It looked like your bank. The voice sounded familiar. The caller ID showed the bank's number. Then something felt slightly off — a pause a little too long, a sentence a little too smooth. You hung up. Then you found out it wasn't your bank at all.
AI scams are everywhere now. Voice cloning (an AI that copies someone's voice from a short audio sample), AI-written emails, and AI video "deepfakes" (realistic but fake video of a person) are being used to steal money, passwords, and personal details. You don't need to be technical. You just need a small set of checks you can run in seconds.
Before you start
You won't need any special app. A phone, a notepad, and two minutes are enough. You do need a way to look up an official number yourself — that's a phone book, a recent bill, or the company's website that you visit by typing the address into your browser (never by tapping a link inside a message). If something feels off and you want to report it later, the FTC (the US consumer protection agency) takes reports at reportfraud.ftc.gov. Other countries have equivalent public pages — search "report scam" plus your country name.
Step 1 — Hang up and verify the number yourself
If a caller claims to be from your bank, the tax office, or a delivery company, the safest move is to end the call and call back on a number you found yourself.
What to do: End the call. Open your browser and type the company's website address directly — never click a link in the message. Find their contact number on the "Contact us" page. Call that number and ask if anyone from the company just tried to reach you.
Where to find the official number: a paper bill, your account settings, or the company's site — one you typed in yourself.
💬 Try this script: "I got a call claiming to be from your company. Can you confirm this on a number I called you on?"
You'll know it worked when the second call reaches the real company and they have no record of the first one. That alone confirms the first call was fake.
Step 2 — Listen for AI voice tells
Real human voices have natural texture. AI voices usually don't — yet.
What to listen for: (1) Background noise — typing, breath, distant traffic. AI audio is often eerily clean. (2) Pitch variation — does the tone rise and fall naturally, or stay flat on words meant to be emotional? (3) Pause length — gaps that are slightly too long and don't sound like natural thinking pauses.
When to check: the first minute of any call from someone you weren't expecting.
💬 Try this line: "Sorry, could you say the last part again?" Humans rarely repeat a sentence word-for-word. AI voices often do.
You'll know it worked when you can name one specific thing the voice did that didn't sound human — flat urgency, perfect pause, total silence in the background.
Step 3 — Read AI-written text for its tells
Scammers use AI to write emails and texts too. AI text has fingerprints (small signs that something is machine-written) — and they're easy to spot once you know them.
What to do: Open the message and look for three signs. (1) Urgency on the first or second line — "Act within 24 hours or your account closes." Real companies usually give you time. (2) Slightly off formality — "We kindly request your immediate attention to this matter." Real people rarely write that way. (3) Almost-right typos — "verifcation" instead of "verification."
Where to check the sender: open the email and tap the sender's name to see the full address. Real companies send from their own domain (e.g., @yourbank.com). Scams use lookalikes (@yourbank-secure.com, @yourbank.help).
💬 Try this line: "I don't click links in messages. What's the page I should visit?" A real person names a specific page. An AI will hedge.
You'll know it worked when you can name at least two specific tells in the message — odd tone, suspicious sender domain, or pushy deadline.
Step 4 — Ask a question only the real person would know
A real agent from your bank knows your account. A real delivery service knows your order. An AI scammer does not.
What to do: Pick one question the real company would know but a stranger wouldn't. Ask once, calmly, while you have a moment in the call.
💬 Try one of these: "Before we go on, can you confirm the email address on file for me?" or "What's the order number you have?" A real agent answers both in two seconds.
You'll know it worked when the answer is fast and specific. Vague replies or long pauses are a red flag — politely end the call and verify through Step 1.
Step 5 — Report confirmed scams the same day
If you spotted a scam — even one you didn't fall for — report it. Reports help agencies track patterns and warn others.
What to do: Write down date, time, what the caller wanted, the number they used, and what you noticed. Screenshot the message if there is one. Then go to your country's fraud-reporting page and file.
Where to file: in the US, that's reportfraud.ftc.gov. Other countries have equivalent public pages — search "report scam" plus your country's name, or check your national consumer agency's site.
💬 Try this wording in the form: "Received a [call/message] on [date] at [time] from [number]. They claimed to be [company] and asked for [what]. I did not share details. I believe it was AI-generated because [what you noticed]."
You'll know it worked when you get a confirmation number or email. Save it — if anything else happens later, you have a paper trail.
Step 6 — Set up protection for next time
Most AI scams work because one person feels rushed. A few settings buy you months of safety.
What to do: Turn on two-factor authentication (2FA) — login confirmation through a second device or code — on your email, bank, and social accounts. Set a family "safe word" — a nonsense word only your family knows — for any urgent request.
Where to find 2FA: in each account's Security or Login settings. Look under your name or profile icon → Settings → Security. The exact menu label varies ("Two-step verification" is also common), but it's always under Security.
💬 Use this with your family today: "Our safe word is [pick a noun — e.g., 'silver kettle']. If anyone calls saying it's me or someone in the family and they can't say the safe word, we hang up."
You'll know it worked when 2FA is on for your email and bank, and your family knows the safe word by heart.
Common mistakes
- Trusting the caller ID. Caller ID can be "spoofed" — faked to show any number. Don't trust the screen; verify by calling the company back on a number you found yourself (Step 1).
- Clicking links in "urgent" messages. Even when they look real. The fix: type the address into your browser yourself, or open the company's app directly.
- Feeling rude for hanging up. You don't owe a stranger your time. Hanging up and verifying is the safe move, not the rude one.
- Thinking you're not a target. Voice cloning needs only a few seconds of audio, often taken from public social media videos. Anyone can be targeted — being "too ordinary" doesn't protect you.
- Skipping the report. "It didn't work on me" still helps the next person. Reports build the pattern that agencies warn others about. The fix: file the same day (Step 5).
AI scams will keep getting better. Your checks don't have to be fancy. Hang up. Listen. Read closely. Ask. Report. Set up the basics. That's the whole skill.
