Cloud Engineer Lab
Cloud Engineer Lab
Cloud Engineer Lab
Cloud Engineer Lab
© 2026
AI Scams Are Getting Smarter: How to Protect Yourself

AI Scams Are Getting Smarter: How to Protect Yourself

Voice clones, deepfake video calls, and flawless phishing emails are fooling smart people. Real cases, red flags, and practical steps to stay safe.

12 min read
Share

In February 2024, a finance employee at the engineering firm Arup joined a video call with who he believed was his CFO and several colleagues. Everyone on the call looked and sounded right. They asked him to authorize a series of transfers. He did it: 15 transactions, totaling HK$200 million (about US$25 million). Every single person on that call except him was an AI-generated deepfake, built from public video footage of real executives. This case was widely reported by Hong Kong police and international media, and it remains one of the clearest signals of where scams are headed.

That's not a phishing email with bad grammar and a suspicious link anymore. That's a scam that passed the two checks most of us are trained to trust most: seeing a face and hearing a voice.

The one sentence to remember

AI hasn't invented new scams. It has removed the tells that used to give the old ones away.

This is a practical guide: how AI scams actually work now, real cases worth knowing, the warning signs that still hold up, and the specific habits that protect you and your business, even against a scam that looks and sounds completely convincing.


Why "AI Scams" Are a Different Problem Now

Every generation of scam relies on the same three ingredients: urgency, authority, and a channel you trust. What's changed is that AI now lets scammers fake all three convincingly, cheaply, and at scale.

What used to protect youWhat AI has quietly removed
"I'll recognize my boss's voice"Voice cloning needs as little as 3–10 seconds of audio, often lifted from a video, podcast, or voicemail
"Scam emails have typos and weird phrasing"LLMs write fluent, personalized, error-free emails in seconds, in any language
"I'd notice a fake video call"Real-time deepfake video tools can now mimic a specific person's face and expressions live on a call
"It would take real effort to target me specifically"AI can scrape your public posts, job title, and connections to write a scam that references real details about your life
"Scammers can't fake a whole conversation"AI chatbots can now run entire multi-week romance or investment scams, texting like a real person around the clock

The economics changed, not just the technology

A human scammer could only run so many convincing conversations at once. AI removes that ceiling: the same scam script now runs against thousands of targets simultaneously, each one personalized.


Real Cases Worth Knowing

These aren't hypothetical warnings. They're documented incidents that show exactly how AI scams play out in practice.

CaseWhat happenedTechnique
Arup deepfake video call (Hong Kong, 2024)An employee authorized ~$25 million in transfers after a video call with deepfaked versions of the company's CFO and colleaguesReal-time deepfake video and audio, built from public footage
UK energy firm CEO voice fraud (2019)A UK-based energy company's managing director wire-transferred €220,000 after receiving a call in what he believed was his German parent company's CEO's voice, urgently requesting the paymentEarly AI voice cloning, reported by the company's insurer
"Grandparent" and "kidnapping" voice-clone callsFamily members receive calls with a cloned voice of a relative claiming to be in an accident, arrested, or kidnapped, demanding money be sent immediatelyVoice cloning from social media clips, paired with manufactured panic and urgency
Celebrity deepfake investment adsAI-generated videos of well-known public figures "endorsing" crypto or investment platforms circulate on social media, driving victims to fake trading sitesDeepfake video and audio, paired with fake news branding
AI romance and "pig butchering" scamsScammers use AI chatbots to sustain long-term relationships with victims over weeks or months before introducing a fraudulent investment opportunityAI-generated persistent chat personas, often paired with stolen or AI-generated profile photos

Notice what these all have in common

None of them relied on a victim clicking a suspicious link. Every one of them relied on the victim trusting a face, a voice, or a relationship that felt completely real.


The Main Types of AI Scams

Voice cloning: a few seconds of audio becomes a convincing clone of someone you trust
Deepfake video calls: a live or pre-recorded fake face standing in for a real person
AI-written phishing: personalized, fluent emails and texts with no red-flag typos
AI chatbot personas: romance, job, or investment "relationships" run by a bot at scale

1. Voice Cloning ("Vishing 2.0")

Modern voice cloning tools need only a short audio sample, often scraped from a YouTube video, podcast appearance, voicemail greeting, or social media clip, to generate a convincing clone of someone's voice. Scammers use this for fake emergency calls to family members and fake executive calls demanding urgent wire transfers.

