Sharon Brightwell, a retiree from Dover, Florida, answered her phone in July 2025 to the sound of her daughter sobbing. The voice on the line said she had been in a car accident, was in jail, and needed $15,000 in cash immediately. It sounded exactly like her daughter, April. The panic was real. Sharon withdrew the money and handed it to a courier who arrived at her home. April was at work the whole time. Her voice had been cloned from a few seconds of audio. A local news report on the incident was headlined “Dover woman loses $15K after scammers used artificial intelligence to impersonate daughter.”
That call is one of more than 22,000 AI-enabled fraud complaints logged by the FBI’s Internet Crime Complaint Center (IC3) in 2025, the first year the bureau broke out AI fraud as a distinct category in its 26-year history. The adjusted losses reached $893 million. The FBI published its annual report in April 2026, and the figure is best read as a floor, not a ceiling, because most victims never learn a machine was involved. The bureau’s press release was headlined “FBI: AI-Enabled Fraud Topped $893M in 2025—Real Toll Likely Far Higher.”
Total U.S. cybercrime losses in 2025 hit $20.9 billion, a 26% increase in a single year. For Americans aged 60 and older, the toll was $7.7 billion, a roughly 59% jump on the previous year. The FBI’s data on senior losses was headlined “FBI: Seniors lost $7.75B to cybercrime in 2025 — a 59% jump.” The IC3’s press release was headlined “Cryptocurrency and AI Scams Bilk Americans of Billions.” The real number is almost certainly higher. The FBI has long acknowledged that its data understates the problem.
The emotional mechanism the scam exploits is love for a grandchild, weaponised. Liz Benz, a mother from Buffalo, endured what she described as “a good twenty minutes of terror” when a cloned voice told her her son had been taken hostage. Gary Schildhorn, a Philadelphia attorney, said of the call he received: “I will go to my grave swearing that it was your voice.”
The Weapon: Three Seconds of Audio and the Race That Was Lost
AI voice cloning requires as little as three seconds of audio to produce a synthetic voice indistinguishable from the original. The raw material is often volunteered publicly: voicemail greetings, podcasts, social media videos. A grandchild’s TikTok clip is enough. The attacker does not need a studio recording. They need a snippet of a child saying “Hi Grandma” or a voicemail that says “I’ll call you back.” That is all it takes to build a digital mask.
Consumer Reports assessed the voice-cloning products of six companies in March 2025: Descript, ElevenLabs, Lovo, PlayHT, Resemble AI, and Speechify. The findings were stark. Four of the six required only a checkbox to affirm the legal right to clone a voice. No technical mechanism confirmed consent. Four of the six required only a name or email to open an account. The headline of the Consumer Reports investigation was “Consumer Reports’ Assessment of AI Voice Cloning Products.” NBC News and The Register amplified the findings under headlines like “Consumer Reports calls out poor AI voice-cloning safeguards” and “AI can steal your voice, and there’s not much you can do about it.”
ElevenLabs stood apart. The company has a multi-layered safety program: a prohibited-use policy, an AI speech classifier, traceability features, and “no-go voices” safeguards. But most safeguards operate after the fact. They help establish provenance after fraud has already occurred. The speech classifier can flag suspicious audio, but it does not stop the call from being made. The traceability features can help law enforcement identify the source of a cloned voice, but by then the money is gone. The no-go voices list blocks cloning of public figures, but it does not protect a grandmother in Florida.
Amit Gupta of the voice-security firm Pindrop explained the attacker’s logic: “The objective is not perfect voice replication. The objective is creating enough emotional uncertainty and urgency that the victim acts before verifying.” The attacker does not need to fool a forensic analyst. They need to fool a panicked parent. The threshold is low. A voice that sounds 80% like a loved one, delivered in a moment of crisis, is enough to bypass rational thought.
Hany Farid is the world’s foremost authority on deepfake forensics, a professor at the University of California, Berkeley. In June 2026, the New York Times profiled him under the headline “In the Age of A.I., the World’s Leading Deepfake Expert No Longer Trusts His Own Eyes.” Farid admitted he can no longer reliably distinguish real audio from AI-generated. “I feel like I’m going blind,” he said.
