Skip to main content

AI Scams: How to spot fake messages, voices and videos

03 July 2026

Personal

Share this post:

Picture this. You get a call from your mum and she sounds panicked. She says she has been in an accident, needs money transferred urgently and asks you not to tell anyone yet. Your heart sinks.

Without thinking too much about it, you reach for your banking app.

The problem is that it was not your mum on the other end of the line. It was an AI-generated clone of her voice, created from a short audio clip taken from social media.

That may sound like something from a film, but scams like this are becoming more realistic. AI can now help scammers write better messages, copy someone’s voice, create fake photos and generate videos that look believable at first glance.

The good news is that you do not need to be a cybersecurity expert to protect yourself. You just need to know the warning signs and give yourself a moment before reacting.

What are AI scams?

These are exactly what they sound like, scams that use artificial intelligence to appear more convincing.

A few years ago, many scam messages were easier to spot. The grammar was strange, the logo looked wrong or the story did not quite make sense. Today, that is not always the case. AI can help scammers write polished messages, translate them into different languages and make them sound much more natural.

In fact, with AI tools, scammers can now create:

  • Emails that look like they came from your bank, workplace or a delivery company
  • SMS messages with urgent links
  • Social media profiles with realistic-looking photos
  • Voice calls that sound like a friend, family member or colleague
  • Deepfake videos featuring public figures, company leaders or people you know
  • Fake documents, screenshots and payment confirmations
  • Customer support chats that feel professional and helpful

That’s why the old advice of “look for spelling mistakes” doesn’t always work anymore. Poor spelling can still be a warning sign, but a perfectly written message isn’t proof that something is genuine.

These days, it’s less about how professional something looks and more about what it’s asking you to do.

Why AI scams are harder to spot

Cybersecurity reports have shown that AI is increasingly being used in phishing emails, identity fraud and deepfake scams with these surged 1,210% in 2025, while deepfake fraud attempts have increased 2,137% over the last three years, now showing up in roughly 1 in every 15 detected fraud cases.

That does not mean we need to panic. It simply means we need to update the way we spot scams.

Instead of asking, “Does this look professional?”, ask:

  • Was I expecting this?
  • Is it asking me to act quickly?
  • Is it asking for money or personal details?
  • Can I verify this another way?
  • Would this person or company normally contact me like this?

Those questions can stop a scam before it goes any further.

Deep fake videos

The three main types of AI scams to watch for

Most AI scams fall into three main groups:

  1. Fake AI-generated messages
  2. AI voice scams
  3. AI deepfake videos

Let’s look at each one.

1. Fake AI-generated messages

This is probably the most common type. You receive a message that looks like it came from a trusted company, friend, colleague or organisation. It might arrive through email, SMS, WhatsApp, Messenger, Instagram DM, LinkedIn or even a fake website chat box.

The message usually asks you to do something like clicking a link, verifying your account, updating payment details, claiming a prize, paying a fee or replying with personal information.

Since AI can write naturally, these messages may not look suspicious at first. They can sound polite, professional and even personal. And unfortunately, it’s working. AI-generated phishing emails now achieve a 54% click-through rate, compared to around 12% for traditional phishing emails. That means nearly one in every two recipients clicks on the message.

Example 1: the fake delivery message

You receive an SMS that says:

“Your parcel could not be delivered due to an incomplete address. Please update your details here to avoid return fees.”

If you are expecting a parcel, it is easy to assume the message is real. That is exactly what the scammer is counting on.

Rather than clicking the link, open the courier’s official website or app and check your delivery there. If there is really a problem, you should be able to find it without using the link in the message.

You can also read our guide to online shopping scams for more examples of fake delivery, payment and shopping messages.

Example 2: The fake bank alert

You receive an email that says:

“Unusual activity has been detected on your account. Please confirm your login details immediately to avoid temporary suspension.”

At first glance, it sounds serious. The language is professional and the warning creates a sense of urgency that makes you want to act quickly. That’s a common tactic used by scammers. They want you to react before you have time to think.

As a general rule, banks will not ask you to share your password, card PIN or one-time verification code through a link in an email or text message. If you are worried about your account, open your bank’s official app or website directly.

Example 3: The fake HR or work message

This type of scam targets people in the workplace and can be surprisingly convincing.

You might receive a message that appears to come from your manager or HR team:

“Hi, can you quickly send me your phone number? I need your help with an urgent payment.”

Or:

“Please review the attached salary adjustment document.”

A message like this may sound normal, especially if it uses the right tone or refers to something work-related. But if it involves money, passwords, confidential files or unexpected attachments, pause and verify it through another channel.

A quick call or separate message can prevent a much bigger problem.

Man speaking on the phone outdoors

How to spot fake AI-generated messages

The most important thing is to focus less on how the message looks and more on what it wants from you.

Here are some of the most common red flags.

