← All articles

Staying safe on the phone

Someone called sounding exactly like your grandchild

The advice to listen for a robotic voice is quietly going out of date. Here is a way to settle who is calling that doesn't depend on your ear — and the three ways a family code word fails in real life.

The 15-second answer: hang up and call the person back on the number already saved in your phone. If they don't pick up, call another family member. Send no money, gift cards or cash to anyone until you have reached the real person through a number you chose yourself.

Do that even if you were told to keep the call quiet. Especially then.

Your ear is no longer the test

Most guidance on these calls still tells you to listen for the tells: flat delivery, odd pauses, a slightly robotic edge. That advice was reasonable a couple of years ago. It is ageing badly, and it is worth being blunt about why.

Voice cloning tools are widely available and need only a short sample of someone speaking. That sample is not hard to find: a birthday video, a few seconds of a graduation clip, an outgoing voicemail greeting. The output has stopped sounding synthetic in the way people expect.

The problem with "listen for the robotic voice" isn't that it's wrong. It's that it teaches the wrong habit: running the test in your ear. A test that gets less reliable every few months is a bad thing to build a family rule on, and a caller sounding exactly right should not move your assessment at all.

The useful reframe: a cloned voice can reproduce how someone sounds. It cannot reproduce anything that was agreed privately, and it cannot answer the phone when you dial the real person's number. Every method below is built on those two facts rather than on how good the audio is.

The script is designed to stop you checking

These calls follow a recognisable shape, and it's more useful to know the shape than to know any particular story.

There is an emergency, and it is happening now: an arrest, a crash, a hospital, a border. There is a reason you can't hear the voice clearly or for long — they're hurt, they're crying, the police are taking the phone back. A second person often takes over: a lawyer, an officer, a bail agent, someone with an official manner who explains what needs to happen. And money has to move immediately, in a form that doesn't come back.

That last part has drifted over the years. Gift card numbers read out over the phone, cash paid into a cryptocurrency kiosk, and increasingly a courier who comes to the house to collect cash in person. The FBI's Internet Crime Complaint Center has publicly warned about scammers sending couriers to collect cash from victims at home. There is no such thing as a court-appointed courier, and no lawyer, court or police force collects money that way.

But the piece worth remembering is the instruction to keep it quiet. Don't tell your daughter. Don't tell his parents, he's ashamed. There's a gag order until the hearing. It arrives sounding like an awkward detail of the emergency, and it is doing the most important work in the whole call.

If a caller asks you not to tell another family member, the call is a scam. That is close to a rule without exceptions. Secrecy is requested for one reason: the fastest way to end the scam is to ring someone else and ask. A real emergency has never once been improved by you telling fewer people about it.

What actually settles it

The reliable checks are the ones where you pick the channel. There are two, and both are free.

1. Call back on a number you already have

End the call, then dial the person from your own contacts. Not a number the caller read out, not a number that showed on the screen, and not by pressing a key to be "put through". Caller ID displays whatever the calling system claims, so what appeared on your phone tells you nothing — the same reasoning applies when the call claims to be from a bank, which I've written about in more detail in how to check that a phone call is really from your bank.

If they don't answer, that is not evidence the story is true. It is a Tuesday afternoon and people don't pick up. Ring a second family member, message the family group, try a video call. Two independent attempts to reach someone beat any amount of listening to the voice you were given.

2. Ask for something that was agreed in advance

A code word settled between you beforehand is the one thing a cloned voice cannot produce, because it was never in any recording. It is the strongest thing you can set up in an evening, and it costs nothing.

There is a small irony here worth noting: the criminals already know this works. In the courier version of the scam, the caller gives the victim a password or a bank note serial number to check against the person who arrives, precisely because a shared secret settles identity in a way a voice cannot.

The three ways a code word actually fails

Almost every article on this subject stops at "agree a safe word". That's the right advice and it's incomplete, because in practice the word fails in three predictable ways. Deciding what you'll do about each is what turns it into a real defence.

It gets forgotten in the moment. Under real stress, people cannot retrieve a phrase they set six months ago and never used. This cuts both ways: your genuinely frightened grandchild may also blank on it. So the rule cannot be "no word, no help". The rule has to be: no word, no money over this call — then hang up and reach them another way. That keeps the door open for a real emergency while removing the thing the scam needs.

It gets spent. A code word said aloud on a call someone else overheard, or typed into a text thread, or shared to a group chat, has stopped being secret. Fixed words leak slowly. Agree that after it's been used out loud, you pick a new one at the next family gathering.

Someone can't hold it. If the person most likely to be targeted has memory difficulties, a phrase they must recall under pressure is not a defence for them. Invert it: the rule becomes procedural rather than mnemonic. Any call about money, I hang up and ring Sarah first. One name, one action, no recall required. Write it on a card by the phone.

Choosing a word: two unrelated concrete nouns work best. Nothing that has appeared on social media, no pet, no street you lived on, no school. Say it out loud a few times so it is genuinely retrievable, and agree it in person rather than over text.

Do this this week

This is a single conversation, and it is worth having before anyone needs it.

  1. Agree a code word in person with parents, grandparents, partner and adult children. Two unrelated words.
  2. Agree the rule out loud: no word means no money on that call, and we hang up and call back. Say explicitly that nobody will be offended by being asked.
  3. Name the scenario in advance: "If I ever ring you sounding panicked about money, ask me for the word." Naming it now is what makes it recognisable later.
  4. Add the secrecy rule: if any caller asks you not to tell the rest of the family, that is the moment you ring the rest of the family.
  5. Write the fallback on a card by the landline for anyone who would rather not rely on memory: hang up, ring [name] first.

If a call already got through

If money has already moved, speed matters most, and so does not being embarrassed: these calls are built by people who do this full time, and being taken in by one is not a character flaw. Call your bank straight away; gift cards can occasionally be frozen if you ring the issuer quickly with the numbers. Report it to the FBI's Internet Crime Complaint Center and to the FTC. Then tell the rest of the family what happened, because the same number often works down a list.

When you do need to send something sensitive

Confirming who you're talking to is one half. The other half is what happens next, because once someone is verified people tend to text the account number or email the document, and it sits in a thread indefinitely.

The principle holds whatever you use: send it through something that encrypts it and doesn't keep it afterwards. SimplyAuth does this, and so do the one-time link features in the major password managers. Any of them is better than a text message.

I'm Kevin — I build SimplyAuth, which does a rotating version of the code word: a fresh phrase generated for each conversation, shown on both people's screens at once, expiring after a minute, so there is nothing fixed to leak. It needs both people to have the app, so it fits the handful of people you exchange sensitive things with regularly, and is no use against a cold call from a stranger. For the call this article is about, the free methods above are the answer — use those.

More on how the verification works in the FAQ.