AI Deepfakes Fuel Kidnap and Fake Doctor Scams

Biometric Update · High sophistication
Last updated August 1, 2026

A U.S. Senate hearing highlighted how criminals are using AI to make classic scams more believable, including voice cloning and fabricated “trusted” identities. One victim reported a phone-based “kidnapped daughter” deepfake that drove her to send cash, while a doctor described deepfake ads using his likeness to sell a fake medical product.

How the attack worked

Testimony described at a U.S. Senate hearing showed two distinct AI-enabled fraud patterns hitting different targets. In one case, a 64-year-old woman received a call from a man claiming he had kidnapped her daughter. He put a crying voice on the line that sounded exactly like her daughter's, then threatened violence unless she sent money. For 5.5 hours the caller controlled her movements by phone, directing her and her husband to multiple stores around the San Francisco Bay Area to transfer cash, ultimately resulting in $5,400 sent.

In a separate case, scammers took footage from a physician's YouTube channel and combined it with an AI-generated likeness and voice of a colleague, celebrity images, and copied media logos to build advertisements for a fake 'miracle' lipedema cream. Some patients bought the product before learning the endorsement was fabricated.

Why it succeeded

Both scenarios relied on emotions that predate AI: fear, urgency, and trust in authority. What changed is how cheaply and convincingly the 'evidence' behind those emotions can now be produced. A cloned voice that sounds exactly like a family member, or a doctor's face and voice paired with copied media logos, gave victims signals that used to reliably indicate authenticity. The kidnapping scam also used a control tactic, keeping the victim on the phone continuously, which prevented her from pausing to verify the claim independently.

What to watch for

  • Callers who create extreme urgency around a family emergency and discourage hanging up or calling back
  • Requests to move cash between multiple locations or send money quickly to an unfamiliar destination
  • Advertisements using a recognizable doctor's face, celebrity imagery, or media logos to promote a product, especially one framed as a 'miracle' cure
  • Endorsements or claims that cannot be verified on the person's official channels
  • Takedown-resistant scam content, where removed ads or sites reappear in new versions shortly after being reported

Building resistance

  • Establish a private family code word for emergencies and verify unexpected requests through a known telephone number rather than the number that initiated contact, since hearing a familiar voice is no longer enough
  • Train staff and customers to treat 'stay on the line' pressure combined with threats as a major red flag
  • Encourage skepticism toward ads using authority signals like doctor faces, media logos, or official-looking branding, and verify endorsements through official channels before buying
  • Promote fast reporting to banks and law enforcement, since recovery options such as the FBI's Recovery Asset Team are far more effective when cases reach them quickly

Key findings

  • A victim received a call from a man claiming he had kidnapped her daughter and used a crying voice that “sounded exactly like her daughter’s.”
  • The scammer controlled the victim’s movements “for 5½ hours,” directing her to move between stores to transfer cash, resulting in $5,400 sent.
  • A physician reported scammers used his YouTube footage plus AI-generated likeness/voice and copied media logos to create ads for a fake “miracle” medical cream.
  • Witnesses emphasized that AI doesn’t change the emotions exploited (fear/urgency), but makes “evidence” (voices, faces, seals, phone numbers) easier to fabricate at scale.
  • A recommended defense was a family code word and verifying emergencies through a known number, because “Hearing a familiar voice is no longer enough.”

Who’s being targeted

  • Commonly targeted roles: All employees (deepfake awareness), Executives and administrative staff, Finance and payments teams, Customer support / call center staff, Healthcare staff (brand/identity impersonation awareness).
  • Affected industries: Consumer / household victims (older adults), Banking and payments, Healthcare (patient scams and physician impersonation), Online advertising and social media platforms.
  • Attack channels: vishing, website.
  • Impersonated: Kidnapper holding a family member (and a voice-cloned family member), A real physician (and a colleague) plus copied media logos/celebrity imagery.

Red flags to watch for

  • Caller keeps the target on the phone and “controlled her movements by phone” to prevent independent verification
  • High-pressure threats of violence and urgency to pay immediately
  • Refuses or discourages calling the family member back directly on a known number
  • Uses “copied media logos” and celebrity images to manufacture credibility
  • Deepfake video/voice claiming endorsements that can’t be verified on the physician’s official channels
  • Rapid reappearance of takedowned ads/sites (“each removal was followed by another version”)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake kidnapping scam work?

A caller told a 64-year-old woman he had kidnapped her daughter and played a crying voice that sounded exactly like her, then kept her on the phone for 5.5 hours directing her to move cash between stores, resulting in $5,400 sent.

How was a real doctor impersonated in an ad scam?

Scammers combined footage from a physician's YouTube channel with an AI-generated likeness and voice of a colleague, celebrity images, and copied media logos to advertise a fake 'miracle' lipedema cream.

Why is verifying a familiar voice no longer enough?

Because familiar signs of authenticity like a loved one's voice, a doctor's face, or a bank's phone number can now be generated or manipulated cheaply and at scale, so a callback to a known number or a family code word is needed to confirm identity.

What should someone do if they suspect they sent money to a scammer?

Report it quickly, since the FBI's Recovery Asset Team can freeze roughly half the money at risk when cases reach it quickly, but recovery odds drop sharply once time passes.

Read the video transcript

Imagine this: your phone rings, a man says he’s kidnapped your daughter, then you hear her crying voice… and it sounds exactly like her. This really happened. For five and a half hours, the caller kept her on the line, moving her between stores to send $5,400 in cash transfers, threatening murder if she hung up. Same tech, different scam: a real doctor’s YouTube clips were turned into a deepfake video ad, complete with copied media logos, selling a fake 'miracle' medical cream that patients actually bought. Here’s the move: if you get an urgent, emotional call like this, hang up and call back on a number you already know, family, doctor, bank. Hearing a familiar voice is no longer enough.

Similar attacks

AI Vishing Works Because Scripts Persuade

AI Vishing Works Because Scripts Persuade

Researchers tested AI and human voice scam calls and found people comply mainly because the caller’s script is persuasive, not because the voice sounds…

July 17, 2026
FaceTime Spoof Calls Steal Codes and Money

FaceTime Spoof Calls Steal Codes and Money

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

July 17, 2026