Elder fraud hit $7.7 billion in 2025 — why banks can't rely on safe words

A grandmother in Ohio gets a call. It's her grandson's voice — panicked, crying, saying he's been in a car accident and needs bail money wired immediately. Except it isn't her grandson. It's three seconds of audio lifted from a social media video, run through a voice cloning tool, and weaponized against the one demographic least equipped to question it. In 2025 alone, adults aged 60 and older reported $7.7 billion in fraud losses to the FBI's Internet Crime Complaint Center (IC3) — a 37% jump over the prior year — and for the first time, the agency broke out a category just for AI-enabled fraud: $352 million in losses driven specifically by tools like voice cloning.
The new grandparent scam is a banking problem
"Grandparent scams" used to rely on a scammer's ability to fake urgency and vague familiarity — "it's me, your grandson" — hoping panic would fill in the gaps a stranger's voice couldn't. AI voice cloning removes that gap entirely. Investigations by outlets like CBC Marketplace have shown scammers cloning a real family member's voice well enough to fool even close relatives on the first call.
What starts as a personal tragedy ends at a bank teller's window or a wire transfer form. The average loss per senior victim now exceeds $38,000, and seniors are the largest victim group by total dollar losses of any age category the FBI tracks. That makes this squarely a financial institution problem, not just a consumer-education one — every one of these calls eventually asks a bank to move money.
Why the "safe word" defense doesn't scale
The most common advice given to families right now is to agree on a private "safe word" that only real relatives would know, then require it before acting on any emergency call. It's a reasonable stopgap for a single household. It is not a fraud control a bank, call center, or fintech can build a program around.
- It depends on consumer behavior banks can't enforce. A panicked 78-year-old customer on the phone with someone who sounds exactly like their grandson is unlikely to remember to ask for a code word.
- It doesn't touch the transaction layer. Safe words protect a phone call between family members; they do nothing when the fraud moves to a wire request, an authorized push payment, or a call into the bank's own contact center impersonating the account holder.
- It doesn't scale across an institution. There's no equivalent of a "family safe word" for a bank verifying thousands of daily callers — which is exactly where voice biometrics and deepfake detection are designed to operate instead.
What the FBI's numbers reveal
The IC3's 2025 Elder Fraud Report, the first to carve out AI-specific losses, points to a pattern financial institutions should treat as a leading indicator rather than a one-off statistic:
- $7.7 billion in total reported losses among victims 60+, up 37% year over year
- $893 million in AI-enabled fraud losses across all age groups, with $352 million attributable to victims 60+
- Family and government impersonation scams remain among the fastest-growing categories, now supercharged by cloned voices
- Banking partners working with the IC3's Recovery Asset Team helped freeze tens of millions in fraudulently wired funds in recent kill-chain interventions — proof that fast, accurate detection at the transaction stage still works
Where banks fit into the fraud kill chain
Detection at the point of the call, not after the wire clears
The FBI's Financial Fraud Kill Chain has shown that funds can sometimes be recalled if a bank flags a suspicious transfer within hours. But that window is shrinking as scammers move faster and sound more convincing. The more durable fix is catching the impersonation earlier — at the call center, the authentication step, or the video KYC check — before a transfer request is ever submitted.
This is precisely the gap that voice-to-face matching and real-time deepfake detection are built to close. Instead of relying on a customer to remember a password phrase under emotional distress, banks can verify whether the voice on the line, or the face on a video call, actually belongs to the person it claims to be — without needing a pre-enrolled database of every family member a fraudster might impersonate.
Building a defense that doesn't depend on the victim
Elder fraud prevention has historically leaned on educating customers: watch for urgency, verify by calling back, don't wire money to strangers. That guidance still matters, but 2025's numbers show it isn't keeping pace with how convincing synthetic voices have become. The institutions best positioned to bend this curve are the ones building detection into the transaction itself, so protection doesn't hinge on a stressed customer getting it right in the moment.
Corsound AI helps banks and financial institutions detect voice deepfakes and verify caller identity in real time, closing the gap that safe words and customer education alone can't. Learn more about how our tools support fraud teams at corsound.ai/banking-and-finance.
See Corsound AI Voice Intelligence In Action

