AI voice scams, and the code word that beats them
A few seconds of audio is now enough to clone a voice convincingly. The defence is not clever technology — it is one agreed word and a habit of hanging up.
Microsoft has been switching passkeys on by default, Google reports over 800 million accounts using them, and most large firms have deployed them. Here is the honest state of play.
A passkey replaces the password with a pair of cryptographic keys. The private half never leaves your device and is unlocked by your fingerprint, face or device PIN. The site holds only the public half, which is useless on its own.
Two consequences follow, and they are the entire point. There is no password for a criminal to steal from a breached database, because none exists. And a passkey is bound to the real website, so a convincing fake login page cannot use it — the phishing page simply does not match, and nothing happens.
That second property is what makes this genuinely different from "a better password". Passkeys do not depend on the user spotting the scam.
The platforms stopped waiting. Microsoft auto-enabled passkey profiles across Entra ID tenants in March 2026, applying defaults to organisations that had not configured their own. Google reports over 800 million accounts using passkeys and Amazon around 175 million. The FIDO Alliance counts roughly 1.3 billion passkey authentications a month, double a year earlier.
On the business side, 87% of US and UK companies have deployed or are actively deploying them. This is no longer an early-adopter question — it is a default that will arrive whether or not you plan for it.
It would be dishonest to pretend this is finished. Apple, Google and Microsoft each store passkeys in their own ecosystem, and moving between them is clumsier than it should be. Somebody with an iPhone and a Windows laptop hits that seam constantly.
The sign-in experience is also inconsistent enough that a lot of people give up at the prompt and click "use password instead", which is why adoption figures look better than real-world usage. Some reports describe adoption as stalling for exactly this reason.
And there is the losing-your-phone question, which is the one everybody asks. The answer is that passkeys sync through your account — iCloud Keychain, Google Password Manager, Microsoft — so a new device restores them. But that makes the security of that account the thing everything else rests on, and it needs to be locked down properly.
At home, turn passkeys on for the accounts that would ruin your month: your email above all, then your bank, then anything with a card stored. Email first is not arbitrary — whoever controls your email can reset everything else, so it is the master key whether you think of it that way or not.
In business, do not attempt a big-bang switch. Enable passkeys alongside existing sign-in, start with the accounts that have the most damaging blast radius — finance, admin accounts, anything with payment authority — and let the rest follow.
Whatever you do, do not remove your password fallback before your recovery process actually works. Getting locked out of your own systems is a self-inflicted outage, and we have seen it happen to businesses that moved faster than their documentation.
Where the facts in this article came from. If any of it goes out of date, tell us and we will correct it.
A few seconds of audio is now enough to clone a voice convincingly. The defence is not clever technology — it is one agreed word and a habit of hanging up.
The NCSC recorded 204 nationally significant incidents in a year, up 130%. Attackers are automating with AI, and small firms are targeted precisely because they are somebody's supplier.
Copilot+ machines need a 40+ TOPS neural processor, 16GB RAM and 256GB storage. The AI features are real, but the reason to buy one is probably the battery.
Tell us what you are running and we will tell you honestly whether this affects you, what it would cost to put right, and how quickly we can do it. No hard sell.
Open 9am–9pm, 7 days a weekSpeak to a real, local engineer — call us straight away, or leave your number and we'll ring you back.