Last updated · first published · reviewed by the Smart Money Verified Team
AI & Deepfake Scams
Cloned voices and synthetic video calls have broken the oldest safety rule in fraud prevention: that you can trust a familiar voice or a familiar face.
In 2024 the engineering firm Arup confirmed a Hong Kong employee sent roughly $25 million after a video call in which every other participant was AI-generated.
The employee suspected the first email. The video call is what convinced them.
What actually changed with AI scams?
The scam scripts are old. The evidence criminals can now fake is new.
Fraud has always run on impersonation. What is different is that three checks most people relied on — does this sound like them, does this look like them, and is this written the way they write — can now be manufactured cheaply and at scale by software anyone can rent.
That has two practical consequences. First, the old advice about spelling mistakes and robotic phrasing is close to worthless; AI-written messages read cleanly and are personalized to you. Second, adding a phone call or a video call to a suspicious request no longer makes it safer. In several documented cases the call is precisely the step that removed the target's doubt.
So the defense has to move away from judging the message and towards verifying through a channel the attacker does not control. That is the whole of this guide.
What are the six AI scam patterns you might meet?
Each one has a tell that survives the technology.
Voice cloning ('grandparent') calls
A cloned voice of a child or grandchild calls in distress — an accident, an arrest, a hospital, a lawyer who needs bail money now. The story always requires secrecy and speed.
The tell: The request is urgent, emotional, and asks you not to tell other family members.
Deepfake executive video calls
A finance employee joins a video meeting where senior colleagues appear on camera and approve a confidential transfer. The faces and voices are synthetic.
The tell: The transfer bypasses the normal approval chain because it is 'confidential'.
AI-written phishing and smishing
Language models produce clean, personalized messages at scale, in fluent English, referencing your employer, your bank, or a real recent transaction.
The tell: Poor grammar is no longer a reliable clue. Check where the link actually goes.
Deepfaked endorsements
Short video clips show a recognisable figure endorsing a trading platform, a recovery service, or a giveaway, then push you into a chat group or app.
The tell: Any real opportunity would exist on a registered firm's own website, not in a chat group.
Synthetic identity onboarding
AI-generated faces and documents are used to pass selfie checks and open accounts, mule networks, and fake 'advisor' profiles that look fully credentialed.
The tell: A polished profile photo and website prove nothing. Check the registration record.
Live-operator hybrid fraud
A human runs the conversation while software converts their speech into the cloned voice in real time, so the caller answers your questions naturally.
The tell: Being able to hold a conversation is not evidence of identity.
What are the warning signs, ranked by severity?
The first three should stop a payment on their own.
What verification routine still works?
Five steps. Use them in order, every time money or credentials are involved.
Stop the clock
Say you will call back and hang up. No genuine emergency, employer, bank, or agency is harmed by a ten-minute delay. Every AI-assisted scam depends on you acting inside the first few minutes.
Change the channel yourself
Dial the number you already have stored, or the number printed on your bank card or statement. Never call back a number the caller supplied and never trust the caller ID display, which is trivially spoofed.
Ask for the shared secret
Use a family code phrase agreed in person and never posted anywhere. For work, use a callback to a directory number and a second named approver.
Verify the firm, not the person
If money is going to a company, check registration and disclosure history in the official records before you send anything. A convincing human is not a licensed firm.
Assume nothing about audio and video
Write your household or company rule down: voice and face are no longer proof of identity. Only an independent channel or a pre-agreed secret is.
How does one of these calls actually unfold?
A composite example built from patterns regulators and police have described publicly.
4:42 p.m., Thursday. An email arrives from a senior executive's real address, or a close imitation of it, describing a confidential acquisition and asking that nothing be discussed with the wider team.
4:58 p.m. The recipient is uneasy and asks to speak to someone. A short video call is arranged. Two familiar faces appear, slightly pixelated, on a weak connection. They confirm the instruction and thank the recipient for being discreet.
5:20 p.m. The doubt is gone, because the call answered it. The first transfer goes out before the banking cut-off. Further instructions arrive the next morning, and by then the recipient has an internal reason to keep going.
Notice where the defense had to sit. Not in spotting the pixelation — in a rule that a confidential payment request is never approved on the strength of a call, only through a callback to a directory number plus a second named approver.
What rules should I set before I need them?
At home
- Agree a code phrase in person; never text it or post it.
- Any emergency money request gets a hang-up and a call back on a stored number.
- Tell older relatives you will never ask them for money by phone.
- Lock down public voice and video on social accounts where you can.
- Agree that no one in the family is ever in trouble for pausing to check.
At work
- Write down that video and voice are not approval evidence.
- Require callback to a directory number for any new payee or changed bank details.
- Require a second named approver above a set amount, with no exceptions for urgency.
- Remove 'confidential, do not discuss' as a valid reason to skip a control.
- Rehearse the refusal, so junior staff know declining is expected behavior.
What should I do if money already left?
The first few hours matter more than anything else you do.
- Call your bank or payment provider now and say plainly: "I am reporting fraud." Ask about recall or chargeback while the payment may still be reversible.
- Write down every detail while it is fresh: times, numbers, names, account details, screenshots.
- File with the FBI Internet Crime Complaint Center and the FTC. Filing builds the record investigators work from, even when your own funds are not returned.
- If a registered firm or adviser was involved, complain to the SEC and FINRA as well.
- Expect a call or message offering to recover your money for a fee. That is the follow-on scam; read our recovery-scam guide before replying to anyone.
Where can I find the official sources?
Check the company behind the request
A convincing voice or face tells you nothing about whether a firm is registered. Run a free check on the company name before any money moves.
Frequently Asked Questions
Protect Your Investments
Download our free Investor Protection Guide with actionable steps to verify companies and avoid scams.
How do you check a company or person right now?
Use the free check on this site. Enter the name and it searches the official registers for you in one step, then shows you what those records say — registration status and anything reported against them. Every answer names the official source behind it, so you can confirm it yourself if you want to.
Related Topics
You May Also Be Interested In
Take Action
Who writes these guides
Written and reviewed by the Smart Money Verified Team. We build every guide from primary regulator material, we take no payment from any company we write about, and we say plainly when public records cannot answer a question. Our guides are education, not financial advice.
Primary sources we work from
How we check things: our methodology · disclosures