Privacy / Analysis
How AI Changed Scams
The tells everyone was taught — bad grammar, obvious fakes — are gone. The defences that survive are about process rather than perception.
The advice for spotting fraud was based on production limitations: scammers wrote badly, faked images poorly, and could not sound like someone you know. Those limitations are gone.
What actually changed
Written fraud is now fluent. Perfect grammar, correct branding, appropriate register, in any language. The "bad English" tell is finished.
Personalisation is cheap. Messages referencing your employer, your recent purchase, your colleagues' names, drawn from public sources and breach data. What required manual research is now automated.
Voice cloning works from seconds of audio. A few seconds from a social media video is enough to produce a convincing imitation. This is used in calls claiming a family member is in trouble.
Video is arriving. Real-time face and voice replacement in video calls has moved from demonstration to documented use in corporate fraud, including cases where employees transferred large sums after a video call with what appeared to be executives.
Fake businesses at scale. Complete websites, product photography, reviews and support pages, generated in an afternoon.
Romance and long-con fraud at volume. Sustained convincing conversation with many targets simultaneously.
Why the old advice fails
"Look for spelling mistakes." Gone.
"Check the images look real." Gone.
"You would recognise their voice." Not reliably.
"Video call them to check." Increasingly not sufficient.
"Look for the sender's name." Display names are arbitrary and caller ID is forged trivially.
Perception-based defences are failing because the production quality now exceeds what perception can assess.
What still works
The defences that survive are structural. They do not depend on judging whether something looks real.
Verify through a channel you chose. Hang up and call back on a number you looked up. Contact the person on a different service. Walk to their desk. This defeats every impersonation regardless of quality, because the attacker does not control the channel you initiate.
Never authenticate from a link in a message. Go to the service the way you normally do.
A family verification word. Agreed in advance, used when someone calls in distress asking for money. Costs nothing, defeats voice cloning entirely, and is the single most effective personal measure against the family emergency scam.
Process for money movement. Any payment above a threshold requires a second person and a callback on a known number. This is the control that would have prevented the documented corporate deepfake frauds, and it does not require anyone to detect anything.
Delay. Every fraud requires urgency, because urgency prevents verification. Any request that cannot wait an hour for a check is suspect for that reason alone.
No legitimate institution asks you to move money to keep it safe. No exceptions.
No legitimate institution asks for a code they just sent you.
Phishing-resistant authentication. A passkey or hardware key does not authenticate to the wrong site, so a perfect replica fails anyway. This is the strongest available technical defence and it is available now.
The specific scenarios to prepare for
The family emergency call. A voice that sounds like your child or parent, in distress, needing money urgently. Agree the verification word now.
The executive request. An email or call from a senior person requesting an urgent unusual payment. The process control handles it.
The support call. Someone claiming to be from your bank or a technology company, warning of a problem. Hang up, call back on a known number.
The investment introduction, developed over weeks of friendly conversation.
The job offer requiring you to buy equipment or process payments.
What to tell people who are vulnerable
The perception advice is worse than useless now, because it teaches people to trust things that look right.
Teach one rule: if someone contacts you about money, hang up and call the organisation or person back on a number you find yourself.
That single habit defeats nearly all of it and requires no ability to detect anything.
Setting up the family verification word
The single most effective personal measure against voice cloning, and it takes one conversation.
Choose something not guessable and not public. Not a pet's name, not a birthday, not anything on social media.
Tell everyone who might be called about you — parents, children, siblings, anyone who would send money if you sounded desperate.
Explain what it is for without alarming anyone: if someone calls sounding like me asking for money urgently, ask for the word.
Agree that the answer is always to hang up and call back if the word is not given, or if there is any hesitation.
Practise it once, so nobody freezes when it matters.
Include the reverse case. You should expect to be asked for it too.
Older relatives are the primary target of these calls, and they are also the group most likely to be embarrassed about being uncertain. A pre-agreed word removes the need for anyone to judge whether a voice sounds right, which is the thing that no longer works.