Drücke „Enter”, um zum Inhalt zu springen.
Hinweis zu diesem Datenschutz-Blog:
Anscheinend verwenden Sie einen Werbeblocker wie uBlock Origin oder Ghostery, oder einen Browser, der bestimmte Dienste blockiert.
Leider wird dadurch auch der Dienst von VG Wort blockiert. Online-Autoren haben einen gesetzlichen Anspruch auf eine Vergütung, wenn ihre Beiträge oft genug aufgerufen wurden. Um dies zu messen, muss vom Autor ein Dienst der VG Wort eingebunden werden. Ohne diesen Dienst geht der gesetzliche Anspruch für den Autor verloren.

Ich wäre Ihnen sehr verbunden, wenn Sie sich bei der VG Wort darüber beschweren, dass deren Dienst anscheinend so ausgeprägt ist, dass er von manchen als blockierungswürdig eingestuft wird. Dies führt ggf. dazu, dass ich Beiträge kostenpflichtig gestalten muss.

Durch Klick auf folgenden Button wird eine Mailvorlage geladen, die Sie inhaltlich gerne anpassen und an die VG Wort abschicken können.

Nachricht an VG WortMailtext anzeigen

Betreff: Datenschutzprobleme mit dem VG Wort Dienst(METIS)
Guten Tag,

als Besucher des Datenschutz-Blogs Dr. DSGVO ist mir aufgefallen, dass der VG Wort Dienst durch datenschutzfreundliche Browser (Brave, Mullvad...) sowie Werbeblocker (uBlock, Ghostery...) blockiert wird.
Damit gehen dem Autor der Online-Texte Einnahmen verloren, die ihm aber gesetzlich zustehen.

Bitte beheben Sie dieses Problem!

Diese Nachricht wurde von mir persönlich abgeschickt und lediglich aus einer Vorlage generiert.
Wenn der Klick auf den Button keine Mail öffnet, schreiben Sie bitte eine Mail an info@vgwort.de und weisen darauf hin, dass der VG Wort Dienst von datenschutzfreundlichen Browser blockiert wird und dass Online Autoren daher die gesetzlich garantierten Einnahmen verloren gehen.
Vielen Dank,

Ihr Klaus Meffert - Dr. DSGVO Datenschutz-Blog.

PS: Wenn Sie meine Beiträge oder meinen Online Website-Check gut finden, freue ich mich auch über Ihre Spende.
✓ Ausprobieren DSGVO Website-Check sofort DSGVO-Probleme finden

Grandparent Scam 2.0: How Fraudsters Cash In with Cloned Voices

0
Dr. DSGVO Newsletter detected: Extended functionality available
More articles · Website-Checks · Live Offline-AI

The phone rings. On the other end is a voice that silences every doubt at once, because it sounds exactly like your own child or grandchild. The person is crying, out of breath, talks about an accident or an arrest and needs money within the next few minutes. Thousands of families in Germany are currently going through exactly this scenario every month, and in a growing share of cases the familiar voice does not come from a human being at all, but from a piece of software. The classic grandparent scam, known in Germany as the “Enkeltrick” and around since the 1990s, has received a technological upgrade. Experts now speak of the grandparent scam 2.0.

This article explains how criminals use artificial intelligence for this type of fraud, what is behind it technically, which safeguards exist – and why they still often come too late when it matters.

From the grandparent scam to the grandparent scam 2.0: what is new?

The original grandparent scam worked through psychology, not technology. A caller opened the conversation with a question such as “Guess who this is?” and let the victim come up with a name, which the fraudster then adopted. Anyone who listened closely could often spot the fraud by the unfamiliar voice or the lack of detailed knowledge. The new generation of the scam undermines exactly these two safeguards.

Today, a few seconds of audio are enough for a convincing voice clone, often taken from a publicly accessible social media video. This is all it takes to create a synthetic copy that reproduces not only the sound but also the speech melody, the emphasis and even emotional nuances such as crying or trembling. The most important giveaway of the old scam, the unknown voice, disappears completely.

Criminals currently use the technology in three typical variants:

  • Modernised grandparent scam: The cloned voice of a child or grandchild calls with an alleged emergency.
  • CEO fraud: Employees receive a supposedly urgent instruction from management, usually linked to a money transfer.
  • Shock call: An alleged police or official voice uses a dramatic scenario to create immediate pressure to act.

How voice cloning works: the technology behind the deception

To understand why this type of fraud has become so effective, it is worth looking at the technology. Two methods are involved that are often confused:

Text-to-Speech (TTS) converts written text into spoken language, usually with a ready-made, generic AI voice. This is familiar from navigation devices or read-aloud functions.

