Family codewords offer simple defence against growing AI deepfake scams
AI-enabled scams are becoming increasingly difficult to identify by voice or other familiar cues alone
As artificial intelligence makes it easier for criminals to imitate the voices of relatives and other trusted people, experts are recommending a simple defence: a private family codeword.
AI-enabled scams are becoming increasingly difficult to identify by voice or other familiar cues alone. In 2025, Americans lost an estimated $148.2 billion to online crimes, including $6.3 billion from scams involving artificial intelligence, with such fraud growing rapidly, according to the BBC.
"This is not hypothetical... These scams are being perpetrated all over the world," said Hany Farid, co-founder of GetReal Security.
The rise of AI voice scams
Criminals can use AI-generated voices to create convincing emergency scenarios, in which a caller claims to be a loved one facing an accident or another immediate danger and demands money. The aim is often to frighten victims into acting before they have time to verify the caller's identity.
Elizabeth Benz, who was targeted in a deepfake scam involving her son, described the experience as overwhelming.
"It was the most terror I've ever felt."
"It was my 16-year-old-son, John... He was sobbing, 'Mom, my friend is dead. He's dead.'"
The call later escalated when a scammer took over.
"He said, 'We are going to kill your son.'"
Benz said she was unable to think through the situation clearly enough to use a safeguard that was already available to her family.
"It just didn't occur to me to ask for it... These scams get you to an active place of panic where you can't think straight."
How a family codeword works
Farid recommends that families establish a codeword that can be used to verify identity during unusual situations. The word should be easy to remember but difficult for an outsider to guess, such as an inside joke or another private reference.
"My wife and I have a password. If either of us gets an unusual call, we use it to verify identity."
The codeword does not need to be used for ordinary requests, Farid said.
"If my wife calls and asks me to pick up milk, I'm not asking for the password... But if I happen to know she's in a meeting, or she says been in an accident and needs me to transfer money, anything unusual, that's when you use it."
Farid said the growing sophistication of AI scams means people should prepare for scenarios that may once have seemed implausible.
"Imagine getting a call at 02:00, a voicemail, a video call, a loved one saying they're in trouble... Or maybe it's your CEO, screaming that he needs help logging in. The average consumer is not ready for this."
The danger is not limited to voice calls. AI tools can be used in increasingly convincing communications, making it more difficult for people to rely solely on what they hear or see when assessing whether a caller is genuine.
Three warning signs to watch for
Scam-safety advocate Gary Schildhorn said victims should watch for three common warning signs: pressure to act immediately, demands for difficult-to-trace payments and attempts to prevent them from consulting others.
"There are three red flags."
"One red flag is time. Everything has to be done right away... Two is they never ask for traceable funds. If they need Bitcoin or gift cards or cash, you know the agenda. And three is they try to control who you speak to."
Requests for Bitcoin, gift cards or cash should therefore be treated with particular caution, especially when combined with claims of an emergency and demands for immediate action.
Preparing for panic
Experts also stress the importance of preparing mentally for such calls. Brian Long, co-founder of Adaptive Security, said people should establish a response before they encounter a crisis designed to trigger panic.
"One of the most important things is how you react... You need to train your mental model to prepare for this scenario."
A practical response is to pause, ask for the family codeword and consult another trusted person before taking action, particularly before transferring money.
Benz said her own experience demonstrated why preparation alone may not be enough if people are not accustomed to using the safeguards under pressure. She later discovered that her son was safe.
"I couldn't believe it."
She said she has shared her experience to encourage others to prepare for the possibility of such scams.
"I share my story because I want people to know how urgent and scary and psychological and realistic these calls can be... Awareness is the greatest tool."
Experts recommend that families periodically review their codeword and emergency procedure, such as every three months, to keep the process familiar and easier to follow if a convincing deepfake call arrives.
