Cybersecurity, explained for the rest of us.

Phishing & Scams

Deepfake Video Calls: The Step-by-Step Defense Guide for Families

Margot 'Magic' Thorne@magicthorneSeptember 20, 202612 min read
Split-screen video call showing identical faces, one real and one AI-generated, with verification steps overlaid

The call came from my niece's number. Her face filled the screen. She was crying. She'd been in a car accident. The other driver was threatening to call the police unless she paid cash immediately. She needed $5,000 wired in the next hour.

Everything looked right. Her voice. Her face. The panic in her eyes. The background noise of traffic. The slight lag you get on international calls. I almost sent the money.

Then I asked her to tell me the name of her childhood cat.

She couldn't.

That's when I knew the face on my screen wasn't my niece. It was an AI-generated deepfake, synthesized in real time, using publicly available photos and voice samples to impersonate someone I love. The operators behind the scam were good. The technology was better. But the family password we'd set up six months earlier stopped the attack cold.

Here's how deepfake video calls work, why they succeed, and the exact step-by-step process to protect your family before the next call arrives.

How Deepfake Video Calls Actually Work

Deepfake video synthesis combines three technologies: voice cloning, facial mapping, and real-time rendering. Each component has existed for years. What changed in 2025 and 2026 is that the tools became accessible, the processing became fast enough for live calls, and the quality became indistinguishable from reality under stress.

Voice cloning analyzes speech patterns from publicly available audio, YouTube videos, TikToks, Instagram stories, voicemails left on public-facing business lines. Some systems need around 30 seconds of clean audio to generate a convincing voice model. Others work with less. The cloned voice can then speak any words the operator types, with the right cadence, accent, and emotional tone.

Facial mapping uses photographs and video clips to build a 3D model of someone's face. The model captures bone structure, skin texture, eye movement, and micro-expressions. Social media provides the training data. Profile pictures, tagged photos, stories, and reels give the AI everything it needs to render a face that moves, blinks, and reacts like the real person.

Real-time rendering combines the cloned voice with the mapped face and streams the result through a video call. The operator sits at a computer, typing what they want the deepfake to say. The AI generates the audio and animates the face in sync. The victim sees someone they know, speaking in real time, on a platform they trust.

The technology isn't perfect. Real-time deepfakes struggle with certain movements, rapid head turns, extreme angles, hands near the face, complex lighting changes. But under the emotional pressure of an emergency call, most people don't notice the subtle artifacts. They see a loved one in distress and react.

Why Traditional Verification Fails

You've been told to verify callers by asking personal questions. Favorite color. Mother's maiden name. Street you grew up on. High school mascot. First car. Pet's name.

That advice assumed the attacker was guessing. It assumed personal information stayed private. It assumed the caller couldn't research you.

None of those assumptions hold in 2026.

Data brokers sell detailed dossiers on nearly every American. Social media posts from a decade ago still live on archived servers. People-search sites aggregate public records, property ownership, voter registration, and court filings. A determined attacker with $50 and an hour can learn your mother's maiden name, your childhood address, your high school, and the name of every pet you've ever mentioned online.

Asking "What's my mother's maiden name?" doesn't verify identity anymore. It verifies that the caller can use Google.

The second problem is that traditional verification questions assume you're calm enough to think of them. Emergency calls create urgency. Someone you love is hurt, arrested, stranded, or in danger. The caller gives you seconds to decide. Your brain shifts into crisis mode. You don't think about verification protocols. You think about how to help.

That's the mechanism attackers exploit. The call isn't designed to fool you under calm scrutiny. It's designed to bypass scrutiny entirely by triggering panic.

The Family Password Defense

A family password is a shared secret that only your family knows. It's a word, phrase, or question-and-answer pair that you establish in advance, during a calm moment, and commit to using every time someone calls with an urgent request.

The password isn't personal information. It's not derived from your life. It's arbitrary. Random. Impossible to research or guess. The only way to know it is for someone in your family to tell you directly.

When someone calls claiming to be your daughter, your parent, your sibling, or your spouse, and they need money or action immediately, you ask for the password. If they can't provide it, you hang up. No matter how convincing the voice. No matter how real the face. No matter how urgent the story.

The password works because AI can only use information it has access to. It can clone a voice from public audio. It can map a face from public photos. It can research your life from public records. But it can't guess a secret you've never shared outside your family.

