6 ms·
Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) gr
by offsign 3mo ago
Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this:
1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..."
My grandmother fell victim to this almost 20 years ago, which only stopped when Western Union refused to let her continue sending wires... she was forced to call her daughter (at which point they just called my brother.)
Our takeaway (at the time)... the voice doesn't even need to be terribly accurate, since the original interaction is brief / somewhat inaudible over the tears. Typically just requires an older vulnerable adult, a lucky strike with the initial setup (e.g. grandparent actually has a grandkid), and a lot of high pressure / duress salesmanship.
- Foobar8568 3mo agoI told my parents that I will never ask for money, doesn't matter the situation, even with live video, it's trivial to generate live audio and video nowadays. I hope they got the message.
- abirch 3mo agoFortunately for me, my parents wouldn't be able to get the live video working.
- saidnooneever 3mo agoi agreed key phrases. id recommend it. something unrelated to the family and totally arbitrary, agreedupon only verbally. (or write it down for them if they are old and memory is an issue. you can remind them to read your note out loud.. easy). this way, you do not footgun yourself in the event you'd ever need to ask something. Money isnt the only thing they can ask, and no one (i think) has a glass orb to tell their future and know for certain such a call would never happen. its easy to think it wont happen to you, i think that is most peoples' sentiment until it does. (having a need for help from family that is)
- mikepurvis 3mo agoKey phrases make sense to put in place, but another easy safeguard is: "Before you send anything to anyone, ever, call them back. Doesn't matter if it's me, the bank, a lawyer, whatever... tell them 'hang on I have another call coming in, let me just call you back in a few minutes, okay?'"
- ceejayoz 3mo ago"They say they're going to cut a finger off every time you hang up."
- toast0 3mo ago"I guess we'll start calling you Pinky"
- xp84 3mo agoNot a thorough safeguard, if scammers have half a brain cell they can provision a VOIP number for such a request. They’re nothing if not accommodating.
- wlesieutre 3mo agoYou're supposed to call them back on a number you know is really that person/company. This ensures the person you're talking to is actually from your bank and not just calling from a random number and saying "I'm from your bank," or even spoofing a real number of your bank or a family member, because when you call back it will go to the real person and not the impostor. This is a very useful precaution for banks, and for or calls that come from a family member's real phone number. But scammers will just open with "I'm in trouble and my phone died" or "I'm in jail calling from a pay phone" and calling back won't do anything to help with that.
- xp84 3mo agoYes, that's my point. There will be a "reason" why the callback needs to be another number. Also, given at least in America, our cell phone providers STILL haven't fully blocked caller ID spoofing (last I checked, they just add some tiny icon in the rare case that the CID is trustable, and I'd bet 99.9% of people don't even know that exists!) they can spoof the initial call as your number and many targets will probably mistakenly think the CID match is good enough to just skip it, especially in this "very urgent situation" with you being held at knifepoint by the corrupt third-world cops or whatever.
- chrisjj 3mo agoThey might not believe it - for good reason.
- stronglikedan 3mo agoI recently did the same, and I, too, hope they got the message. We agreed that there is nothing that needs to be acted upon immediately, and that anything questionable would be discussed with the whole family first.
- root-parent 3mo agoThe best things to stop these AI voice schemes, is to agree on a family password. The cloned AI voice will not known it.
- ferngodfather 3mo agoThat's a great idea. What do you use as your family password?
- root-parent 3mo agoNice try.
- kirubakaran 3mo agoHey "nice try" is my family password too!
- kibwen 3mo agoNice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******
- alienbaby 3mo ago********* Oh yeah! Neat.
- pixelready 3mo agoThis thread just gave me a pang of nostalgia. I think the first time I saw this interaction was in an AOL chat room, or maybe an early MUD. I miss the good old silly internet…
- spiddy 3mo agoJoke's on you, now I know your password is 7 chars, but more importantly, I also know your password is not 7 stars.
- f1ay 2mo agoThat wasn't enough for my mom. I went through an identical scenario, and about 6 months after we had the conversation she got hit.
- psygn89 3mo agoI remember my JROTC instructor also running into that and how she said afterwards they have a secret phrase between them two as a way of verifying it's truly them.
- throwaway89201 3mo agoIt's very, very hard for untrained people to be strict about verifying any secret phrase. The attacker can make all kinds of excuses, while creating urgency, and many people quickly abandon verifying the phrase. A scene in One Battle After Another comes to mind.
