The phone rings. You hear your grandson’s voice. He’s crying, the words tumbling out:
“Grandma, I had an accident, I smashed my phone, please don’t tell Mum and just send me some money, quick…”
The voice fits. The tone fits. The crying and the fear in it sound completely real. And it still might not be him.
This isn’t a scenario from a cybersecurity conference any more. It’s a scam that’s ringing real phones in 2026 — and it leans on the one thing that used to be rock solid for us: that we know the sound of our own child’s voice.
I run a repair shop and I work with IT and artificial intelligence, so I use AI every day and I know what it can do. And it can clone a voice better than you’d expect. This article is about one specific con — “a relative in trouble is calling” — and above all about how to defend against it. Spoiler: the best defence isn’t technology, it’s one secret word you agree on over dinner.
If you want a broader overview of the newer AI scams (the fake boss, deepfake video, AI phishing emails), I’ve got a separate roundup: AI scams in 2026. Here I go deep on just one of them.
How a stranger can speak in your child’s voice
The principle is simpler than you’d like to believe. An AI voice-cloning tool listens to a short recording of someone’s voice and from then on can “read” any text in that voice — including sentences the person never said.
How much recording is enough? According to the Czech outlet investigace.cz, which dug into the anatomy of these scams, 3 to 10 seconds of voice is enough to build a usable model. That’s less than a voicemail message takes.
And where does the scammer get the recording? They don’t have to break in anywhere. They take it from things we hand over publicly ourselves:
- a video on Instagram, TikTok or YouTube where you or your kids are talking,
- a story of a granddaughter wishing grandma a happy birthday,
- a voice message, a podcast, a recording of an online talk,
- anything with a few seconds of clean voice.
I’m not going to write a how-to on cloning a voice here — I’m leaving that out on purpose. What matters is that you understand why the voice on the phone “fits”: because it was built from a real recording of a real voice. It isn’t an actor doing an impression. It’s a model trained directly on your relative’s voice.
And spotting it by ear? That’s the unpleasant part. The Olomouc Region, which issued an official warning titled “deepfakes and AI scams using your grandson’s voice”, puts it plainly: don’t trust sound or video. The public broadcaster’s iROZHLAS, in its February 2026 fact-check, cites research showing that the success rate for catching a good deepfake fell below 30% even for trained people. In other words: counting on “I’d recognise my own child” simply isn’t enough today.
What the call usually looks like
The “relative in trouble” scenario has a surprisingly fixed skeleton. It isn’t random — it’s tuned to get to you before you have time to think.
- A crisis, and a voice you know. An accident, being held at a police station, a car crash, trouble abroad. And the voice of your grandson/daughter/son telling you about it.
- Urgency. “I have to sort this out right now, or else…” You mustn’t be given time to think it over.
- Secrecy. “Don’t tell Mum, she’ll be furious.” That cuts you off from the one person who’d see through the con.
- A second person on the line. Often the phone is “handed over” to a lawyer, a police officer or a doctor who confirms the situation and tells you where to send the money. It lends the whole thing weight.
- Specific instructions for the money. A bank transfer, cash via a courier, sometimes even a taxi that comes to pick you up.
The classic — still “pre-AI” — version of this con was described by iROZHLAS in a real case involving an elderly woman: just before Christmas a “grandson” called and asked for 330,000 Czech koruna (about €13,000). She thought it odd that his voice sounded different — and the scammer brushed it off by saying he had a cold. He even sent a taxi for her. She was saved only by the taxi driver, who didn’t buy it and rang her real son.
Notice that detail about the cold. Back then the scammer had to explain why the voice didn’t match. With an AI clone, he no longer has to. And that’s exactly why I’m writing about this now.
Why it works, even on smart people
This isn’t about being naïve. It’s about how the human brain works under pressure.
When you hear a crying child in danger, emotion switches off critical thinking. The body flips into “help right now” mode. In that moment you’re not weighing up account numbers or logic — you’re dealing with the fact that your child is in tears. The scammer knows this, and the whole script is built to keep you in that state and never give you the space to hang up and check.
That this isn’t some fringe problem, the numbers show:
- The US FBI, in its 2025 elder-fraud report, says people over 60 reported losses of $7.75 billion — up 59% year on year. For “emergency” scams using a cloned voice of a loved one specifically, reported losses topped $5 million for the year.
- For the first time ever, the FBI carved out a separate category for AI scams — over 22,000 cases and almost $893 million in losses. Seniors account for 43% of all losses from AI scams, even though they’re only in a fraction of the cases.