Step 1: Choose Your Family Password

The password needs to be memorable, unambiguous, and impossible to guess. Here's the process:

Sit down with your family. Explain that you're setting up a verification system for emergency calls. This isn't paranoia. It's the same principle as a smoke alarm. You set it up before you need it.

Choose a word or short phrase that has no connection to your family history, your interests, or anything an attacker could research. Don't use pet names, favorite movies, inside jokes that you've mentioned online, or phrases from family stories.

Good examples: "purple giraffe," "flannel Tuesday," "meteor sandwich," "the answer is seven." These are arbitrary. Meaningless. Easy to remember but impossible to derive.

Bad examples: "Gandalf" (if you've posted about Lord of the Rings), "1998" (if that's a birth year), "Chicago" (if you've lived there), "Max" (if that's a pet's name you've mentioned publicly).

Write the password down and store it somewhere every family member can access. A shared note in a password manager. A physical card in each person's wallet. A document in a shared family folder. The password isn't useful if someone forgets it during a crisis.

Practice using it. Call each other occasionally and ask for the password. Make it routine. The goal is for the question "What's the family password?" to feel as natural as "How are you?"

In The Fellowship of the Ring, Gandalf stands at the Doors of Durin, stumped by a riddle he should know. "Speak, friend, and enter." The answer isn't clever wordplay or ancient lore, it's the Elvish word for "friend." Simple. Arbitrary. Impossible to guess unless you know. Your family password works the same way. The strength isn't in complexity. It's in the fact that only your family knows it exists.

Step 2: Establish the Verification Protocol

The password alone isn't enough. You need a protocol, a set of rules everyone follows every time an emergency call arrives.

Rule 1: Any request for money, account access, or urgent action triggers the protocol. No exceptions. Even if the caller sounds exactly like your daughter. Even if the video looks perfect. Even if the story makes sense.

Rule 2: Ask for the family password immediately. Don't wait. Don't let the caller control the conversation. Interrupt if you have to. "Before we go any further, I need you to tell me the family password."

Rule 3: If the caller can't provide the password, hang up. Don't argue. Don't give them a chance to explain. Don't let them guilt you into skipping verification. Hang up.

Rule 4: Call the person back using a number you already have saved. Not a number they gave you during the call. Not a number from caller ID (which can be spoofed). Use the contact information you stored before the emergency.

Rule 5: If you can't reach them, contact another family member to verify the situation. Don't act alone. Don't send money based on a single call.

Write these rules down. Share them with everyone in your family. Make sure elderly relatives understand the protocol. Make sure teenagers know to ask for the password even if the caller claims to be a parent.

The protocol feels awkward the first time you use it. That's fine. Awkward is better than defrauded.

Step 3: Prepare for Resistance and Guilt

Attackers using deepfake calls know about verification protocols. They plan for them. They'll try to make you feel guilty for asking.

"Mom, I'm in trouble. I don't have time for games. Just send the money."

"You don't trust me? I'm your daughter. I'm scared. Please."

"If you loved me, you wouldn't make me jump through hoops right now."

This is manipulation. It's designed to make you override the protocol by making you feel like a bad parent, a bad child, a bad sibling.

The response is the same every time: "I need the family password. If you can't give it to me, I'm hanging up and calling you back."

If they escalate, crying, yelling, pleading, that's confirmation. A real family member in a real emergency would understand why you're asking. They'd provide the password immediately. Someone pretending to be your family member will get angry when verification fails.

Hang up. Call back. Verify through a second channel.

Step 4: Test the System Regularly

A family password only works if everyone remembers it and uses it. Test the system at least once every few months.

Call a family member and say, "This is a test. What's the family password?" If they can't answer immediately, you know the system needs reinforcement.

Update the password if it's been compromised. If you've mentioned it in a public space, written it in an email, or shared it with someone outside the family, change it.

Rehearse the protocol with elderly relatives. Walk through a scenario. "If someone calls and says I'm in the hospital and need money, what do you do?" Make sure they know the steps.

The goal isn't to create paranoia. It's to build a habit. The password becomes automatic. The protocol becomes reflex.

Step 5: Recognize the Limits of Video Verification

Seeing someone's face on a video call doesn't prove they're real. The assumption that "I can see them, so it must be them" is the vulnerability deepfakes exploit.

