AI Scams Targeting Seniors in 2026: The Safe Word That Beats Them All
The short version: in 2026 a scammer can sound exactly like your grandson, and no amount of listening carefully will save you. What saves you is a safe word your family agreed on in advance, and the habit of hanging up and calling back on a number you already have. This guide shows you how to choose one, how to teach it to someone who worries about forgetting things, and — if money has already left an account — exactly what to do in the next sixty minutes.
Why trust this: I’m a professor of AI and robotics and a former Samsung researcher. I build and study these systems, so I’ll tell you plainly what they can do — and every figure below comes from the FBI, the FTC, or the Justice Department’s own 2026 publications, not from a security company selling software.

Web story · 60 seconds
The Safe Word That Beats a Cloned Voice — the four rules for choosing one, in a form you can hand to a parent in under a minute.
First, the honest part: your ears are no longer the defense
For thirty years the advice was “listen for something odd.” That advice is finished. Voice-cloning tools now reproduce a familiar voice — the catch in the throat, the way your granddaughter says your name — from a short sample of ordinary audio. There is nothing wrong with your hearing; you are being asked to detect something built specifically to be undetectable.
So this guide will not ask you to spot a fake voice. It asks for something you can actually do: verify the person, not the voice.
The scale, in the government’s own numbers
The FBI’s Internet Crime Complaint Center published its 2025 report in April 2026. For Americans over 60:
| 2025, victims 60+ | Figure |
|---|---|
| Complaints filed | 201,266 (up 37% in one year) |
| Reported losses | $7.75 billion (up 59%) |
| Average loss | $38,500 |
| People who lost more than $100,000 | 12,444 |
| Complaints with an AI element | 3,143 — $352 million |
| ““Distress” scams using cloned voices — the FBI’s name for family-emergency calls (all ages) | over $5 million |
One detail matters more than the totals: 2025 is the first year the FBI tracked artificial intelligence as a category at all. The report marks earlier years with an asterisk — the data simply wasn’t collected. So when you see an article claiming AI fraud “rose 312% year over year,” you’re reading an invented number. There is no previous year to compare with. I’d rather tell you that than borrow a scary statistic.
The 2026 scam that targets you because you started using AI
Here is the one almost nobody has written about yet, and it’s the reason I wanted to write this guide.
Security researchers documented in December 2025 that criminals are now planting fake “official” customer-support phone numbers across the web in a way designed to be swallowed by AI assistants. Their tests found Perplexity, Google’s AI Overview, ChatGPT and Claude all returning scam support numbers as if they were the real thing — including a bogus airline line the researchers published as proof.
Think about who that hurts. Not the technically fearless. It hurts the person who just learned to ask an AI assistant a question, who reasonably assumes the machine looked it up properly.
The rule, and it is not negotiable: never dial a phone number an AI gave you. Get support numbers from the back of your card, your paper statement, or by typing the company’s own web address yourself. AI assistants are wonderful for explaining things and terrible as a phone book.
(New to AI assistants generally? My plain-English ChatGPT walkthrough covers the safe habits from day one.)
The six that take the most money — hook, ask, and the tell

1. The family emergency call
The hook: a panicked voice — a grandchild in a crash, in jail, in a hospital — often followed by a calm “lawyer” or “officer” who takes over. Frequently it arrives as a voicemail rather than a live call, because a recording can’t be interrupted with questions.
The ask: cash handed to a courier at your door, a wire, gift-card numbers read aloud, or crypto — and “please don’t tell Mom and Dad.”
The tell: the secrecy. A real emergency spreads through a family within minutes; only a scam needs it kept quiet. Voice quality tells you nothing anymore. Secrecy still tells you everything.
2. The companion who is never free for a video call
The hook: warm, attentive, tireless conversation. AI now lets one operator run dozens of relationships at once, which is why the replies come instantly and the story never slips.
The ask: money, eventually — small at first, then a crisis, then an “opportunity.”
