3-Second Voice Rule
A few seconds of audio from social media is enough to clone a voice. "It sounds like them" is not safety.
For your whole life, recognising a voice was proof of who was speaking. That rule just broke. A short clip of someone's voice — your daughter's, your boss's, a familiar customer-service tone — is now enough to clone them well enough to fool you on a call. The 3-Second Voice Rule is the single mental switch that keeps you safe: a voice is no longer evidence. It tells you who to answer, never what to do.
Hearing is no longer believing
The FBI is now explicit about it: criminals "generate short audio clips containing a loved one's voice to impersonate a close relative in a crisis situation, asking for immediate financial assistance." The same technique is used to impersonate "well-known, public figures or personal relations to elicit payments" — and even to "obtain access to bank accounts using AI-generated audio clips of individuals."
Read that again: the same trick clones your family, your bank's voice, and a celebrity's pitch. The raw material is everywhere — a few seconds from a voicemail greeting, a social video, a podcast clip, a work all-hands recording. There's no longer a relationship where a voice on its own can be trusted, because there's no longer a voice that can't be copied.
A voice is now the caller, not the proof
It helps to demote what a voice means. A familiar voice used to do two jobs at once: it got you to pick up, and it proved who was there. It can still do the first job — but it can no longer do the second. Treat every voice as just "the caller": a reason to listen, never a reason to act.
That one reframe defuses the whole class of attack. You stop asking "does this sound like them?" — a question the scam is built to win — and start asking "have I confirmed this through something a voice can't fake?" Until you have, you simply don't move money, share a code, or grant access, no matter how perfectly it sounds like someone you know.
Same trick, four disguises
The cloned voice shows up wearing whichever face fits you best. As family: a panicked child or grandchild who's been in an accident and needs cash now. As your bank or a government office: a calm, official-sounding "fraud agent" walking you through moving your money to a "safe" account.
As your boss: an urgent voice note or call from the "CEO" telling finance to wire a supplier today and keep it quiet — the voice version of business email compromise, which the FBI tracks as a multi-billion-dollar loss. As a celebrity or expert: a familiar voice in a video "guaranteeing" an investment return. Different costumes, one engine — your trust in a voice.
What you put in place of your ear
You don't need to detect the fake — you need a check the fake can't pass. For each relationship, add one independent confirmation the voice has no access to. For family, agree a private safe word and call back on a known number. For a bank, agency, or "support" line, hang up and use the number on your card or the official site (the Call-Back Rule). For anything at work, confirm any payment or account change on a second channel you already trust (Two-Channel Verification).
Underneath all of them is the same backstop: the moment a voice is pushing you to move money fast or keep a secret, slow down. A real person — relative, banker, or boss — survives the two minutes it takes to verify. A cloned one is counting on you not to take them.
- Make the rule a reflex: "a voice is who is calling, not proof of what to do." Decide it now, before the call comes.
- Never let a voice alone authorize anything — money, a code, account access, a bank-detail change — no matter how certain you are it’s them.
- Set the family check: agree a safe word, and the rule that no word means hang up and call back on a number you already have.
- Set the institution check: for any bank, agency, or "support" caller, end the call and dial the number on your card or official site yourself.
- Set the work check: confirm any payment or supplier-detail request on a second, independent channel — never act on the voice note alone.
What it looks like at work — a voice note that sounds exactly like your CEO:
Sources
Frequently asked
Can’t I just listen carefully and tell when a voice is AI?
You can't rely on it. The whole point of the FBI's warning is that generative AI now makes these clips convincing enough to fool people in the moment, and the quality keeps improving. Trying to ear-detect the fake is the losing game the scam is designed around. The rule works precisely because it doesn't depend on spotting the clone — it depends on verifying through something the clone can't reach.
So I have to treat every phone call as a scam now?
No — you treat every voice as "the caller," not as proof. Talk to people normally. The rule only kicks in at the point of action: when a voice asks you to move money, share a code, grant access, or keep a secret. At that single moment, you stop and confirm through an independent check. Everyday conversation is fine; it's authorising things on a voice alone that's no longer safe.
It sounded exactly like my daughter / my boss. How is that even possible?
Because a clone needs only a short sample, and we leave that sample everywhere — voicemail greetings, social videos, podcasts, recorded meetings. The FBI describes criminals generating "short audio clips" of a loved one's voice from material like this. "It sounded exactly like them" is now the expected result of the attack, not evidence against it — which is exactly why the voice can't be your proof anymore.