword or phrase that you use with your loved ones so even if the scammers use your voice, they won't know the phrase.
- TomK32 2mo agoI'm getting a lot of calls recently and don't give them more than a Hello and whatever music, radio show or Tour de France broadcast I'm listening to. Sometimes they hang in there for half a minute.
- xp84 2mo agoSometimes if I’m suspicious about the number now, I just answer and say nothing. A human will get confused after 5 seconds and say “Hello?Hello??” But the very shitty bots that usually call, just wait patiently for a long time for your hello, and don’t seem at all fazed by it.
- pavel_lishin 2mo agoYou get actual humans calling you from unknown numbers? Lucky! I only ever get "Chase" from "Home Security Solutions" or whatever.
- xp84 2mo agoYeah, recently I've had quite a few legitimate ones, mostly having to do with home renovations or other transactions. I like most am deeply unsatisfied with the archaic system though of a basically unchangeable 10-digit number granting permission for anyone to fill up my phone with messages and interrupt me with calls, and hate that I have to ever answer calls from a number I don't know. I really would like a mutual opt-in system, where you have to pre-establish consent before it's even possible to message or call you, but it seems impossible to get there from here. We can't even get the stupid cell phone companies to strongly enforce that caller ID isn't spoofed!
- baxtr 2mo agoI somewhere read about a service that would use AI generated voices to combat these scam calls, basically talking to the forever. Forgot the name though...
- kerridge0 2mo agoIt's Lenny
- Nzen 2mo agoThank you [0]. I searched and all I could find was Virgin Media's Daisy [1]. [0] https://en.wikipedia.org/wiki/Lenny_(chatbot) https://en.wikipedia.org/wiki/Lenny_(chatbot) [1] https://news.virginmediao2.co.uk/o2-unveils-daisy-the-ai-granny-wasting-scammers-time/ https://news.virginmediao2.co.uk/o2-unveils-daisy-the-ai-gra...
- f1ay 2mo agoSo, full disclosure I’m a sec founder in the space, and was already planning on launching a solution deepfake “grandparent scams” right before hacker summer camp but this post was too on the nose to ignore so I ended up moving it up and launching the waitlist for dontscamgrandma.com tonight. Long story short, some fraud associated events cropped up last year at work and I was concerned about my mom getting scammed, so we kitchen tabled it and I told her flat out will never ever call you asking for money" and walked her through some quick scenarios and left it there. About 5 months later, someone called literally screaming, pretending to be me having just gotten into a car accident and killing a pregnant woman, then the phone transferred over to a 'lawyer' and she ended up getting scammed out of most of her life savings. It sat really poorly with me, so I quit my dayjob at the end of last year and started silversight.ai to solve the ai scam / fraud problem for b2b, but I’ve been wanting to roll out something for regular people from the beginning. This post was the bump I needed to validate that other people were feeling the pressure. So thanks for posting. We have more features in the pipe, but as of today dontscamgrandma is backed by an engine that does regular recurring real time phone based training scenarios with an AI that roleplay's common grandparent scams with your loved one with the goal of getting them to recognize and defend themselves from sketchy calls. Pretty excited to share it. Feedback welcomed https://dontscamgrandma.com https://dontscamgrandma.com
- Mr_Minderbinder 2mo ago> “He warned Brightwell not to tell the bank what the money was for…” That should have been a red flag.
- orbitalventures 2mo agoSad sad times indeed, specially because AI empowers more those who seem to do wrong more than good. What we discovered is that implementing a double agent verification, specially in aging population is the way to mitigate. That is family members or more exposed members are required to have a double authorization notification for performing transactions. Banks are doing it quite well and is completely align with MFA. Of course this requires configuration of a trust circle among every person, and generates another avenues for abuse like was pointed. Sadly we are always running behind into protecting people.
- siar 2mo ago[dead]
- chuckadams 2mo agoOne reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.
- ActionHank 2mo agoI mostly answer unknown calls with monotone "hello" and then wait for their introduction before talking normally.
- fhdkweig 2mo agoI answer with silence. I wait for them to speak first. Not even once has a scammer ever spoken first. I say nothing, they say nothing for a full minute before they hang up.
- ghaff 2mo agoI mostly just don't answer them unless it seems like something that may be legit.
- DANmode 2mo agoThis is the only way to avoid validating your number for spam lists, and receiving more.
