AI virtual kidnapping scams show why voice alone can no longer prove identity

Worried man on a phone call, illustrating an AI voice-cloning virtual kidnapping scam

Deborah Del Mastro picked up the phone to hear a man say he'd kidnapped her daughter and wanted $20,000 for her release. Then she heard her daughter's voice on the line, crying and pleading for help. She wired $5,000 before learning the truth: her daughter was safe the entire time, and the "kidnapper" was an AI clone built from a few seconds of audio pulled off social media. The FBI says Americans lost more than $893 million to AI-related scams last year, and this variant — the AI "virtual kidnapping" call — has spread fast enough that the Bureau issued a nationwide warning about it in 2026.

How an AI "virtual kidnapping" call gets built

The scam doesn't require a real abduction — just a convincing enough phone call. Scammers scrape social media for a target's name, relationships, and travel habits, then clone a voice from as little as a few seconds of publicly posted audio or video. They call a family member claiming to have kidnapped a loved one, play the cloned voice crying for help, and demand immediate payment by wire transfer, cryptocurrency, or gift card before the victim has time to verify anything.

The FBI's advisory lists the tells investigators look for once a call is reported:

  • Unusual pauses, flat tone, or odd fluctuations in the "loved one's" voice
  • Pressure to act immediately and avoid contacting anyone, including police
  • Payment demands via wire transfer, crypto, or gift cards — methods that are hard to trace or reverse
  • "Proof of life" photos or videos with subtle flaws: missing tattoos or scars, odd body proportions, mismatched lighting, or strange image artifacts

Voice stopped being proof of identity a while ago

The Del Mastro case isn't an outlier — it's a symptom. Entrust's 2026 Identity Fraud Report, which analyzed more than a billion identity verifications, found that deepfakes now drive 1 in 5 biometric fraud attempts globally, deepfaked selfie attempts rose 58% in a year, and injection attacks — feeding fabricated audio or video directly into a system rather than presenting it to a camera or microphone — rose 40% year over year. A voice that "sounds exactly right" is no longer meaningful evidence of anything, whether it's convincing a parent to wire money or convincing a bank's call center that the person on the line is who they claim to be.

Why banks, telecoms, and law enforcement all have a stake

Virtual kidnapping calls look like a consumer problem, but the institutions in this playbook's path are the ones with the tools to actually interrupt it:

Financial institutions

A panicked, time-pressured wire transfer to an unfamiliar account is exactly the pattern fraud teams are trained to flag — except when the customer insists they just spoke to their own child. Banks that can verify whether a voice on a call is synthetic, rather than relying on a teller's judgment under pressure, close a gap that policy alone can't.

Telecom carriers

Spoofed caller ID is a standard part of the script, making the incoming call look like it's from a known number. Carriers that flag spoofed or synthetic-origin calls before they connect cut the scam off earlier in the chain.

Law enforcement

Officers fielding a reported kidnapping need a fast way to distinguish a real abduction from an AI fabrication so resources go where they're actually needed — and so victims aren't kept in prolonged panic over a crime that never happened.

Family code words are a start, not a defense

Authorities recommend agreeing on a family code word and always calling back a known number before sending money — sound advice, and worth doing. But it's a manual defense that depends on a frightened person remembering to use it in the moment, and it does nothing for the banks, call centers, and carriers that process the transaction after the call ends. Closing that gap takes verification that works the same way whether or not the person on the phone thinks to ask for a password: detecting a synthetic voice in real time, at the point where the money — or the panic — is about to move.

Corsound AI's Deepfake Detect analyzes live audio and video to flag synthetic voices as a call is happening, giving banks, call centers, and telecom carriers the ability to catch a cloned "loved one" before a single dollar moves. If your organization fields the calls that scams like this are designed to exploit, it's worth finding out before the next Deborah Del Mastro does.

Photo: Sarah Blocksidge / Pexels

See Corsound AI Voice Intelligence In Action
Thank you.
Your submission has been received.
Oops! Something went wrong while submitting the form.