AI Voice Cloning Scam UK: A Call That Isn't Them
A call sounds exactly like your relative but something feels off? AI can clone a voice from a short public clip — here's how to check safely.
Fake support calls, virus pop-ups and remote-access requests: how UK tech support scams work, how to shut one down, and what to do if you granted access.
Tech scams may seek direct payment, remote control, credentials or access to accounts. A pop-up announces that your PC is infected. A caller reports a fault on your line. A sticker on a parking meter sends you to a payment page that is not the operator's. A voice on the phone sounds exactly like your daughter. In every version the criminal is borrowing something you already trust — a brand, a network name, a familiar voice.
Technology companies do contact their customers, so the channel settles nothing. The request is what gives it away: remote access to your device, a payment to fix a problem you never reported, a security code read aloud, or credentials typed into a page you did not navigate to yourself. Not sure about a pop-up, call or message? Paste it into our free AI scam checker for an automated second opinion. It is a fallible assessment, not a verdict, so still verify the contact independently.
The unsolicited support call. A caller claims a virus, a fault or a refund and works towards remote access or a payment. Microsoft says it does not make unsolicited calls or send unsolicited messages to provide technical support, and that genuine Microsoft error and warning messages do not include telephone numbers — the basis of our Microsoft support scam guide. HP says it does not provide unsolicited technical support, covered in our printer support scam guide. Broadband and phone providers are impersonated the same way, as our guide to BT, Sky, Virgin Media and Openreach impersonation calls explains. Do not stretch those company statements into a belief that no technology company ever telephones anyone — many do, for genuine reasons.
The browser pop-up. A full-screen warning, often with an alarm sound and a number to ring, appears while you are browsing. Apple's guidance is to treat such browser alerts as fraudulent; our Apple tech support scam guide covers what to do instead of calling. A number displayed in a warning is a number the attacker chose, so dialling it is not the same as contacting the company.
The environmental trick. Here the attacker changes something in the world rather than contacting you: a code sticker placed over a genuine one, explained in our QR code 'quishing' guide, or a wireless network that copies a venue's name, covered in our fake Wi-Fi hotspot guide.
The attack on your identity rather than your device. Criminals take over your mobile number to intercept security codes — see SIM swap fraud warning signs — or use AI to imitate someone you know, in voice cloning scams and in sextortion using AI-generated images or video. Cifas recorded a 38% rise in unauthorised SIM swaps in its Fraudscape 2026 report, which also logged a record 444,993 cases filed by its members during 2025; more dated figures are in our UK scam statistics research.
AnyDesk, TeamViewer, Quick Assist and Chrome Remote Desktop are legitimate products, used every day by real IT departments and by trusted family, friends and workplace IT. Installing one is not inherently a scam. Remote-access tools are legitimate; the danger is granting control to a person or service you have not independently authenticated. An unsolicited call is a major warning, but so is a support number taken from a pop-up, message or search advert. Start from the vendor's official site or an existing trusted support channel.
The exposure is the whole point. Google says a person given Chrome Remote Desktop support access can have full access to apps, files, emails, documents and history. Microsoft's Quick Assist warning is specifically about someone claiming to be Microsoft Support: allow that helper in only if you started the contact with Microsoft Support yourself. TeamViewer says it does not provide remote-support services itself, so a caller presenting themselves as 'TeamViewer support' deserves immediate suspicion. Our remote access scam guide sets out what to do the moment you realise access has been granted.
Send suspicious emails to report@phishing.gov.uk, and a suspicious SMS text can be forwarded to 7726 free of charge. Report money lost or details shared to Report Fraud (formerly Action Fraud) at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland, or Police Scotland on 101 in Scotland. Tell the impersonated company through its official website, and report a tampered physical code to whoever owns the site, such as the council or car park operator. For consumer-rights help, use the service for your nation: Citizens Advice in England and Wales on 0808 223 1133, Advice Direct Scotland in Scotland on 0808 800 9060, or Consumerline in Northern Ireland on 0300 123 6262.
A call sounds exactly like your relative but something feels off? AI can clone a voice from a short public clip — here's how to check safely.
Criminals can use AI-generated sexual images or video in sextortion. Stop contact, do not pay, preserve evidence and use the correct UK support route.
A QR code sticker looks slightly different from the one next to it? That mismatch is the clearest sign of a tampered parking or payment code.
Suddenly lost mobile signal with no clear reason why? Here's what a SIM swap fraud attempt looks like, and exactly how to respond fast.
An “evil twin” copies a legitimate Wi-Fi name. Ask the venue for the correct network and prefer mobile data for sensitive activity.
Scammers impersonate UK broadband providers or Openreach, then ask for remote access, payment or security details. How to check safely.
Got a pop-up or call saying your iPhone or Mac is infected and Apple support needs access? How to spot an Apple tech support scam and report it.
Remote-access tools are legitimate but can expose apps, files and banking when granted to a scammer. Disconnect, contact the bank and secure the device.
An unsolicited caller or pop-up claims a printer fault and asks for remote access or payment. HP says it does not provide unsolicited technical support.
Got a call or pop-up saying your PC is infected and Microsoft needs remote access? How to spot a Microsoft support scam and report it.
Microsoft says it does not make unsolicited calls or send unsolicited messages to provide technical support, and that its genuine error and warning messages do not include telephone numbers. Apple's guidance is to treat browser alerts claiming your device is infected as fraudulent. That does not mean no technology company ever telephones a customer, so judge any contact by what it asks for — remote access, a payment or a security code are the warning signs, whatever name is used. A number from a pop-up or search advert is no safer just because you dialled it, and an official app is no safer if an unexpected caller is directing what you approve in it.
No. They are legitimate remote-access tools, used routinely by genuine IT support teams and by trusted family, friends and workplace IT. The danger is granting control to a person or service you have not independently authenticated — which includes a helper reached on a number from a pop-up, message or search advert, not only an unsolicited caller. Microsoft's Quick Assist warning is specifically about someone claiming to be Microsoft Support: allow that helper in only if you started the contact with Microsoft Support yourself. TeamViewer says it does not provide remote-support services itself, so a caller presenting themselves as 'TeamViewer support' deserves immediate suspicion.
End the session and disconnect the device from the network, then remove or disable the remote-access application, update the operating system and security software, and run a security scan. From a different, trusted device, change your email password first, then banking and shopping, turn on two-step verification, revoke unfamiliar sign-in sessions, app passwords and connected applications, and check your email forwarding and account-recovery settings. Review bank and card activity from that trusted device, and contact your bank on the number on your card or by dialling 159 if money may be exposed. If the helper had administrative access, installed software you cannot identify, or access seems to persist, get trusted technical help and consider a full reset. Then report it to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland, or Police Scotland on 101 in Scotland.
Indirectly, yes. A code sticker placed over a genuine one can send you to a convincing but fraudulent payment page. An evil-twin hotspot copies a trusted network name: it can steer users towards phishing and expose unencrypted traffic or connection metadata, while HTTPS limits direct reading of protected page content. Inspect a code's destination without opening it where your device offers a preview or long-press option, ask venue staff to confirm the exact network name, prefer mobile data for sensitive tasks, and do not treat a VPN as protection from a fraudulent site.
Treat it as unverified. AI can clone a recognisable voice from recordings of that person speaking, so a familiar voice is not sufficient evidence of identity on its own, particularly when the call combines an emergency with an urgent payment. Hang up and ring the person back on the number you already have saved, or check with another family member. Agreeing a private family codeword in advance gives you a quick way to confirm a genuine call later.