- jonathanlydall 2mo agoI think it's a somewhat South African cultural thing, but when I get calls from businesses or spammers, the first thing the caller tends to say is "Hello, how are you?", which is completely stupid when you're calling someone who wouldn't know who you are, so it tends to immediately make me annoyed that they don't know that they should have introduced themselves first. As 99% of the time these are spam calls, I used to respond with something like "I'm fine, but who are you / do I know you?", but that was pretty much always inefficient as that might say their name (which from a spammer is useless information), maybe a sales pitch "how much do you spend on x?" or maybe something deliberately misleading about their company and saying something like <major brand name> even though they're some independent sales crowd getting commission selling contracts for them. Eventually I found that the most effective response is "Sorry. Where are you calling from and what is this in regard to?" which I've found without fail seems to surprise, disarm them and immediately elicit whether the call is a waste of my time. At which point I either become very friendly (because it's a call I'm expecting) or I simply respond with "Sorry, not interested, goodbye." and immediately put down the phone. I just want the disruption to be as minimal as possible and to not let myself even get an emotional reaction from it, so I don't want to get annoyed at them, never mind wasting time telling them off, besides, I suspect that my ruthlessly efficient getting rid of them without them even having a chance to try their pitch is received as a super cold shoulder, akin to being told to f-off.
- ThrowawayTestr 2mo agoThey make you give a voice sample now when you're arrested. You need to do so in order to use the phone.
- dec0dedab0de 2mo agowho is they?
- ThrowawayTestr 2mo agoThe US government
- dec0dedab0de 2mo agoBut which US governments? There are thousands of them, and they all have different policies.
- ThrowawayTestr 2mo agoMontgomery County in Indiana, specific enough for you?
- altcognito 2mo agohttps://www.justice.gov/archives/jm/criminal-resource-manual-257-voice-exemplars-search-and-seizure https://www.justice.gov/archives/jm/criminal-resource-manual... The federal government.
- mrngld 2mo agoWe (the people) have pushed body cams on almost all law enforcement at this point, which had a noble enough motivation behind it -- but we also have pushed for and have various public disclosure laws (also well intended!) that mean those body cams are torrents of data entering the public sphere if anyone simply asks for it. Now in the era of AI, this means anyone in the vicinity of an officer has a voice sample in the public domain, plus potentially their image. Complex issue. I like body cams, I like freedom of information laws, but don't love this particular outcome.
- intended 2mo ago[dead]
- reactordev 2mo agoWhat’s terrible is each time I am forced to call the bank, the more they try to tell me voice ID is secure and want me to provide my voice to authenticate. Never. Did ya’ll never play Uplink? With voice cloning as good as it is now, there’s no way a voice ID is secure enough for authentication.
- fouc 2mo agoname and shame the bank
- reactordev 2mo agorofl, IYKYK
- eclipticplane 2mo agoSchwab still does voice passwords. "At Schwab, my voice is my password" https://www.schwab.com/voice-id https://www.schwab.com/voice-id
- ipdashc 2mo ago> my voice is my password So... This has to be a Sneakers reference, right?
- Havoc 2mo agoYeah my bank does the same except don’t think there is an opt out. Kinda crazy
- reactordev 2mo agoSpam 0, you’ll eventually get some customer service agent
- Havoc 2mo agoFancy private bank so getting a human isn't the issue ...but I know one of the signals they use for authentication is voice analysis in background...which I do not love.
- revolvingthrow 2mo agoThe problem described in the article is unsolvable, given that a mid-range desktop from a few years ago can easily clone a voice that's convincing enough and there are no guardrails to those. Some silly KYC laws might limit a highschool kid making deepfakes of his crush, but once a model exists it's trivial to spread it around, and for organized groups to get ahold of those. Similar will happen with images, it's just that nobody with any serious money bothered releasing image gen models that compete with gemini or chatgpt -- but it's just a question of time. A year or three, what difference does it really make? As the cost goes down to near-zero you can scale it up almost infinitely, especially if the profits are high enough to get some smart people working on the problem, which going by the article is already the case ("INTERPOL's finding that AI-enhanced fraud is four and a half times more profitable than the traditional kind"; incidents rose by 26% last year). If AI does succeed on mutilating white collar work enough there will be a large supply of knowledge workers that might just join International Scam Co. rather than have their families go homeless. Drowning man clutching at straw and all. So if technologically it's impossible to prevent and societally it's impossible to prevent (like the attorney that got pwned same as the grandma), I'm not sure if there exists an answer that isn't worse than the thing it's supposed to prevent. I suppose we'll soon be in a situation where nothing we don't directly perceive in real life is provably true. That journalism and media in general seem to be in a deep crisis of trustworthiness means that you won't even get the benefit of the chain-of-trust as a proxy for whether something is or isn't real. Ignoring everything happening outside of your immediate surroundings is a choice, and probably even good for people's mental health, but my gut feeling is that it does make humanity as a whole dumber and disempowered. What does corruption matter if nobody cares, or even hears about it? It was AI generated by $current_enemy anyway; nothing to see here, citizen.
