Consumer advice about AI voice cloning and deepfakes is built almost entirely on detection: listen for the tell, look for the glitch. The two agencies that issue the real warnings do not give that advice. The FTC says to distrust the voice and call the person back on a number you already know. FBI Boston, on 19 August 2026, says to hang up and verify on a number you found yourself, because the pause is what shuts the scam down. The reason detection is the wrong tool is structural. A clone only has to survive the length of one conversation, every check you run inside that conversation runs on the caller's clock, and the fake can supply its own corroboration. The control that works is not a better check. It is a delay, on a channel you chose.
On 19 August 2026 the Boston Division of the FBI published a warning about a scam that is worth reading closely, not because the story is exotic but because of the order the steps come in.
It opens with a call from someone posing as a representative of a financial institution, who tells the victim their details were used to open an account to buy illegal firearms. The victim is transferred to a person claiming to be an FBI special agent investigating that fraud. The victim is invited to verify the number, and at that point the call disconnects. Moments later the phone rings again, and the display shows FBI Boston's real main line, 857-386-2000. The caller supplies a name and a badge number. Then, the FBI says, the scammer may tell the victim to move the conversation to an encrypted messaging application, and that everything discussed is confidential and must not be shared with anyone.

Look at where the verification step sits
The victim in that sequence is not passive. They try to check. They are invited to verify the number, and the callback appears to come from the genuine FBI line. That is the entire trick, and it is why detection advice keeps failing: the check was performed inside the conversation the scammer was running, using information the scammer supplied.
This is the part almost every article on deepfakes gets wrong. Advice like ask a personal question, or listen for unnatural pauses, treats the call as a test you can pass with enough attention. But the test is being administered by the person you are testing. They chose the moment, they control the pacing, and they can answer anything you throw at them, including a callback that rings from the right number.
Even noticing does not save you
The strongest evidence that detection is the wrong battlefield comes from the case most often cited as a warning to look harder.
In February 2024, CNN reported that a finance worker at a multinational firm paid out about 25 million US dollars after joining a video call with what he believed were several colleagues. Hong Kong police told the public broadcaster RTHK that everyone he saw on that call was fake. In May 2024 the company identified itself: Arup, the British design and engineering firm behind the Sydney Opera House, which confirmed to CNN that "fake voices and images were used".
The detail usually cut from the retelling is the one that matters most. According to the police account CNN reported, the worker was suspicious. He took the original message for a phishing email, precisely because it demanded a secret transaction. Then he put those doubts aside after the video call, because the other people attending looked and sounded like colleagues he recognised.
Read the order of that again. His scepticism was correct. What dissolved it was the verification step. He joined a call to check whether the request was real, and the call was the attack. He paid across fifteen transfers, and was only certain something was wrong when he later checked with head office, on a channel the attackers did not control.
Arup's global chief information officer, Rob Greig, has since spoken publicly about what happened. The World Economic Forum's account of his lessons puts the point plainly: this was not the kind of cyberattack that compromises a company's systems, and Arup confirmed none of its internal systems were. The technology was the costume. The attack was social.
Now read the official advice again
Set the detection checklists aside and look at what the agencies actually say.
The FTC, writing about criminals using AI in family emergency scams, does not suggest you evaluate the voice. It says not to trust the voice at all, and to call the person who supposedly contacted you on a number you already know is theirs.
FBI Boston's warning ends with a quote from Ted E. Docks, the special agent in charge of that division. Scammers, he says, use fear, urgency and increasingly sophisticated tactics including spoofing trusted phone numbers, to push people into acting before they can think it through. His instruction is: stop, hang up, then verify the caller by contacting the organisation directly using a number you found yourself. And then the line that is worth more than every detection tip published this year: that pause can shut down a scam.
The reason this advice looks boring next to a list of deepfake tells is that it does not scale with the technology. A detection tip has a shelf life measured in model releases. A callback on a number you already had works identically against a clumsy 2023 clone and against something rendered perfectly next year, because it does not care how good the fake is. It removes the attacker's two real assets: control of the channel and control of the clock.
The inversion: a deepfake wearing the reporting channel
There is a reason to insist on the callback rather than clicking a link, and the FBI's Internet Crime Complaint Center documented it on 20 July 2026.