And in the Czech Republic? For now what dominates here is more scam texts and emails and “fake bankers” — but the trend is clear. The Czech Banking Association reports that in the first half of 2025 alone more than 44,000 people lost almost 886 million koruna, and the share of phone-based (vishing) attacks aimed at pensioners jumped 40% year on year. iROZHLAS and the experts agree: deepfake calls will keep cropping up more and more here. Better to get ready for them now than wait until the phone rings.
Defence number one: the family password
Here’s the good news. Against technology you can’t outsmart by ear, there’s a laughably simple defence — and you don’t need any app for it.
Agree on a secret family password (a safe word). One word or a short phrase that only you and your closest family know. When someone calls with a crisis and asks for money, you just ask: “What’s our password?” The real grandson says it. The scammer — even with a perfectly cloned voice — doesn’t know it.
The Olomouc Region recommends exactly this as one of its five main rules, and even gives an example: it could be the name of your first family cat or dog. A few ground rules so the password actually works:
- It mustn’t be googleable or readable off social media. No child’s name, no birth date, no town. Ideally something with no obvious connection (“watermelon”, “boiler room”).
- Everyone who might call in an emergency has to know it — grandchildren, children, parents. Go over it at a family dinner so everyone remembers it.
- Don’t send it by text or messenger. Say it in person. A password sitting in a chat isn’t a password.
- Don’t use it anywhere else — it’s not your banking password, it’s only for verifying calls within the family.
If you have older relatives, this is the most valuable thing you can do for them. It’s not about scaring them. It’s about giving them a simple tool to win back a few seconds of certainty in a panic.
By the way, technology is starting to help too. Google has just launched fake-call detection in its Phone app in June 2026: when a contact calls and you both use Google’s Phone app, the phones quietly verify in the background that the call really is leaving that contact’s device — and warn you if it isn’t. And the Czech operator O2 has rolled out an AI “granny Alenka”, which ties scammers up on a call so they don’t have time to bother real people (between them, operators block hundreds of thousands of scam calls a day). Nice helpers. But the family password works on every phone, and right now.
When a call like this comes in
Have a simple plan ready. It reads better in calm than in a panic:
- Take a breath and slow down. No real accident is solved by sending money within five minutes. Urgency is the scammer’s tool, not a sign of a genuine crisis.
- Ask for the family password. Or for something only your relative knows and that can’t be looked up: “What was our dog called?”, “Where did we go on holiday last year?” An AI voice falls flat on a specific memory.
- Hang up and call back on a number you have saved in your phone — not the one that just called you (that can be spoofed). If the call was genuine, nobody will be offended.
- Don’t send money or take it anywhere. No lawyer or police officer wants cash via a courier over the phone. The Czech cyber-security agency NÚKIB and the central bank ČNB say it again and again: no trustworthy institution asks you to transfer money over the phone and in a hurry.
- Don’t let yourself be cut off. “Don’t tell anyone” is a red flag. Do the opposite — call someone else in the family and check it.
When it’s already happened
It happens even to careful people. If you’ve already sent the money, don’t wait around — speed decides:
- Call your bank immediately. Ask them to block or stop the payment. The Czech National Bank advises contacting the bank as soon as possible — a fresh transaction, especially within the country, can sometimes be stopped or clawed back by the bank.
- Report it to the police — the line is 158 (or 112, the EU-wide emergency number). Even when it looks hopeless, a report helps the investigation and protects other people. The Czech Police has experienced people for scams targeting seniors.
- Write down what happened — the number that called, the time, exactly what was said, where the money went. The bank and the police will both need it.
- Warn the family. Scammers come back to “successful” numbers. Make sure everyone else is on guard.
No shame in it. These cons are engineered precisely to get even smart, careful people. What matters is acting fast and not facing it alone.
In short
- AI can now clone a voice from a few seconds of publicly available recording. The voice “fits” because it was built from a real voice — you can’t reliably tell by ear.
- The “a relative in trouble is calling” scenario runs on emotion, urgency and secrecy. Know them in advance and half the magic disappears.
- Agree on a secret family password. It’s the simplest and most effective defence — it works even against a perfect clone.
- When the call comes: slow down, verify with the password, hang up and call back on a saved number. No money in a hurry.
- When it’s already happened: bank first, then police (158/112). Speed decides.
For a broader overview of the other AI scams (the fake boss, the deepfake video call, AI phishing) see AI scams in 2026. And if something feels off — whether it’s a call, an email, or how your computer is behaving after clicking a dodgy link — get in touch. I’ll advise you over the phone at no charge, and often five minutes is all it takes to work out whether it’s a scam. Better to ask for nothing than to lose money.
Call +420 774 777 774 (Mon–Fri 10:00–16:00) or write to info@servispc-brno.cz. If money is going out right now or you’re dealing with the fresh aftermath of a scam, there’s a 24/7 line at 775 556 063.