
AI Scams Are Getting Smarter: How to Protect Yourself
Voice clones, deepfake video calls, and flawless phishing emails are fooling smart people. Real cases, red flags, and practical steps to stay safe.
In February 2024, a finance employee at the engineering firm Arup joined a video call with who he believed was his CFO and several colleagues. Everyone on the call looked and sounded right. They asked him to authorize a series of transfers. He did it: 15 transactions, totaling HK$200 million (about US$25 million). Every single person on that call except him was an AI-generated deepfake, built from public video footage of real executives. This case was widely reported by Hong Kong police and international media, and it remains one of the clearest signals of where scams are headed.
That's not a phishing email with bad grammar and a suspicious link anymore. That's a scam that passed the two checks most of us are trained to trust most: seeing a face and hearing a voice.
The one sentence to remember
AI hasn't invented new scams. It has removed the tells that used to give the old ones away.
This is a practical guide: how AI scams actually work now, real cases worth knowing, the warning signs that still hold up, and the specific habits that protect you and your business, even against a scam that looks and sounds completely convincing.
Why "AI Scams" Are a Different Problem Now
Every generation of scam relies on the same three ingredients: urgency, authority, and a channel you trust. What's changed is that AI now lets scammers fake all three convincingly, cheaply, and at scale.
| What used to protect you | What AI has quietly removed |
|---|---|
| "I'll recognize my boss's voice" | Voice cloning needs as little as 3–10 seconds of audio, often lifted from a video, podcast, or voicemail |
| "Scam emails have typos and weird phrasing" | LLMs write fluent, personalized, error-free emails in seconds, in any language |
| "I'd notice a fake video call" | Real-time deepfake video tools can now mimic a specific person's face and expressions live on a call |
| "It would take real effort to target me specifically" | AI can scrape your public posts, job title, and connections to write a scam that references real details about your life |
| "Scammers can't fake a whole conversation" | AI chatbots can now run entire multi-week romance or investment scams, texting like a real person around the clock |
The economics changed, not just the technology
A human scammer could only run so many convincing conversations at once. AI removes that ceiling: the same scam script now runs against thousands of targets simultaneously, each one personalized.
Real Cases Worth Knowing
These aren't hypothetical warnings. They're documented incidents that show exactly how AI scams play out in practice.
| Case | What happened | Technique |
|---|---|---|
| Arup deepfake video call (Hong Kong, 2024) | An employee authorized ~$25 million in transfers after a video call with deepfaked versions of the company's CFO and colleagues | Real-time deepfake video and audio, built from public footage |
| UK energy firm CEO voice fraud (2019) | A UK-based energy company's managing director wire-transferred €220,000 after receiving a call in what he believed was his German parent company's CEO's voice, urgently requesting the payment | Early AI voice cloning, reported by the company's insurer |
| "Grandparent" and "kidnapping" voice-clone calls | Family members receive calls with a cloned voice of a relative claiming to be in an accident, arrested, or kidnapped, demanding money be sent immediately | Voice cloning from social media clips, paired with manufactured panic and urgency |
| Celebrity deepfake investment ads | AI-generated videos of well-known public figures "endorsing" crypto or investment platforms circulate on social media, driving victims to fake trading sites | Deepfake video and audio, paired with fake news branding |
| AI romance and "pig butchering" scams | Scammers use AI chatbots to sustain long-term relationships with victims over weeks or months before introducing a fraudulent investment opportunity | AI-generated persistent chat personas, often paired with stolen or AI-generated profile photos |
Notice what these all have in common
None of them relied on a victim clicking a suspicious link. Every one of them relied on the victim trusting a face, a voice, or a relationship that felt completely real.
The Main Types of AI Scams
1. Voice Cloning ("Vishing 2.0")
Modern voice cloning tools need only a short audio sample, often scraped from a YouTube video, podcast appearance, voicemail greeting, or social media clip, to generate a convincing clone of someone's voice. Scammers use this for fake emergency calls to family members and fake executive calls demanding urgent wire transfers.
