You're Probably Setting Up Your Safe Word Wrong
Most families that already have a family safe word are still exposed. Plus some simple phone settings that reduce your AI scam call volume.
Marilyn Crawford was asleep when the phone rang. A man said he was with the police. Then another voice came on the line, posing as her grandson Ian, who claimed he’d been arrested for stealing a car and needed $9,000 to get out of jail.
She believed it enough to get in a taxi the “police” had sent for her. She then went to her bank in Ontario to wire the money. Fortunately for Marilyn, an alert bank employee stopped the transaction and called her son. Crawford and her family now suspect the voice on the phone was an AI clone of Ian. The scammers had likely reconstructed his voice from audio of Ian’s real voice that the fraudsters pulled off the internet (CBC News).
Most of you are probably thinking the answer to this problem is to implement a family safe word. Some of you may already have one in place because it’s become the standard advice everywhere from local news to the FBI’s own tips page.
Safe words are important. The problem is creating a safe word is only part of the solution. Without a proper system in place, relying solely on a single safe word could even make things worse (I’ll explain later).
In this post I’ll walk you through:
how these scams work (feel free to skip if you already know)
why relying on the law to save you is a losing bet
how to properly prepare your elderly relative for a scam like this (creating a safe word isn’t enough)
Bonus: show you some phone and carrier settings that can drastically cut the number of scam calls you and your relative receive.
How the Scam Call Actually Works
The first step is, no surprise, the scammer need a sample of your relative’s voice. Retired CIA officer and certified fraud examiner Peter Warmka, who’s studied these scams, says three to five seconds is enough. Common sources include a birthday video, a voicemail greeting, a podcast clip, or a public TikTok (CBC News). McAfee’s research team tested this directly and were able to produce a clone with an 85% voice match using just three seconds of audio. They were able to improve that to 95% with a bit more training data, using simple, readily available software (McAfee).
Next, the scammer builds a script centered around fear. They’ll claim there’s been a car accident, or an arrest or a robbery. Chuck Herrin, a security executive at F5, put it plainly to CBS News (CBS News):
The calls are designed to hack the limbic system, because when people get scared they get worse at judgment, not better.
Then comes the ask, and it’s almost always for money that’s hard to trace or claw back. Gift cards are common. Sometimes wire transfers are preferred. Cash handed to a courier or a taxi is ideal from a scammer’s POV. Each scammer has their preference and also looks to change things up to confuse law enforcement.
Fourth, and this is the part that makes the whole thing work, the scammer creates time pressure. They insist you can’t tell anyone and implore you not to hang up. And everything must be done immediately.
A family with no plan in place has to improvise their way through a crisis with a clock running, using a voice that sounds like their loved one. That’s a losing battle for most and a recipe for financial loss.
The Numbers Behind the Rise in AI Scams
To help put the AI scam trend line into perspective, here are some stats from the U.S. government.
The FTC says imposter scams were the single most reported fraud category in 2025, with people losing $3.5 billion, nearly triple what was reported in 2020 (FTC). A separate FTC data spotlight found something more specific and, frankly, more alarming. Reports from older adults who lost $10,000 or more to impersonation scams have more than quadrupled since 2020. The subset who lost over $100,000 saw their combined reported losses jump eight-fold, from $55 million in 2020 to $445 million in 2024 (FTC).
The FBI’s 2025 Internet Crime Report gives the AI-specific breakdown for the first time in its 25-year history. It logged 22,364 AI-related complaints costing Americans nearly $893 million, with voice clones and fake videos of loved ones named specifically as tactics. Older adults accounted for $352 million of that, according to AARP’s reporting on the same FBI data (FBI; AARP). Adults 60 and older reported $7.7 billion in total fraud losses last year, up 37% from 2024, per the FBI’s own numbers.
And all of that is almost certainly an undercount. Fraud against older adults is chronically underreported, which means the real total is higher than what any agency can put a number on.