If the world’s leading expert cannot tell the difference, the average person has no chance. Detection-based defences are failing. The race has been lost in the audio domain. Any plan that ultimately rests on the target being able to tell the difference between a real voice and a cloned one is already obsolete. The technology has advanced to the point where the human ear is no longer a reliable instrument of verification.
The vulnerability is located in the human auditory system itself, which evolved to treat a recognised voice as proof of a recognised person. The attacker does not need to be perfect. They only need to be good enough to trigger the emotional reflex that bypasses rational verification. The brain does not stop to analyse the audio quality. It hears a familiar voice and responds with love, fear, and a desperate need to help.
Brian Long, CEO of Adaptive Security, described the asymmetry of the threat: “One guy in a room with a keyboard can make an infinite number of attackers.” The economics of the crime are brutal. The attacker invests a few seconds of compute time and a few dollars in phone credits. The victim loses their life savings. The attacker can try again a thousand times a day. The defender has to be right every single time.
The Scale of the Problem: $442 Billion Worldwide and an Industrialised Crime Machine
INTERPOL published the second edition of its Global Financial Fraud Threat Assessment in March 2026. The report described the “industrialisation of fraud”: a migration from opportunistic individuals to organised transnational operations that intersect with human trafficking and cybercrime. Worldwide losses to financial fraud in 2025 were estimated at $442 billion, a figure comparable to the entire annual economic output of Denmark. Help Net Security and ICLG reported on the findings under the headline “INTERPOL report warns of increasingly sophisticated global financial fraud threat.”
The report detailed how criminal networks now operate like legitimate businesses. They have dedicated departments for technology development, customer service, and money laundering. They recruit software engineers to build custom AI tools. They run call centres in countries where enforcement is weak. They use encrypted messaging apps to coordinate across borders. The days of the lone hacker in a basement are over. Fraud is now an industry.
AI-enhanced fraud is roughly 4.5 times more profitable than its traditional equivalent, per INTERPOL. Agentic AI systems can now autonomously plan and execute entire fraud campaigns, from reconnaissance to ransom demand. An AI agent can scrape social media for personal information, generate a cloned voice, craft a convincing script, and place the call, all without human intervention. The defensive gap is measured in years because attack is a technology problem and defence is an institutional one. The attacker can deploy a new technique in days. The bank needs months to update its fraud detection models. The regulator needs years to write new rules.
For older adults, the numbers are devastating. The Federal Trade Commission published a report to Congress in December 2025 titled “Protecting Older Consumers 2024–2025: A Report of the Federal Trade Commission.” Total fraud losses reported by people aged 60 and older roughly quadrupled between 2020 and 2024, reaching about $2.4 billion. Of that sum, 68% was attributable to individual losses of $100,000 or more. The FTC’s own estimate of the true annual cost for older adults, accounting for underreporting, ranged as high as $81.5 billion. The median reported loss for older adults exceeds $1,600.
The FBI IC3 report for 2025 showed AI-enabled fraud losses for victims aged 60 and older at $352 million. Older adults are the single most heavily targeted demographic in AI-enabled financial crime. The AFP wire story in June 2026, carried by The Straits Times and the Manila Times under the headline “‘20 minutes of terror’: AI boosts US voice impersonation scams,” noted that shame is a major factor: many victims stay anonymous due to humiliation. They do not report the crime because they feel stupid for falling for it. They do not tell their families because they are embarrassed. The FBI’s own analysis concluded that “older adults remain disproportionately vulnerable to AI-enhanced scams.”
The shame is a feature of the scam, not a bug. The attacker deliberately exploits the victim’s fear of being judged. The victim is told not to tell anyone. The victim is told the police will not believe them. The victim is told they will be blamed. And they are right. The victim is often blamed. The question “How could you be so stupid?” is the most common response from friends and family. That question is the attacker’s greatest ally.
The scale of underreporting is enormous. The FTC estimates that only about 5% of fraud victims report their losses. The FBI’s IC3 data captures only a fraction of the total. The $893 million figure for AI-enabled fraud is almost certainly a small fraction of the real number. The true toll is likely in the tens of billions. The victims are not just numbers. They are retirees who lose their pensions. They are parents who lose their savings. They are grandparents who lose their dignity.
Why the Safe Word Fails and the Burden That Should Not Be Yours
The most widely circulated advice from the FBI, the American Bankers Association, and consumer advocates throughout 2026 was to use a family “safe word.” The idea is simple: agree on a secret word that only family members know, and if someone calls claiming to be a relative in distress, ask for the word.