The tell: they will never do an unscheduled video call. There is always a camera problem, a bad connection, a hospital rule. Ask for a spontaneous call, right now, and watch what happens. Romance and confidence scams took $584 million from people over 60 last year.
3. The investment that shows profits but won’t pay out
The hook: a wrong-number text or a friendly account that becomes, in the Justice Department’s own words, trust built “through friendship or romance.”
The ask: the DOJ describes the pattern exactly — scammers “assisted victims in setting up accounts and transferring cryptocurrency to investment platforms that, unbeknownst to the victims, were false,” and “encouraged their victims to borrow money from friends and family and take out loans.”
The tell: the dashboard shows gains, but withdrawing triggers a fee, a tax, or a delay. Money you cannot take out was never there. Investment fraud is the single largest category of loss for people over 60: $3.5 billion in 2025.
The encouraging half of that story: in April 2026 an international operation dismantled nine scam centers and made 276 arrests, and the FBI’s Operation Level Up has warned roughly 9,000 victims mid-scam, saving about $562 million.
4. The famous face endorsing something
The hook: a video of a well-known investor, doctor, or news anchor recommending a platform. The FBI’s report describes “AI-generated videos and voices of celebrities, CEOs, or trusted figures.”
The tell: it exists only in an ad or a forwarded clip — never on that person’s own verified channel. Go look there. It won’t be there.
5. The renewal notice with a help number
The hook: a flawless email about a subscription renewing — Norton, Microsoft, Amazon — with a number to call and cancel. AI killed the broken-English tell; these letters are now perfect. Phishing is the most reported crime for people over 60: 48,064 complaints in 2025.
The ask: “let me remote into your computer to process the refund” — followed by a wire. The FTC has documented individual losses of $50,000 and $49,500 from exactly this script.
The tell: you called them. Any number that arrives inside an unexpected message is the danger — same rule as the AI-given number above.
6. The government call: Medicare, Social Security, or the IRS
The hook: “Your Medicare card has been compromised.” “Your Social Security number has been suspended.” “The IRS has a warrant.” The caller ID shows a government-looking number, because caller ID is trivially faked. Government impersonation took $413 million from people over 60 last year.
The ask: your Medicare or Social Security number “to verify,” or payment to clear the matter — often by gift card, wire, or crypto.
The tell: real agencies don’t work this way. Medicare does not call to sell you plans or ask for your number. Social Security numbers are never “suspended.” The IRS opens with a letter, not a phone call, and no agency on earth accepts gift cards. If you’re unsure, hang up and call the agency yourself: Medicare 1-800-633-4227, Social Security 1-800-772-1213.
The safe word: how to choose it, teach it, and rehearse it
Every article on this subject tells you to have a family code word. Almost none tells you how to make one that works. The FBI has recommended it twice in public alerts — “create a secret word or phrase with your family to verify their identity” — so let’s do the part they leave to you.

Free printable
The Family Safety Kit (PDF, 6 pages)
The safe-word card, the First 60 Minutes sheet, and photo first aid — print them tonight, share them with anyone. No sign-up required.
Choosing it — four rules
- Not a name from your life. No pets, no children, no street you lived on. Those are the first things a stranger can learn about you.
- Not findable online. If it has ever appeared on Facebook, in an obituary, or in a school newsletter, it isn’t a secret. Assume the caller has read all of it.
- Absurd, so it survives panic. Two unrelated words — purple tractor, waffle Tuesday — are far easier to recall while frightened than something clever. Nonsense sticks.
- Spoken only. Never typed. Not in a text, not in email, not in a family group chat. A safe word that lives in writing is one hacked account away from being useless.
Using it — the whole script is four words
When a call frightens you, you do not need to argue, investigate, or be clever. You say:
“What’s our safe word?”
