VERICODE vericode.com.au

Hi Mum learned to talk, and the defences did not move

Vericode · 25 March 2026


The most ordinary scam in Australia just got a voice. “Hi Mum” used to turn up as a text from a number nobody recognised: broken capitalisation, a borrowed sob story, a please-help. Mum caught it, or she didn’t. This month it turned up as a phone call. The voice was the kid’s voice. The crying was the kid’s crying. Same story as always, except the part that used to save people had been cut out.

It sounded like them.

That’s the change. The old version asked you to believe a message from a strange number. The new one asks you to believe your own ears. It’s a much nastier test, because most of us have spent a whole life treating a familiar voice as proof of who’s calling.

The wider numbers make it hard to wave away. Voice-cloning scams have already been tied to Australian losses. Hiya’s State of the Call reporting has deepfake voice calls turning up often enough to register in ordinary consumer experience. Apate.ai is diverting big volumes of scam calls with bots. Telstra is still blocking millions of scam calls a month.

Those defences are real. The blocking matters, the bots matter, the bank controls matter. What none of them answer is the moment a real call gets through and sounds correct.

That’s the difference between detection and verification.

Detection is for the call you want to stop. It asks whether the traffic looks bad, whether the number has history, whether the pattern matches known scam behaviour, whether the sender belongs on a block list. It works best when the channel carries enough signal to act before anyone says hello.

Verification is for the call you can’t just block. It asks whether the person in the conversation is who the conversation needs them to be. Different problem. A parent, a customer, a supplier, a staff member, a banker.. any of them can be a legitimate caller. The risk isn’t that every call is bad. It’s that the bad one sounds normal.

Voice cloning drags that risk into the ordinary home. The fake CEO calling finance was already a known trick. The child calling a parent is the same move on a softer target. It works because it borrows intimacy. It doesn’t need a perfect script if the voice creates enough panic to push the victim past doubt.

Underneath sits the leakage problem. A voice clone needs audio. The pretext needs a name, a relationship and a reason. That material comes from somewhere. Public videos, social accounts, breached data, old forms, scraped profiles, plain oversharing.. all of it feeds the model and the script. The call sounds personal because it’s been fed personal things.

Privacy reform can thin that feed over time. Better platform action can shrink the harvesting surface. Telco blocking can cut volume. Bank controls can stop some of the money moving. But the voice-clone upgrade lays bare the gap between reducing bad traffic and proving a live caller.

That gap is uncomfortable, because the call is exactly where people want to stay human. Nobody wants to make a frightened parent feel like a suspect. Nobody wants every family call to become a security ritual. The answer can’t be panic. It has to be a cleaner way to pause the risky moment without making every ordinary chat heavy.

The old advice was to hang up and call back on a number you know. Still useful, but it’s a behaviour, not infrastructure. It leans on the victim having time, calm and the nerve to override what they just heard.

The part that always saved us was the voice. It isn’t anymore.