The advice places the entire burden on the victim. It assumes they will recall and execute a protocol under maximum stress, when their brain is flooded with adrenaline and the voice on the line sounds exactly like their grandchild. A defence that works only when the target performs flawlessly under maximum stress is not a defence. It is a way of allocating blame to the victim after the fact.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
The grandmother in her kitchen does not operate at the chokepoints where fraud could be interdicted at scale. The banks, the telecoms, and the platforms do. The article argues that awareness campaigns and family safe words are the last and weakest line, useful only as a backstop to structural defences. They are the equivalent of telling people to lock their doors after the burglar has already broken in.
The safe word advice also ignores the sophistication of the attacker. The attacker knows about safe words. They have scripts for handling the safe word question. They tell the victim that the safe word is not important right now because the victim is in danger. They create a false choice: verify the safe word or save the loved one. The victim chooses to save the loved one. The safe word is never asked.
Yixin Zou led a study published in early 2026 on fraud interventions for older adults. The team developed a simulation tool called ROLESafe. The paper was titled “Experiencer, Helper, or Observer: Online Fraud Intervention for Older Adults Through Role-based Simulation.” The research found that older adults who participated in role-based simulations were better prepared to recognise scam tactics, but the study also underscored that the burden of education should not rest solely on the potential victim. The simulations helped, but they were not a substitute for systemic protections.
Charm Security, a security firm, proposed the Human Vulnerabilities and Exploits Framework (HVE) in an arXiv paper published in June 2026. The framework treats human vulnerabilities as something to be catalogued and managed, not blamed. It draws an analogy to software vulnerabilities: you do not tell a user to stop clicking links; you patch the system. The HVE framework catalogues specific psychological triggers that attackers exploit: urgency, authority, emotional attachment, social proof. It then maps those triggers to specific technical and procedural countermeasures.
The article argues that human vulnerability should be treated as something to be managed, not blamed, using systematic cataloguing like the HVE framework. The burden of interdiction should be placed on institutions: banks, telecoms, and platforms. The article concludes that closing the gap requires deciding, as a matter of law and engineering, that institutions are responsible for what passes through their hands.
The current system is inverted. The victim bears the entire risk. The bank processes the transaction without question. The telecom carries the call without verification. The platform hosts the cloned voice without consent. The victim is left to figure it out alone. That is not a system. It is a trap.
The Regulatory Landscape: FCC Rules, UK Liability, and the Tools That Come Too Late
The Federal Communications Commission declared AI-generated voices in robocalls illegal under the Telephone Consumer Protection Act in February 2024. But that ruling governs mass automated dialling, not one-to-one emergency calls. The STIR/SHAKEN framework authenticates caller ID, not the human or the voice. Criminals evade it by routing through non-IP networks. The FCC’s Wireline Competition Bureau published a triennial efficacy report on STIR/SHAKEN in December 2025 under the title “Combating Spoofed Robocalls with Caller ID Authentication (STIR/SHAKEN).” The commission spent much of 2025 and 2026 trying to close the non-IP network loophole and pushing towards Rich Call Data.
The problem with STIR/SHAKEN is that it verifies the phone number, not the person. A cloned voice call can come from a verified number. The number belongs to the victim’s daughter. The call is technically legitimate. The system does not check who is speaking. It only checks where the call came from. That is like checking the return address on a letter but not reading the contents.
The C2PA standard, ratified as an ISO specification in 2025, attaches cryptographic provenance to media. Google’s SynthID and Meta’s AudioSeal are watermarking schemes that work alongside it. A 2026 analysis of these tools was headlined “C2PA Deepfake Detection 2026: AI Image Watermarks & SynthID.” But provenance has a fatal asymmetry: missing credentials are not proof of fakery, and metadata is often stripped. More critically, provenance does little to stop live cloned-voice calls because the analogue gap destroys digital watermarks. The article notes that the FCC’s TCPA ruling was in February 2024, and the C2PA standard was ratified in 2025.
The analogue gap is the killer. A cloned voice call travels through the phone network as an analogue signal. The digital watermark is lost in the conversion. The provenance metadata is stripped. The call arrives as pure audio with no trace of its origin. The forensic tools that work on digital files do not work on phone calls. The attacker exploits this gap deliberately.