A real grandchild will answer, or laugh, or be annoyed at you. A cloned voice will do one of three things: hesitate, get angry, or insist there’s no time. All three are your answer. Hang up and call the person on the number already stored in your phone. The FTC’s guidance is the same: call back on a number you know is theirs, and if you can’t reach them, try another family member.
Teaching it — the part families get wrong
If you’re reading this for a parent, resist the urge to send them a link to this article and consider the job done. What actually works, from families who’ve done it:
- Introduce it as your protection, not theirs. “Mom, I want us to have a word so that I can prove it’s me when I call.” Nobody resists protecting their child. Many people resist being handled.
- One word for the whole family. Different words per person is how a system dies in month two.
- Write it nowhere. Say it aloud three times today. Repetition beats storage.
- Give permission in advance. Say plainly: “If anyone ever tells you not to hang up, hang up. You will never be in trouble with me for hanging up on me.”
Rehearsing it — once a season, thirty seconds
A safe word you’ve never used out loud is a safe word you won’t retrieve at 11 p.m. with your heart pounding. So test each other: call from an unexpected number, ask the question, hear the answer. Do it at Thanksgiving. Do it on birthdays. That’s the whole drill, and it is the difference between a good idea and a working defense.
Fewer calls to begin with — the settings that help
A safe word protects you when a call gets through. This reduces how many get through at all. None of it is perfect, and none of it stops a determined, targeted scammer — but it removes most of the noise, and noise is what wears people down.
- iPhone: Settings → Apps → Phone → turn on Silence Unknown Callers. Anyone not in your contacts goes straight to voicemail, and you can still see who called.
- Android: open the Phone app → the three dots (top right) → Settings → Caller ID & spam → turn on spam filtering.
- Landline: call your phone company and ask what free call-blocking they offer on your line — most now have it and simply don’t advertise it.
- Your mobile carrier’s free app: AT&T ActiveArmor, Verizon Call Filter, T-Mobile Scam Shield. All free, all label suspected scam calls before you answer.
- Register free at donotcall.gov. It won’t stop criminals — they were never obeying the law — but it makes legitimate telemarketing stop, so the calls that do come through are easier to judge.
And the habit that matters more than any setting: you never have to answer. If it’s real, they leave a message. If you missed something important, you can always call back — on a number you looked up yourself.
About that “three seconds of audio” claim
You’ll see it everywhere: three seconds of your voice is enough to clone you. Here’s where that number actually comes from. It comes from a McAfee laboratory study published in 2023 — a security company’s own research, not a government finding — which reported that about three seconds of audio produced an 85% voice match, and trained models reached 95%. Other outlets quote fifteen seconds. Both numbers circulate as fact.
As someone who works with these models: the true threshold depends on the tool, the audio quality, and how much the model has already learned from other voices, and it keeps falling. Which is exactly why I don’t want you memorizing a number. Assume that any recording of your voice — a voicemail greeting, a video of a birthday party, a “hello?” to an unknown caller — is enough. Then rely on the safe word, which doesn’t care how many seconds it took.
Watch how it actually sounds
Reading about a cloned voice is not the same as hearing one. This local-news segment (KSL, a 474,000-subscriber station channel; about 136,000 views as of August 2026) is the clearest one I’ve found on protecting your voice from being harvested in the first place:
And this 2026 CBS Los Angeles investigation follows deepfake scams from the victim’s side:
If money already left the account: the first 60 minutes

Read this part before you need it, because the whole game is speed. And read this first, because most articles won’t say it: money is recovered more often than people think. When the FBI’s Recovery Asset Team went after frozen funds in 2025, it succeeded in 58% of cases — $679 million frozen. For victims over 60 specifically, about half of the money involved was frozen. Not a guarantee. Not nothing, either.
- Minute 1 — call your bank, say the words “fraudulent transfer,” and ask them to attempt a recall. The FBI’s own report puts it bluntly: “If you discover a fraudulent transfer, time is of the essence.” Do this before you tell anyone, before you feel embarrassed, before you research anything.
