Also on CyberFence: compare CyberFence to other VPNs side-by-side · the free CyberFence security tools .

Older man with a worried expression holding a smartphone to his ear in a softly lit living room, representing the moment of receiving a suspicious phone call

For the first time in its 25-year history, the FBI's Internet Crime Complaint Center (IC3) gave artificial intelligence its own line item in this year's annual crime report. The number attached to it: 22,364 complaints and $893,346,472 in losses in 2025 alone — reported fraud that victims recognized as involving AI, out of an estimated $20.877 billion in total cyber-enabled crime losses for the year (FBI IC3 2025 Internet Crime Report).

The bureau's language is careful and worth repeating: this is what victims recognized and reported as AI-related. The real number is almost certainly higher, since most people who receive a call from a cloned voice have no way of knowing the voice wasn't real (SecureWorld). Voice cloning specifically shows up across several fraud categories in the report — business email compromise, romance and confidence scams, investment fraud, tech support scams, and government impersonation — because a convincing synthetic voice is now a tool available to any of them.

How the Scam Actually Works

The mechanics are simple, which is exactly why the technique has spread so fast. A scammer needs a few seconds of someone's real voice — often lifted from a social media video, a voicemail greeting, or a public interview — to generate a synthetic clone using widely available AI tools. From there, the attack plays out in one of a few recurring patterns documented in FBI and FTC data:

  • The family emergency call. A cloned voice, sounding exactly like a grandchild, spouse, or parent, calls or leaves a voicemail claiming to be in trouble — arrested, in a car accident, kidnapped — and needs money sent immediately, often by wire transfer or cryptocurrency. FBI data attributes over $5 million in 2025 losses specifically to this "family in trouble" voice-clone scenario, and researchers note that figure is a floor, not a ceiling, since many victims never realize the voice was synthetic (Axis Intelligence analysis of FBI IC3 data).
  • The executive payment authorization. A cloned voice impersonating a CEO or CFO calls or leaves a voice message authorizing an urgent wire transfer. This is the most financially damaging pattern in the data — AI-linked business email compromise carried the highest loss density of any category, averaging $224,123 per incident, more than 12 times the average loss in a family-emergency scam.
  • The investment pitch. Synthetic voices imitating executives, celebrities, or financial influencers appear in fake endorsement calls and "investment club" pitches. Investment fraud accounted for roughly 71% of all AI-linked losses in the FBI's 2025 data, driven partly by this pattern.
  • The support or government impersonation call. A synthetic voice posing as a bank fraud investigator, tech support agent, or government official builds urgency and trust before asking for payment or account access. Government-impersonation complaints alone jumped 87% year over year.

Why Older Adults Are Losing the Most

The FBI's age breakdown is stark. Americans 60 and older filed 14.1% of AI-related complaints in 2025 but absorbed 39.5% of the losses — an average of $112,153 per complaint, nearly three times the overall AI-fraud average. Across all fraud types, not just AI-related, people 60 and older reported $7.748 billion in losses in 2025, up 59% year over year (HIPAA Journal, citing the FBI report).

Part of the reason is straightforward: the family-emergency scam is built to exploit the instinct to help a grandchild or child in a crisis, and older adults are disproportionately targeted with it. But there's also a detection problem that affects everyone, not just older adults.

A scammer needs your personal details to make the call convincing. CyberFence's Breach Monitor tells you the moment your information shows up in a known data breach — before it ends up in a scammer's script.

See CyberFence Plans →

Why It's So Hard to Tell a Cloned Voice From a Real One

A peer-reviewed University of California, Berkeley study published in Scientific Reports tested 604 listeners against 220 cloned voices using a commercial voice-cloning service. The results explain why this scam works as well as it does: listeners correctly identified an AI-generated clip as AI only 60.8% of the time on scripted audio — barely better than a coin flip once you account for false positives — and struggled specifically to tell a real person's voice apart from that same person's clone, correctly matching them as "the same person" 83.3% of the time (in other words, the clone consistently fooled listeners into thinking it was genuine).

There was one meaningful exception. When the audio included spontaneous, unscripted answers to unexpected questions, detection accuracy rose to 76.7–83.3%. That single finding is the basis for the most effective consumer-level defense against this scam: a cloned voice reciting a script is convincing; a cloned voice trying to improvise a real-time answer to a question it wasn't prepared for is not.

What Actually Stops This — and What Doesn't

It's worth being precise here, the same way it's worth being precise about any security claim. A VPN's encryption doesn't detect or block a phone call — this isn't a network-interception attack, it's a social engineering attack delivered over the phone network. Being clear about that matters more than overselling a fix that doesn't apply.

What actually helps:

  • A pre-agreed family verification method. The FTC's standing guidance for a suspicious "emergency" call from a relative is simple: hang up, then call that person back directly using a number you already have saved — never a number the caller provides. Some families also set a private verification phrase to use in a real emergency.
  • Keep the caller talking off-script. Ask a specific, unexpected question the caller's script can't anticipate — not "is it really you," but something only the real person would know and would need to improvise an answer to. The Berkeley research shows this is exactly where cloned voices break down.
  • A callback to a known-good number for any payment request — personal or business. Never authorize a wire transfer, gift card purchase, or cryptocurrency payment based solely on a voice on the phone, no matter how familiar it sounds.
  • Breach Monitor coverage for your household. Scammers build convincing scripts using leaked personal details — your child's school, your employer, your travel dates. CyberFence's Breach Monitor alerts you when your information appears in a known breach, so you know what's already out there and can be more skeptical of calls that reference it.
  • Web Shield DNS blocking for the follow-up. Many voice-cloning scams push the victim toward a "verification" or "payment portal" link sent by text or email after the call. Web Shield blocks known malicious domains at the DNS level before that page ever loads.

The Regulatory Response So Far

Regulators have started to catch up. In February 2024, the FCC issued a unanimous ruling that AI-generated voices count as "artificial" under the Telephone Consumer Protection Act, making unconsented AI-voice robocalls explicitly illegal and giving state attorneys general a direct enforcement tool. The FTC's Impersonation Rule, in effect since 2024, has produced more than $70 million in consumer redress and a dozen enforcement actions, including cases against IRS and government-impersonation operations. Imposter scams overall cost consumers $3.5 billion in 2025 — the single most-reported fraud category in the country (FTC data via Axis Intelligence).

None of that regulatory activity stops a phone from ringing. The practical defense still sits with the person answering the call — and the small habits that make a convincing clone fall apart under a few seconds of unscripted conversation.

Protect what scammers use against you. CyberFence's Breach Monitor and Web Shield work together across every device your family uses — so you know when your data is exposed and your family's devices are protected from the phishing links that often follow these calls.

Protect Your Family →

The Bottom Line

Voice cloning turned a decades-old scam — the panicked call from a "relative in trouble" — into something dramatically more convincing, and the FBI's own numbers show it's already cost Americans hundreds of millions of dollars, with older adults absorbing a disproportionate share. The fix isn't a piece of software that detects a fake voice in real time; researchers haven't solved that problem yet either. It's a callback habit, a family verification phrase, and knowing what personal information about you is already sitting in a breached database somewhere, ready to make the next fake call sound just a little more convincing.

Want to go deeper? Read the CyberFence competitor comparison hub , our free privacy and security tools , or CyberFence plans and pricing .