2. Deepfake Video Calls
The Arup case is the clearest example: real-time deepfake tools can now overlay a fake face and voice onto a live video call. This is far more resource-intensive than voice cloning alone, so it's currently reserved for high-value targets, but the cost of running it keeps dropping.
3. AI-Generated Phishing and Spear-Phishing
The classic advice, "look for typos and bad grammar," no longer works. LLMs can write flawless, personalized emails referencing your actual employer, job title, recent LinkedIn activity, or a real project name pulled from public sources, making the message feel legitimately targeted at you specifically.
4. AI Chatbot Personas (Romance, Job, and Investment Scams)
Instead of one scammer juggling a handful of victims, an AI chatbot can run hundreds of "relationships" simultaneously, texting like a real love interest, recruiter, or financial advisor, remembering details from earlier conversations, and never breaking character.
5. Fake AI Job Offers and Recruiter Scams
Scammers use AI to generate convincing job postings, recruiter profiles, and even AI-run "interview" chatbots to collect personal information or upfront "training fee" payments from job seekers.
Warning Signs That Still Work
Even against AI-powered scams, certain patterns hold up because they target human psychology, not technology.
Urgency plus secrecy, together
"Do this right now, and don't tell anyone else" is one of the oldest scam patterns in existence, and it's still the single strongest predictor across every AI scam case above. Legitimate requests almost never demand both speed and silence at once.
A request to move money or share credentials, out of the blue
Whether it's a voice, a video call, or an email, the actual ask (wire funds, buy gift cards, share a one-time passcode, send crypto) is the moment to slow down, regardless of how convincing the messenger was.
Pressure to use one specific channel
Scammers push you toward the one channel they control: "call me back on this number," "reply only to this email," "don't use the office phone." A legitimate request survives you switching channels to verify it.
Small technical glitches in video or audio
Real-time deepfakes still often show subtle artifacts: unnatural blinking, lighting that doesn't quite match the face, lip-sync drifting slightly out of time with the audio, or a voice with an odd flatness during emotional moments.
A story that changes slightly on repetition
Ask a follow-up question that a real person would answer naturally but a scripted scam wouldn't anticipate. Genuine callers handle unexpected questions fluidly; scam scripts, human or AI, often stall, repeat, or contradict themselves.
The single best test
Ask a question only the real person would know the answer to, that isn't public information: an inside joke, a detail from a private conversation, a nickname you use. This defeats voice clones and deepfakes far more reliably than trying to spot visual glitches.
How to Protect Yourself: Practical Steps
For Individuals and Families
Set a family safe word
Agree on a word or phrase with close family members that would never appear on social media or in a public conversation. If someone calls claiming to be in an emergency, ask for the safe word before doing anything else.
Always verify through a second, independent channel
If you get an urgent call, text, or video request, hang up and contact the person directly using a number or method you already have saved, never one provided in the suspicious message itself.
Limit public voice and video samples where it's reasonable to
You can't eliminate your digital footprint, but think twice before posting long, clear audio or video clips publicly, especially anything discussing money, travel plans, or family details.
Slow down when you feel a rush of adrenaline
Scams are engineered to trigger panic, excitement, or fear because those emotions short-circuit careful thinking. If a message makes you want to act immediately, that reaction itself is the warning sign.
Never send money or codes based on a single unverified contact
No legitimate emergency, tax authority, bank, or employer will ever require you to act within minutes using only gift cards, crypto, or a wire transfer, with no other confirmation available.
For Businesses and Teams
Require callback verification for any payment change or urgent transfer
Any request to change bank details or authorize a large or unusual transfer, no matter who appears to send it or how senior they seem, must be confirmed via a callback to a known, pre-verified number before action is taken.
Use dual approval for financial transactions above a set threshold
No single person, regardless of seniority claimed on a call, should be able to authorize a large transfer alone. This single control would have stopped the Arup case.
