Share
THREAT REPORT - FAMILY IMPERSONATION

"Hi Mum, I dropped my phone": the text that is not from your child

It arrives from a number you do not recognise. Someone says they are your son or daughter, that their phone is broken or lost, and that this is their temporary number. There is no link to inspect and nothing to hover over. The whole attack is a conversation, and the request for money comes two or three messages later, once you have already replied as a parent.

SafeBrowz Threat Research Security ResearchAugust 2, 20268 min read

There is no broken phone. The new number is the scam.

If a message from an unknown number opens with "Hi Mum" or "Hi Dad" and explains that the sender's phone was lost, stolen or damaged, treat it as a scam until you have spoken to your child on the number you already have for them. This is the family impersonation scam, and it is one of the best documented text frauds in the world. Australia's Scamwatch recorded more than 1,150 victims and A$2.6 million in reported losses in the first seven months of 2022 alone, with victims contacted most often through WhatsApp. The first message almost never contains a link, so there is nothing to scan and nothing to click wrong. The only reliable defence is the callback, and it takes about thirty seconds.

If the conversation does eventually send you a link, SafeBrowz checks it before you open it. Add to Chrome, free Get the free Android app or scan a URL now →

The thread, as it actually arrives

The first message is deliberately small. Something close to "Hi Mum, I dropped my phone in the sink and it is dead, I am on a temporary number for now." Sometimes it is water, sometimes it is a cracked screen, sometimes the phone was left in a taxi. The details change, the shape does not: a parent, a broken phone, a new number, no link.

Notice what is missing. No attachment, no login page, no payment request. Nothing a security tool can inspect, because at this point in the conversation nothing has been sent except a sentence. The attacker is not trying to steal anything yet. They are trying to get you to answer.

And most people answer, because the alternative feels worse. If it really is your daughter with a dead phone and no way to reach anyone, ignoring her is unthinkable. So you reply, usually with her name in the message: "Emma? Is that you?" You have now handed over the one thing the scammer did not have, which is which of your children they are pretending to be.

From there the tone stays warm and slightly harried. There is a bill they cannot pay because their banking app is on the dead phone. A transfer that has to go out today. A friend who lent them money and needs it back tonight. The amount is usually plausible rather than dramatic, a few hundred rather than a few thousand, because a modest figure invites a quick yes instead of a considered no.

Then the bank details arrive, and they belong to a name you do not recognise. There is always an explanation ready for that too: it is a friend's account, a landlord's account, a colleague covering for them. If you push, the story is that the account is new because the old one is locked with the phone. The scammer is not improvising. They have had this conversation hundreds of times and they know which objection you will raise.

Why it works on careful people

The instinct is to assume the victims were not paying attention. The data says otherwise. Scamwatch reported that over two thirds of family impersonation reports came from women over 55, accounting for more than A$1.4 million in losses, and the losses concentrated in the months when the campaign ran hardest, June and July of that year. These are not people who click every link they see. They are people who answered a message from someone they thought was their child.

Three things make it land. The first is that it inverts the usual advice. Everything we are taught about phishing is about links: check the address, hover before you click, look at the domain. This scam sends no link, so all of that training simply does not fire.

The second is the identity handshake. By naming your child first, you do the attacker's research for them. They can now reference a name, and a message that uses your daughter's name reads as though it came from your daughter.

The third is that the pressure is emotional rather than technical. There is no countdown timer and no threatened account closure of the kind you see in a typical scam text. There is just a child who cannot pay a bill, and a parent who can. Urgency built out of love is much harder to argue with than urgency built out of fear.

Since 2025 the pattern has picked up a newer and uglier variant: a short voice note in the conversation. A few seconds of a public clip from social media is enough to produce a usable clone of a young person's voice, which is why hearing what sounds like your child is no longer proof of anything. We covered how that works in detail in our piece on AI voice cloning in family emergency scams. The countermeasure below is the same either way, and it is the reason it is worth learning as a habit rather than as a one-off.

The 30-second check that ends it

You do not need to analyse the message. You need to reach the real person by a route the sender does not control. That is the entire method, and it takes about half a minute.

  • Seconds 0 to 10, do not reply to the new number. Open your contacts and call your child on the number you already have saved. Scamwatch's own advice is exactly this: call the number already stored in your phone and confirm whether it is genuinely out of use. If they answer, the conversation is over.
  • Seconds 10 to 20, if there is no answer, try a second route. Their partner, a sibling, their workplace, a video call, or a message on a different app that was already installed on their real phone. One unanswered call proves nothing on its own. Two independent silent routes are still not proof of an emergency, only of a busy day.
  • Seconds 20 to 30, ask something only they could answer. Not a birthday and not a pet's name, both of which are usually somewhere online. Ask about something shared and unremarkable: what you ate on Sunday, what the neighbour's car looks like, what you argued about last month. A scammer will deflect, change the subject, or push the urgency harder. Your child will simply answer.

If the answer is that you cannot reach them and the money request is still sitting there unanswered, the correct move is to wait, not to send. A real emergency survives a fifteen minute delay. A scam usually does not, because the operator is working a queue and will move on to a parent who replied faster.