- TacticalCoder 2mo agoI don't know about that but finding excuses for the scum of this earth is certainly not a solution. Take Europe for example: nobody dies of hunger in Europe. And yet there are plenty of thieves. People stealing tens of thousands, hundreds of thousands, millions of EUR aren't doing it to "feed their families". Think of the situation today. Think of the victims today. Instead of thinking of tomorrow's hypothetical situation where supposedly all the honest fathers out of work would join the crime syndicate, think of today's victims. Projecting your own insecurity about the future to excuse scummy behavior by the scum of this earth is of no help. There are people, right now, who have a roof. Who have a family. And who are fucking scums stealing the hard earned money of others because they choosed the easy life of crime. Zero tolerance for such motherfuckers. I care about the victims and you should too.
- skybrian 2mo agoThis blog is kind of an interesting hybrid: > Every article published on SmarterArticles is authored and editorially controlled by Tim Green. Artificial intelligence tools are used within a structured and supervised workflow as research and drafting instruments. All arguments, framing decisions, source selections, and final publication choices remain human-directed and under my full responsibility. There are references at the bottom, but I would have preferred direct links or footnotes within the article. Also, direct quotes are nice. I didn’t notice any glaring AI cliches.
- aqfamnzc 2mo agoI suspect this is much more common than you're imagining. I think it'd be silly for publishers of any kind, really, to not use AI tools for things like fact checking and so on.
- rda2 2mo agoInteresting, something about the phrasing and pacing felt like AI to me, but not a model I’m familiar with - I guess that’s why. Usually I close articles once I realize they’re AI written, but this one was mild enough that I finished the whole thing.
- saaaaaam 2mo agoInteresting. To me it reeks of AI, and the first major tell was the first paragraph, at which point I stopped reading. > No human had. The crying had been synthesised from a fragment of audio, and the daughter she thought she was rescuing existed only as a pattern of numbers in someone else's machine.
- Brendinooo 2mo agoYeah, I can't explain it but the headings feel very AI. And there are a bunch of things in the text that remind me of chats I have with Claude during the day job >and it is worth being clear about why >The emotional mechanism the scam exploits is not a gap in knowledge that a leaflet can fill; it is the love a person has for their grandchild, weaponised >These are not the numbers of a credulous minority being separated from pocket money. They are the numbers of a generation's accumulated savings being drained >that a fraud requiring the absolute frontier of machine learning can be perpetrated against an ordinary grandmother in her kitchen, at scale, for the price of nothing (To be clear this isn't automatically disqualifying to me. But I am interested in LLM writing patterns and my ability to detect them. And in the case of this article I sense the kind of linguistic padding that has made Claude a little harder to work with in the more recent Opus point releases because it obscures the most important bits of information.)
- offsign 2mo agoSounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Western Union refused to let her continue sending wires... she was forced to call her daughter (at which point they just called my brother.) Our takeaway (at the time)... the voice doesn't even need to be terribly accurate, since the original interaction is brief / somewhat inaudible over the tears. Typically just requires an older vulnerable adult, a lucky strike with the initial setup (e.g. grandparent actually has a grandkid), and a lot of high pressure / duress salesmanship.
- Foobar8568 2mo agoI told my parents that I will never ask for money, doesn't matter the situation, even with live video, it's trivial to generate live audio and video nowadays. I hope they got the message.
- f1ay 2mo agoThat wasn't enough for my mom. I went through an identical scenario, and about 6 months after we had the conversation she got hit.
- abirch 2mo agoFortunately for me, my parents wouldn't be able to get the live video working.