Don’t Wait on the Law to Fix This
Banks do sometimes catch these cases before payment is made. Crawford’s case above is proof of that. But that’s a person noticing something felt off, not a system built to catch this specific scam.
A wire transfer your mother authorizes herself, at her own branch or through her own login, looks like a perfectly normal transaction to the human or software actually monitoring the transactions. Banks aren’t failing some obvious test by missing most of these. There’s nothing technically fraudulent about the transaction from their POV.
And the real problem isn’t that no law applies here. Wire fraud and mail fraud statutes are old and broad enough to cover a scam call whether it runs on a script or a cloned voice. The location of the scammers is usually what impedes law enforcement.
For example, the U.S. Justice Department extradited a string of grandparent scam operators out of the Dominican Republic in 2024 (DOJ). Scammers operating out of developing countries have become such a problem that the U.S. DOJ, Treasury, and Secret Service stood up a dedicated Scam Center Strike Force in late 2025 to pursue the industrial-scale scam compounds spread across Southeast Asia. So far, they’ve seized or restrained more than $700 million in cryptocurrency in their first several months alone (DOJ).
And this isn’t a scattered handful of isolated con artists. It’s organized, transnational, and based almost entirely in countries where U.S. and other Western law enforcement has limited reach. The Dominican Republic case alone took roughly two years between the scheme running and defendants standing in a U.S. courtroom.
The law can reach these people eventually. In reality, “eventually” is measured in years, and it does nothing in the near term for the family that got scammed. Tactics also change faster than laws do. Voice cloning barely existed as a consumer threat five years ago, and the legal system is still catching up to it the way it’s still catching up to everything else AI touches.
Recovery after a scam depends almost entirely on what the money moved as, and on how fast someone reports it. The FBI’s Recovery Asset Team can sometimes freeze a wire transfer through what it calls the Financial Fraud Kill Chain. In 2025, it froze $679 million across roughly 3,900 incidents, a 58% success rate, according to the FBI’s own 2025 Internet Crime Report. That’s a legit legal tool, but it depends on reporting fast, generally within about 72 hours, and it only applies to wire transfers. Cash handed to a courier, a gift card read over the phone, or cryptocurrency sent to a wallet is effectively gone the moment it changes hands. There’s no kill switch for any of those, which is exactly why scammers ask for them.
Building a Reliable Response to AI Pressure Scams
Safe words are nothing new. Banks and alarm companies have used a variation for decades. Done right, a safe word will work effectively against voice clone scams. Done wrong though, which is how most families do it, it barely helps at all.
Start with the safe word phrase itself.
Security experts at Keeper Security recommend at least four words, chosen specifically because nobody could ever look them up (CBS News). So right off the bat, most people are using this tactic incorrectly by using a single word. The key is to use a phrase.
When doing that, you want to skip anything connected to your life that already exists somewhere online or in public records. That means never use street names, school names, pet names and birthdays. Two unrelated, slightly ridiculous words strung together work better than anything meaningful. “Soggy trombone” is harder for a stranger to guess than “Fluffy 1962,” and it’s also harder for a scammer running multiple scams a day to reverse-engineer.
Ideally you want to establish the safe phrase in person, or at least on a phone call you initiated to a number you already trust. Don’t text the safe phrase (even via Signal), never email it and don’t save it somewhere like in a cloud document or note app. The whole point is that the safe phrase never touches the internet because as soon as you do that, you’ve provided material for a scammer to start building their voice clone scam.
This rule seems simple, but it surprisingly gets overlooked:
The phrase only does its job if the other person says it first.
Eva Velasquez, CEO of the Identity Theft Resource Center, sees this mistake constantly. A family sets up a safe word, and then in the panic of an actual emergency call, the intended victim blurts it out themselves trying to be helpful or trying to speed things along. A scammer who hears “wait, is this about our safe word, it’s soggy trombone” now owns your safe word. The rule has to run one direction only. Whoever is asking for money says the phrase unprompted, or the call gets treated as fraud, no exceptions.
