• 2 min read
AI voice scam drains Hong Kong man of $1.27 million
Scammers used WhatsApp AI voice messages to steal $1.27 million from a Hong Kong man. A family codeword can help expose impersonators.

Image: TechRadar
A Hong Kong man lost HK$10 million ($1.27 million) after scammers used WhatsApp voice messages to impersonate his father, according to reporting cited by TechRadar. The fraud shows how AI-generated audio can turn a familiar voice into a highly convincing payment request.
According to Hong Kong police’s CyberDefender platform, the criminals first requested an urgent transfer of HK$1 million ($127,000). The message persuaded the victim because the sender’s “voice and manner of speech” matched his father’s, the South China Morning Post reported. The scammers repeated the tactic until the victim had transferred his entire savings.
“Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.”
The reporting does not establish how the criminals generated the voice, whether they used recordings of the father, or whether anyone has been arrested. It also does not include an independent technical examination of the audio. What is clear is that the victim treated a familiar voice as proof of identity—and paid the price.

Recommended reading
Shield AI tests Hivemind swarm with Taiwan drone boats
The codeword defense against AI voice scams
Experts cited by the BBC recommend that families agree on a secret codeword for emergencies. A caller who has copied someone’s voice may sound authentic, but is unlikely to know a private phrase shared only by the family.
The codeword should be easy to remember but difficult to guess; the BBC suggests using an inside joke. Scammers often create time pressure to trigger panic and prevent victims from checking the request, so taking a pause is part of the defense.
Philadelphia lawyer and anti-scam activist Gary Schildhorn identified three warning signs:
- Pressure to act immediately
- A request for difficult-to-trace payment, such as cash, cryptocurrency, or gift cards
- Attempts to control who the victim can speak to during the call
If any of those appear, stop the conversation and contact the supposed family member using a known phone number—not the number or account provided in the message. Hong Kong police also advise enabling two-factor authentication and reviewing connected devices, removing any that look suspicious.
A secret codeword is not a technical fix, but it is a practical identity check that works precisely where synthetic audio is strongest: exploiting trust. The facts support treating voice alone as insufficient evidence for a financial transfer; the missing details about the attack mean the codeword and an independent callback remain the most concrete safeguards reported here.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