- saidnooneever 2mo agoi agreed key phrases. id recommend it. something unrelated to the family and totally arbitrary, agreedupon only verbally. (or write it down for them if they are old and memory is an issue. you can remind them to read your note out loud.. easy). this way, you do not footgun yourself in the event you'd ever need to ask something. Money isnt the only thing they can ask, and no one (i think) has a glass orb to tell their future and know for certain such a call would never happen. its easy to think it wont happen to you, i think that is most peoples' sentiment until it does. (having a need for help from family that is)
- christkv 2mo agoWe all have a safe word in the family just for this issue to identify if it´s the real person or not.
- xp84 2mo agoSomeone else pointed out how easy it would be to make a video of anyone having a finger cut off, or similar torture, to scare the victim into believing that the “grandchild” forgot their password and needs you to override the password protocol to save their other 9 fingers. I have to agree. That’s like 80¢ of compute to do. If that’s effective even 30% of the time, it means “just have a password” doesn’t make you safe.
- codedokode 2mo agoWhat are legitimate uses for copying someone's voice without permission? I see none. Those scientists are just helping criminals to fully automate scamming and governments to create fake videos.
- AStrangeMorrow 2mo agoWell of course as you pointed out the legitimate one would be copying voices WITH permission (yours, someone you know who gives authorization, through contracts for movies/bots etc). The model can’t differentiate between voices for which you have permission or not. But more generally while recordings might be copyrighted, the voice itself isn’t so copying a voice isn’t a crime, at least as it currently stands. You cannot however use said voice for deceptive practices. You can however for advertisement (needs permission). And in the US you can for satire, at least in the US, withOUT permission (falls under the 1st amendment).
- codedokode 2mo agoMaybe the voice should be copyighted or protected then, I do not want anyone use to my voice, let them use their own boring afwully sounding voice. I am sure such models are used in 99% cases for illegal purposes or creating fake news. Also, one's likeness (like face image) should also be protected from being used by anyone.
- fhdkweig 2mo agoParody for one. Trey Parker and Matt Stone (of South Park) created a nice one that clones faces (but uses celebrity impersonators for voices). https://en.wikipedia.org/wiki/Sassy_Justice https://en.wikipedia.org/wiki/Sassy_Justice https://www.youtube.com/@SassyJustice/videos https://www.youtube.com/@SassyJustice/videos Full video at https://www.youtube.com/watch?v=9WfZuNceFDM https://www.youtube.com/watch?v=9WfZuNceFDM
- codedokode 2mo agoThey can do the parody using their own voices. There is no need for cloning someone's real voice.
- deleted 2mo ago[deleted]
- fantasizr 2mo agoI've been waiting for a steelman argument why building the world's best deepfake machine is a good thing. Unironically cryptography could verify identity for all comms.
- chrisjj 2mo ago> ... the hardest for its victims to be believed about — because the evidence, by design, sounds exactly like someone they love. Uh? Surely this makes believing the victims easy not hard to believe. Its like revenge porn. "It's not me. It's a deepfake" is easy to believe.
- laszlojamf 2mo agoAI definitely amplifies this problem, but it's not like it didn't exist before. Old people get scammed the old way all the time too. My mom calls me every once in a while asking about some freebie offer that she gets emailed from sketchy domains claiming to be spotify or something. Not saying that "there's nothing we can do" or anything, but it does feel like this is one of those instincts that you develop growing up with the internet. Like, my first instinct reading that (and I hope getting that call) would be "what the hell is the lawyer doing at the scene". You have to treat _everything_ coming through your phone as potentially untrusted. I don't have any data on this, but it feels like my friends, and especially younger people, do that automatically. The primary defence against all phishing is to tell yourself: nothing is ever really that urgent. Nothing is ever that good.
- geor9e 2mo agoI fear this whenever I acidentally say too many words to a telemarketer/scam call.
- zuluworksai 2mo agoi wish i could still warn them...
- butvacuum 2mo ago> Welcome to Voice Print Identification. When you see the red light turn on please state in the following order: Your destination, Your nationality, and your Full Name.
- LiteUser 2mo agoMoon, American, Floyd, Heywood R.
- zuluworksai 2mo agoIf they were still around i would have to warn them for sure! Crazy stuff this new future!
- arbuge 2mo ago"They kidnapped my daughter? That's terrible. Yes, I'll definitely pay the ransom but to get access to my bank account I need you to write a poem about corn and a curl script in PHP. Please go ahead." Inspired by this headline I saw in the news today... haven't read the full article yet: https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too/ https://arstechnica.com/security/2026/07/now-defenders-are-e...