- Minute 10 — file at ic3.gov. Here is the correction that matters: the internet is full of a “$50,000 minimum, 72 hours, international wires only” rule. That is the FBI’s internal trigger for its own team — not a bar you must clear. The Bureau’s instruction to victims is exactly this: “Regardless of the amount lost, file a complaint at www.ic3.gov.” File.
- Minute 20 — report to ReportFraud.ftc.gov. Do it even if no money moved; attempted scams are what build the cases.
- Minute 30 — freeze your credit at all three bureaus: Equifax 800-685-1111, Experian 888-397-3742, TransUnion 888-909-8872. It’s free, and it takes minutes.
- Minute 45 — write it all down while it’s fresh: names used, the number that called, dates and times, what you were told, how money moved and to where. The FBI asks for exactly this, and memory fades fast after a shock.
- Then call a human. The Justice Department’s National Elder Fraud Hotline, 833-372-8311, assigns you a case manager and walks you through it. Weekdays, 10 a.m. to 6 p.m. Eastern.
“I didn’t lose money — but I told them things”
This is the most common version of the story, and almost nobody writes about it. You realize partway through, you hang up, and then you lie awake wondering what you gave away. Here is what each one actually means, and what to do about it.
- Your Social Security number. Go to IdentityTheft.gov — it builds you a personal recovery plan, free — and freeze your credit at all three bureaus. Your number cannot be “cancelled,” and you don’t need a new one. A freeze is the real protection.
- A card or bank number. Call the number on the back of your card and ask for a replacement. Don’t wait to see if something happens.
- Gift card numbers you read aloud. Act in minutes: call the card’s own fraud line (Apple, Google Play, Amazon, Target all have one), give them the card number and keep the card and receipt. Funds are sometimes still frozen. Then report it to the FTC.
- Access to your computer. If you let anyone connect remotely: disconnect from the internet, restart, run a security scan, and change your important passwords from a different device. Then call your bank — remote-access scams usually end at a bank account.
- Your name, address, phone, or email. Uncomfortable, but not an emergency. Expect more attempts; your defenses are the same ones in this guide.
- A recording of your voice. There is no way to take it back — and that is exactly why the safe word exists. Tell your family today, not next month.
One thing you never have to do: explain yourself. These operations run scripts refined on tens of thousands of people. Being fooled by a professional is not a character flaw.
If it already happened to your mother or father
Searches like “my mom got scammed, what do I do” arrive by the thousand, so let’s answer it properly.
- Lead with relief, not blame. “I’m so glad you told me” buys you their cooperation. Shame is why most elder fraud goes unreported — and unreported means unrecoverable.
- Do the sixty-minute list with them, not for them. Sit beside them for the bank call. Let them hold the phone.
- Then warn them about the second wave. In July 2026 the FBI issued an alert about criminals impersonating IC3 itself — contacting people who were already scammed and offering to recover their money for a fee. The Bureau’s line is worth taping to the wall: IC3 will never contact individuals by phone, email, social media, apps, or chat. Anyone promising to get your money back for an upfront payment is the same crime, second helping.
- Don’t take over their finances as the fix. Add a second set of eyes instead — many banks let a trusted family member receive alerts without any control over the account. Dignity intact, safety improved.
Numbers worth keeping by the phone
| If you need… | Call or visit |
|---|---|
| A person to help you through it | 833-372-8311 — National Elder Fraud Hotline (DOJ) |
| Free help and a friendly ear | 877-908-3360 — AARP Fraud Watch Helpline (no membership needed) |
| To report money lost online | ic3.gov — FBI |
| To report any scam, money or not | ReportFraud.ftc.gov · 877-382-4357 |
| Identity theft recovery plan | IdentityTheft.gov · 877-438-4338 |
| To check your credit report | annualcreditreport.com · 877-322-8228 |
One honest note: there is no federal hotline specifically for deepfakes. The channels above are the channels. Anyone implying otherwise is guessing.