Flag the payment link before you act on it

SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus an Android app on Google Play. It is a link checker, so it is useful in this scam at the specific moment a link finally appears: a payment page, a "confirm your details" form, or a fake bank login sent later in the conversation. Paste it, or let the extension check it as the page opens, and you get a plain verdict before you type anything into it. The AI deep scan (Premium, $14.99/year) reads the page itself in over 100 languages, which is what catches a payment page registered this morning.

Chrome Add to Chrome Firefox Add to Firefox Edge Add to Edge Google Play Get it on Google Play

Where a link checker helps here, and where it plainly does not

It is worth being straight about this one, because a security tool that oversells itself on a scam like this is doing the reader a disservice. SafeBrowz runs a 3-layer detection architecture, Local + APIs + AI, and all three of those layers analyse a URL or a page. This scam frequently contains neither.

  • Where it does nothing. A message that says "Hi Mum, I lost my phone" and later asks for a bank transfer to a sort code and account number has no link in it at any point. There is nothing for any link checker, ours included, to examine. No product on the market stops that message. The callback stops it.
  • Where it does help. A large share of these conversations do eventually send something clickable, because a bank transfer to a stranger's account makes some people hesitate. That is when a payment page, a fake bank login or a "verify your identity to release the transfer" form appears, often on a throwaway domain registered days earlier, something shaped like secure-transfer-verify[.]top. Layer 1 checks the URL shape locally before the page renders, Layer 2 cross-references the domain server-side against our 550+ brand database plus Google Safe Browsing, PhishTank and URLhaus feeds, and Layer 3 reads the page itself. A fake bank login is exactly the thing this engine is built for.
  • Where it helps a second time. The same conversation is often the delivery route for an account takeover: a request to forward a six digit code, which is how WhatsApp accounts get stolen and used to run the same scam on the next family. If that step involves a login page, it is checkable.

The honest limit, stated plainly: on the pure no-link version of this scam, a link checker is not the control that saves you. Your own thirty second callback is. We would rather you learn that habit than trust an extension to catch a message that contains nothing to catch.

Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.

If you already sent the money

Speed matters more than order here, and it matters most in the first hours, while the funds may still be sitting in the receiving account rather than moved on.

  • Call your bank immediately and ask them to recall the payment. Describe it as a transfer you made yourself after being deceived, and ask them to contact the receiving bank. In the UK the term for this is authorised push payment fraud, and under the Payment Systems Regulator rules in force since October 2024 banks must reimburse eligible victims, so say the phrase and ask about reimbursement. Elsewhere the term differs, but the request is the same: recall the payment and freeze the receiving account.
  • Keep everything. Screenshot the full conversation, the number it came from, the account name and number you were given, and the timestamps. Do not delete the thread; it is your evidence.
  • Report it. In the UK, report to Action Fraud and forward the scam text to 7726, the free reporting shortcode that reaches the mobile networks. In Australia, report to Scamwatch. In the US, file at reportfraud.ftc.gov and, if money was lost, at the FBI's ic3.gov.
  • Block the number, then warn the family group. These lists are worked through in batches, so if one parent in a family has been targeted, others often are within days. A single message to the group chat is the cheapest protection available.
  • Do not engage with anyone who contacts you afterwards offering to recover the funds. That is a second scam that follows the first, and our walkthrough of what to do after a scam covers the recovery-fraud pattern in full.
🛡 LIVE CHECK

Sent a link by someone claiming to be family?

If the conversation moved from a message to a payment page or a login form, paste the address here first. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

I got a text saying "Hi Mum, I lost my phone, this is my new number". Is it real?

Assume it is not until you have confirmed it by calling your child on the number already saved in your phone. This is the family impersonation scam, documented by Australia's Scamwatch, which recorded more than 1,150 victims and AA$2.6 million in reported losses in the first seven months of 2022, with most victims contacted through WhatsApp. Your real child losing their phone and your real child being impersonated look identical in a text message. Only the callback tells them apart.

There is no link in the message. What is the scammer actually after?

Money, usually by bank transfer, and they get there in stages. The first message only asks you to reply, which confirms the number is live and often gets you to volunteer your child's name. The next messages build a small, plausible emergency, typically a bill that cannot be paid because the banking app was on the broken phone. The request that follows is for a transfer to an account in an unfamiliar name, with a ready explanation for why the name does not match.

They sent a voice note and it sounded like my daughter. Does that prove it is her?

No. Since 2025 these conversations have increasingly included short voice notes, and a few seconds of publicly posted audio is enough to produce a usable clone of someone's voice. A voice that sounds right is no longer evidence. Call the number you already have for them, or ask for a live video call, or ask a question only they could answer from shared memory rather than from anything posted online.

What is the safest question to ask to check it is really them?

Something shared, recent and unremarkable, which is not the same as something secret. Birthdays, pet names and schools are often findable online or guessable. What you ate together on Sunday, what the neighbour's car looks like, or what you disagreed about last month cannot be researched. A genuine relative answers instantly and is usually amused. A scammer deflects, gives a vague answer, or increases the urgency.

Can SafeBrowz stop this scam?

Partly, and it is worth being precise. SafeBrowz checks links and pages, so on the version that contains no link at all it has nothing to inspect, and no link checker does. Where it helps is the later stage many of these conversations reach, when a payment page, a fake bank login or a verification form is finally sent. That is a URL, and our 3-layer engine checks it before you type anything into it. For the no-link version, the thirty second callback is the control that works.

Last updated 2026-08-02

Related SafeBrowz coverage