When the scammer has your "grandchild's" voice: protecting your organisation and the vulnerable from AI fraud
An elderly donor gets a phone call. It is their "grandchild" – the voice matches, the crying matches – in distress and needing money immediately. Or your organisation discovers that someone has used your logo and name to collect "donations" that never arrive. Both are examples of a threat exploding right now: AI-driven fraud. The FBI reports that such scams grew 1,210 percent in a year, with losses of over 893 million dollars in the US alone.
For nonprofits this hits twice: you can be defrauded yourselves, and – perhaps worse – the people you exist for can be. Here is a measured guide to protecting both.
The key thing to know
AI has not invented new types of fraud. It has made the old ones cheap and far more convincing. Cloning a voice now requires just three seconds of audio – scraped from a social-media video – and costs almost nothing. That is why scammers can now target individuals they previously would not have bothered with, including vulnerable elderly people and individual donors. The goal is always the same: create urgency so the victim does not get a chance to check.
Protect the organisation
- Always confirm money requests through another channel. If the "director" or a "partner" makes an urgent payment request, call back on a known number before doing anything.
- Verify account changes. If a supplier or recipient changes bank account, confirm it verbally on a known number first.
- Be mindful of what you post. Video and audio of staff and leaders is raw material for voice cloning. It does not mean you should stop sharing – just be aware of the connection.
Protect the people you serve
Here the nonprofit sector has a unique role. Many of you are in contact with exactly the groups scammers target – the elderly, people in vulnerable situations, those with low digital literacy. You can make a real difference by spreading a few simple tips:
- Hang up and call back. If you get an upset call from "family" or "authorities" urgently demanding money – hang up, and call the person or agency back on a number you know.
- Agree on a family code word. A secret word the family can use to confirm it really is them. A cloned voice cannot supply it.
- No real agency or bank asks for urgent payment by phone. Time pressure is the scam itself.
And your own AI tools
If your organisation uses AI tools, remember they often gather sensitive information. Even large players fail here: McDonald’s AI recruitment bot leaked 64 million applicants’ data because an account was left with the password "123456." Treat any AI tool as a database of sensitive data – and keep the basics in order, in line with the ground rules for safe AI use we have written about before.
The message is both serious and encouraging: the threats are more powerful, but the defense is simple and familiar – and that is precisely why this is something you can teach onward. Helping people hang up and call back may be the most low-threshold, high-value security work an organisation can do right now.