In a public service announcement updating an earlier alert, IC3 described criminals impersonating FBI personnel in order to revictimise people who had already lost money. One variant uses AI-generated videos of a senior FBI leader, posted on social media, encouraging people to file complaints on a spoofed IC3 website. The fake site mirrors the real one closely enough to pass a glance, but only the complaint form works. It asks for a name, phone number, email address, scam type and estimated loss, then returns a reference number and promises someone will be in touch.
Read what that actually is. It is a form that collects exactly the fields needed to identify a person with money already lost and a demonstrated willingness to engage, dressed as the government office you were told to report to. The deepfake here is not being used to impersonate your bank or your family. It is being used to impersonate the safe channel itself.
What this actually means for you
None of the following requires you to identify a fake. That is the point.
Got a call you are not sure about? Send it to us before you call back.
Paste the message, the number that called you, what they asked for. A real expert reviews every case and replies within 24 hours, and our consultation exists for exactly this moment: a calm second opinion before any money moves. Free case review, confidential, no pressure.
Common questions about AI voice scams and deepfakes
Can you actually hear the difference in an AI voice clone?
Sometimes, and it will not save you, because the fake does not have to beat your suspicion. It only has to answer it. In the best documented case of its kind, an employee of the British engineering firm Arup paid out about 25 million US dollars from its Hong Kong office. CNN reported that Hong Kong police described the worker as having grown suspicious of the initial message and having suspected a phishing email, because it demanded a secret transaction. He then put those early doubts aside after the video call, because the other people attending looked and sounded like colleagues he recognised. Every one of them was a deepfake. That is the part worth sitting with. His scepticism was correct, and the thing that dissolved it was the verification step itself. Looking harder would not have helped him, because looking is what the attackers had prepared for.
What do the FBI and the FTC actually tell you to do about cloned voices?
Neither of them tells you to listen for a tell. The FTC's guidance on AI in family emergency scams is to distrust the voice itself and to call the person back on a number you already know is theirs. FBI Boston's warning of 19 August 2026 says to hang up and then verify the caller by contacting the organisation directly on a number you found yourself, and Special Agent in Charge Ted E. Docks adds that the pause can shut down a scam. Both instructions have the same shape and neither depends on your ear. They move the conversation onto a channel the caller does not control, and they put time between the demand and the money.
How do I verify a caller if the number on my screen looks genuine?
Assume the number proves nothing, because spoofing it is trivial. FBI Boston documented scammers spoofing that division's own main line, 857-386-2000, so that a victim who tried to check the number saw it call back. Verification only counts when you begin it. End the call yourself, find the organisation's number on a source you already trust, such as the back of your bank card, a printed statement or the official website you navigated to independently, then call that number and ask. A genuine caller will not mind. A scammer will supply a reason you must not hang up, and that reason is the tell.
Why do these scams push you onto WhatsApp, Telegram or Signal?
Because an encrypted messaging app hands the whole conversation to the person who asked you to move there. It leaves the channel your bank or the agency can see, it drops the recording and the call logs, it removes anyone who might overhear, and it makes the contact feel private and privileged rather than suspicious. FBI Boston states plainly that the FBI will never ask you to communicate via an encrypted application, and its warning describes scammers doing exactly that, along with telling victims the matter is confidential and must not be discussed with anyone. Treat a request to change apps as the moment to stop, not as a step in a process.
A deepfake pretended to be a government agency. How is that even possible?
It is already happening, and the target is people who have been scammed once. In a public service announcement dated 20 July 2026, the FBI's Internet Crime Complaint Center described criminals impersonating FBI personnel to revictimise earlier victims, including AI-generated videos of a senior FBI leader urging people to file complaints on a spoofed IC3 website. That fake site copies the real one's look, accepts a single short form asking for name, phone number, email, scam type and estimated loss, then issues a reference number and promises contact. It is a data-collection funnel wearing the uniform of the place you were told to report to. If you need to report, type the address yourself rather than following any link you were sent.
What if I already spoke to one of these callers or sent money?
Move on the money first, because the fastest recoveries happen through the payment system within hours rather than through any later process. Call your bank and card issuer, say the transaction was fraud, and ask them to attempt a recall. If you installed anything the caller asked you to install, or shared login details, change those passwords from a different device and remove the software, or get someone to help you do it. Then report it: in the United States to the FBI at ic3.gov and the FTC at ReportFraud.ftc.gov, and elsewhere to your national agency. Do not let embarrassment delay any of that. Being targeted a second time is something the criminals engineer deliberately, not evidence of any failing on your part.
Sources & further reading
Claims in this piece are attributed to these sources. Click any of them to verify.