- ceejayoz 3mo agoAt some point, the scam evolves to a live video of a gagged loved one being tortured. "Stop wasting my time or they lose another finger." People aren't prepared for this shit.
- xp84 3mo agoOh, man. That does seem likely. What a world. I wonder if eventually there won’t be a human in the loop, just a model trained to make money with a strategy like that, automatedly selecting victims and a person to be impersonated for each. Pre-render a few videos, place multiple calls in parallel. Basically a turnkey Docker container that takes a bitcoin address as a parameter and fills it with stolen money.
- Martinussen 3mo agoJust add video and a better voip endpoint to existing setups and you're already there. A lot of scams can be (and are) run by a small handful of people now. Phishing at scale with stuff like fake tracking links etc. is already fully automated by people in a ton of ways and can definitely handle some back-and-forth over sms/whatsapp/whatever.
- trollbridge 3mo agoLong-term, it would mean that videos like that no longer function as a proof of life nor as a credible threat.
- saidnooneever 3mo agolucky strike is the key here they can do this with VOIP really easily to massive amounts of numbers. its staggering amounts if you look at the traffic really. worst is if they proxy that via residential proxy services which often come from end-user / individuals phones so the traffic is hard to detect for carriers etc. since it looks like a regular VOIP app connection.
- glaslong 3mo ago"Greasing the wheels" seems right in principle, but possibly putting the accelerant factor a bit... mildly. Like going from burning the turkey in the oven, to deep frying and burning your whole house down. > cybercrime losses across the United States rose 26 per cent in a single year > The FBI was candid that even these figures understate the problem. AI attribution in the report reflects only what victims recognised and reported, and most victims of a cloned-voice call never learn that a machine was involved at all. > INTERPOL found that AI-enhanced fraud is roughly four and a half times more profitable than its traditional equivalent, and that so-called agentic AI systems can now autonomously plan and execute entire fraud campaigns, from reconnaissance through to the ransom demand.
- Forgeties79 3mo agoTo build on your point, I have this comment I wrote months ago that I end up pasting (or pasting a bit altered) probably every week: “Before LLM’s there was_____” I see this whenever an LLM’s impact is assessed. We know. The issue is scale and the ability for smaller and smaller groups (down to individuals) to execute at scale. LLM’s are pouring massive amount of gasoline on existing issues and people just keep shrugging. Fake news always existed. Now one dude in India can flood multiple sock puppet media accounts with right wing content/images (actual example) at a scale previously unimaginable - or in this case, can target even more vulnerable elderly populations far more effectively. People could always die crossing a street. Still, cars changed the discussion about pedestrian safety pretty materially. People didn’t simply throw up their hands and go “people have always been able to die crossing the street.”
- kraquepype 3mo agoDon't worry, it's all worth it so long as we can get braindead summaries we didn't ask for, pretend to be the 10x engineer we always wanted to be, and generate fake videos for internet points! (sarcastic rant over) Most of the benefits of AI are being overshadowed by the lack of regulation and reckless abandon at which they are being developed. Given the current trajectory I don't know if that's going to change before it's too late.
- trhaynes 3mo agoYC S27's ScamMyGrandparents.com lets you simulate these against your own grandparents, so you can shame and educate them when they naively wire your college trust fund to a safe account. You are able to refund either the whole amount, or keep some for yourself since they won't know any better. The cost of service is variable depending on how many homes they own.
- ikesau 3mo agoYou got me excited, because I've wanted something like this for a while. Obviously without the actual extortion, but everything up to that point. White hat scamming, to teach our parents what it's actually like before it happens.
- exolymph 3mo agoI read this comment and was like "but what is their business model?" before I realized
- f1ay 2mo agoYou got me dead to rights with this, because I literally bought dontscamgrandma.com earlier this week and it took a heart jumping second to catch the joke. We're staying away from the trust funds and shame though.
- red-iron-pine 2mo agoin 2026 grift is the way of life, not crazy to see YC going that way eventually
- pavel_lishin 3mo agoIt's not "just" greasing the wheels, because previously each call required a human being to spend the equivalent amount of time on the phone with a victim, interacting with them - you couldn't just play a cassette tape at them, you know? And it likely requires working with other people, your "employees", who are both a liability, and a cost. With AI, you can make a thousand calls in parallel, for significantly cheaper, out of your own basement. This greases the wheels of voice fraud like a gatling gun greases the wheels of hitting a guy with a rock.
- written-beyond 3mo agoSounds like something gogograndparent can add as a VAS