You hear a familiar voice on the phone. Panicked, in a hurry, in trouble, asking for money right now. The voice really does sound like your relative, because technically it is: someone took a recording of that voice and produced an imitation.

The rise of AI-powered voice cloning tools has made this attack easier. In the pattern known as virtual kidnapping in particular, fraudsters call in a family member's voice, invent an emergency and ask for money or personal information.

The security firm ESET's answer to this attack is simple and needs no technology: a security word agreed in advance among family members. This guide covers that method, how to set it up and where it falls short. It requires no installation and no app; all it needs is one short conversation in the family and for the decision made in it to be taken seriously by everyone.

Why the usual verification fails

Trying to judge a call's authenticity by the voice no longer works. Tone, accent and speech habits can be imitated, and a long recording is not required for it.

Looking at the phone number is not safe either; spoofing the calling number is a known and easy technique. That leaves one reliable ground: a piece of information agreed beforehand that the other side could not possibly know.

  • A voice sounding familiar does not count as verification.
  • A number looking right does not count as verification.
  • The sense of urgency is itself the trap built to bypass verification.
  • Verification has to happen outside the call, not inside it.

How the attack is built

This fraud runs in three steps, and all three are psychological rather than technical.

The first step is collecting a voice sample. A short video shared on social media, a voice message or a brief phone call can be enough. The second is choosing the target: usually a relative of that person, and often an older family member.

The third step is the scenario. An accident, a detention, a hospital, a lost phone. What they share is urgency, leaving no time to think. What the fraudster really manufactures is not a voice but a sense of emergency.

How to choose the security word

The method rests on family members agreeing on a word or short phrase only they know. In a suspicious call, that password serves to verify that the caller really is family.

ESET's selection criterion is clear: the word should be easy to remember but hard for anyone else to guess.

Bad choiceWhy
A birthdayAlready written on social media
A pet's nameLearnable from photo captions
A hometown or school nameOpen in profile information
A child's middle nameInferable from family posts

The general rule: nothing reachable through social media can be a security word. The word itself should never be shared on any platform, never sent in a message and never written on paper carried in a wallet.

When choosing the phrase, a two-word combination that would not come up in everyday conversation works well. A single common word is both guessable and liable to be said by accident mid-conversation; an odd two-word pairing removes that risk.

How to set it up

Setting it up is short enough to finish over dinner, but a few details matter.

  • Agree the word face to face; do not discuss it in a messaging app.
  • Be clear about who in the family will know it, and keep the list narrow.
  • Include older family members without fail; they are the main target of this attack.
  • Teach children the word, and also explain that it is never told to anyone.
  • Change the word once a year, and make the change face to face again.

The point about age matters. In this fraud the target is often someone who believes they are hearing their grandchild or their child, and the most fragile link is usually the person who has never heard of this attack.

Deciding in advance which second number a person will call should be part of the setup too. If it is already settled who to reach on a suspicious call, there is nothing to work out in the moment.

The moment you use it

Agreeing on a word is not enough; the hard part is remembering it at the time. A person in a panic tends to skip the verification step, and the fraudster is playing for exactly that.

So asking for the word should be set up as a standard step, not a discourtesy. Once the family has said "we ask on every call about money", asking becomes an ordinary procedure nobody takes offence at.

  • Ask for the word as soon as the call starts, not at the end of the conversation.
  • If the other side says "there is no time for that now", that sentence is already the answer.
  • Do not say the word yourself; ask the other side to say it.
  • Do not react to a wrong answer; end the call calmly.

The third item is the most common mistake. Asking "was our password such-and-such?" hands the answer to the fraudster as a gift.

If the word does not work

Rehearsing it once after agreeing the word also helps: one family member calls another and asks for the word, so the moment has been lived through once and hesitation drops in a real call.

The security word is not a system on its own but the first door. If the other side does not know the word or brushes past the subject, it is time for the second step.

The most effective second step is ending the call and reaching that person yourself on their previously saved number. Not calling back the incoming number, but dialling the one in your own contacts.

  • Write in the family group; the real person usually replies within minutes.
  • Ask a question only family would know, but do not rely on that alone.
  • Remember that personal details can be gathered online; the more specific the question, the better.
  • If the other side is trying to keep you from hanging up, that alone is a strong warning sign.

Seen locally

The quality of synthetic speech in languages beyond English has risen markedly in the past two years, and tools that reproduce an accent correctly are now common. The assumption that a call is real because it is in your own language no longer holds.

Against that, an established habit helps: in many families money is not discussed by phone at all; people meet instead. Turning that habit into a rule provides a defence even stronger than a security word.

There are also periods when such calls cluster: before holidays, during vacation seasons and in the months when travel abroad rises. An urgent request for money while a family member is travelling is where the scenario becomes easiest to believe.

Warnings from banks and institutions are increasing too, but most of them arrive after the fact. A single rule set inside a family works faster than an institutional warning.

The same problem at work

The same attack works in business, and the sums there are larger. A finance employee called in the chief executive's voice can receive an urgent transfer instruction.

The corporate equivalent is similar: voice approval should not be sufficient for payment instructions. Every transfer above a certain amount should be confirmed a second time through a separate channel by a predefined person.

How much voice is enough

A common question: how much recording does a fraudster need to imitate my voice? With today's tools that length has shortened markedly over the years and is now measured in seconds.

The practical consequence is that "I don't share my voice anyway" is not an adequate defence. A voice message, a livestream, a wedding video, even a brief phone call can serve as the source.

The conclusion is not to stop sharing audio, which is not realistic. The conclusion is to move verification somewhere other than the voice itself; that is the entire logic of the security word.

If you have been targeted

Once you realise you are the target, the order of actions is settled. Panic does the most damage at this stage, because the minutes lost turn directly into money.

  • Cut contact with the fraudster immediately; do not argue, do not try to stall.
  • If you have sent money, contact your bank without losing time.
  • Change passwords on any account that may have been compromised.
  • Turn on two-factor authentication on those accounts.

Contacting the bank comes first, because for some transfer types recall is only possible within a short window. A password change can wait; the money cannot.

Having the time of the call and the amount sent ready speeds up the call to the bank.

Reporting should not be skipped either. Notifying the police does not bring the loss back, but it lets calls from the same number be linked together, and that is where progress in these cases actually comes from.

What it does not solve

The security word is cheap and effective but does not solve everything. It is no help against calls from an unknown number claiming to be a bank or an institution; there is no shared password with them in the first place.

The scope of this method is narrow and clear: filtering out urgent money requests that arrive in a relative's voice. And the reason it works in that narrow space is not technical; it is that the one thing a fraudster cannot obtain is a family agreement that was never written down. A voice can be generated, a number can be spoofed, personal details can be collected; a word spoken within a family and written nowhere is not data that can be gathered.