How to Spot AI Scams and Deepfakes Before They Cost You
Not long ago, you could spot a scam by its bad grammar. The clumsy email from a "prince," the text riddled with typos, the robotic phone voice — they carried their own warning labels. That era is ending. The same AI tools that help you write a clean email now help scammers write flawless ones, clone a voice from a few seconds of audio, and generate a photo of a person who doesn't exist. This isn't a reason to panic, but it is a reason to update your instincts. The old tells are fading, and a few new habits do a much better job of keeping you safe.
The good news is that AI has not changed what scammers ultimately want or how they operate. They still need you to do something — send money, hand over a password, click a link, buy gift cards. AI just makes their bait more convincing. So while you can't always spot the fake by looking at it anymore, you can still catch nearly all of these schemes by paying attention to what you're being asked to do. Let's walk through the new landscape and the handful of moves that protect you.
Why the old advice stopped working
For years, the standard guidance was "look for spelling mistakes and awkward English." Scammers, often working in a second language, gave themselves away in the writing. AI erased that tell overnight. A scammer anywhere in the world can now produce a message in perfect, natural English — or in a convincing imitation of your bank's exact tone, your boss's brisk style, or your grandchild's casual texting.
The same goes for images. "Reverse image search the profile photo" used to unmask fake dating and investment profiles, because scammers reused stolen pictures that appeared elsewhere online. Now they can generate a brand-new face that exists nowhere else, so there's nothing to match. The lesson isn't that these old tricks are useless — reverse image search still catches lazy scammers — it's that passing those checks no longer means something is real.
The scam that should worry you most: the cloned voice
If there's one AI-powered scam worth understanding in detail, it's voice cloning, because it targets your heart faster than your head. With a short clip of someone's voice — easily pulled from a social media video or a voicemail greeting — AI can generate new speech in that person's voice saying anything at all. The classic version is a phone call: a panicked voice that sounds exactly like your child, grandchild, or spouse, saying they've been in an accident, arrested, or kidnapped, and they need money wired right now.
It is deeply convincing because the voice is right and the fear is real. Here is the single habit that defeats it: hang up and call the person back on the number you already have for them. Don't call back the number that just called you — call the one saved in your phone, or their known number. If you reach them, the scam collapses instantly. If you can't, call another family member who might know where they are.
It's also worth setting up a family "safe word" — a simple, private word or question that only your real family members would know the answer to. If you ever get one of these frightening calls, you ask for the safe word. A scammer with a cloned voice won't have it. It feels a little paranoid to set up, and it works beautifully.
The new tells for text and email
Since you can no longer trust grammar as a signal, shift your attention to structure and pressure. Nearly every scam, no matter how polished, has the same skeleton, and AI can't hide it because the skeleton is the scam.
Urgency and secrecy. "Act within the hour or your account will be closed." "Don't tell anyone until the deal is done." Real institutions don't operate on artificial countdowns, and legitimate requests rarely demand secrecy. When a message is engineered to make you feel you have no time to think, that engineered feeling is itself the warning.
An unusual payment method. Gift cards, cryptocurrency, wire transfers, payment apps to a stranger — these are the scammer's favorites because they're fast and nearly impossible to reverse. No real government agency, utility, or company will ever ask you to pay a bill in gift cards. If that's the ask, it's a scam, full stop, regardless of how legitimate everything else looks.
A request that arrives out of the blue. Your "bank" texting a link to verify your login. Your "CEO" emailing you to buy gift cards for a client. A "delivery company" texting about a package you don't remember ordering. The channel and the ask together are the tell — banks don't text you links to log in, and bosses don't email urgent gift-card errands.
Deepfake images and videos
AI-generated photos and videos are getting good, but they still leave fingerprints if you slow down and look. In images, check the small, fiddly details the AI tends to fumble: hands and fingers (often the wrong number or bent oddly), teeth, jewelry, the arms of eyeglasses, and text in the background, which frequently comes out as garbled nonsense letters. Look at where things meet — where hair blends into a forehead, where a collar meets a neck — for a smeared, melted quality.
