Security Scams: how they work and what to do if you fall for one
AI powered scams: what actually changed and what did not
Cloned voices, flawless phishing text and fake video calls: which AI scam threats are real today, which are overstated, and the verification habits that survive all of them.
The short answer
- AI made scams cheaper, more fluent and more personal, but it did not change what a scam needs from you: speed, secrecy and an unusual payment route.
- Bad grammar is no longer a warning sign, so any defense built on spotting a clumsy message has already stopped working.
- Voice cloning is real and cheap, and a cloned voice copies how someone sounds without knowing anything they know.
- Deepfaked video calls exist but are mostly used against company finance teams rather than households.
- The habit that beats every version of this is verifying on a channel you chose: hang up, and call back on a number you already had.
- A family code word and a callback rule work when individual vigilance fails, because they do not depend on how calm you are.
Artificial intelligence changed the production side of fraud, not the structure of it. A scammer can now write flawless English in any language, generate a usable copy of a voice from a short clip of someone speaking, and run thousands of personalized conversations at once instead of a handful. What has not changed is the ask. Every one of these scams still ends with urgency, secrecy, and money or a login moving through a channel you did not choose. That is why the defense that still works is not spotting the fake. It is checking through a route you picked yourself, which makes the quality of the fake irrelevant.
What AI genuinely changed
Five things got cheaper or better, and each one has a different answer.
Volume. Writing a convincing message used to take a person time. Generating five hundred variants of it now takes seconds, so the economics that once reserved good scams for valuable targets no longer apply.
Language. The broken grammar people learned to watch for was never a security feature. It was a side effect of someone writing in a language they did not speak well. Translation is now fluent and idiomatic, including regional register, so a scam aimed at a British reader says car park and a scam aimed at an American reader says parking lot.
Personalization. Public details about you (employer, job title, recent posts, your manager's name, your child's school) can be gathered and stitched into a message automatically. The research step that made spear phishing expensive is the step that got automated, so ordinary people now get messages full of things that are genuinely true about them.
Voice. A short recording is enough to produce new speech in someone's voice, including the pauses and breathing that make a call feel real. That turns the old grandparent scam, which relied on a panicked voice being hard to recognize, into something that sounds correct from the first word.
Live video. Face and voice replacement can now run during a call rather than only in a finished clip. It is still fiddly and compute hungry, and shows up mainly in corporate payment fraud rather than scams aimed at households.
What did not change at all
Fraud has hard constraints that no amount of generated text removes. The attacker needs four things, and all four leave marks.
They need the money somewhere they can keep it, which means a route that is hard to reverse: a transfer you push yourself, a wire, gift card codes, crypto, a payment app. They need you to act inside a short window, before the feeling wears off. They need you not to check with anyone, so the matter is always confidential or embarrassing or too urgent for that. And they need you off your normal procedure, which is why the conversation moves to a personal number or a one time exception.
None of those four are about wording. They are structural, because the crime does not work without them. A cloned voice asking for something ordinary through the usual channel is not a threat. A cloned voice asking for something unusual, quickly and quietly, is the whole scam, and it was the whole scam before voices could be cloned.
Which AI threats are real today
Not everything written about AI fraud is actually happening to ordinary people. It helps to sort the claims.
| The threat | How real it is today | What actually blunts it |
|---|---|---|
| Flawless phishing email or text | Routine and everywhere | Never acting from an inbound link; going to the site or app yourself |
| Cloned voice on a phone call | Real, and cheap enough to be used on ordinary families | Hanging up and calling back on a number you already had |
| Deepfaked video call | Real but rare, aimed mostly at company finance teams | A second approver and a callback for any payment or detail change |
| Chat scams run at scale (romance, fake investment) | Growing, because one operator can now hold many conversations | Refusing to move money to a platform the other person introduced |
| AI that cracks your password | Overstated; length still beats guessing | Long unique passwords and a second factor |
| AI malware that defeats antivirus | Overstated for consumers; delivery is still social | Updates, and not installing what a stranger suggests |
AI improved the persuasion layer and left the plumbing alone. Put your defenses in the plumbing.
Voice clones and fake video calls
A voice clone is built from a sample of someone talking. The source is rarely dramatic: a voicemail greeting, a story posted to social media, a podcast appearance, a work webinar, or a nuisance call where the caller says nothing and waits for you to say hello twice. The mechanics, and how little audio is needed, are covered in how a few seconds of audio becomes a fake call.
