Urgent warning over ‘Hi Mum’ WhatsApp scam: Fraudsters are using AI to mimic children’s voices to steal millions of pounds from unsuspecting parents

Urgent warning over ‘Hi Mum’ WhatsApp scam: Fraudsters are using AI to mimic children’s voices to steal millions of pounds from unsuspecting parents

For millions of people, WhatsApp is a vital connection to friends and family around the world.

But cybersecurity experts have issued a fresh warning over an insidious scam which has already duped users out of almost half a million pounds since the start of 2025.

In the so-called ‘Hi Mum’ scam, criminals impersonate a family member to trick their victims into sending them money.

Now, fraudsters are even using AI voice impersonation technology to dupe their victims.

The scam begins by sending a WhatsApp message saying ‘Hi Mum’ or ‘Hi Dad’ as the sender claims they have lost their phone and have been locked out of their bank account.

Having won their target’s trust, the scammer then asks the person to transfer them some money to help cover rent or buy a new phone.

To make things even more realistic, the scammers may use AI to generate voice messages that impersonate the voice of their victim’s child.

Jake Moore, global cybersecurity advisor at ESET, told MailOnline: ‘With such software, fraudsters can copy any voice found online and then they target their family members with voice notes that are convincing enough to make them fall for the scam.’

Cybersecurity experts have issued a fresh warning over the WhatsApp ‘Hi Mum’ scam which has cost users almost half a million pounds since the start of the year 

Although it is known as the ‘Hi Mum’ scam, this phishing tactic doesn’t always involve posing as children.

By using publicly available information on social media, scammers learn enough about their target’s family to choose the best person to impersonate.

In some cases, scammers might claim to be a close personal friend of the target or even their parents.

Research conducted by Santander found that scams pretending to be someone’s son were the most successful, followed by daughters, and then mothers.

The scam usually begins with a text from an unknown number claiming to be someone close to the recipient.

The sender might claim that they have lost their phone and are using a friend’s phone for the time being, which is why their number isn’t familiar.

If the target does reply, the fraudster will try to enter into a conversation about generic details they might have been able to learn from social media.

Once they have their target’s confidence, the scammer will suddenly claim that they urgently need financial help.

In the 'Hi Mum' scam, criminals send a message pretending to be a family member or close personal friend

Once they have gained the target's trust, the scammer will claim they urgently need money

In the ‘Hi Mum’ scam, criminals send a message pretending to be a family member or close personal friend. Once they have gained the target’s trust, the scammer will claim they urgently need money 

What to do if you receive a message asking for money

STOP: Take five minutes before you respond.

THINK: Does this request make sense? Are they asking you to share a PIN code which they have had sent to you? Are they asking for money? Are they rushing you into taking action? 

CALL: Make sure that it really is your friend or family member by calling them directly, or asking them to share a voice note. 

Source: WhatsApp  

The sender will insist that their normal bank account cannot be accessed for some reason, and demand that the money be sent to an unfamiliar account.

To ensure their targets don’t take the time to think, the scammer will push them to act straight away by creating a compelling story.

Mr Moore says: ‘Scammers are increasingly getting better at manipulating people into doing as they ask as the story can often sound convincing and legitimate.’

While it might be easy to ignore a fake text, scammers are now using cutting-edge AI technology to create extremely convincing voice messages tailored for their victims.

‘Scammers are also starting to take advantage of impressive generative AI technology where cloning any voice is now simple – even in a matter of moments,’ says Mr Moore.

Using recordings of someone’s voice taken from social media or other sources, it is easy to make a convincing duplicate.

Mr Moore says that he was even able to convince his own mother that an AI-generated recording of his voice was the real thing.

Worryingly, these techniques are now becoming increasingly common.

A clear sign of the scam is that the sender will ask for the money to be sent to an unfamiliar bank account rather than one associated with the person they are impersonating

A clear sign of the scam is that the sender will ask for the money to be sent to an unfamiliar bank account rather than one associated with the person they are impersonating 

How to report a scam text

If you receive a scam text or WhatsApp message you can report it by:

  • Forward the message to 7726
  • Call Action Fraud on 0300 123 2040
  • Report it online at this link 
  • Send a screenshot of the message to the National Cyber Security Centre at report@phishing.gov.uk

Chris Ainsley, head of fraud risk management at Santander, says: ‘These scams are evolving at breakneck speed.

‘We’re hearing of instances where AI voice impersonation technology is being used to create WhatsApp and SMS voice notes, making the scam seem ever more realistic.’

Since the start of 2025, Santander says that 506 of these scams have already tricked WhatsApp users out of £490,606 ($651,230).

In April alone, 135 successful scams cost WhatsApp users £127,417 ($169,133).

If you do get a text from a friend or relative, it is important that you take the proper precautions to ensure you are sending it to the right person.

Mr Moore says: ‘It goes without saying but never send money to any new account without doing your due diligence – even if the narrative sounds plausible.

‘If you ever receive a suspicious message claiming to be a loved one requesting sensitive or financial information, call the person they are claiming to be on the number you already have stored in your phone first.’

Likewise, due to the increasing risk of AI fakes, Mr Moore recommends creating a ‘code word’ within your family for emergencies to prove you are speaking to the right person.

Experts warn that criminals are now using AI to create fake voice notes pretending to be the children of their victims. These are extremely convincing and can be made easily using voice recordings found on social media (stock image)

Experts warn that criminals are now using AI to create fake voice notes pretending to be the children of their victims. These are extremely convincing and can be made easily using voice recordings found on social media (stock image)

Mr Moore says you should ensure this is ‘not obvious or something that could be found on social media too’.

A spokesperson for WhatsApp told MailOnline: ‘We want to make WhatsApp the safest place for private, personal communication, which is why we protect your personal conversations with end-to-end encryption.

‘However, just like regular SMS or phone calls, anyone who has your phone number may attempt to contact you.’

If you receive a message on WhatsApp from someone not in your contacts, you will get a notification in the message.

This will let you know if you have group chats in common with the number or if they are texting from a different country.

You also won’t be able to open any links from a number that isn’t in your contacts since these could contain malware or connect you to further scams.

If you do believe the message is a scam, you can report it via the WhatsApp app by forwarding the message to the number 7726, which goes to the telephone network providers.

In the case that you have transferred money or given out your details, call your bank immediately as they may be able to stop the transaction.

CHOOSING A SECURE PASSWORD

According to internet security provider Norton, ‘the shorter and less complex your password is, the quicker it can be for the program to come up with the correct combination of characters. 

The longer and more complex your password is, the less likely the attacker will use the brute force method, because of the lengthy amount of time it will take for the program to figure it out.

‘Instead, they’ll use a method called a dictionary attack, where the program will cycle through a predefined list of common words that are used in passwords.’

Here are some steps to follow when creating a new password:

DO:

  • Use a combination of numbers, symbols, uppercase and lowercase letters
  • Ensure that the password is at least eight characters long
  • Use abbreviated phrases for passwords
  • Change your passwords regularly
  • Log out of websites and devices after you have finished using them

DO NOT:

  • Choose a commonly used password like ‘123456’, ‘password’, ‘qwerty’ or ‘111111’
  • Use a solitary word. Hackers can use dictionary-based systems to crack passwords
  • Use a derivative of your name, family member’s name, pet’s name, phone number, address or birthday
  • Write your password down, share it or let anyone else use your login details
  • Answer ‘yes’ when asked to save your password to a computer browser

 

0 Shares:
Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like