The new AI voice scam that is emptying bank accounts in Spain
First there were the poorly written emails promising non-existent inheritances. Then came the calls from fake support technicians, the bank texts with poisoned links. Every time technology advances, scammers find a way to use it against us. But what is happening now in Spain is different. It is more sophisticated, more personal and, above all, much harder to detect.
Generative artificial intelligence has put within anyone’s reach a tool that until just a couple of years ago required advanced audio studies and professional equipment: voice cloning. You no longer need to kidnap someone to impersonate them. With just a few seconds of audio taken from social media, phone calls or WhatsApp videos, a scammer can recreate your voice with chilling fidelity.
And in recent weeks, cases in Spain have multiplied. Law enforcement agencies are warning of a wave of scams in which criminals call victims posing as their relatives using AI-cloned voices. The voice sounds real. The urgency, too.
How the scam works
The modus operandi follows a pattern that repeats with small variations. The scammers obtain audio samples of the person they want to impersonate. They can get them from Instagram stories, TikTok videos, WhatsApp voice messages or even recordings from video calls leaked in security breaches.
With those samples, they feed AI-based voice cloning tools available on the web or through APIs, such as those from ElevenLabs, Respeecher or similar. In a matter of minutes, they generate synthetic audio in which the person says whatever they want. The technology is so good that even the victims’ own relatives do not notice the difference.
The call usually follows this script: “It’s me, mum/dad. I’ve lost my phone, I’m calling you from a friend’s phone. My wallet has been stolen and I need you to send me money urgently to pay for something. I’ll send you the account number by SMS.” The voice is recognizable. The tone of urgency, believable. And the victim, believing they are helping a loved one, makes the transfer.
Data in Spain: a growing threat
According to data from the Ministry of the Interior, scams using artificial intelligence shot up 450% during 2025 compared to the previous year. Although overall cybercrime figures are still led by traditional phishing, AI voice cloning is the fastest-growing modality.
The Civil Guard, through its Cybercrime Group, has issued several alerts in recent weeks warning about this new threat. In a recent statement, they point out that most of the victims are people over 60, although there are increasingly more cases among young people who, ironically, trust technology more and let their guard down.
One of the most high-profile cases took place in Madrid last March. A man received a call from who appeared to be his daughter, who claimed she was stranded at a gas station after an accident. The voice was identical. The “friend” accompanying her gave him an account number to transfer 3,000 euros to “pay for the tow truck”. The victim made the transfer. Minutes later, when he contacted his daughter by another means, he found she was at home, perfectly fine. He had lost the money.
Why it is so hard to detect
The fundamental problem is that our brain is wired to trust familiar voices. Recognizing a loved one by their tone of voice is a deep instinct, and scammers exploit it mercilessly. Unlike a suspicious text or email, a phone call generates a sense of immediacy and emotional connection that overrides critical thinking.
Moreover, technology has advanced so much that automatic detection systems for voice deepfakes are still not one hundred percent reliable. According to a study by the University of Oxford, current classifiers get it right only in 73% of cases when faced with audio cloned with the most modern tools. That means one in four fraudulent calls goes unnoticed even by the most advanced security systems.
The phone companies themselves admit they are in a race against time. Movistar, Vodafone and Orange have begun implementing real-time call analysis systems that look for anomalous patterns, but cloning technology advances faster than the countermeasures.
How to protect yourself
Authorities recommend setting up a family keyword. Agree with your loved ones on a verbal password that only you know. If someone calls asking for urgent money, ask for the keyword before acting. If they don’t say it, don’t do anything.
Other practical measures include:
- Be wary of urgent calls. Scammers create false urgency so you have no time to think or verify. Hang up and call the person on their usual number.
- Verify through another channel. If someone calls asking for money, contact that person by another means (WhatsApp, SMS, another call) before doing anything.
- Limit your public voice footprint. Review the privacy settings of your social networks. The less audio of yours is publicly available, the harder it will be for scammers to get samples.
- Don’t share voice audio on public platforms. Voice messages in WhatsApp groups, Telegram channels or public TikTok videos are a goldmine for voice cloners.
- Enable two-step verification on your bank accounts. Many banks offer additional confirmation systems that can detect unusual transfers.
What the authorities are doing
The National Police’s Central Cybercrime Unit and the Civil Guard’s Cybercrime Group have launched specific awareness campaigns, but they admit that pursuing these crimes is complex. The calls are made through virtual numbers or VoIP services routed through several countries, and the receiving bank accounts usually belong to “mules” who are also victims of the scheme.
On the legislative front, the Spanish Data Protection Agency (AEPD) has launched a public consultation to update the rules on the non-consensual use of biometric data, including voice. For its part, the European Union, through the AI Act, will require mandatory labeling of AI-generated content starting in August 2026, although the measure focuses more on transparency than on scam prevention.
The future of AI scams
Experts warn that this is just the beginning. Real-time voice cloning during a call is already technically possible: systems such as those being developed by Silicon Valley companies allow you to hold a conversation in which the other person believes they are talking to a real person when in fact it is an AI that imitates their voice instantly.
The next step, which is already beginning to be seen in countries such as the United States and the United Kingdom, is combining cloned voice with deepfake video calls. The victim not only hears their relative’s voice, but sees them on screen. The simulation is total.
In the meantime, the best defense remains the oldest: common sense, verification and, above all, a pause before acting. No one with a real emergency will ask you not to hang up to call another number.
Marta, for inteligencia intermitente.