It creates a sense of urgency

  • “Your account will be blocked.”
  • “Your payment has failed.”
  • “Legal action will be taken.”
  • “Your parcel will be returned today.”

Anything that pressures you to act immediately is worth slowing down for.

It asks for sensitive information

Be cautious if you’re being asked for passwords, PINs, verification codes, card details or banking information. Legitimate organisations rarely, if ever, request this through messages or emails.

It pushes you to click a link

If you’re being urged to click a link right away, pause. Instead, go directly to the official website or app and check there.

The link or email address looks slightly off

Small changes in spelling, extra characters, hyphens or unusual domain endings are a common trick. At a glance, they can look legitimate.

It tries to move you to another platform

For example, shifting a conversation from a marketplace app to WhatsApp or from email to an external payment link. This is often done to bypass platform safety checks.

It sounds unusually good or unusual in general

Prizes you didn’t enter, refunds you didn’t request or jobs that offer high pay for very little effort are all common scam patterns.

It asks for payment in unusual ways

Be especially wary of requests involving gift cards, cryptocurrency, instant transfers or “friends and family” payments. These methods are hard to trace or reverse.

2. AI voice scams

AI voice scams use voice cloning to make it sound like someone you know is speaking.

That person could be a family member, friend, colleague, manager or even someone from your bank. In some cases, scammers only need a short audio clip to create a voice that sounds familiar. That audio might come from social media videos, podcasts, voice notes, webinars or public clips.

What makes this particularly concerning is how effective it can be. Among victims who confirmed they had lost money to voice-cloning scams, 77% reported an actual financial loss. Voice-based impersonation is now widely considered one of the most significant AI-driven fraud risks.

The family emergency scam

This is a modern version of a very old scam. A fraudster calls someone, often an older relative, pretending to be a child or grandchild in trouble. The story is emotional and urgent:

“Nanna, I’m in trouble, I need money, please don’t tell Mum”

With voice cloning, the call can sound much more convincing. The voice may have the same tone, pauses and little speech habits as the real person.

According to a 2024 McAfee study, 1 in 4 adults have already experienced an AI voice scam, and 1 in 10 have been personally targeted. It’s no longer a rare or experimental type of fraud, it’s becoming part of mainstream scam activity.

The workplace voice scam

Voice scams are also used in business settings.

A scammer might pretend to be a senior manager, supplier or colleague and ask for an urgent payment, password reset or confidential document.

One well-known case involved engineering firm Arup, where criminals used deepfake technology in a video call to trick an employee in Hong Kong into transferring a large amount of money. It is an extreme example, but it shows how convincing these scams can become.

How to spot a fake voice call

1. Unnatural pauses or timing

Since cloned or AI-generated voices are sometimes produced in real time, you may notice unusual pauses, slightly odd pacing or breaks in conversation that don’t feel natural.

Real conversations have rhythm and AI-generated speech doesn’t always get that right.

2. The voice sounds slightly “off”

Cloned voices can sometimes sound compressed, flat or unusually consistent in tone. It might feel like the person is speaking through a filtered line or without the usual variation in emotion and emphasis.
If something about the voice feels unfamiliar, even though it’s meant to be someone you know, it’s worth paying attention.

3. Panic, urgency and secrecy are being used together

Most voice scams rely on the same emotional pattern, which is to create panic, push urgency and discourage you from checking with anyone else.

Phrases like “don’t tell anyone” or “just do it quickly” are a major warning sign. Real emergencies don’t usually come with instructions to keep them secret.

4. Set up a family “safe word”

This is one of the simplest and most effective ways to protect yourself.

Agree on a word or phrase that only your close family knows. This should be something memorable but not obvious. If someone calls claiming to be a relative in trouble, you can ask for the safe word. An AI-generated voice won’t know it.

5. Hang up and call back using a trusted number

If you receive a call from someone claiming to be your bank, your employer or a family member in distress, don’t rely on the number they provide. End the call and contact the organisation or person directly using a verified number from an official website or contact list.

6. Pay attention to your instinct that something isn’t right

Many people say they aren’t confident they could tell the difference between a real and cloned voice. Even so, people often still notice when something feels slightly off.

That feeling is worth taking seriously. If something doesn’t sit right, pause and verify it before taking any action.

Man looking at his emails

3. AI deepfake videos

Deepfake videos use AI to make it look like someone said or did something they never actually did. That person could be a celebrity, public figure, company leader, friend or family member.

Deepfakes are often used in scams such as:

  • Fake investment schemes
  • Crypto promotions
  • Fake giveaways
  • Charity appeals
  • Political misinformation
  • Fake customer testimonials
  • Video call impersonation
  • Fabricated proof of emergencies

One common version is the fake investment video. You might see a well-known person apparently explaining how they made money through a new platform. The video looks polished, the comments seem positive and the offer feels exclusive. But scammers can fake more than the video. They can also create fake comments, fake reviews and fake success stories to make the whole thing look real.

