⚠ The Scam-Proof Test

Could You Spot an AI Scam?

Scams used to give themselves away with bad grammar and blurry logos. AI removed those tells: a scammer can now copy a relative’s voice, write a flawless bank alert, or appear on a video call as someone you know.

Here are 10 real-world situations. Some are scams, some are legit. Decide the way you would in real life — quickly — then see the explanation after each one.

Question 1 of 10
Don't Get Scammed by AI — book cover

Don’t Get Scammed by AI

Written by ExamineIP. Every scam in this test explained in depth, with red-flag checklists, annotated examples and step-by-step defences for you and your family.

See the book on Amazon →

How AI Changed Scams

The scams themselves are old: fake emergencies, fake bank alerts, fake investments, fake jobs. What AI changed is how convincing and how cheap they are to run.

  • Voice cloning. Security researchers at McAfee produced a clone with an 85% match to the original voice from just three seconds of audio. A short video on social media can be enough.
  • Deepfake video. Live video calls can now show a convincing fake face and voice. Businesses have lost millions after staff joined calls with what looked like their own senior managers.
  • Flawless writing. Phishing emails and texts no longer have the spelling mistakes people were taught to look for, and they can be personalised with details from your social media in seconds.
  • Scale. One person can run conversations with hundreds of targets at once.

The FBI’s 2025 Internet Crime Report counted AI-related scams separately for the first time: 22,364 complaints and nearly $893 million in reported losses in the United States alone. Those are only the cases where victims realised AI was involved and reported it.

🚩 The Red Flags AI Can’t Remove

AI can fake a voice, a face and a writing style. It can’t change what the scam needs from you. Nearly every scam in the test — and in real life — relies on at least one of these:

Red flagWhat it sounds likeWhy scammers need it
Urgency“Within 24 hours”, “right now”, “or your account will be closed”Pressure stops you checking
Secrecy“Don’t tell anyone”, “keep this between us”Someone else would spot it
Unusual paymentGift cards, crypto, wire transfer, “move your money to a safe account”These are hard or impossible to reverse
They contacted youAn unexpected call, text, email, DM or dating matchYou didn’t choose the channel, so you can’t trust it
A request for a code“Read me the number we just sent you”One-time codes are the key to your accounts
Moving you elsewhere“Let’s continue on WhatsApp”, “use this link instead of the app”It gets you away from the platform’s protections
Too good to be trueGuaranteed returns, a job after a five-minute chat, a prize you didn’t enterGreed and hope override caution

Six Habits That Beat Almost Every Scam

  1. Never act inside the message that contacted you. Don’t click the link, call the number given or reply. Go to the company yourself — its app, the website you type in, or the number on your card.
  2. Call back on a number you already know. If “your daughter” calls from an unknown number, hang up and ring her real one. A clone can copy a voice, but it can’t answer her phone.
  3. Agree a family code word. Pick something that isn’t on social media. Anyone calling in a “family emergency” should know it.
  4. Never share one-time codes. No bank, delivery company or tech support team needs the code they just sent you. Anyone asking for it is trying to get into your account.
  5. Wait before moving money. Real emergencies survive a ten-minute delay to check. Scams usually don’t.
  6. Read the actual web address. Look at the part just before .com or the country ending: chase.com is Chase; chase-secure-verify.com is someone else. A padlock only means the connection is encrypted, not that the site is honest — see what HTTPS really proves.

🔍 Check a Suspicious Message With Free Tools

If an email or link doesn’t feel right, these free tools help you look behind it. None of them needs an account.

  • Where did that email really come from? Paste its headers into the email header analyzer. It shows the servers the message passed through and whether it passed the sender checks that fake emails usually fail.
  • How old is that website? Look the domain up with the WHOIS lookup. A “bank” or “delivery” site registered a few days ago is a strong warning sign.
  • Has your password already leaked? The password tools check it against known breaches without sending the password itself.
  • Is that address known for abuse? The IP reputation check shows whether an IP address appears on spam and abuse blacklists.

Scammers also find targets through the personal details already online about you. The free opt-out directory walks through removing yourself from data brokers, and what your browser tells every website shows what any page can learn about you without asking.

The Scams in This Test, Explained

ScamHow it worksThe tell
Fake bank alertA text or email about a blocked payment, with a link to “verify”A link to a look-alike domain, plus urgency
Voice-clone emergencyA relative’s cloned voice asks for money urgently and secretlyUnknown number, secrecy, gift cards or crypto
Look-alike senderAn email from a domain one character off the real one“paypa1” instead of “paypal”; “Dear Customer”
Fake-cheque jobYou’re “hired”, sent a cheque, and asked to forward part of itAny employer asking you to send money back
QR code swap (“quishing”)A sticker over a real QR code on a meter, table or chargerA code on top of another code; a page asking for card details
Romance investment (“pig butchering”)Weeks of friendship or romance, then a “guaranteed” crypto platformAny investment tip from someone you only know online
Delivery feeA text says a parcel is held until you pay a small feeA link in a text instead of the courier’s own app
Recovery scamSomeone offers to get back money you already lost — for a feeAn upfront fee to recover your own money

If You’ve Already Been Scammed

Act fast, and don’t be embarrassed. These scams are built by professionals to fool careful, intelligent people. The sooner you act, the better the chance of stopping a payment.

Be ready for a second contact, too. Scammers keep lists of people who have already paid, and a common follow-up is a call or message from a fake “fund recovery” agent, lawyer or even the FBI, offering to get your money back for a fee. That’s a recovery scam — the real FBI never charges to recover money.

  1. Stop all contact with the scammer. Don’t send anything more, even if they threaten you.
  2. Call your bank or card provider on the number on your card. Ask them to stop or recall the payment and to watch the account.
  3. Change your passwords, starting with email and banking, and turn on two-step verification.
  4. Keep the evidence: screenshots, phone numbers, email addresses, payment receipts and wallet addresses.
  5. Report it. In the US, report to the FTC at reportfraud.ftc.gov and to the FBI at ic3.gov. In England, Wales and Northern Ireland, use Report Fraud (it replaced Action Fraud) or call 0300 123 2040; in Scotland, call Police Scotland on 101. Elsewhere, contact your national police or cybercrime unit.
  6. Watch for the second wave. Victims are often targeted again by “recovery” services. As the FTC puts it, government agencies and legitimate organisations will never ask for money to help you get a refund.

Frequently Asked Questions

How do AI scams work?

Scammers use AI to clone voices from short clips, create fake video, and write convincing personalised messages at scale. The technology removes the old warning signs, but the scam still needs urgency, secrecy or an unusual payment from you.

How can I tell if a call is a voice clone?

You often can’t by listening. Hang up and call the person back on their known number, or ask for your family code word. A clone can imitate a voice but can’t answer the real person’s phone or know a secret you agreed offline.

What’s the single best defence against scams?

Verify on a second channel. Never act inside the call, text or email that contacted you — check through a route you already trust, such as the official app or the number on your bank card.

Are real companies ever urgent?

Yes, fraud alerts can be. The difference is what they ask for: a genuine alert asks you to confirm a charge or call the number you already have, and never asks for codes, passwords or payment through a link.

I clicked a link but didn’t enter anything. Am I safe?

Usually, if you entered no details and downloaded nothing. Close the page, don’t return to it, and keep your device updated. If you did enter a password, change it everywhere you use it, starting now.

Why do smart people fall for scams?

Because scams target moments, not intelligence: a busy day, a frightening call, loneliness or a financial worry. Having a rule you follow automatically — like always calling back — protects you when you’re not at your sharpest.

Related Reading

Scroll to Top