- lowbloodsugar 2mo ago> It requires, second, regulating the supply of the weapon Heavy sigh. The “weapon” is software. It cannot be regulated unless we live in the fascist dystopia where I have to ask the governments approval to run any piece of software.
- zengid 2mo agoOne regulation i would like to see is some auditory fingerprint in an AI voice where any person can immediately recognize their speaking to a clanker but it's not unpleasant. It should be illegal to "impersonate" a human voice.
- wrs 2mo agoEveryone suffers from this, not just the scam victims. I opened a bank account for a new business this year, and the friction for doing perfectly normal things was ridiculous due to the bank’s paranoia about scams. I couldn’t even make an initial deposit from my previous business, or transfer money to my personal account, without triggering a fraud alert and freezing the entire account (couldn’t even log into the bank website) until I could call and verify that it really was me on both ends of the transaction.
- dieselgate 2mo agoFrom a business perspective genuinely curious to know general location and bank name for this. In WA state I've only dealt with minor scrutiny (from credit union not bank) asking if the business is involved with cannabis otherwise it's been easy.
- wrs 2mo agoThis was Chase, in WA. Part of the problem may be that I used an address on the account application that didn't match the one on the state company registration. Rather than let me update the application, they required that I update the state registration to match it ($50 fee btw). (To be clear, both addresses were current and valid.) That may have set some kind of risk flag that increased scrutiny later. But they were specifically worried about the transfers being scams -- at least, that's what they said. They insisted on calling my other bank to verify that I was in fact the owner of the other business account. And I know there's been a big increase in things like fake real-estate scams, so paranoia is understandable. However, the way bank fraud/risk departments work is generally completely opaque. I've previously had Bank of America refuse to open an account, with no reason given and no possible recourse. And I can't imagine a much more vanilla, boring, good-credit person than me, so I have no idea what set them off!
- pmarreck 2mo agoArrange a secret phrase in advance- ideally generated randomly. Stick it up on the wall of the aging parent or grandparent- maybe in the bedroom, where guests are unlikely to go. Make it innocuous-looking (hidden in plain sight). Require that phrase to be said to prove identity. Reset it if it ever gets used on a call legitimately.
- ButlerianJihad 2mo agoPersonally, I require all my aging grandparents to carry a Yubikey, with an identical one always stored in a safe-deposit box. Then, on demand, they simply mate their Yubikey with a specially-prepared GrapheneOS device, open their Firefox app, and connect to the dedicated mesh network, run by and for aging grandparents. Then they run their right ring finger over the fingerprint sensor, but it must be done in a Morse-code pattern that matches their unique tattoo (I am unable to divulge the location or encoding of this tattoo). Once these conditions are met, their physical presence is confirmed by the Yubikeys of at least 2 other aging grandparents of equal or higher reputation. It's really simple and straightforward, and there is no need to really document the workflow here, because all the aging grandparents are extensively trained and drilled every two weeks, by the aging great-grandparents who've been using this same exact system for the past 50 years.
- ButlerianJihad 2mo agoSeriously though, I'd like to make two points: 1: Your family members already have shared "secrets" if they communicate regularly. It could be pet names, terms of endearment, shared experiences, unique monikers for things. It's language that is already familiar and you already use quite often. You should leverage that, and rely on that familiarity in a crisis, rather than trying to contrive something special for crisis-only ID. The attackers' greatest weapon is your own confusion, your own willingness to believe, and creating a sense of urgency. Your attackers' 3 greatest weapons. Don't panic. 2: My maternal grandmother was widowed and lived alone for decades. She had certain ways of knowing things. For example, every time we'd come home, she would test the doorknob. If some stranger had come and tried to jiggle the doorknob, we could tell by its feel. Just a simple mechanical giveaway. When Mom and/or Dad came by, they rang the doorbell by a special pattern. It wasn't complex, but it was distinct and recognizable from inside. It wasn't a securely encrypted ID, just a "secondary ring" that was unlike a stranger's touch on the doorbell button. And, of course, my parents can always interpret the antics of their indoor cat, in regards to who is approaching the house by car or on foot...
