AI Scams & Deepfakes: How to Spot Them in 2026

Quick answer: AI scams now include cloned voices, deepfake video calls, and phishing emails written well enough that “bad grammar” is no longer a reliable red flag. The one defence that still works against almost all of them: verify through a channel the scammer doesn’t control — call the person back on a number you already have, don’t trust the one they gave you.

Why the Old Advice Stopped Working

“Look for spelling mistakes” and “the voice sounds a bit off” used to be reasonable scam-detection advice. They aren’t reliable anymore. Scammers can clone a voice convincingly from a few seconds of audio pulled off a social media video, and AI-written phishing emails read as fluently as anything a real colleague would send. Content-based detection — trying to spot that something is fake by how it looks or sounds — gets less reliable every year as the underlying tools improve. The practical response isn’t to get better at spotting fakes visually; it’s to change how you verify who you’re actually talking to.

The Main Types You’ll Actually Encounter

Voice cloning. A call that sounds exactly like a family member, in distress, needing money urgently — built from a short clip of their real voice, often pulled from something they posted publicly.

Deepfake video. A realistic face on a video call or in an ad, used to impersonate someone trusted (a colleague, a public figure, sometimes a company’s own “official” representative).

AI-written phishing. Personalised, well-written emails or messages that reference real details about you or your company, making them far more convincing than the generic “Nigerian prince” era of phishing.

Fake AI apps. Apps marketed as AI tools that actually exist to harvest data or install malware — capitalising on genuine interest in AI to get past normal caution.

The Tell That Still Works: Urgency

Almost every version of this scam relies on the same pressure: act now, before you have time to check. A “family member” in a crisis who needs money transferred immediately. A “boss” who needs an urgent payment approved before a call ends. An account that will be “permanently locked” unless you act in the next ten minutes. That urgency is doing the scammer’s work for them — it’s designed to stop you from pausing to verify. The single most useful habit is treating urgency itself as the warning sign, not a reason to skip verification.

How to Actually Verify

  • Call back on a number you already have — not one given to you in the suspicious message or call. If it’s really your bank, your sibling, or your boss, they’ll still be reachable on the number you already had for them.
  • Use a different channel entirely. If the “urgent” message came by text, verify by calling. If it came by call, verify by messaging on an app you know they actually use.
  • Set a family code word. Agree, in advance, on a word or phrase only real family members would know, to use if anyone calls claiming an emergency. This defeats voice cloning outright, because the scammer has your relative’s voice but not the agreed word.
  • Slow down on anything urgent + financial. The combination of “right now” and “money” is the single strongest scam signal that exists, AI-powered or not.

Reducing How Exposed You Are

Voice cloning needs source audio — the less of your (or your family’s) voice is publicly available in videos and posts, the harder you are to clone convincingly. This isn’t about disappearing from the internet; it’s a reason to lean toward private accounts for anything with a lot of spoken audio, particularly for children.

Multi-factor authentication on financial accounts remains one of the highest-value single defences available — even a scammer with a cloned voice or a convincing phishing email usually can’t get past it. For the practical version of setting this up properly, see our guide on passkeys vs passwords.

What To Do If You Think You’ve Been Targeted

Don’t act on anything under pressure — hang up, close the message, and verify independently first. If money has already been sent, contact your bank immediately (many can freeze or recall a transfer within a short window) and report it via Action Fraud in the UK. If it’s ongoing harassment or impersonation, keep evidence (screenshots, call logs) before it disappears.

If this is a concern involving your kids specifically, our Cybersecurity for Kids guide covers the family-safety version of all of this.

FAQ

Can AI really clone someone’s voice from just a few seconds of audio? Yes — this is now well-documented and doesn’t require special access or expensive tools, which is exactly why “the voice sounded right” is no longer a safe way to verify someone’s identity on a call.

How do I explain this to older relatives who might be targeted? Keep it concrete rather than technical: agree on a family code word for emergencies, and make “I’ll call you back on your usual number” a normal, expected response to any urgent call — not something that would seem rude or distrustful.

Are deepfake video calls common yet, or mostly a future risk? They’re already being used in real scams, particularly in impersonation of executives for business payment fraud — not yet as common as voice-based scams for individuals, but the underlying technology is accessible enough that this is a genuine near-term concern, not science fiction.

Leave a Comment

Your email address will not be published. Required fields are marked *

Pin It on Pinterest

Scroll to Top