2. Deepfake Video Calls

The Arup case is the clearest example: real-time deepfake tools can now overlay a fake face and voice onto a live video call. This is far more resource-intensive than voice cloning alone, so it's currently reserved for high-value targets, but the cost of running it keeps dropping.

3. AI-Generated Phishing and Spear-Phishing

The classic advice, "look for typos and bad grammar," no longer works. LLMs can write flawless, personalized emails referencing your actual employer, job title, recent LinkedIn activity, or a real project name pulled from public sources, making the message feel legitimately targeted at you specifically.

4. AI Chatbot Personas (Romance, Job, and Investment Scams)

Instead of one scammer juggling a handful of victims, an AI chatbot can run hundreds of "relationships" simultaneously, texting like a real love interest, recruiter, or financial advisor, remembering details from earlier conversations, and never breaking character.

5. Fake AI Job Offers and Recruiter Scams

Scammers use AI to generate convincing job postings, recruiter profiles, and even AI-run "interview" chatbots to collect personal information or upfront "training fee" payments from job seekers.


Warning Signs That Still Work

Even against AI-powered scams, certain patterns hold up because they target human psychology, not technology.

Urgency plus secrecy, together

"Do this right now, and don't tell anyone else" is one of the oldest scam patterns in existence, and it's still the single strongest predictor across every AI scam case above. Legitimate requests almost never demand both speed and silence at once.

A request to move money or share credentials, out of the blue

Whether it's a voice, a video call, or an email, the actual ask (wire funds, buy gift cards, share a one-time passcode, send crypto) is the moment to slow down, regardless of how convincing the messenger was.

Pressure to use one specific channel

Scammers push you toward the one channel they control: "call me back on this number," "reply only to this email," "don't use the office phone." A legitimate request survives you switching channels to verify it.

Small technical glitches in video or audio

Real-time deepfakes still often show subtle artifacts: unnatural blinking, lighting that doesn't quite match the face, lip-sync drifting slightly out of time with the audio, or a voice with an odd flatness during emotional moments.

A story that changes slightly on repetition

Ask a follow-up question that a real person would answer naturally but a scripted scam wouldn't anticipate. Genuine callers handle unexpected questions fluidly; scam scripts, human or AI, often stall, repeat, or contradict themselves.

The single best test

Ask a question only the real person would know the answer to, that isn't public information: an inside joke, a detail from a private conversation, a nickname you use. This defeats voice clones and deepfakes far more reliably than trying to spot visual glitches.


How to Protect Yourself: Practical Steps

For Individuals and Families

Set a family safe word

Agree on a word or phrase with close family members that would never appear on social media or in a public conversation. If someone calls claiming to be in an emergency, ask for the safe word before doing anything else.

Always verify through a second, independent channel

If you get an urgent call, text, or video request, hang up and contact the person directly using a number or method you already have saved, never one provided in the suspicious message itself.

Limit public voice and video samples where it's reasonable to

You can't eliminate your digital footprint, but think twice before posting long, clear audio or video clips publicly, especially anything discussing money, travel plans, or family details.

Slow down when you feel a rush of adrenaline

Scams are engineered to trigger panic, excitement, or fear because those emotions short-circuit careful thinking. If a message makes you want to act immediately, that reaction itself is the warning sign.

Never send money or codes based on a single unverified contact

No legitimate emergency, tax authority, bank, or employer will ever require you to act within minutes using only gift cards, crypto, or a wire transfer, with no other confirmation available.

For Businesses and Teams

Require callback verification for any payment change or urgent transfer

Any request to change bank details or authorize a large or unusual transfer, no matter who appears to send it or how senior they seem, must be confirmed via a callback to a known, pre-verified number before action is taken.

Use dual approval for financial transactions above a set threshold

No single person, regardless of seniority claimed on a call, should be able to authorize a large transfer alone. This single control would have stopped the Arup case.

