For years, we taught people to spot phishing by its clumsiness: broken English, weird formatting, “Dear Costumer.” That advice is now dangerously outdated. Generative AI writes flawless, personalized scam messages at industrial scale — and it clones voices, too. The scammers upgraded. Your defenses need to as well.
Here’s what modern AI-powered scams look like, and the tells that still work.
What’s changed
Perfect writing, personal details. AI lets scammers scrape your public footprint — LinkedIn job title, recent posts, your company’s org chart — and generate a message that reads like it genuinely came from your manager or your bank. Grammar is no longer a signal.
Voice cloning. A few seconds of audio from a social media video is enough to clone a voice convincingly. The classic version: a panicked call that sounds exactly like your child or parent, claiming an emergency and needing money now. Businesses face the corporate flavor — a “CEO” calling accounts payable to authorize an urgent transfer.
Deepfake video. High-value corporate fraud has already featured fake video meetings with AI-generated “executives.” Rare for ordinary people, but no longer science fiction.
Scale. The scariest change is volume. What once required a skilled human scammer per victim can now be automated across thousands of targets simultaneously.
The red flags that AI can’t erase
Here’s the good news: AI improved the costume, but the script is unchanged, because the psychology of scams is unchanged. Every scam still needs these ingredients — and each one is a detectable flag:
Urgency. “Act within 24 hours.” “Your account will be suspended.” “Don’t tell anyone, there’s no time.” Urgency exists to bypass your thinking brain. Real institutions almost never require instant action, and genuine emergencies survive a five-minute verification.
Unusual payment channels. Gift cards, cryptocurrency, wire transfers, payment apps to personal accounts. No legitimate company or government agency settles debts in Google Play cards. This flag alone catches an enormous share of scams.
Requests for credentials or codes. No real support agent needs your password or the one-time code that was just texted to you. That code request specifically means someone is actively trying to log into your account right now.
Channel switching. “Let’s move this to WhatsApp/Telegram.” Scammers push you off monitored platforms and away from records.
Something’s slightly off with the sender. Check the actual email address, not the display name. Hover over links before clicking. A domain like yourbank-security-verify.com is not your bank.
Your two strongest defenses
- Verify through a second channel — always. This single habit defeats nearly everything, including perfect deepfakes. Boss emails asking for a payment? Call the number you already have for them. “Bank” calls you? Hang up and dial the number on the back of your card. Family emergency call? Contact the person directly, or ask a question only they’d know. The scammer controls the channel they contacted you on; they don’t control the channels you already trust.
- A family code word. Agree on a private word or question with close family. Any emergency money request that can’t produce it is fake. It’s low-tech, slightly silly, and remarkably effective against voice cloning.
Lock the doors in advance
Turn on two-factor authentication everywhere (app-based or passkeys beat SMS). Consider limiting how much of your voice and personal detail sits on public profiles. And talk to older relatives — they’re targeted disproportionately, and one conversation about gift-card scams and code words does more than any antivirus.
The mindset shift
The old rule was “look for sloppiness.” The new rule is “trust the process, not the message.” Any unexpected contact that wants money, credentials, or secrecy gets verified through a channel you choose — no matter how perfect it looks or how familiar it sounds. Polish is now free. Skepticism has to be, too.