Last updated · first published · reviewed by the Smart Money Verified Team

AI & Deepfake Scams

Cloned voices and synthetic video calls have broken the oldest safety rule in fraud prevention: that you can trust a familiar voice or a familiar face.

In 2024 the engineering firm Arup confirmed a Hong Kong employee sent roughly $25 million after a video call in which every other participant was AI-generated.

The employee suspected the first email. The video call is what convinced them.

What actually changed with AI scams?

The scam scripts are old. The evidence criminals can now fake is new.

Fraud has always run on impersonation. What is different is that three checks most people relied on — does this sound like them, does this look like them, and is this written the way they write — can now be manufactured cheaply and at scale by software anyone can rent.

That has two practical consequences. First, the old advice about spelling mistakes and robotic phrasing is close to worthless; AI-written messages read cleanly and are personalized to you. Second, adding a phone call or a video call to a suspicious request no longer makes it safer. In several documented cases the call is precisely the step that removed the target's doubt.

So the defense has to move away from judging the message and towards verifying through a channel the attacker does not control. That is the whole of this guide.

What are the six AI scam patterns you might meet?

Each one has a tell that survives the technology.

Voice cloning ('grandparent') calls

A cloned voice of a child or grandchild calls in distress — an accident, an arrest, a hospital, a lawyer who needs bail money now. The story always requires secrecy and speed.

The tell: The request is urgent, emotional, and asks you not to tell other family members.

Deepfake executive video calls

A finance employee joins a video meeting where senior colleagues appear on camera and approve a confidential transfer. The faces and voices are synthetic.

The tell: The transfer bypasses the normal approval chain because it is 'confidential'.

AI-written phishing and smishing

Language models produce clean, personalized messages at scale, in fluent English, referencing your employer, your bank, or a real recent transaction.

The tell: Poor grammar is no longer a reliable clue. Check where the link actually goes.

Deepfaked endorsements

Short video clips show a recognisable figure endorsing a trading platform, a recovery service, or a giveaway, then push you into a chat group or app.

The tell: Any real opportunity would exist on a registered firm's own website, not in a chat group.

Synthetic identity onboarding

AI-generated faces and documents are used to pass selfie checks and open accounts, mule networks, and fake 'advisor' profiles that look fully credentialed.

The tell: A polished profile photo and website prove nothing. Check the registration record.

Live-operator hybrid fraud

A human runs the conversation while software converts their speech into the cloned voice in real time, so the caller answers your questions naturally.

The tell: Being able to hold a conversation is not evidence of identity.

What are the warning signs, ranked by severity?

The first three should stop a payment on their own.

An urgent money request from a familiar voiceVoice clones are convincing. Treat the voice as unverified until you reach the person on a number you already had.
A payment approved only on a video callFaces and voices on a call can be synthetic. Large transfers should follow a written approval path that does not depend on what you saw on screen.
Pressure to keep the request secretSecrecy exists to stop you from making the one phone call that would end the scam.
A public figure endorsing a financial opportunity in a short videoDeepfaked endorsements are mass produced. Verify the firm's registration before anything else.
The caller pushes you to a new channelMoving from a call to WhatsApp, Telegram, or a new app removes the trail and the people who might warn you.
Small oddities in timing, phrasing, or backgroundFlat delivery, missing breaths, delayed responses, or a story that avoids specifics you would both know.

What verification routine still works?

Five steps. Use them in order, every time money or credentials are involved.

1

Stop the clock

Say you will call back and hang up. No genuine emergency, employer, bank, or agency is harmed by a ten-minute delay. Every AI-assisted scam depends on you acting inside the first few minutes.

2

Change the channel yourself

Dial the number you already have stored, or the number printed on your bank card or statement. Never call back a number the caller supplied and never trust the caller ID display, which is trivially spoofed.

3

Ask for the shared secret

Use a family code phrase agreed in person and never posted anywhere. For work, use a callback to a directory number and a second named approver.

4

Verify the firm, not the person

If money is going to a company, check registration and disclosure history in the official records before you send anything. A convincing human is not a licensed firm.

5

Assume nothing about audio and video

Write your household or company rule down: voice and face are no longer proof of identity. Only an independent channel or a pre-agreed secret is.

How does one of these calls actually unfold?

A composite example built from patterns regulators and police have described publicly.

4:42 p.m., Thursday. An email arrives from a senior executive's real address, or a close imitation of it, describing a confidential acquisition and asking that nothing be discussed with the wider team.

