LearnAI home

Spotting Fakes ยท Lesson 2

How to Recognise an AI-Powered Scam

Voice cloning, fake urgency and the calls that sound like family.

The call that sounds like your daughter

It is late. Your phone rings from a number you do not recognise. The voice is your daughter's, and she is crying. There has been an accident, or an arrest, or a problem at the airport. She needs money now and she cannot talk long. Then a calm adult takes the phone and explains what you have to do.

Almost nobody thinks clearly in that moment, and that is the entire design. Before we go any further: if something like this has already happened to you or to someone you love, you were not stupid. These scripts are built, tested and refined precisely because they work on careful, intelligent people. Shame is the scammer's best friend, because it keeps victims quiet and lets the same script run on the next family.

In plain English

Voice cloning:
Recreating someone's voice from a short sample of their speech, often taken from a video they posted publicly.
Phishing:
A message pretending to be from a person or company you trust, designed to get a password, a payment or a click.
Social engineering:
Manipulating a person rather than a computer. Urgency, authority and secrecy are the usual levers.
Code word:
A word agreed in advance with family or colleagues, used to confirm that a caller really is who they claim to be.

What AI actually changed

Scams are old. What changed is the cost of doing them well.

Voice cloning used to need a studio and now needs a short clip, which for most of us is sitting in a public video somewhere. Phishing emails used to be full of spelling errors, which is how many of us learned to spot them. That tell is gone: the grammar is now perfect, the tone matches your industry, and the message can reference your employer, your role and a real project. Fake job offers arrive with a company website, a LinkedIn presence, a recruiter with a face and a friendly video interview.

Stop using bad spelling as your main filter. A well written message is not a safe message. It is now the cheapest thing in the whole operation to get right.

The two defences that actually hold

Everything else in this lesson is detail. These two are the substance.

Agree a code word. Pick a word with your family, and a second one with your team at work. Something no search engine could guess and nothing you have posted anywhere. If a distressed call asks for money or a transfer, ask for the word. A real relative will find this mildly irritating for four seconds. A cloned voice cannot answer.

Call back on a number you already have. Not the number that called you, not the number in the email signature, not the link in the message. The number already in your contacts, or printed on your bank card, or on the company website you navigated to yourself. Hang up, then dial. This single habit defeats almost every impersonation, because the whole attack depends on you staying inside a channel the attacker controls.

Checkpoint

A family code word plus calling back on a number you already had defeats nearly every voice or identity impersonation.

The pressure signals

Cloned voices are convincing, so watch the shape of the request instead of the sound of it. Real emergencies rarely have all of these at once.

Urgency. It must happen in the next few minutes.

Secrecy. Do not tell your husband, your manager, the police, the bank.

An unusual payment route. Gift cards, crypto, a transfer to a new account, a courier collecting cash.

Authority. A police officer, a bank fraud team, a tax office, a chief executive. Real institutions expect you to hang up and call back, and none of them ask for passwords.

A story that discourages checking. Their phone is broken, they are about to be taken into a room, the line is bad.

Using AI to check a message

The tools that make these scams cheaper are also perfectly good at explaining them to you.

โŒ Weak prompt

Prompt

Is this email a scam?

Output

This email appears legitimate. It comes from a corporate domain and contains no obvious red flags.

A yes or no verdict from a model that cannot see the sending headers, the domain age, or your relationship with the sender. A reassuring answer here is worse than no answer.

โœ… Good prompt

Prompt

Here is an email I received. Do not tell me whether it is genuine, because you cannot know. Instead list every pressure tactic and every claim in it that I could independently verify, and tell me exactly how to verify each one without using any link or number in the message.

Output

Pressure tactics: a 24 hour deadline, a warning about account suspension, and a request for secrecy. Verifiable claims: that your account is suspended (log in directly), that an invoice is overdue (call the supplier on the number from your own records)...

It plays to what the tool is good at, which is spotting patterns and listing checks, rather than what it cannot do, which is confirm identity.

Prompt you can copy: pull apart a suspicious message

Here is a message I received. Do not judge whether it is real, because you cannot. Instead give me:

  1. Every urgency, secrecy or authority tactic used in it.
  2. Every factual claim I could check independently.
  3. For each claim, how to verify it WITHOUT using any link, number or address in the message itself. Then give me one short, polite way to stall while I check.

MESSAGE: [paste it]

Prompt you can copy: set up a family code word

Help me set up a code word with my family so we can confirm each other's identity on a phone call. Suggest what makes a good code word and what makes a bad one, explain in plain language why we need one (voice cloning), and write a short message I can send to relatives including older ones who may find this alarming. Reassuring, not frightening. Under 150 words.

Prompt you can copy: check a job offer

I have received a job offer or recruiter approach. Here are the details: [company name, role, what they have asked me to do next]. List everything about this I should verify before responding, in order of importance. Flag anything that is a known pattern in recruitment fraud, such as requests for payment, requests for identity documents very early, or interviews conducted only over text chat.

If it already happened

Move quickly and skip the self-recrimination, which can wait. Contact your bank straight away, because speed genuinely matters with transfers. Change the password on any account involved, starting with your email. Report it to the fraud or cybercrime reporting body in your country, and to your employer if any work system was touched. Then tell one other person. Scams thrive on the silence that embarrassment produces, and the person you tell may be the next target.

If you work with older relatives on this, do not lead with how obvious the scam was. Lead with the code word. It is a concrete, dignified thing to set up together, and it takes five minutes.

๐Ÿ“ Quiz

Question 1 of 4

You get a distressed call that sounds exactly like a family member asking for money urgently. What is the strongest response?

Found this useful? Pass it on.