- farceSpherule 2mo ago[dead]
- saltcured 2mo agoSad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many people will be slipping into cognitive decline without a formal transition to address their incompetence. Sadly, there is a point where the older person really needs to permanently delegate important decision-making to a trusted third party. They should no longer be legally empowered to authorize funds transfers, sign contracts, or even make medical decisions. We're not really setup to handle this well. Not at the systemic level of protecting people from themselves, and not at the personal level of relinquishing control over our own lives. So we often have to let the sufferer fumble along and cause a lot of damage before the protections eventually kick in. And, ironically, these protection mechanisms can also be corrupted into another scam and form of abuse. To totally de-risk would require some kind of time travel or perfect foresight. But in the real world, the damage is often not fully reversible when it is detected after the fact.
- aaron695 2mo ago[dead]
- pavel_lishin 2mo agoI think the hardest thing to come to terms with is not that this is the new reality, or even that this is soon going to be the new reality for our older relatives, but that this is coming for almost all of us.
- Perseids 2mo agoI'm usually not one to focus on technological solutions given sociological problems, but this one seems to be a good exception. If we "just wanted to" [1] all this fake calls could be stopped by requiring strong authentication/authorization. We are very much used to just anybody being able to call my number, but that doesn't need to be the case. At the very least, cold calls should be treated as skeptical in the UI as instant messengers like Signal treat first messages. Probably this isn't enough, though, as it wouldn't have prevented the cases described in the article. Cold calling someone should probably require the caller to be traceable to a real, government-ID-verified person [2]. Even if that person is being defrauded themselves ("get a thousand bucks by installing this app and clicking a few screens") is would destroy the economics of the attack, as it would make each call expensive again. [1] Structural inertia is the killer here. It will certainly not happen until the problem is huge enough. [2] Exceptions can of course apply to numbers that are meant to primarily be cold called, like doctors offices. The callee possibly have to be specially trained to withstand this kind of attacks.
- reddit_clone 2mo agoA friend and his wife _almost_ fell victim to this last year, in Texas. I think it is a standard script now. Call comes from police department. 'Your son hit a pregnant woman. He is about to be booked. You need to pay $$$$ yada yada'. With an authentic sounding voice conversation from their son. In spite of several red flags (in hindsight) they withdrew $15K from bank, and somehow at the last minute pulled back. Edit: Scammers know how to push the right buttons.
- Animats 2mo agoThis article is about the retail version of this kind of fraud. Impersonating CEOs is a thing, and the dollar amounts are much larger. The attackers created AI-generated video and audio replicas of the CFO and other executives of the global engineering firm. These deepfakes were deployed in a live video call – not as a pre-recorded video, but as a real-time conference with multiple participants. The finance employee saw and heard his superiors in what appeared to be a normal conference situation. The instructions came through clearly and consistently. Urgency was created by framing the situation as a supposed corporate acquisition. Within a single session, he approved 15 individual transfers to various accounts in Hong Kong.[1] That fraud yielded US$25 million. [1] https://www.securitytoday.de/en/2026/04/04/deepfake-attacks-c-suite-ai-voices-ceo-fraud/ https://www.securitytoday.de/en/2026/04/04/deepfake-attacks-...
- dredmorbius 2mo agoThe possible silver lining of enterprise-scale fraud is that it might be the pain which finally pushes telephony / voice comms to adopt true call-level authentication and security. This need not be a centralised security / authentication / identification system, but the protocols must be standardised and near-universally applied. If these rely on some hardware token (YubiKey, NFC ring, RSA keyfob OTP, or even a smartphone's native ID features). The other side of this is that networks and carriers who transact largely fraudulent traffic must be penalised for this. I'd like to see both financial and technical penalities, e.g., ruinous fines, with a sufficiently large balance disqualifying the carrier from interconnect rights, and the right for terminating / bridging carriers to reject traffic in proportion to the level of malicious traffic logged. (This also implies some distributed facility for monitoring traffic from various comms networks and sharing that information with carriers and other security provisioning parties.) A worse outcome would be a two-tiered system in which large enterprises have access to reasonably fraud-free comms, and the rest of the world does not.
