LatestPentagon gives Musk 120 days to design the next war and Micron's margin hits 86%
THE ZAO°EFFECT

Guides · Updated October 3, 2026

How to Spot AI Scams: Cloned Voices, Deepfake Videos and Smarter Phishing

Scammers clone voices from seconds of audio and fake whole video calls. The real warning signs and a simple protocol to protect your family and business.

The underlying con is ancient. Impersonating a relative in trouble or an authority figure to get your money predates the internet by decades. What's new is that AI gave it superpowers: now the voice on the phone sounds exactly like your son, your “boss” shows up on a video call asking for a wire transfer, and the email from your “bank” doesn't have a single typo.

This guide covers all three fronts —voice, video and text— with documented real cases, the warning signs that actually work, and a simple protocol for your family and your business. No paranoia and no jargon: you don't need to understand the technology, you need three habits that cost nothing.

Why the old cons just got more dangerous

For years, the classic anti-scam advice was “look for the typos” or “that voice sounds robotic.” That advice is dead. The FBI publicly warned that criminals are using generative AI to make their fraud more believable and at a larger scale: flawless text, fabricated profile photos, cloned voices and fake videos.

There's only one mental shift you need to make: you can no longer trust how something looks or sounds. Anything you see or hear can be fabricated. What can't be fabricated is the channel: if you hang up and call the number you've always had, the scammer is out of the game. This entire guide boils down to that principle.

One important nuance before we continue: this doesn't mean AI is the enemy. The same tools we recommend in our free AI tools guide are neutral; the problem is who uses them and for what. Understanding how scammers operate is, today, part of basic digital literacy.

Cloned voices: the “family emergency” call that isn't

Here's how it works: the scammer gets audio of you or a relative —forwarded voice notes, social media videos, an Instagram live— and uses it to generate a copy of the voice. The US FTC has been warning about this scheme since 2023: they call a mother or grandmother with a cloned voice of her son saying he had an accident, he's been arrested, he needs money now. According to security experts, a few seconds of audio are enough for a convincing imitation.

In Latin America the scheme has a well-known variant: your WhatsApp account (or a contact's) gets hijacked, and from that real number they ask to borrow money “for an emergency,” sometimes with generated voice notes. Because the message comes from your friend's actual number, your guard drops.

The defense has two layers, and neither requires technology. First: hang up and call them yourself at the number you've always had. If the emergency is real, they'll pick up or call you back. Second: agree on a family safe word —a word or phrase only your family knows, to be asked for whenever there's an urgent request for money. It's exactly what the FBI recommends in its alert, and it turns a sophisticated scam into a failed ten-second call.

Deepfake videos: from the fake “boss” on a call to celebrities selling investments

The case that put this risk on the map is real and widely documented: in 2024, a finance employee at engineering firm Arup, in Hong Kong, wired about US$25 million after a video call “attended” by the CFO and several colleagues. Every attendee was a deepfake. It wasn't a suspicious email: it was a video meeting that looked normal.

The second format doing the most damage is celebrity ads. Fake videos of figures like Elon Musk “recommending” investment platforms with guaranteed returns have circulated massively on social media, and organizations like AARP have documented victims who lost their savings. The rule here needs no technology: guaranteed returns don't exist. If a celebrity promises to double your money in an ad, it's a scam, no matter how real the video looks.

For suspicious video calls there are simple checks that raise the cost of the con: ask for something unpredictable —have the person turn their head, pass a hand in front of their face, or answer something only they would know— and be suspicious if the “camera fails” right when you ask. Caveat: these tests help but aren't foolproof, because the technology improves every month. The verification that never expires is the old one: confirm through another channel before moving money. If you handle payments for your business, make sure no transfer ever goes out on the authority of a single call or video call, no matter who it appears to come from.

AI phishing: emails and messages with zero typos

Classic phishing gave itself away: pixelated logos, weird wording, “dear customer.” With generative AI, the scammer writes flawlessly, mimics the exact tone of your bank or a platform you use, and can personalize the message with information about you that's publicly available online. The visual filter no longer protects you; the behavioral filter does.