The clone copies timbre and delivery. It does not copy knowledge. It does not know what you argued about last Christmas or the name of the street your sister grew up on, and it tends to struggle with interruption and with questions it has no script for.
That gives you two practical moves. Ask something only the real person could answer, and make it specific and recent rather than a fact that appears anywhere online. Then, whatever the answer is, end the call and dial the number you already have saved. Caller ID is not evidence either, since the displayed number is supplied by the caller, which is explained in how spoofed numbers work.
Grammar tells are dead, process tells are not
Spelling, odd spacing, a strange greeting and a blurry logo were useful for a while because they were expensive to fix. They are free to fix now. Trying to detect a fake by how polished it is puts you in a race you will lose, and automated detectors do not rescue you either: a score from a tool is not proof of anything, as set out in why AI detector scores are not evidence.
Process tells hold up because they describe what the fraud needs rather than how it was written. Watch for these.
- The contact came to you, and it is steering you toward a link, a login, a code or a payment.
- A payment destination has changed, or a new one has appeared, no matter how good the explanation.
- You are asked for a code that was sent to you, which exists only to prove you are you.
- You are asked to keep it quiet, or told that checking will cause a problem.
- The conversation jumps channels, from an email thread to a personal phone, or from a company chat to a message app.
- A normal safeguard is being skipped just this once, usually by someone senior.
Two or more of those together is enough to stop, regardless of how right everything looks. The older version of this list, for messages rather than calls, is in the red flags that still work, and the ones tied to presentation are the ones that have aged worst.
A protocol for your family and your team
Individual vigilance fails at the worst moment, because the whole design of these scams is to catch you when you are rushed or frightened. An agreed rule works better, because it does not depend on how you feel.
For a family, pick a code word now. Choose something that does not appear in anyone's social media, keep it off shared documents and group chats, and agree what it is for: any call about an emergency, an arrest, a hospital, or money. The rule is simple. The caller supplies the word, and if they cannot, the call ends and you dial the person back. Add one more rule that matters more than the word itself: no money moves until someone has been called back on a saved number, and nobody is ever in trouble for pausing to do that.
For a company, the target is usually whoever can move funds. Require that any change to bank details is verified by a call to a number already on file, never a number in the request, and that the caller is not the person who received the request. Keep dual approval above a threshold you set in advance, and say plainly that urgency from an executive is not a reason to skip it, since that instruction is exactly what a fake executive would issue. The household version of the same pressure is the safe account scam.
What to set up this week
Three things, in order of what they return. Agree the callback rule with the people you would actually be called about, and say the code word out loud so it exists. Turn on a second factor everywhere that holds money or email, since a harvested password buys much less when it is not enough on its own; the options are in two-factor authentication explained. Then remove the easiest voice samples: a generic voicemail greeting and a private social account.
If something has already happened and money has left, speed matters more than certainty, and the ordered steps are in what to do in the first hour after sending money to a scammer. If you are not sure whether anything went wrong, that is still worth acting on. Nothing about these scams requires you to have been careless.
Common questions
How much audio does someone need to clone my voice?
Far less than people expect. Short clips of clear speech are usually enough for a copy good enough to survive a stressful phone call, and the quality improves with more audio. A voicemail greeting, a video posted to social media or a few sentences spoken to a cold caller can all serve as the sample.
Can I just ask an AI caller whether they are a real person?
No. There is no question that forces an honest answer, and the software is not obliged to admit anything. Asking about shared private history is more useful, but the only reliable step is to end the call and dial the person back on a number already in your contacts.
Are scam emails written by AI detectable?
Not reliably, and it is the wrong test. Detection tools produce a probability, not proof, and they are wrong in both directions often enough to mislead you. Judge the request instead: who contacted whom, what is being asked, and whether the payment or login route is one you chose yourself.
Should I delete my voice and photos from social media?
It reduces the easiest sources, but it is not a fix. Plenty of audio and images sit in places you do not control, including other people's posts and work recordings. Treat reducing your public footprint as tidying up rather than protection, and put the real effort into the callback rule.
Is a spoofed video call really possible on a normal work meeting?
Yes, though it is still uncommon and takes effort. It has been used against finance staff asked to approve transfers. Visual glitches around hair, glasses and fast head turns can give it away, but those tells will fade, so treat a payment instruction given in a meeting as needing the same callback as one sent by email.