Train employees specifically on deepfake and voice-clone scenarios

Most security awareness training still focuses on email phishing. Update it to cover video-call impersonation and voice cloning explicitly, using real cases like the ones above.

Establish a verified out-of-band channel for sensitive requests

Set up a company-wide policy: sensitive or financial requests get a mandatory confirmation through a separate, pre-agreed system, such as an internal chat tool or a known extension, never through the same channel the request arrived on.

Run simulated deepfake/vishing drills alongside phishing drills

Just as organizations test phishing awareness with simulated emails, test voice and video impersonation awareness with authorized internal simulations.

Process beats detection

You will not reliably out-spot a well-made deepfake by eye or ear alone. The controls that actually work are procedural: callback verification, dual approval, safe words, because they don't depend on you correctly judging whether something looks real.


Can Detection Tools Help?

A growing number of tools claim to detect AI-generated voice, video, and text (deepfake detectors, AI-content detectors, voice liveness checks). They can be a useful extra signal, but treat them as one input, not a verdict.

Tool typeWhat it doesLimitation
Deepfake video detectorsAnalyze facial movement, blinking patterns, and compression artifactsDetection tools and generation tools are in a constant arms race, so accuracy varies and degrades as generation quality improves
Voice liveness/anti-spoofing checksUsed by some banks and call centers to flag synthetic voice patternsNot available to individuals in most everyday calls
AI text detectorsFlag whether text was likely AI-generatedUnreliable enough on short messages that it shouldn't be your primary defense

Detection tools are a backup, not a strategy

The safe-word, callback-verification, and "slow down" habits above work regardless of how good the fake is. Build your defense around those first.


If You Think You've Been Scammed

Stop all further contact and payments immediately

Don't send "just a little more" to try to recover funds already lost. That's a common follow-up scam targeting people who've already been victimized once.

Contact your bank or payment provider right away

Wire transfers and crypto payments are hard to reverse, but the earlier you report it, the higher the chance of freezing or recovering funds.

Report it to the relevant authority

In most countries, there's a dedicated fraud or cybercrime reporting body, for example the FTC (US), Action Fraud (UK), or your local police cybercrime unit. Reporting also helps authorities track and take down the networks behind these scams.

Change passwords and enable MFA on any account that may have been exposed

If the scam involved sharing any credentials or codes, assume the account is compromised until secured.

Tell the people around you

Scammers often reuse the same script against coworkers, friends, or family. A quick warning can stop the next attempt before it succeeds.


The Bottom Line

AI hasn't made scammers smarter. It's made their oldest tricks harder to catch by removing the visual and audio tells we used to rely on. A voice you recognize and a face on a video call are no longer proof of anything on their own.

The defense that holds up isn't better lie-detecting. It's building verification into the process itself: a safe word, a callback to a number you already trust, a second approver, a pause before you act on urgency. None of those depend on spotting a glitch in a deepfake. They work whether the fake is clumsy or flawless.

Start with the one habit that matters most

Before you act on any urgent request involving money, credentials, or personal information, no matter who it appears to come from, verify it through a channel you already trust, not one the message itself provided.

AI can now fake a face, a voice, and a relationship. It still can't fake a phone call to a number you already had saved before the message arrived.

CChetan Yamger

Written by

Chetan Yamger

Cloud Engineer · AI Automation Architect · Modern Workplace Consultant

Cloud Engineer, AI Automation Architect, and Modern Workplace Consultant based in Amsterdam, Netherlands. Specializing in scalable, secure enterprise solutions with Microsoft Azure, Intune, PowerShell, and AI-driven automation using ChatGPT, Gemini, and modern LLM technologies.

Cloud & Modern WorkplaceMicrosoft Intune & MDMAzure & Microsoft 365AI AutomationPrompt EngineeringPowerShell & Graph APIWindows AutopilotConditional Access & Zero TrustSCCM / MECM & MSIXVDI / WVDPower BINode.js & Next.js
Newsletter

Stay in the loop.
New articles, straight to you.

Deep-dive technical articles on Intune, PowerShell, and AI — no noise, no spam.

New article notifications
No spam, ever
Free forever

Discussion

Share your thoughts — your email stays private

Leave a comment

0/2000

Your email is used to prevent spam and will never be displayed.