- inferhaven 2mo agoSuper interesting read, makes me wonder if audio data poisoning could be employed en masse to help defend against this kinda stuff
- onetokeoverthe 2mo ago[dead]
- spenvo 2mo agoThis old post of mine may be of interest, where I point out: "After a bit of threat modeling, it becomes apparent that future spearphishing robocalls may not directly con you, but rather “farm” your voice data by asking you benign questions, and use that to train a voice model to penetrate more deeply into your network." A lot of this writing has been on the wall forever and many (I'm sure otherwise smart people in) mission critical industries like banking, ISPs, and more refused to even acknowledge the risks. 2021 - "Despite the prevalence of deepfake audio tech, banks and ISPs rush ahead with “voice print” authentication" https://keydiscussions.com/2021/12/07/despite-the-prevalence-of-deepfake-audio-tech-banks-and-isps-rush-ahead-with-voice-print-authentication-%f0%9f%92%80/ https://keydiscussions.com/2021/12/07/despite-the-prevalence... ends with a section called "The next crisis: robocalls that spoof the voices of victims at scale"
- franktankbank 2mo agoDo not answer calls from random numbers. When has that ever been a benefit?
- spenvo 2mo agoTelcos need to implement STIR/SHAKEN in a binding way and it needs to be fully integrated into iOS/Android's UI. Spammers call from spoofed numbers, even numbers of, say, local schools (or from other people in your business) - so, if you get a call from a school and you've got kids, would you pick up? A couple of years ago I got a text that was "sent" from my boss (he didn't send it), etc.. The numbers aren't random.
- titanomachy 2mo ago> most victims of a cloned-voice call never learn that a machine was involved at all. They believe, as Sharon Brightwell initially believed, that they spoke to their own child. This doesn’t make any sense. At some point they will speak to their child and learn that the call wasn’t real.
- neuroelectron 2mo agoYet the government refuses to do anything about the massive amount of phone spam we get every day which is an open door to AI voice cloning. But won't anybody please think about the telecom profits?
- linsomniac 2mo agoA year ago I promoted the idea among my wife's family that we should establish a sign/countersign system for the family and use it regularly so that in the event of something like this we could positively identify a legit request. Would have come in handy when our niece was traveling in Asia and asked for money a few times, but in this case it wasn't a scam. I got no traction with it, which I was a bit surprised by because one of the family members works at the Puzzle Palace.
- Cider9986 2mo agoA shared TOTP in an app could also work.
- linsomniac 2mo agoMy concern there is that the friction is too high: it wouldn't be something that family members would use in casual conversation, and could also be written off by the AI: "They won't give me my phone", "I lost my phone", etc... "Did you see that game last night" replied to with "The Visitors are my favorite team" is something you could say instead of "hi" as a family.
- attila-lendvai 2mo ago> It requires, second, regulating the supply of the weapon. [...] i guess even local models can do this now, especially in non-interactive mode. so, i have a hard time reading this part as mere naivitee, as opposed to enemy propaganda in support of mandatory digital ID's for everything. or for straight out criminalizing "unauthorized" compute altogether?
- m463 2mo agoThis makes me REALLY question "this call may be recorded for quality purposes" Now other businesses are starting to reference their privacy policy at the beginning of a call, which leads me to think there are many more uses popping up for our recorded voice. I'm sure a certain percentages of recordings of our voice "to stop fraud" might be used to start fraud.
- ambicapter 2mo agoMaybe a good time to bring up (again) the fact we don't impose enough liability risk on companies that collect data willy-nilly.
- milesvp 2mo agoDoes anyone know if Ben Jordan's AI generated music algorithm would work here to spot fake voices? He's looking for compression artifacts introduced from the training data in the output music. I'd expect similar compression was used for training general voice data. Only issue I can think of is the compression of the audio link most of these scams are going to be using might mask the training data compression.
- jongjong 2mo agoI'm kind of glad now that I had some really bad experiences in my career and experienced negative-trust environments. When I told my parents some of what happened to me in my career, initially, I don't think they fully believed me because people in my stories behaved so differently than they're used to. My parents lived in an environment where they could expect reciprocity and money wasn't so difficult to come by that it would be worth risking prison time. I kind of believe that a lot of people are essentially forced into fraud. I don't believe that they are necessarily bad people. A lot of people are just trying to get by. So it's very important to convey to family members what kind of world we live in. I think most of my family members are essentially conspiracy theorists now.
- semiquaver 2mo agoThis article is 100% LLM generated according to pangram, which is a bit funny given its topic. I didn’t need the detector though; It is pretty grating, sounds like Claude Opus with its talk of “load-bearing” and such.
- jabrown44 2mo ago[flagged]