Voice Cloning goes one step further: it reconstructs the voice of one specific, real person. To do this, a model analyses a short reference recording and extracts what is known as a voice embedding, a mathematical representation of pitch, timbre, speaking rate and characteristic quirks. With this embedding, the system can then speak any new text in exactly this voice, including pauses for breath and emotional colouring.

Comparison chart: text-to-speech with a generic voice on the left, voice cloning of a real person from a few seconds of reference audio on the right
Text-to-Speech (TTS) and Voice Cloning compared.

Until a few years ago, a convincing clone still required several minutes of clean audio. Today, professional and criminal providers alike sometimes need only a few seconds from an Instagram video or a voice message. This lower technical barrier is the real reason why the grandparent scam 2.0 is spreading so quickly.

The invisible tool chain: what happens behind the scenes of every AI request

What many people do not know: behind every request to an AI system, whether it is a harmless chat or speech synthesis, a multi-stage processing chain runs in the background. With reputable providers, this tool chain is active regardless of what the AI is being used for, and it explains both the strengths and the weaknesses of today’s safeguards.

Input and normalisation. First, the input is technically prepared. For voice cloning services this means, for example, that uploaded audio is brought to a uniform volume level and cleaned of background noise so that the downstream model can work properly.

Check before processing. Even before the actual AI request is handled, many providers run an upstream safety filter. It checks whether a request violates the usage policies, for instance because someone else’s voice is to be cloned without authorisation. Reputable providers now require proof of consent: the person whose voice is to be cloned has to speak a sentence specified by the system, which is then matched against the request and stored as evidence.

The actual model inference. Only then does the actual AI model process the request. In speech synthesis, the desired text is first translated into a phonetic structure, combined with the previously extracted voice embedding and converted into an actual audio waveform by what is known as a vocoder.

Check after processing. After generation, a further downstream filter often evaluates the result once more before it is delivered. In this step, many providers now also embed invisible watermarks in their audio output so that AI-generated content can later be identified as such.

Logging and abuse detection. In the background, providers also evaluate usage patterns in order to detect suspicious clusters, such as a conspicuously high number of cloning requests for prominent or public figures.

This entire chain runs in fractions of a second for every single request, no matter whether someone is generating a voice for an audiobook, a commercial or indeed a scam call. But this is also exactly where the limits of this protection system lie: it only works if the provider has actually implemented the chain. Criminals instead fall back on freely available, open-source cloning tools without consent checks, run their own unregulated infrastructure or use services outside the EU that do not adhere to the standards described here. Current research also shows that even technical safeguards such as acoustic interference signals, which are meant to prevent a voice from being cloned, can in part be circumvented again with specialised cleaning methods. The tool chain is therefore not a sure-fire success, but a race between safeguards and their circumvention that continues across the industry.

AI scam calls usually follow the same pattern.

The course of a scam call: how the perpetrators proceed

The scam follows a recurring pattern. Calls are preferably made late in the evening or at the weekend, when the supposedly affected person is harder to reach and family members have less time to double-check. Through so-called number spoofing, a trustworthy-looking German phone number often appears on the display, even though the call actually comes from abroad.

After the first emotional sentences from the cloned voice, further callers join in many cases, posing as police officers or lawyers and building up additional pressure with technical jargon. The aim is always to leave as little time to think as possible, because every minute in which the victim reflects or consults someone increases the risk of the fraud being exposed.

Figures that make you sit up and take notice

The scale of the development is reflected in several recent figures. In January 2026 alone, the Bundesnetzagentur (Germany’s Federal Network Agency) registered more than 555,000 reported fraudulent calls, and a considerable number of unreported cases must be assumed. In a worldwide survey by the security company McAfee, about a quarter of respondents said they had either experienced a scam call with a cloned AI voice themselves or knew a victim in their own circle.

For 2024, the Bundeskriminalamt (Germany’s Federal Criminal Police Office) recorded around 6,700 cases in the area of grandparent scams and shock calls; AI-supported fraud attempts are not yet reported separately. In Bavaria alone, fraudsters made off with more than 18 million euros through this form of fraud in 2023, with individual cases in the six-figure range.

Documented cases from recent months show how concrete the damage can be: in Düsseldorf, a married couple lost around 230,000 euros in cash and gold coins to an alleged lawyer. In Pfaffenhofen, a 60-year-old woman handed over 60,000 euros in a supermarket car park. In the canton of Schwyz in Switzerland, an entrepreneur transferred several million francs in January 2026 after perpetrators had cloned the voice of his business partner. As early as 2019, an early case of AI CEO fraud in the United Kingdom had caused a stir, in which a cloned voice with a slight German accent triggered a transfer of 220,000 euros.

