A code word agreed with your family
A word or phrase agreed in person, known only to your household, to verify identities when an urgent call asks for money or data. The FBI recommends it in writing against cloned-voice impersonation.
- Level
- Community
- Cost
- No cost
- Effort
- Minutes
- Evidence
- Observed
What it does not solve
It only works if the whole family knows and uses it, which makes it a community measure disguised as a technical one. Nobody has measured how much fraud it prevents: what is documented is the attack and the official recommendation, not the effect size.
It works if somebody calls with the voice of a relative urgently asking for money or data. The FBI alert of May 2025, on the impersonation of senior US officials through AI-generated voice messages, recommends it in so many words: “create a secret word or phrase with your family members to verify their identities”. And it adds the rest of the procedure, which is worth just as much: independently identify a phone number for the person and call to verify, be wary of imperfections and delays in the voice, and confirm through another channel before sending money [394]Senior US Officials Impersonated in Malicious Messaging CampaignView source ↗.
It does not work if the other side does not take part. It is a community measure disguised as a technical one: it only works if the whole family knows it, remembers it and uses it, including older adults, who are the preferred target of this fraud.
Evidence. The attack is documented and the recommendation is official. What nobody has measured is how much fraud it prevents, and that nuance is worth stating even though the measure is obviously sensible [244]Implementing Phishing-Resistant MFAView source ↗.
Cost. Zero. It is agreed in a conversation, in person, and is not sent over chat.
What it does NOT solve. Nothing systemic, and not the frauds that do not involve impersonating someone you know either. It covers one specific route, the one that has grown most with voice cloning.
Works if…
- AI as normal technology · Works
It is how AI risk actually reaches a home today: a familiar voice asking for something urgent.
- Catastrophe through misuse · Partial
Does not work if…
- Gradual disempowerment · Does not work
- Power grab by a small group · Does not work
Risks it addresses
See in the protection matrix →Report a mistake in this entry →
Sources
- [394] Senior US Officials Impersonated in Malicious Messaging Campaign · FBI IC3 2025
- [244] Implementing Phishing-Resistant MFA · CISA 2022