The signals that survive AI are behavioral ones, because the scammer can't avoid them: artificial urgency (“your account will be suspended today”), requests for data or payments that no legitimate company asks for over messages, links you never asked for, and pressure to switch channels or keep things secret. Payment requested in crypto, gift cards or immediate wire transfer is a red flag in any context: those are the methods that can't be reversed.

The right response is never to reply to the message: it's to go in directly yourself — type your bank's or the platform's address into the browser, or open the official app, and check there. And the single most cost-effective preventive measure is enabling two-step verification on WhatsApp, email and banking. On WhatsApp it's under Settings → Account → Two-step verification, and it stops cold the account hijacking that kicks off many of these scams. If you use WhatsApp for your business, this matters as much as everything in our WhatsApp automation guide; and if you get paid online as a freelancer, double your care with payment links people send you — we cover it in the getting paid in dollars guide.

Your anti-scam protocol in three habits (and what NOT to do)

Everything above boils down to three habits that cost nothing and work against today's scam and whatever they invent next year. Share them with your family —especially the older members— and if you run a team, turn them into a written business rule.

  • Verify through another channel. Any request for money, data or codes gets confirmed by hanging up and calling the number you've always had, or going directly to the official site yourself. No exceptions, not even for the “boss.”
  • Family safe word. Agree on a secret word with your family for emergencies. Whoever asks for urgent money and doesn't know it, isn't who they claim to be.
  • Pause when rushed. Urgency is the scammer's weapon: every scheme needs you to act before you think. A fifteen-minute pause defuses almost all of them.
  • DON'T trust caller ID: the number displayed can be spoofed.
  • DON'T call back the number that called you or the one left in the message: look up the official number yourself.
  • DON'T install apps or share codes requested by “the bank” or “tech support” over the phone: the codes that arrive by SMS are the keys to your accounts.
  • NEVER pay an “emergency” with crypto, gift cards or remittances to strangers: no legitimate agency or company charges that way.

If you already fell for it: the first steps matter more than the embarrassment

First, breathe: these scams are designed by professional crews and people at every level fall for them —including a finance employee at a multinational engineering firm. Embarrassment is the scammer's best ally, because it keeps people from acting or reporting.

The order of operations: (1) contact your bank or payment platform immediately to try to freeze or reverse the transaction — every hour counts; (2) change the passwords on compromised accounts and turn on two-step verification; (3) if your WhatsApp or a social account was hijacked, warn your contacts through another channel so they don't fall in a chain; (4) report it: in the US, at reportfraud.ftc.gov; elsewhere, with your local police cybercrime unit.

And a final warning that is itself a second-round scam: after losing money, you may be contacted by supposed “fund recovery” services —sometimes posing as government agencies— promising to get your money back for a fee. It's the same people or their colleagues. The FBI has even warned about fake videos of its own spokespeople being used for this second round. No legitimate party charges you upfront to recover your money.

Work with me

Want this applied to your business?

Digital strategy, automation and AI workflows for companies in the US and Latin America.

Tell me about your project →

Frequently asked questions

Can they really clone a voice from just a few seconds of audio?

Yes. The FTC and security specialists agree that a few seconds of public audio —a voice note, a social media video— are enough to generate a convincing imitation. You don't need to be famous: your voice being online is enough. That's why the defense isn't hiding, it's verifying through another channel.

Do deepfake detector apps actually work?

Don't stake your safety on a detector. Results are inconsistent and generation technology moves faster than detection. Verifying through a separate channel —hanging up and calling yourself— remains more reliable than any app, and it never becomes obsolete.

Should I delete my audio, photos and videos from social media?

It's neither realistic nor necessary. It is worth reviewing your profiles' privacy settings (who can see your stories and posts), avoiding posting data like your phone number next to videos of you speaking, and assuming anything public can be copied. The real protection is in verification habits, not in disappearing from the internet.

How do I protect my parents or grandparents without scaring them?

Three concrete things: explain how the cloned-voice “family emergency” call works (knowing the trick is half the defense), agree on the family safe word, and set up two-step verification on their WhatsApp. Close with the golden rule: with any urgent request for money, hang up and call the relative directly.

Related guides

The signal, straight to your inbox.

Every weekday: the tech and AI stories that matter, verified and condensed to a 3-minute read. No spam, ever.