Deepfake videos of Elon Musk promoting fake crypto giveaways circulated widely online, along with similar scams involving figures like Warren Buffett and Jeff Bezos. Romance scams have also evolved, with AI-generated voices and increasingly realistic video calls being used to maintain long-term deception. According to the FTC, romance scam losses exceeded $1.3 billion in 2024.

The rule is simple – do not trust a video just because it looks convincing.

If a public figure or company is genuinely promoting something, it should usually appear on their verified channels or in reputable media.

How to spot deepfake videos

Deepfakes are improving, so there is no perfect visual checklist. Still, these signs can help.
Look for odd face or mouth movement: The lips may not match the words perfectly. Facial expressions may feel slightly delayed or too smooth.

Check the lighting: The face may look a little different from the background. Shadows may not behave naturally.
Watch the hands and edges: Hands, teeth, jewellery, glasses and hair can sometimes look strange or change shape.
Listen to the voice: Does the voice sound flat, robotic or too clean? Does the emotion match the situation? Does the person use phrases they would not normally use?
Look at the source: This is the big one. A believable video from a random account is still a random account. Check the original profile, official website or reputable news source.

Be careful with “act now” offers

Deepfake scams often create urgency with lines like:

  • “Invest before midnight”
  • “Only 100 spots left”
  • “This secret has just been leaked”
  • “Banks do not want you to know this”

When a video is pushing you to act fast with money or personal details, slow down.

What to do if you receive a suspicious AI message, call or video

If it is a message

  • Do not click the link.
  • Do not download attachments.
  • Do not reply with personal information.
  • Take a screenshot if you need to report it.
  • Delete the message or report it through the platform.
  • Go directly to the official website or app.

If it is a phone call

  • Hang up.
  • Call the person or company back using a trusted number.
  • Do not share one-time codes.
  • Do not install apps or allow remote access.
  • Do not transfer money while still on the call.

If it is a video

  • Do not share it straight away.
  • Search for the story on trusted sources.
  • Check the official profile of the person or organisation.
  • Look for signs that the clip has been edited or reposted.
  • Report it if it appears fraudulent.

What to do if you already clicked or shared details

First, do not panic. Scammers are very good at creating pressure, and anyone can be caught off guard.
What matters now is acting quickly.

If you clicked a suspicious link

  • Close the page.
  • Do not enter any more information.
  • Run a security check on your device.
  • Change the password for the account involved.
  • Turn on two-factor authentication where possible.

If you entered your password

  • Change it immediately.
  • If you use the same password anywhere else, change it there too.
  • Log out of other active sessions if the platform allows it.
  • Turn on two-factor authentication.
  • Watch for unusual account activity.

If you shared card or bank details

  • Contact your bank immediately.
  • Ask them to block or monitor the card or account.
  • Review recent transactions.
  • Keep screenshots and messages as evidence.

If you sent money

  • Contact your bank or payment provider as soon as possible.
  • Report the scam to the relevant platform or authority.
  • Save all messages, phone numbers, usernames, payment details and screenshots.

How to make yourself harder to scam

You cannot control every scammer online, but you can make their job much harder.

Use strong, unique passwords

Avoid using the same password across different accounts. A password manager can help you create and store strong passwords safely.

Turn on two-factor authentication

Two-factor authentication adds an extra layer of security. Even if someone gets your password, they still need a second step to log in.

Where possible, use an authenticator app instead of SMS codes.

Keep your devices updated

Updates often include important security fixes. Yes, they always seem to arrive when you are busy, but they really do help.

Take a look at this 20-minute phone storage clean-up that actually works to keep your phone organised and running smoothly.

Review your privacy settings

Limit who can see your phone number, email address, birthday, family connections, photos and videos.
Scammers love personal details because they help make scams feel more believable.

For more on this, take a look at what data privacy is and why you should protect it.

Be careful with what you post publicly

A birthday reel, holiday post, school photo, voice note or work update can all reveal small pieces of information. On their own, they may seem harmless. Together, they can help a scammer build a convincing story.

Use official apps and websites

Do not log in through links sent by message. Open the app or type the official website yourself.

Talk about scams with family

This is especially important for children, teenagers and older relatives.

AI scams may be getting smarter, but small habits can still protect you.

You do not need to become suspicious of every message, call or video. You just need to build a short pause into your online routine.

So next time something feels urgent, surprising or just a little too perfect, remember: pause first, verify second, act third.

That tiny pause could save your money, your account and a lot of stress.

Sources:
AI scams explained: how AI-powered fraud works and how enterprises detect it
Evolving AI-based techniques pose new security challenges
AI Calling—Scammers turn to AI voice cloning tools for a new breed of scam
Catfishing Statistics 2026