If you're on a video call and something feels wrong, ask the person to perform a physical action the AI can't predict. Hold up three fingers. Turn your head to the left and show your profile. Stand up and take two steps back. Touch your nose with your left hand.

Real-time deepfakes struggle with unexpected physical requests. The AI can animate a face talking. It can't reliably animate a full body performing arbitrary movements on command.

If the caller refuses, makes excuses, or the video freezes at the moment you ask, that's a red flag. Hang up. Call back.

Step 6: Secure the Information Deepfakes Use

Deepfakes rely on publicly available data. The more photos, videos, and audio clips you share online, the easier it becomes to build a convincing model.

You don't need to delete your social media presence. But you can reduce the attack surface:

Limit who can see your posts. Use privacy settings to restrict photos and videos to friends only, not public.

Avoid posting high-quality video clips where you're speaking directly to the camera for extended periods. Those clips are ideal training data for voice cloning.

Don't post photos of your kids with their full names visible. Don't tag them in posts that reveal where they go to school, where they play sports, or where they spend time.

Review old posts. If you've shared detailed personal information, addresses, phone numbers, family relationships, pet names, consider deleting or restricting access.

The goal isn't to become invisible. It's to make it harder for an attacker to build a high-fidelity deepfake without significant effort.

Step 7: Educate Elderly Family Members

Elderly relatives are disproportionately targeted by deepfake scams. Attackers know that older adults are more likely to have savings, less likely to question a panicked call from a grandchild, and less familiar with AI-driven fraud.

Sit down with your parents or grandparents and walk through the family password system. Explain that scammers can now fake voices and faces on video calls. Explain that the password is the only reliable way to verify identity.

Make sure they know the protocol. Write it down and leave it next to their phone. Rehearse it with them. Call them periodically and ask for the password so it becomes routine.

Explain that it's okay to hang up. It's okay to say, "I need to call you back." It's okay to feel suspicious. The real emergency can wait five minutes while they verify. The fake emergency can't.

Step 8: Know What to Do If You Fall for a Deepfake Scam

If you send money based on a deepfake call, the first hour matters most.

Contact your bank immediately. Explain that you were defrauded. Request a wire recall if the transfer hasn't completed. Most banks can reverse or freeze transfers if you act within minutes.

If you used a payment app like Zelle, Venmo, or Cash App, contact the platform's fraud department. Recovery is harder with peer-to-peer apps, but report it anyway.

File a report with the FTC and the FBI's Internet Crime Complaint Center. Include details about the call, time, platform, amount, and any identifying information about the caller.

Change passwords on any accounts you mentioned during the call. If the caller asked about your bank, your email, or your phone, assume they're targeting those accounts next.

Warn your family. If the attackers have a deepfake model of one family member, they may try the same scam on others.

The Reality Behind the Hype

Deepfake video calls are real. The technology works. The scams succeed. But the threat isn't what headlines suggest.

Most deepfake scams still rely on audio-only calls or pre-recorded video clips, not real-time video synthesis. The real-time version requires more skill, more processing power, and more setup. It's used selectively, targeting high-value victims or situations where the payout justifies the effort.

The defense isn't complicated. It's a shared secret and a protocol. The family password stops the attack because AI can't guess what it doesn't know.

The vulnerability isn't the technology. It's the assumption that seeing and hearing someone means they're real. That assumption no longer holds. The sooner your family internalizes that, the safer you are.

Set up the password today. Practice the protocol. Make it routine. The next deepfake call might come tomorrow. Or next year. Or never. But if it does, you'll know exactly what to do.

Family gathered around a phone, reviewing a shared password document together
→ Filed under
deepfakevideo callsAI scamsfamily securityvoice cloningimpersonation fraud
ShareXLinkedInFacebook

Frequently asked questions

Ask the caller to perform an action the AI can't predict, like holding up a specific number of fingers or turning their head to show a specific angle. Real-time deepfakes struggle with unexpected physical movements and specific requests.
A family password is a secret word or phrase only your family knows. When someone calls claiming to be in an emergency, you ask for the password. AI can't guess what it doesn't know.
Yes. Deepfake technology works on any video platform. The vulnerability isn't the app—it's the human assumption that seeing someone's face means they're real.
Hang up immediately. Call the person back using a number you already have saved. Don't use any contact information provided during the suspicious call.
No. The defense is behavioral, not technical. Establish verification protocols with your family before a crisis happens, and follow them every time.

You might also like