The UK has taken a different approach. The Payment Systems Regulator made reimbursement for authorised push payment fraud mandatory in October 2024. Liability is split 50-50 between the sending and receiving banks, up to £85,000, within five business days. The consumer negligence exception is explicitly barred for vulnerable customers. The PSR’s consolidated policy statement on APP scams reimbursement was published in May 2025 under the title “PS25/5 Consolidated policy statement: APP scams reimbursement requirement.”
The results are striking. The PSR dashboard showed that 89% of money lost to APP scams, £243 million, was reimbursed in the 15 months to December 2025, compared to 65% before the rules took effect. The article argues that the UK reimbursement regime demonstrates the mechanism: when banks own the loss, banks build the friction. Confirmation of Payee, an account-name-checking service, now runs on billions of transactions in the UK.
The UK model is not perfect. Critics point out that reimbursement alone can create moral hazard. If the bank always pays back the victim, the victim has less incentive to be careful. But the evidence suggests otherwise. The reimbursement rate went up, but the total fraud losses also went up. The banks are now investing heavily in prevention because they are tired of paying the bill. They are building real-time fraud detection systems. They are training staff to spot scam indicators. They are delaying high-risk transactions for manual review.
Critics warn that reimbursement alone risks becoming a subsidy to fraudsters if not paired with prevention. Electronic Payments International published an analysis under the headline “Why the UK’s scam strategy must move beyond reimbursement.” The article argues that liability is the lever that forces prevention, not a substitute for it. The UK is now moving to the next phase: mandatory prevention measures, including confirmation of payee for all transactions and real-time fraud alerts.
The EU AI Act obligations for general-purpose models began applying through 2025 and 2026. Tennessee’s ELVIS Act requires written consent to clone a voice. These are early steps. The article argues that regulating the supply of the weapon, voice-cloning tools, is necessary, with mandatory verifiable consent. The ELVIS Act is a start, but it only applies in Tennessee. The EU AI Act covers a larger market, but enforcement is still being built. The global nature of the crime means that regulation must be global to be effective.
The Path Forward: Institutions Must Own the Loss
The article argues that detection cannot be the primary line of defence. Generation has outrun discrimination. The industry built a tool capable of impersonating anyone and placed it behind a self-attestation checkbox. That must change. The checkbox is not a safeguard. It is a fig leaf. The companies that build voice-cloning tools must implement mandatory verifiable consent. The user must prove they have the right to clone a voice before the tool works. That means government-issued ID verification, biometric matching, or a notarised consent form. Anything less is negligence.
Regulation of voice-cloning tools is technically feasible. Mandatory verifiable consent, as partially implemented by Descript and Resemble AI, should be the standard, not the exception. The article argues that liability regimes, like the UK’s, force banks to build friction and intervention protocols. The burden of interdiction should be placed on institutions. The bank should not process a $15,000 withdrawal from a retiree who has never made such a withdrawal before without a human check. The telecom should not route a call from a cloned voice without a warning. The platform should not host a voice-cloning tool that can be used without consent.
The article argues that human vulnerabilities should be catalogued and managed, not blamed. The HVE framework is a start. The article concludes that closing the gap requires law, engineering, and institutional responsibility. The law must define liability clearly. The engineering must build friction into the system. The institutions must accept that they are the gatekeepers.
The grandmother in her kitchen cannot be expected to outwit a machine that sounds exactly like her granddaughter. The system must protect her. The article, published on smarterarticles.co.uk by Tim Green, a UK-based systems theorist and independent technology writer, argues that the asymmetry between attack speed and defence speed is the core problem. Closing the gap will come from deciding, as a matter of law and engineering, that institutions are responsible for what passes through their hands.
The solution is not a better safe word. The solution is a system that does not require the victim to be a security expert. The solution is a system that interdicts the fraud before the victim ever hears the call. The solution is a system that holds the institutions accountable for the damage they enable.
Sharon Brightwell lost $15,000. She is one of thousands. The FBI’s $893 million figure is a floor. The real toll is measured in shattered trust, emptied bank accounts, and the quiet humiliation of people who believed they were helping a loved one. The question is whether the institutions that enabled this crime will be the ones to stop it.

