Overview
Artificial intelligence can make impersonation scams more convincing. A scammer may imitate a person's voice, create altered audio or video, reproduce a familiar writing style, or use personal information from social media to make an urgent request sound believable.
A safe word, code phrase, or verification phrase is a shared secret that trusted people can use to confirm identity during an unexpected or high-risk situation. It can help families, close friends, roommates, and other trusted groups pause and verify a request before sending money, sharing information, or taking another sensitive action.
A safe word is an additional check, not proof by itself. It does not replace calling a known number, contacting another trusted person, using MFA, or following established financial and business controls. A safe word may also be exposed if it is stored in a compromised message or shared too broadly.
How It Works
The group chooses a word or short phrase that:
- Is easy for authorized people to remember.
- Is difficult for someone else to guess from social media, public records, or ordinary conversation.
- Is not already used as a password, PIN, security-question answer, or account-recovery code.
- Is shared through a trusted method rather than posted publicly or sent in an insecure group message.
The group also agrees when to use it. Examples include:
- An urgent request for money, gift cards, cryptocurrency, a bank transfer, or access to an account.
- A call or message claiming that someone has been arrested, hospitalized, stranded, kidnapped, or otherwise needs immediate help.
- A request from an unfamiliar phone number or new account that claims to belong to a known person.
- A voice or video call that looks or sounds familiar but cannot be verified normally.
- A request to share sensitive personal, financial, work, or university information.
- A message from a supposed supervisor, coworker, vendor, or family member asking you to bypass a normal process.
When a request meets the agreed conditions, ask for the safe word without giving hints. If the person cannot provide it correctly, stop the interaction and verify through another trusted method.
Choosing and Using a Safe Word
- Choose something unrelated to public information. Avoid names, pets, birthdays, schools, addresses, sports teams, favorite places, or phrases that appear in posts or messages.
- Do not reuse a credential. A safe word should not be a password, MFA code, PIN, recovery code, or answer used for an account.
- Share it carefully. Agree on the phrase in person or through another method the group considers trusted. Do not label it “safe word” in an unprotected contact, note, or chat.
- Define the trigger. Decide which requests require the phrase so everyone knows when to pause.
- Do not provide clues. Ask the other person to state it. Do not say the first letter, category, or part of the phrase.
- Use a separate verification channel. End the call or conversation and contact the person through a known phone number, existing conversation, or trusted third party.
- Create a backup plan. Decide whom to contact when the person cannot be reached and what to do during a genuine emergency.
- Change the phrase if it may have been exposed. Replace it after accidental disclosure, a compromised account, a lost device, or a change in group membership.
- Keep the group small. A phrase shared broadly is harder to protect and easier to disclose accidentally.
- Practice the process. Make sure everyone understands that pausing to verify is expected and is not a sign of distrust.
Do not trust a request merely because the caller knows personal details or sounds like someone you know. Scammers may obtain names, relationships, travel details, photographs, audio, or prior messages from public sources or compromised accounts.
Warning Signs
An impersonation request deserves additional verification when it:
- Creates fear, urgency, or emotional pressure.
- Says you are the only person who can help.
- Demands secrecy or tells you not to contact family, friends, coworkers, law enforcement, a bank, or UM.
- Requests gift cards, cryptocurrency, wire transfers, cash, payment applications, account credentials, or MFA codes.
- Comes from an unfamiliar number, new account, or unusual communication channel.
- Claims the person's normal phone is broken, lost, confiscated, or unavailable.
- Uses a voice, video, photograph, or writing style as the main proof of identity.
- Refuses a callback, cannot answer a verification question, or gives the wrong safe word.
- Asks you to bypass an established approval, purchasing, payroll, human-resources, financial, or information-security process.
- Involves another person who claims to be a lawyer, police officer, doctor, technician, executive, or government representative and pressures you to act immediately.
A genuine emergency can still be urgent. Verification helps direct assistance to the correct person and prevents a scammer from using urgency to control the response.
How to Protect Yourself
- Pause before acting. Do not let urgency prevent independent verification.
- Call a known number. End the unexpected interaction and contact the person using a number already in your contacts or obtained from a trusted source.
- Contact another trusted person. A relative, friend, coworker, supervisor, or department may be able to confirm the person's location or situation.
- Use the safe word as one check among several. Combine it with a callback, known details, established procedures, and other verification.
- Do not send money while the identity is uncertain. A convincing voice or video does not make an unusual payment request legitimate.
- Do not share passwords or MFA codes. A trusted person should not need them to receive help.
- Limit public information that supports impersonation. Review social-media privacy settings and avoid posting detailed travel, relationship, contact, or routine information unnecessarily.
- Preserve suspicious messages. Save relevant phone numbers, usernames, payment instructions, audio, video, and messages before blocking or reporting the sender.
- Report the account or message. Use the platform's official reporting process for impersonation, fraud, or compromised accounts.
What You Should Do at UM
A personal safe word must not be used to bypass UM identity-verification, purchasing, payroll, hiring, records, data-access, or financial controls. For university business, follow the established process and independently verify unusual requests through official UM contact information.
If a call, email, text, Teams message, social-media message, audio clip, or video appears to come from a UM supervisor, coworker, student, executive, vendor, or office and asks for money, account access, university data, credentials, or an exception to normal procedure:
- Do not act on the request until it is verified.
- Contact the person or office using an official UM website, the UM directory, a known phone number, or a new message to a verified UM address.
- Do not share your password, an MFA code, or an approval prompt.
- Contact the UM IT Helpdesk or UM Information Security Office when the request involves a UM account, device, message, identity, data set, or business process.
If the request arrived by email in your UM mailbox and appears fraudulent, use Outlook's Report Message tool and report it as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.
If you sent university information, approved a payment, entered a UM password, shared an MFA code, or installed software because of an impersonation request, contact the UM Information Security Office, UM IT Helpdesk, and the appropriate UM business office through trusted channels.
For a personal emergency request, call the person directly using a known number and contact another trusted person who may know their location. If independently verified information indicates an immediate threat to someone's safety, contact emergency services through a trusted number.
Additional Questions
For an impersonation request involving a UM account, UM device, university identity, university information, or a UM financial or business process, contact the UM IT Helpdesk and the UM Information Security Office. Involve the appropriate UM financial, human-resources, purchasing, student-services, or business office where applicable.
For a personal impersonation or emergency scam:
- Contact the person being impersonated and other trusted contacts through known communication channels.
- Report the fraudulent account or message to the phone carrier, email provider, social-media platform, or messaging service involved.
- Contact your bank, credit union, card issuer, or payment provider immediately if money or financial information was involved.
- Report consumer fraud to the Federal Trade Commission. Internet-enabled fraud can also be reported to the FBI's Internet Crime Complaint Center.
Additional Resources