Coaching an elderly relative on this works best when you treat it like teaching a new safety habit. Frame it as a modern version of something they already understand. A similar situation is how a bank or credit card company confirms identity with a security question before letting anyone touch an account. Practice it out loud more than once. You’ll want to write the phrase down somewhere private, like a wallet or drawer that only you and your relative can access. Make sure it can’t be accessible by a home health aide or house cleaner.
Ask your relative directly: if someone calls saying I’m in trouble and needs money right now, what’s the first thing you do? Let them get the answer wrong a few times at the kitchen table, where it costs nothing, rather than finding out during an actual call.
Nothing ruins preparation and memory faster than panic. To address that very real risk, provide a pre-approved script for your relative. It doesn’t have to be complicated. Something short enough to get out under stress: “I need to call you back on the number I already have for you.” Then an actual hang-up, not “let me think,” not “hold on.” Your relative should be trained to call the person back using a number saved from before, never a callback number the caller supplies. If the emergency is real, whoever’s supposedly in trouble will still be reachable, and so will someone else in the family who can help verify it in the meantime.
This one may be hard for elderly relatives to understand, but caller ID is not infallible. It can be spoofed to display a name that looks completely legitimate. A lot of non-tech savvy adults still treat the caller ID display as proof the caller is who they say they are. It isn’t, and knowing that ahead of time takes away one of the scammer’s easiest tricks.
Last, make gift cards, wire transfers, cryptocurrency, and cash handed to a courier an automatic no, regardless of who’s asking or how urgent it sounds. Those four payment methods are what scammers reach for precisely because they’re nearly impossible to trace or reverse. No real emergency, bail situation, medical bill, or legal fee requires payment through any of them, which means a request in one of these forms is, by itself, your answer.
Why This Actually Works Against AI Scams
The reason a safe phrase beats even a flawless voice clone is that it doesn’t rely on the voice being fake or real. It relies on information the scammer physically cannot have.
AI can replicate the sound of your son's voice down to his cadence and his laugh, using nothing more than a clip pulled from social media. What it cannot do is reach into a private conversation that happened offline between two people who trust each other, because there's nothing there to scrape, train on, or leak in the first place. The scam depends entirely on emotional pressure filling the gap where verification should be. When used properly, a safe phrase is a killshot for AI scams.
Where This Goes Next
Voice cloning used by a live person is the current threat du jour. It won’t stay that way for long. Real-time conversational AI is already good enough that a scammer doesn’t need a pre-written script anymore. Instead, they can respond live to whatever question you ask, in the cloned voice, without missing a beat. Video is catching up too. The tells that used to give these scams away are disappearing.
None of that changes the fixes I’m proposing. A safe phrase doesn’t care whether the fake on the other end of the line is audio, video, or eventually something we don’t have a name for yet. It’s a low-tech answer to a high-tech problem, and that’s precisely why it will keep working as AI scams evolve.
Looking for help with a privacy issue or privacy concern? Chances are we’ve covered it already or will soon. Follow us on X and LinkedIn for updates on this topic and other internet privacy related topics.
Disclaimer: None of the above is to be deemed legal advice of any kind. These are *opinions* written by a privacy and tech attorney with years of working for, with and against Big Tech and Big Data. And this post is for informational purposes only and is not intended for use in furtherance of any unlawful activity. This post may also contain affiliate links, which means that at no additional cost to you, we earn a commission if you click through and make a purchase.

Want a quick privacy win? Discover the benefits of changing your DNS settings. It’s one of the quickest and highest privacy ROI moves you can make:
Know your doxxing risk. DoxxScore gives you a personalized exposure assessment and action plan in under 5 minutes. Get Your Risk Score →
If you’re reading this but haven’t yet signed up, join for free (5,400+ subscribers strong) and get our newsletter delivered to your inbox by subscribing here 👇