4:58 p.m. The recipient is uneasy and asks to speak to someone. A short video call is arranged. Two familiar faces appear, slightly pixelated, on a weak connection. They confirm the instruction and thank the recipient for being discreet.

5:20 p.m. The doubt is gone, because the call answered it. The first transfer goes out before the banking cut-off. Further instructions arrive the next morning, and by then the recipient has an internal reason to keep going.

Notice where the defense had to sit. Not in spotting the pixelation — in a rule that a confidential payment request is never approved on the strength of a call, only through a callback to a directory number plus a second named approver.

What rules should I set before I need them?

At home

  • Agree a code phrase in person; never text it or post it.
  • Any emergency money request gets a hang-up and a call back on a stored number.
  • Tell older relatives you will never ask them for money by phone.
  • Lock down public voice and video on social accounts where you can.
  • Agree that no one in the family is ever in trouble for pausing to check.

At work

  • Write down that video and voice are not approval evidence.
  • Require callback to a directory number for any new payee or changed bank details.
  • Require a second named approver above a set amount, with no exceptions for urgency.
  • Remove 'confidential, do not discuss' as a valid reason to skip a control.
  • Rehearse the refusal, so junior staff know declining is expected behavior.

What should I do if money already left?

The first few hours matter more than anything else you do.

  1. Call your bank or payment provider now and say plainly: "I am reporting fraud." Ask about recall or chargeback while the payment may still be reversible.
  2. Write down every detail while it is fresh: times, numbers, names, account details, screenshots.
  3. File with the FBI Internet Crime Complaint Center and the FTC. Filing builds the record investigators work from, even when your own funds are not returned.
  4. If a registered firm or adviser was involved, complain to the SEC and FINRA as well.
  5. Expect a call or message offering to recover your money for a fee. That is the follow-on scam; read our recovery-scam guide before replying to anyone.

Check the company behind the request

A convincing voice or face tells you nothing about whether a firm is registered. Run a free check on the company name before any money moves.

Frequently Asked Questions

Commercial voice-cloning tools advertise usable results from very short samples — often well under a minute of clear speech. A voicemail greeting, a podcast clip, a wedding toast posted to social media, or a video where someone speaks to camera is enough raw material. You cannot assume a familiar voice on the phone proves identity anymore.

Yes. In early 2024, the engineering firm Arup confirmed that a Hong Kong employee transferred roughly US$25 million after joining a video call in which the chief financial officer and other colleagues were AI-generated fakes. The employee had doubts after an initial email, but the video call resolved those doubts — which is exactly why the attack worked.

Sometimes, but you should not rely on it. Older fakes showed blinking irregularities, blurred hairlines, mismatched lighting, and lip-sync drift. Current tools have reduced many of those artifacts, and low-bandwidth video calls hide the rest. Verification through a separate channel is far more reliable than visual inspection.

It is a short phrase agreed in advance, in person, and never written down or shared online. If someone calls claiming to be your grandchild in trouble, you ask for the phrase. A voice clone can reproduce the voice, but it cannot know a phrase that exists only inside your family. The FBI has recommended this exact practice.

Almost never. Deepfaked clips of well-known business figures, television hosts, and government officials promoting trading platforms or crypto giveaways are one of the highest-volume forms of AI fraud. No legitimate public figure recruits members of the public into a financial opportunity through a social media video and a messaging app link.

Call your bank or the payment provider immediately and use the words "I am reporting fraud" — speed matters more than explanation, because some wires and card payments can still be recalled within hours. Then file with the FBI Internet Crime Complaint Center at ic3.gov and report to the FTC at reportfraud.ftc.gov. Expect follow-up contact from fake recovery agents afterwards.

Not dependably. A determined attacker researches social media first and may have the real person's stolen email or messages. Worse, live cloning tools let a human operator answer in real time in the cloned voice. Hang up and dial the number you already have for that person instead.

Protect Your Investments

Download our free Investor Protection Guide with actionable steps to verify companies and avoid scams.

I agree to receive recurring automated text messages at the phone number provided. Consent is not a condition to purchase. Msg & data rates may apply. Reply HELP/STOP. Terms & Privacy.

Your information is secure and never sold

How do you check a company or person right now?

Use the free check on this site. Enter the name and it searches the official registers for you in one step, then shows you what those records say — registration status and anything reported against them. Every answer names the official source behind it, so you can confirm it yourself if you want to.

Who writes these guides

Written and reviewed by the Smart Money Verified Team. We build every guide from primary regulator material, we take no payment from any company we write about, and we say plainly when public records cannot answer a question. Our guides are education, not financial advice.

How we check things: our methodology · disclosures