Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

131–140 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#132

Earlier quoted context omitted.

The best things to stop these AI voice schemes, is to agree on a family password. The cloned AI voice will not known it.

That's a great idea. What do you use as your family password?

Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#133
Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals.

A looming problem with shifts in demographics and family structure is that many people will be slipping into cognitive decline without a formal transition to address their incompetence. Sadly, there is a point where the older person really needs to permanently delegate important decision-making to a trusted third party. They should no longer be legally empowered to authorize funds transfers, sign contracts, or even make medical decisions.

We're not really setup to handle this well. Not at the systemic level of protecting people from themselves, and not at the personal level of relinquishing control over our own lives. So we often have to let the sufferer fumble along and cause a lot of damage before the protections eventually kick in.

And, ironically, these protection mechanisms can also be corrupted into another scam and form of abuse. To totally de-risk would require some kind of time travel or perfect foresight. But in the real world, the damage is often not fully reversible when it is detected after the fact.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#134

Earlier quoted context omitted.

The US government

But which US governments? There are thousands of them, and they all have different policies.

https://www.justice.gov/archives/jm/criminal-resource-manual...

The federal government.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#135

Earlier quoted context omitted.

It's very, very hard for untrained people to be strict about verifying any secret phrase. The attacker can make all kinds of excuses, while creating urgency, and many people quickly abandon verifying the phrase. A scene in One Battle After Another comes to mind.

Scammers can also trick the victim into reversing the roles and telling password to scammer. Even banks ocassionaly get this wrong. I have had my bank call me and ask me to read numbers from number card. If a trained bank employee following a script designed by (hopefully) an expert cant get it right, the chance of elderly relative spotting mistakes in protocol is close to 0.

The bank is trying to authenticate you, while you're trying to authenticate the bank. The bank calls and tries to authenticate themselves to the callee by saying "is your birthday such and such?", they're risking sharing PII with an unauthorized third-party. The solutions are a non-trivial amount of effort that no one really wants to put up with, unfortunately.

I used to have a residential mortgage with two other people and my name was stuffed into some ancillary field as a co-holder and they refused to give me any information or transact over the phone. I eventually figured out I needed to tell them to look in some extended info field, and the whole endeavor was annoying but ultimately I was appreciative of the strictness (that the entire mortgage data model—at the time (25 years ago), I don't know what it's like today—seems to assume that it will only ever be two people of opposite gender who are married will be on a mortgage was much more disappointing. The other two people were assumed to be married and the woman was seemingly by default listed as the non-primary).

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#136
post #22

Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Wester…

YC S27's ScamMyGrandparents.com lets you simulate these against your own grandparents, so you can shame and educate them when they naively wire your college trust fund to a safe account. You are able to refund either the whole amount, or keep some for yourself since they won't know any better. The cost of service is variable depending on how many homes they own.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#137

Earlier quoted context omitted.

Key phrases make sense to put in place, but another easy safeguard is: "Before you send anything to anyone, ever, call them back. Doesn't matter if it's me, the bank, a lawyer, whatever... tell them 'hang on I have another call coming in, let me just call you back in a few minutes, okay?'"

"They say they're going to cut a finger off every time you hang up."

"I guess we'll start calling you Pinky"

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#138
A friend and his wife _almost_ fell victim to this last year, in Texas.

I think it is a standard script now. Call comes from police department. 'Your son hit a pregnant woman. He is about to be booked. You need to pay $$$$ yada yada'. With an authentic sounding voice conversation from their son.

In spite of several red flags (in hindsight) they withdrew $15K from bank, and somehow at the last minute pulled back.

Edit: Scammers know how to push the right buttons.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#139
post #22

Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Wester…

YC S27's ScamMyGrandparents.com lets you simulate these against your own grandparents, so you can shame and educate them when they naively wire your college trust fund to a safe account. You are able to refund either the whole amount, or keep some for yourself since they won't know any better. The cost of service is variable depending on how many homes they own.

You got me excited, because I've wanted something like this for a while. Obviously without the actual extortion, but everything up to that point. White hat scamming, to teach our parents what it's actually like before it happens.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#140
This article is about the retail version of this kind of fraud. Impersonating CEOs is a thing, and the dollar amounts are much larger.

The attackers created AI-generated video and audio replicas of the CFO and other executives of the global engineering firm. These deepfakes were deployed in a live video call – not as a pre-recorded video, but as a real-time conference with multiple participants. The finance employee saw and heard his superiors in what appeared to be a normal conference situation. The instructions came through clearly and consistently. Urgency was created by framing the situation as a supposed corporate acquisition. Within a single session, he approved 15 individual transfers to various accounts in Hong Kong.[1] That fraud yielded US$25 million.

[1] https://www.securitytoday.de/en/2026/04/04/deepfake-attacks-...

Post reply on HN