Train employees specifically on deepfake and voice-clone scenarios
Most security awareness training still focuses on email phishing. Update it to cover video-call impersonation and voice cloning explicitly, using real cases like the ones above.
Establish a verified out-of-band channel for sensitive requests
Set up a company-wide policy: sensitive or financial requests get a mandatory confirmation through a separate, pre-agreed system, such as an internal chat tool or a known extension, never through the same channel the request arrived on.
Run simulated deepfake/vishing drills alongside phishing drills
Just as organizations test phishing awareness with simulated emails, test voice and video impersonation awareness with authorized internal simulations.
Process beats detection
You will not reliably out-spot a well-made deepfake by eye or ear alone. The controls that actually work are procedural: callback verification, dual approval, safe words, because they don't depend on you correctly judging whether something looks real.
Can Detection Tools Help?
A growing number of tools claim to detect AI-generated voice, video, and text (deepfake detectors, AI-content detectors, voice liveness checks). They can be a useful extra signal, but treat them as one input, not a verdict.
| Tool type | What it does | Limitation |
|---|---|---|
| Deepfake video detectors | Analyze facial movement, blinking patterns, and compression artifacts | Detection tools and generation tools are in a constant arms race, so accuracy varies and degrades as generation quality improves |
| Voice liveness/anti-spoofing checks | Used by some banks and call centers to flag synthetic voice patterns | Not available to individuals in most everyday calls |
| AI text detectors | Flag whether text was likely AI-generated | Unreliable enough on short messages that it shouldn't be your primary defense |
Detection tools are a backup, not a strategy
The safe-word, callback-verification, and "slow down" habits above work regardless of how good the fake is. Build your defense around those first.
If You Think You've Been Scammed
Stop all further contact and payments immediately
Don't send "just a little more" to try to recover funds already lost. That's a common follow-up scam targeting people who've already been victimized once.
Contact your bank or payment provider right away
Wire transfers and crypto payments are hard to reverse, but the earlier you report it, the higher the chance of freezing or recovering funds.
Report it to the relevant authority
In most countries, there's a dedicated fraud or cybercrime reporting body, for example the FTC (US), Action Fraud (UK), or your local police cybercrime unit. Reporting also helps authorities track and take down the networks behind these scams.
Change passwords and enable MFA on any account that may have been exposed
If the scam involved sharing any credentials or codes, assume the account is compromised until secured.
Tell the people around you
Scammers often reuse the same script against coworkers, friends, or family. A quick warning can stop the next attempt before it succeeds.
The Bottom Line
AI hasn't made scammers smarter. It's made their oldest tricks harder to catch by removing the visual and audio tells we used to rely on. A voice you recognize and a face on a video call are no longer proof of anything on their own.
The defense that holds up isn't better lie-detecting. It's building verification into the process itself: a safe word, a callback to a number you already trust, a second approver, a pause before you act on urgency. None of those depend on spotting a glitch in a deepfake. They work whether the fake is clumsy or flawless.
Start with the one habit that matters most
Before you act on any urgent request involving money, credentials, or personal information, no matter who it appears to come from, verify it through a channel you already trust, not one the message itself provided.
AI can now fake a face, a voice, and a relationship. It still can't fake a phone call to a number you already had saved before the message arrived.
Written by
Chetan Yamger
Cloud Engineer · AI Automation Architect · Modern Workplace Consultant
Cloud Engineer, AI Automation Architect, and Modern Workplace Consultant based in Amsterdam, Netherlands. Specializing in scalable, secure enterprise solutions with Microsoft Azure, Intune, PowerShell, and AI-driven automation using ChatGPT, Gemini, and modern LLM technologies.
Stay in the loop.
New articles, straight to you.
Deep-dive technical articles on Intune, PowerShell, and AI — no noise, no spam.
Discussion
Share your thoughts — your email stays private
Leave a comment