FAQ
How do I stop scam calls?
Turn on Silence Unknown Callers (iPhone: Settings → Apps → Phone) or spam filtering (Android: Phone app → ⋮ → Settings → Caller ID & spam), install your carrier’s free filter app, ask your phone company about free blocking on a landline, and register at donotcall.gov. None of it stops a targeted criminal — but you never have to answer an unknown number. If it’s real, they leave a message.
What if I gave a scammer my Social Security number?
Go to IdentityTheft.gov for a free personal recovery plan and freeze your credit at all three bureaus. Your number can’t be cancelled and you don’t need a new one — the freeze is the real protection.
My parent was scammed — what should I do first?
Say “I’m so glad you told me,” then do the sixty-minute list with them: bank, ic3.gov, FTC, credit freeze. Then warn them about recovery scams — the FBI reported in July 2026 that criminals impersonate IC3 to re-target people who were already victims. IC3 never contacts individuals directly.
What is a good family safe word?
Something absurd and shared — purple tractor — or a private family fact nobody has ever posted. Four rules: not a pet, child, or street name; not findable on social media; easy to say under stress; never sent by text or email. Say it aloud together once a season.
Can you get your money back after being scammed?
Sometimes, and speed decides it. The FBI’s recovery team succeeded in 58% of its 2025 attempts, freezing $679 million; for victims over 60, about half the money in those cases was frozen. Call your bank first, then file at ic3.gov — regardless of the amount lost.
How many seconds of audio does it take to clone a voice?
The famous “three seconds” comes from a 2023 McAfee lab study, not a government finding; others say fifteen. Treat it as unsettled and assume any recording is enough — the defense doesn’t change.
What happens if I answer a scam call and they hang up?
Answering alone doesn’t drain an account. What it tells a scammer is that a real person answers this number — and it can capture a sample of your voice. Don’t repeat “yes,” don’t confirm your name, hang up, block the number.
Can a free AI voice detector tell me if a call was fake?
Not reliably, and not during a live call. Detectors disagree with each other and trail the generators. Verification beats detection every time: hang up, call back on the number already in your phone.
Where do I report an AI scam?
ic3.gov if money moved, ReportFraud.ftc.gov either way, and 833-372-8311 if you’d rather talk to a person. There is no separate deepfake hotline.
The bottom line
Nothing here requires you to become technical, and nothing here is your fault. The criminals have better tools than they had last year, and they will have better ones next year. But the defense doesn’t depend on technology at all — it depends on two sentences you can decide on tonight, over dinner, with the people you’d answer the phone for at midnight.
Pick a safe word. Say it out loud. Then agree, out loud, that in this family nobody is ever in trouble for hanging up.
Share this with someone you love — and if you’d like one short, plain-English AI email a month, join the Lab Report. Unsubscribe anytime.
Keep reading
- How to use ChatGPT: step by step for beginners over 50 — the safe habits built in from the first question.
- Resources — every reporting channel and hotline on this page, kept on one printable page.
- The best free AI tools for seniors — reading labels aloud, hearing the TV, seeing the screen: what’s genuinely free, verified.
- ChatGPT for Excel — formulas from plain English — no memorizing, ever.
- How to Plan a Trip with ChatGPT — five prompts to a relaxed itinerary.
- Prep for a Doctor Visit with ChatGPT — one printed page: timeline, meds, top three questions.
About the author
Prof. H is a professor of AI and robotics, a former Samsung researcher, and the author of dozens of textbooks on AI and automation. He writes hands-on, no-hype guides to AI tools. More about the author →
Full index
Every guide in the Generative AI library
Start with AI, at any age
- ChatGPT, step by step (over 50)
- Free AI tools that actually help
- ▸ AI scams & the family safe word (you are here)
- Restore old family photos
- Write any letter with ChatGPT
AI writing tools, reviewed
Curious about robots, humanoids, and the chips inside them? Physical AI library →