Could You Spot an AI Scam?
Scams used to give themselves away with bad grammar and blurry logos. AI removed those tells: a scammer can now copy a relative’s voice, write a flawless bank alert, or appear on a video call as someone you know.
Here are 10 real-world situations. Some are scams, some are legit. Decide the way you would in real life — quickly — then see the explanation after each one.
Think your family would pass? Send them the test:

Don’t Get Scammed by AI
Written by ExamineIP. Every scam in this test explained in depth, with red-flag checklists, annotated examples and step-by-step defences for you and your family.
See the book on Amazon →How AI Changed Scams
The scams themselves are old: fake emergencies, fake bank alerts, fake investments, fake jobs. What AI changed is how convincing and how cheap they are to run.
- Voice cloning. Security researchers at McAfee produced a clone with an 85% match to the original voice from just three seconds of audio. A short video on social media can be enough.
- Deepfake video. Live video calls can now show a convincing fake face and voice. Businesses have lost millions after staff joined calls with what looked like their own senior managers.
- Flawless writing. Phishing emails and texts no longer have the spelling mistakes people were taught to look for, and they can be personalised with details from your social media in seconds.
- Scale. One person can run conversations with hundreds of targets at once.
The FBI’s 2025 Internet Crime Report counted AI-related scams separately for the first time: 22,364 complaints and nearly $893 million in reported losses in the United States alone. Those are only the cases where victims realised AI was involved and reported it.
🚩 The Red Flags AI Can’t Remove
AI can fake a voice, a face and a writing style. It can’t change what the scam needs from you. Nearly every scam in the test — and in real life — relies on at least one of these:
| Red flag | What it sounds like | Why scammers need it |
|---|---|---|
| Urgency | “Within 24 hours”, “right now”, “or your account will be closed” | Pressure stops you checking |
| Secrecy | “Don’t tell anyone”, “keep this between us” | Someone else would spot it |
| Unusual payment | Gift cards, crypto, wire transfer, “move your money to a safe account” | These are hard or impossible to reverse |
| They contacted you | An unexpected call, text, email, DM or dating match | You didn’t choose the channel, so you can’t trust it |
| A request for a code | “Read me the number we just sent you” | One-time codes are the key to your accounts |
| Moving you elsewhere | “Let’s continue on WhatsApp”, “use this link instead of the app” | It gets you away from the platform’s protections |
| Too good to be true | Guaranteed returns, a job after a five-minute chat, a prize you didn’t enter | Greed and hope override caution |
Six Habits That Beat Almost Every Scam
- Never act inside the message that contacted you. Don’t click the link, call the number given or reply. Go to the company yourself — its app, the website you type in, or the number on your card.
- Call back on a number you already know. If “your daughter” calls from an unknown number, hang up and ring her real one. A clone can copy a voice, but it can’t answer her phone.
- Agree a family code word. Pick something that isn’t on social media. Anyone calling in a “family emergency” should know it.
- Never share one-time codes. No bank, delivery company or tech support team needs the code they just sent you. Anyone asking for it is trying to get into your account.
- Wait before moving money. Real emergencies survive a ten-minute delay to check. Scams usually don’t.
- Read the actual web address. Look at the part just before
.comor the country ending: chase.com is Chase; chase-secure-verify.com is someone else. A padlock only means the connection is encrypted, not that the site is honest — see what HTTPS really proves.
🔍 Check a Suspicious Message With Free Tools
If an email or link doesn’t feel right, these free tools help you look behind it. None of them needs an account.
- Where did that email really come from? Paste its headers into the email header analyzer. It shows the servers the message passed through and whether it passed the sender checks that fake emails usually fail.
- How old is that website? Look the domain up with the WHOIS lookup. A “bank” or “delivery” site registered a few days ago is a strong warning sign.
- Has your password already leaked? The password tools check it against known breaches without sending the password itself.
- Is that address known for abuse? The IP reputation check shows whether an IP address appears on spam and abuse blacklists.
Scammers also find targets through the personal details already online about you. The free opt-out directory walks through removing yourself from data brokers, and what your browser tells every website shows what any page can learn about you without asking.
The Scams in This Test, Explained
| Scam | How it works | The tell |
|---|---|---|
| Fake bank alert | A text or email about a blocked payment, with a link to “verify” | A link to a look-alike domain, plus urgency |
| Voice-clone emergency | A relative’s cloned voice asks for money urgently and secretly | Unknown number, secrecy, gift cards or crypto |
| Look-alike sender | An email from a domain one character off the real one | “paypa1” instead of “paypal”; “Dear Customer” |
| Fake-cheque job | You’re “hired”, sent a cheque, and asked to forward part of it | Any employer asking you to send money back |
| QR code swap (“quishing”) | A sticker over a real QR code on a meter, table or charger | A code on top of another code; a page asking for card details |
| Romance investment (“pig butchering”) | Weeks of friendship or romance, then a “guaranteed” crypto platform | Any investment tip from someone you only know online |
| Delivery fee | A text says a parcel is held until you pay a small fee | A link in a text instead of the courier’s own app |
| Recovery scam | Someone offers to get back money you already lost — for a fee | An upfront fee to recover your own money |
If You’ve Already Been Scammed
Act fast, and don’t be embarrassed. These scams are built by professionals to fool careful, intelligent people. The sooner you act, the better the chance of stopping a payment.
Be ready for a second contact, too. Scammers keep lists of people who have already paid, and a common follow-up is a call or message from a fake “fund recovery” agent, lawyer or even the FBI, offering to get your money back for a fee. That’s a recovery scam — the real FBI never charges to recover money.
- Stop all contact with the scammer. Don’t send anything more, even if they threaten you.
- Call your bank or card provider on the number on your card. Ask them to stop or recall the payment and to watch the account.
- Change your passwords, starting with email and banking, and turn on two-step verification.
- Keep the evidence: screenshots, phone numbers, email addresses, payment receipts and wallet addresses.
- Report it. In the US, report to the FTC at reportfraud.ftc.gov and to the FBI at ic3.gov. In England, Wales and Northern Ireland, use Report Fraud (it replaced Action Fraud) or call 0300 123 2040; in Scotland, call Police Scotland on 101. Elsewhere, contact your national police or cybercrime unit.
- Watch for the second wave. Victims are often targeted again by “recovery” services. As the FTC puts it, government agencies and legitimate organisations will never ask for money to help you get a refund.
Frequently Asked Questions
How do AI scams work?
Scammers use AI to clone voices from short clips, create fake video, and write convincing personalised messages at scale. The technology removes the old warning signs, but the scam still needs urgency, secrecy or an unusual payment from you.
How can I tell if a call is a voice clone?
You often can’t by listening. Hang up and call the person back on their known number, or ask for your family code word. A clone can imitate a voice but can’t answer the real person’s phone or know a secret you agreed offline.
What’s the single best defence against scams?
Verify on a second channel. Never act inside the call, text or email that contacted you — check through a route you already trust, such as the official app or the number on your bank card.
Are real companies ever urgent?
Yes, fraud alerts can be. The difference is what they ask for: a genuine alert asks you to confirm a charge or call the number you already have, and never asks for codes, passwords or payment through a link.
I clicked a link but didn’t enter anything. Am I safe?
Usually, if you entered no details and downloaded nothing. Close the page, don’t return to it, and keep your device updated. If you did enter a password, change it everywhere you use it, starting now.
Why do smart people fall for scams?
Because scams target moments, not intelligence: a busy day, a frightening call, loneliness or a financial worry. Having a rule you follow automatically — like always calling back — protects you when you’re not at your sharpest.