Family Safe Word vs AI Voice Cloning Scams: Making It Work

Imagine your mother’s phone rings just after midnight. The voice on the line is yours. Your rhythm, your slightly-too-fast way of talking when you’re upset, even the little catch before you say her name. “Mum, I’ve been in an accident. My phone’s smashed, I’m borrowing one. I need you to send money for the tow and the deposit before they release the car.” She has heard that voice her whole life. Why would she doubt it?

That is the modern grandparent scam, upgraded. The US Federal Trade Commission warned about it back in 2023: a scammer needs only a short audio clip of your relative, easily lifted from a video posted online, plus a cheap voice-cloning tool, and the “family emergency” call suddenly sounds exactly like family. The FTC’s consumer alert puts it bluntly: don’t trust the voice.

Why the family safe word is genuinely good advice

The standard recommendation from police forces and the FTC is to agree on a family safe word: a word or phrase only your family knows, which a caller must produce before anyone sends money. As advice goes, it is sound. A voice clone reproduces sound, not knowledge. The scammer can make the voice cry, plead, and beg, but they cannot make it say a word they never learned. The safe word moves identity verification away from the one channel the attacker fully controls.

It also works with zero technology. A grandmother with a rotary phone can use it. That matters, because the people most targeted by these scams are often the least likely to install a security app.

So I’m not here to knock the advice. I’m here to tell you where it breaks, because after enough conversations about this while building Hongi, I’ve heard the same five failures come up again and again, and almost nobody writing “just pick a safe word!” articles mentions any of them.

Where the safe word breaks in practice

People forget it. A word chosen once, at a calm Sunday lunch, and never used again has a short shelf life in human memory. The moment it’s needed is precisely the worst moment to recall it: 1 a.m., adrenaline, a crying voice on the line. I’ll admit our own family’s first attempt was the name of a long-dead cat, and within a year two of us remembered a different dead cat.

It can be phished out of you. This is the failure that worries me most. Picture the call again: “Mum, it’s me, I’m in trouble… wait, you’re going to ask for the word, right? Ugh, I can’t think straight. Just say it and I’ll confirm.” If your mother says the word aloud to prove the caller is real, the scammer now owns it. On the next call, to your father, they’ll offer it up unprompted. A safe word spoken to the wrong person doesn’t just fail; it arms the attacker.

It never rotates. Most families set a word once and keep it for a decade. Every time it’s said on a call, texted “as a reminder,” or written in a shared note, its secrecy decays. A static secret only gets weaker with time.

One word for the whole family. If seven people share one word, the secret is only as safe as the least careful of the seven, including the teenager whose accounts get compromised and the uncle who mentions it at a barbecue. Worse, when it leaks you usually don’t know it leaked, and now every family pairing is exposed at once.

Asking feels rude at the worst moment. Several police forces note that victims of these scams often felt something was off and paid anyway. When your grandson is sobbing about a crash, interrupting with “what’s the password?” feels like an act of distrust. Elderly relatives especially will skip the check rather than risk offending someone they love who is, apparently, in danger.

Fixes for each failure, no app required

Every one of those failures has a practical countermeasure. None of them requires a smartphone.

  • Against forgetting: don’t pick a random word, pick a shared private memory and phrase it as a question: “What did we eat when the tent flooded?” Recall of a lived story beats recall of an arbitrary token. Rehearse it twice a year, for instance every New Year and one birthday.
  • Against phishing: fix the direction. The rule is that the caller in trouble must produce the word, and the person receiving the call never says it first, never confirms guesses, never “reminds” anyone. Anyone who asks you to say the word has failed the test by asking.
  • Against staleness: treat a spoken safe word like a used match. Once it has been said on any call, genuine or not, replace it at the next family contact. And rotate on a schedule anyway, tied to dates you already remember.
  • Against the shared-secret problem: use pairs, not broadcasts. You and your mother share one word; your mother and your brother share another. A leak then burns one relationship, not the whole family.
  • Against the shame of asking: agree, out loud and in advance, that asking is an act of loyalty, and that the real family member will be glad to be challenged. Give everyone the same script: “You know the rule, even for you.” And back it with a no-blame default that outranks everything: hang up and call back on the number you already have. The FTC’s page on family emergency scams gives the same instruction, because a callback defeats a spoofed caller ID and a cloned voice in one move.

Write the hint down if you must (“the tent question”), never the answer. A hint in a wallet is recoverable; the answer in a wallet is a gift to whoever steals the wallet.

When the call comes anyway

Protocols fail under stress, so decide the failure behaviour now. If a call demands money urgently and the word doesn’t check out, or you simply froze and forgot to ask: no transfer, no gift cards, no crypto, no courier. Those payment methods are the scam’s signature precisely because they can’t be reversed. Hang up, breathe, call the person back on their known number, and if you can’t reach them, call another family member who can. A real emergency survives a ten-minute verification. A fake one evaporates.

If money already moved, call your bank immediately, then report it: in the US at ReportFraud.ftc.gov, elsewhere to your local police. Reporting feels pointless in the moment. It isn’t; it’s how these campaigns get mapped.

Why Hongi exists, honestly

You may have noticed that the fixes above quietly reinvent cryptography by hand: pairwise secrets, challenge direction, rotation, burn-after-use. That observation is literally why we built Hongi. Two people pair once, in person, by scanning a QR code. From then on each of them sees a rotating codeword, refreshed every 30 seconds, computed offline on their own phone from the shared pairing secret. Nothing to memorise, nothing that goes stale, and because each side reads a different word, an impersonator can’t learn both from one phished call. It’s free, and there’s no account and no server involved in verification.

It is not magic, and I want to be straight about the limits: both people need the app, and they must have paired face to face beforehand. Your grandmother with the rotary phone still needs the paper protocol above, and she always will. Use both. The safe word is the seatbelt everyone can wear today; if you want the version that rotates itself, the FAQ explains how the codewords work under the hood.