Warning signs you can no longer rely on

Many of the classic tips for recognising scam calls date from a time before powerful voice cloning and are now outdated. Anyone waiting for a “robotic-sounding” or monotonous voice will be disappointed: modern clones now also convey breathing, hesitation and emotional outbursts convincingly. Even the once helpful control question about a shared family secret loses its effect when perpetrators have specifically gathered information from social networks beforehand.

What actually protects instead is less a matter of listening closely than a fixed rule of behaviour that works regardless of how perfect a voice sounds.

Concrete protective measures for families

Consumer advocates and police authorities now recommend a clear, easy-to-remember procedure:

How to protect yourself and your family against AI fraud on the phone.

Agree on a family code word. Together with close relatives, decide on a secret word that only the family knows and that is asked for in the event of a suspicious emergency call. A voice clone can imitate a voice, but it cannot guess a code word it has never heard.

Always call back yourself. If you receive an unexpected emergency call, hang up and call the person concerned back yourself on the saved number you already know, never on a number given by the caller.

Treat time pressure as a warning signal. Any demand to act immediately and without consulting other family members should make you suspicious as a matter of principle, regardless of how convincing the voice sounds.

Never hand over cash to strangers. In Germany, neither the police nor the public prosecutor’s office ever demand by phone that cash, jewellery or bail be handed over at the front door or in the street. Any such demand is a clear sign of fraud.

Deliberately limit your own social media content. Since just a few seconds of publicly accessible video are enough for a clone, it is worth taking a critical look at the reach of your own voice recordings on social networks, especially for older and potentially vulnerable family members.

Actively involve older relatives. Since voice clone fraud particularly targets older people, it helps to raise the topic openly within the family and to practise the code word rule together instead of only giving general warnings.

Labelling obligation since August 2026: what the EU AI Act changes

Since 2 August 2026, the transparency obligations under Article 50 of the European AI Regulation have been binding. Providers of AI systems have since had to ensure that their generated output is marked in a machine-readable way as artificially generated, and in the case of deepfakes also directly recognisable as such for humans. This expressly applies to synthetic voices as well: if a voice message or a call is generated with a cloned voice, the person concerned must be formally informed of this.

Technically, the industry is increasingly relying on open standards such as C2PA, which cryptographically sign the origin and editing steps of a file, as well as on invisible watermarks such as SynthID from Google DeepMind, which is now also used by other major providers for AI-generated audio content.

In practice, however, this is only limited cause for relief. The labelling obligation is addressed to the caller, and with a criminally organised gang this rule naturally comes to nothing. For a victim on the phone, the legal requirement initially changes nothing at the moment of the call; the regulation becomes valuable above all in retrospect, for example in the criminal investigation of cases, and in the long term through the pressure on reputable providers to further expand their safeguards.

What to do when the worst happens

Anyone who has received a suspicious call or has already transferred money should immediately inform the police via the emergency number 110 (in Germany), and under no circumstances via a number given by the caller. Transfers that have already been made should be reported to your own bank at once, since a recall within the first few hours significantly increases the chance of the payment being reversed. It is also advisable to report the incident to the Verbraucherzentrale (the German consumer advice centre), as this data helps to identify warning patterns early and pass them on.

Conclusion

The grandparent scam 2.0 is so effective because it combines a decades-old psychological fraud scheme with a technology that was unthinkable just a few years ago. The good news: the most effective protection is not technical but organisational in nature.

An agreed family code word and the fixed rule of hanging up and calling back yourself when in doubt work regardless of how perfect a cloned voice will one day sound. While legislators and providers are catching up technically with labelling obligations and watermarks, one thing above all remains decisive for families in everyday life: an agreement made in advance beats even the most convincing voice on the phone.

KI-Beratung, KI-Lösungen

Umfassende Beratung (fachlich, rechtlich, technisch):

Leistungsangebot:

  • Erstberatung inkl. Machbarkeitsaussagen
  • Schulungen und Workshops für Führungskräfte, Berufsgeheimnisträger, Angestellte, Entwickler
  • KI-Lösungen mit und ohne ChatGPT/Azure. Cloud oder eigener KI-Server

Ihre Anfrage

Oder Mail an ki@dr-dsgvo.de

About the author on dr-dsgvo.de
My name is Klaus Meffert. I have a doctorate in computer science and have been working professionally and practically with information technology for over 30 years. I also work as an expert in IT & data protection. I achieve my results by looking at technology and law. This seems absolutely essential to me when it comes to digital data protection. My company, IT Logic GmbH, also offers consulting and development of optimized and secure AI solutions.

Write a comment

Ihre Mail-Adresse wird nicht veröffentlicht.

Der ständige Modell-Wettlauf: GPT, Gemini, Claude & Co.