In video, watch for unnatural blinking or none at all, a mouth that doesn't quite match the words, lighting on the face that doesn't agree with the background, and a subtle waxy smoothness to the skin. But be honest with yourself about the trend: these flaws are shrinking every year, and a quick glance on a phone screen isn't a reliable test. The durable defense isn't your eye — it's context. Is this video coming from a source you trust, or was it forwarded from a stranger? Does a celebrity or politician really appear to be personally promising to double your money? Extraordinary claims delivered by video deserve the same skepticism you'd give them in text.
Two outside resources are worth bookmarking. The FTC keeps a plain-language page on how to avoid a scam and a specific alert about AI-cloned family-emergency calls, and if money has already gone out the door, the FBI takes reports at ic3.gov.
I pasted a real-looking scam text into Gemini
I fed Gemini a package-delivery text of the kind that hits most phones weekly and asked whether it was a scam. It got every sign right — the lookalike domain, the 12-hour deadline, the fact that USPS doesn't send unsolicited texts — and its advice (don't click, don't reply, forward to 7726, email spam@uspis.gov) matches what the Postal Inspection Service publishes; I checked. The one habit to watch: it opened with “100% a scam.” It was right this time, but it uses that tone whether it's right or not.
Watch out for
A few specific traps are worth calling out.
The "it looked exactly right" trap. The whole point of these tools is that the fake looks and sounds authentic. So don't let "but the voice was really her" or "the logo was perfect" reassure you. Convincing appearance is now the baseline, not evidence of legitimacy. Judge the request, not the polish.
Second contact through a "safe" channel. A sophisticated scam might send an email, then follow up with a text or call that seems to confirm it, making the whole thing feel verified. Two messages from the same scammer aren't confirmation. Verification only counts when you initiate contact through a number or website you looked up yourself.
Links and attachments. A flawless email can still carry a poisoned link. Don't click to "verify," "unlock," or "track." Instead, go to the company the way you normally would — type the web address yourself or use your saved bookmark or the official app — and check your account there. If something's wrong, you'll see it without touching the link.
AI "assistants" and fake support numbers. When you search for a company's customer-service line, be careful which result you call — scammers plant fake support numbers and sometimes buy ads for them. Get contact details from the company's official site or the back of your card, not from a random search result or a pop-up.
The bottom line
AI has made scams look and sound better, but it hasn't changed the one thing that has always mattered: a scam needs you to take an action you'll regret, usually fast and usually involving money or a password. You can stop trusting grammar, photos, and even voices as proof of who's really there — and lean instead on habits that don't care how convincing the fake is. Slow down when you feel rushed. Verify by reaching out yourself, through a number or site you already trust. Never pay in gift cards or crypto to someone who contacted you. Set a family safe word for the scary phone call. None of this requires you to become a tech expert or to spot the seam in a deepfake. It just requires the small, steady discipline of checking before you act — which, comfortingly, is the same discipline that has always kept people safe, working just as well in a world where the fakes finally learned good grammar.
If a scam has cost you money, or you want to report one, in the U.S. you can file with the Federal Trade Commission at reportfraud.ftc.gov. Reporting helps investigators spot patterns even when your own money can't be recovered.
Related reading
- How to Spot AI-Written Content (and Why It Sometimes Matters) — the common tells, and why detector tools are unreliable.
- Is It Safe to Paste Work Documents Into ChatGPT? — the three-bucket test for what to paste, redact, or keep out.
- How to Fact-Check an AI Answer in Under Two Minutes — which parts of an answer to distrust and four checks that work.
Keep reading
Written by Mitch, a software analyst who tests software for a living. Every guide here comes from actually using the tool on a real task — including the parts where it falls over. Tested on ChatGPT Plus, Claude Max and Gemini (free). More about this site · Corrections: acheatsheet@gmail.com.
Get the next guide by email
A new tested how-to when there is one — usually a couple a month. No hype, unsubscribe any time.
Tested in real accounts. No affiliate links.