Americans reported $893 million in losses to AI-powered scams last year, according to the FBI’s 2025 Internet Crime Report. The FTC counted about a million imposter scam reports in the same year, with losses topping $3.5 billion, which made pretending to be someone else the single most reported category of fraud in the country. And the tool doing a lot of the heavy lifting is voice cloning, which now needs as little as three seconds of audio to produce a copy of a voice that will fool the people who love you most.

Three seconds. Your outgoing voicemail greeting is longer than that.

The scam is old, the weapon is new

The grandparent scam has been around forever. Someone calls an older person claiming to be a grandkid in trouble, needs bail money, wire it now. It used to require a con artist who could act. Now it requires a TikTok clip of the actual grandkid and a $20 piece of software, and the voice on the phone is not an impression, it is the kid.

Daniel Kahneman spent a whole career showing that our gut decides long before our brain shows up to check the work. A familiar voice goes straight through the gut. When your daughter’s voice is crying on the phone, you are not evaluating evidence, you are already reaching for your wallet. That is not a character flaw, that is being a parent.

Both trust signals are dead

Think about what your phone actually gives you when it rings. Two things. A caller ID, which can be spoofed for pennies, and a voice, which can now be cloned from three seconds of audio. Those are the only two signals you have ever used to decide the person on the other end is who they claim to be, and both of them are now forgeable by a teenager.

The reality is we never actually verified the person. We verified things near the person, the number, the sound of them, and for a hundred years that was good enough because faking a voice was hard. That era is over and it is not coming back.

The question worth asking

So here is the interesting problem. When my phone rings, what I actually want to know is simple. Is there a real, live human on the other end of this call right now, and is it the human I think it is? Not a recording, not a script, not a model doing an award-winning performance of my kid.

Nothing in the current stack even attempts to answer that question. Caller ID answers “what number.” Contact names answer “what I labeled this number six years ago.” Nothing answers “human, present, right now.”

I wrote last week about how ending spam for good comes down to proving a human is on the sending end. This is the same problem wearing a scarier mask. Spam wastes your time, but voice cloning spends your trust, and trust does not refill.

A phone that could tell you “a verified human is on this call” would be worth more than every filter ever shipped. Next week, why every security check on your phone is answering the wrong question entirely.