How-To Guides

Spot AI-Powered Scams and Deepfakes

The old test used to be bad spelling and odd phrasing. AI removed both. Here is what to check instead.

Step 1. What Has Actually Changed

AI writes fluent, error-free text, in any tone, in any language. It can also clone a voice from a short sample of someone speaking. Both of those are now cheap and quick.

Two pieces of common advice are now obsolete:

  • •Looking for bad grammar and odd phrasing no longer works, because there is none.
  • •Trusting a familiar voice no longer works, because a voice can be copied.

This is not about you being easier to trick than before. It is that the old warning signals have been removed.

The good news is that the reliable defences are habits, not technology. Habits work regardless of how good the fakes get.

Step 2. The One Habit That Defeats Most Impersonation

The habit is called out-of-band verification. If a message asks you to do something important, confirm it through a different channel that you already trust. Not the one in the message.

Phone the number you already have on file. Never the number they gave you, because that number belongs to them.

A concrete example. A supplier emails to say their bank details have changed, and asks you to update them before the next payment.

  1. 1.Do not reply to the email.
  2. 2.Phone the supplier on the number you already had.
  3. 3.Only then, update the details.

That one habit defeats most AI impersonation, no matter how convincing the message is.

Step 3. Deepfake Voice And Video

A short recording of someone speaking is enough to clone their voice plausibly. A few seconds from a video, a voicemail, or a social post will do it.

This makes the family emergency scam far more convincing. A panicked call arrives claiming a relative is in trouble and needs money urgently. The voice sounds exactly right.

Practical defence, agreed in advance:

  • •Agree a shared passphrase or word with family members, to use in an emergency.
  • •Never treat voice or video alone as proof when money is involved.

Be honest with yourself here. You cannot reliably detect a good deepfake by eye or ear. That is exactly why the passphrase matters. It does not rely on spotting anything.

Step 4. Verify The Request, Not The Presentation

Change what you are assessing. Stop asking whether the message looks real. Start asking what it asks you to do.

These are the real warning signs, regardless of how well the message is written:

  • •A request to move money.
  • •A request to change bank details.
  • •A request to buy gift cards.
  • •A request to share a login code.
  • •Pressure to act urgently.

Urgency is the oldest trick in the book, and AI has made it much easier to manufacture. Fluent, well-written urgency is still urgency.

Step 5. Check AI Answers Before You Act On Them

A newer problem sits alongside classic scams: an AI tool giving you a confident, plausible answer that is simply wrong. This matters most when the answer drives an action, such as a price, a legal point, a medical question, or a piece of code you are about to install.

A specific example worth knowing: AI coding assistants sometimes invent names of software packages that do not exist. The name looks entirely convincing. Attackers watch for these invented names and register them in advance, so the package the AI recommends turns out to be malicious. If an AI suggests installing something, confirm it actually exists and is genuinely used before you install it.

The habit that transfers from scam defence: a confident tone is not evidence. Treat any AI output that drives a decision as something to check against a real source, in the same way you would verify an unexpected payment request.

  • •Treat confident tone as presentation, not proof.
  • •Check anything that drives a decision against a real, named source.
  • •Verify software package names before installing anything an AI suggests.

Step 6. Protect Your Voice And Face

You cannot stop someone cloning you, but you can reduce the raw material available. Think before posting recordings or videos publicly.

  • •Be careful with voice notes in group chats with people you do not know well.
  • •For a business, consider how much staff video is published, and where.
  • •Remember that public voice and video can be reused by anyone who finds them.

This does not mean hiding. It means knowing that what you publish is raw material, and choosing what to publish with that in mind.

Step 7. A Ten-Minute Briefing For Your Household Or Team

Make this real by making it shared. Gather the people who might receive such a request, and cover four things:

  1. 1.Explain the one rule: verify by a separate channel before acting, and never trust voice alone.
  2. 2.Agree the family passphrase, and use it consistently.
  3. 3.Agree who to call if something happens, and who to ask before making a decision under pressure.
  4. 4.Agree in advance that nobody will be embarrassed for checking, however urgent it feels.

A short shared rule beats any amount of software, because the target of these attacks is a person under pressure, not a computer. A person who has heard the rule once, in advance, is far harder to rush.

Tips

  • •Stop looking for bad grammar, start looking at what you are being asked to do.
  • •Phone the number you already have, never the one in the message.
  • •A shared family passphrase defeats voice cloning outright.
  • •Urgency is the warning sign, regardless of who appears to be asking.
  • •You cannot reliably spot a good deepfake, so do not rely on spotting it.
  • •Ten minutes of briefing beats any software for this one.

Need More Help?

StarCaller Academy offers 1-to-1 sessions to help you with any of these topics and more.