Every scam in this guide existed before AI. The panicked call from a relative in trouble, the boss's urgent payment request, the too-good investment pitch, the romance that needs money — all classics. What AI changed is the production values: the panicked voice can now *be* your relative's voice, cloned from seconds of audio scraped from a video online; the video call can wear a colleague's face; the phishing email, once betrayed by its broken English, now reads flawlessly and references your actual life. The result is a simple, uncomfortable inversion: your senses are no longer a verification method. The good news fills the rest of this guide — the defenses that work do not depend on your senses, they are decades old in spirit, and a family can install them in an evening.

The upgraded classics, briefly

  • The emergency call. A loved one's voice, in distress, needing money or gift cards *now* — the urgency engineered to outrun your judgment, secrecy ('don't tell mom') engineered to isolate you. Voice cloning turned this from a numbers game into a targeted weapon, and older relatives are its primary market.
  • The executive request. The boss, by voice or video call, authorizing an urgent transfer. Real companies have lost enormous sums to exactly this; the corporate defense is the same as the family one, [plus process](/work/ai-use-policy/): out-of-band verification for any payment request, no matter who appears to make it.
  • The polished phish. AI erased the spelling-error tell and personalized the bait. The message that knows your bank, your recent order, your colleague's name is now cheap to mass-produce.
  • The synthetic endorsement. A celebrity or trusted expert, on video, recommending an investment platform. If a famous person appears to be urging you toward crypto or a trading app, the prior probability you are watching a deepfake ad is overwhelming.
  • The manufactured relationship. Romance scams now run on AI conversation at scale — attentive, fluent, patient — and the tell was never the words anyway: it is the arc that ends in a reason to send money to someone never met.

The defenses that actually work

The unifying principle: verify through a channel the scammer does not control. Everything else is elaboration.

  • Hang up and call back on the number you already have for that person — not the one that called you. This single reflex defeats the voice-clone emergency call completely, because the scammer controls the incoming call and nothing else.
  • Set a family code word. Agree, in person, on a phrase for genuine emergencies — and a question protocol: anyone claiming to be family in crisis gets asked something no scraper of social media could know. Make it a family joke if that helps it stick; it works regardless.
  • Let urgency itself be the alarm. Every one of these scams manufactures time pressure, because delay is fatal to them. Reframe it: *the more urgent and secret the request, the more mandatory the pause.* Legitimate emergencies survive a five-minute verification; scams do not.
  • Move money only on your own initiative. Payments, transfers, gift cards, crypto — never in response to an inbound contact, whoever it appears to be. Initiate through the app, the number on the card, the person down the hall.
  • Harden the easy surfaces. Voicemail greetings in your own voice, public videos of family members, oversharing accounts — this is the raw material of cloning. Locking down what strangers can scrape is worth an afternoon, [especially for kids](/school/ai-literacy-for-families/).

Stop trying to spot the fake

A hard truth stated plainly, because folk advice keeps teaching the opposite: glitch-spotting is a losing strategy. The tells of last year's fakes — odd hands, unblinking eyes, robotic cadence — are the tells of *last year's* fakes, and each generation erases more of them while real, compressed, badly-lit authentic media triggers false alarms. Provenance-labeling standards and platform takedown duties [are advancing](/society/ai-regulation-landscape/) and welcome, but no watermark saves the person deciding in real time on a phone call. The durable skill is refusing the game: not 'does this look real?' but 'has this been verified through an independent channel?' — the [same shift from vibes to verification](/society/how-to-read-ai-news/) this entire track keeps recommending, applied at the kitchen table.

If it happens anyway

Speed matters and shame is the enemy. Contact your bank immediately — fast-reported transfers are sometimes recoverable, and the window is short. Report it: in the US, the FBI's IC3 and the FTC at reportfraud.ftc.gov; elsewhere, your national fraud portal — reports drive both enforcement and the warnings that protect the next family. Warn your circle, because targeting clusters. And say it out loud, especially to the older relatives this guide most protects: these scams work on smart people *by design* — professional-grade psychological pressure delivered with synthetic authenticity. Treating victims as fools is exactly what keeps the next victim from asking for help in time. The family that talks about this stuff openly, code word and all, has already built the only detector that keeps working.