In 2024, AI scams were mostly a topic for industry conferences. Over the course of 2025–2026 they moved into everyday life — you call your son, he picks up, the voice fits, but it isn’t him. An email arrives from your boss with flawless writing, decent style and a logical request to transfer money. Security firms and national CERTs across the EU and the US report that fake calls using a cloned voice (vishing) were the fastest-growing category of fraud in 2025.
This page gives you a practical guide to spotting them and what to do — without the panic and without the technical waffle.
Three typical AI attacks an ordinary user runs into today
1. A cloned voice on the phone (vishing)
The attacker grabs a few seconds of your voice — from Instagram, a webinar, a voicemail greeting. Today’s AI tools need 3 to 30 seconds for a convincing clone. Then they use it in a crisis scenario:
“Mum, I’m in trouble, I urgently need a few thousand, don’t ask, just send it to this account…”
The voice fits. The tone fits. Even the crying or the tension in the voice fits (AI can do that). The victim panics and transfers the money. Often it’s the one phone call there’s nothing to verify it against.
Attackers clone a boss’s voice in companies the same way: a call to accounts payable, the director’s voice, an unusual but “urgent” transfer, don’t ask questions.
2. A deepfake video call
A more advanced variant: the attacker joins a video call (Microsoft Teams, Zoom, Google Meet) and the face is generated live. In 2024 this took serious server capacity; in 2026 it runs on an ordinary gaming PC.
The target is typically a company — a fake CEO instructs the finance director to make a transfer, or a fake client requests a change of billing details.
3. AI-generated phishing emails
The old advice “you can spot phishing by the bad grammar” no longer holds in 2026. AI language models write better than most people. So a phishing email today:
- Has flawless style with no grammatical errors
- Reacts specifically to your recent activity (a LinkedIn post, an online order)
- Addresses you personally — name, role, company, sometimes even a specific project
- Sounds logical — why wouldn’t an invoice arrive, when you ordered something last week?
Using AI, attackers prepare tens of thousands of personalised emails in batches. The cost is low, the return high.
How to spot it — regardless of how good the attack is
A universal rule: the technology is just a means. There’s always a way to verify through another channel.
For phone and video
- Hang up and call back on a number you have saved (not the one that just called you). If the call was genuine, the other side won’t take offence.
- A password / agreed signal — some families now agree on a code word (“our cat’s name is XY”) for crisis calls. It works.
- A question the attacker couldn’t answer — “What did we have for dinner last week?” An AI voice fails on specific shared memory.
- Don’t trust “the rush” — attackers always push for fast action. Real emergencies usually wait five minutes for a check.
For emails and messages
- The sender’s address — click on the name and look at the full address. “Your Bank” from
account-admin@yourbank-info.comis a scam (the official domain isyourbank.com). - Hover over links (without clicking) and watch the URL in the browser’s bottom frame. If it differs from what’s claimed, it’s a trap.
- No company will ask you by email to enter a password or PIN. Your bank, Microsoft, your email provider, Google — none of them.
- Call the official number from the website (not the one in the email) if something feels off. Banks have a line for verification.
For the overall picture
- A second verification channel is a necessity now. Any important financial decision (a transfer, a change of a supplier’s account, a payment outside the approved process) should always be verified through a second route — SMS, Signal, in person, a different phone.
What to do if an attack reached you
If you did NOT click / transfer
- Report the email as phishing in your app (Outlook and Gmail have a button). You’re helping others.
- For a phone scam, note the number and report it to your country’s cybercrime authority. National bodies collect data on new techniques.
- Think about where the attacker got the information — what have you shared publicly? LinkedIn? Instagram?
If you DID click / transfer / send a password
Move fast, but stay calm:
- Change your passwords on every account where you reuse a password. Use a password manager (Bitwarden, 1Password).
- Turn on 2FA everywhere you don’t have it. An authenticator app, not SMS.
- Contact your bank — report the fraudulent transaction. If it’s within 24 hours and domestic, banks can often reverse the transfer.
- Check the computer for malware. Some attacks drop a keylogger or info-stealer.
- Report it to the police — even when it looks hopeless, statistically it helps the investigation of further cases.
If you need to go through account recovery step by step, see Hacked email or Facebook — a step-by-step recovery guide.
What to do as a precaution (5 steps for the weekend)
- Audit your publicly available details — search your own name and see what the internet knows about you. A voice clip on YouTube/Instagram? A public email? A phone number on a company site? That’s the raw material for an attack.
- Agree a code word with your family for crisis calls. A simple phrase is enough.
- Turn on 2FA everywhere — email, bank, social networks, cloud (OneDrive, Google Drive). Without 2FA, a hacked password equals a lost account.
- A password manager — Bitwarden is free. Stop reusing passwords.
- Back up your data — the 3-2-1 rule (three copies, two media, one off-site). If an attack wrecks your computer, backups are the last safety net.
AI tools — when to stay cautious
Generative AI (ChatGPT, Claude, Gemini, Copilot) is an everyday tool in 2026. A few rules so it can’t be used against you:
- Never enter passwords, PINs, card numbers, national IDs or NDA-covered content into an AI. AI services may log inputs and use them for training.
- Watch out for AI “helpers” in the browser — some browser extensions are disguised info-stealers. Install only vetted ones (verified in the store, lots of users, real reviews) and check what data they collect. More in Dangerous browser extensions.
- Verify AI-generated answers, especially on health, legal and financial questions. AI “hallucinates” and states things confidently even when they’re wrong.
- For company data, use enterprise AI services (Microsoft Copilot for Business, ChatGPT Enterprise) with a guarantee that inputs aren’t retained.
FAQ
How did the attacker get our voice? Most often from public videos — Instagram, TikTok, YouTube, company podcasts, online talks. A few seconds is enough.
Is Windows Defender enough against AI phishing? For ordinary PC protection, yes. Against AI phishing no antivirus helps — the attack happens in the user’s head. What matters more is 2FA, a second verification channel and awareness.
Can I tell a cloned voice by the sound? In 2024, often yes (a slight echo, incomplete breathing). In 2026, no longer — good clones are indistinguishable over an ordinary phone. Rely on behaviour, not sound.
What if I call my own family to verify, and the voice accuses me of being an AI? The agreed code word. Then it’s simple.
Is it worth having an expensive antivirus against AI scams? Mostly no — Windows Defender plus 2FA plus a password manager plus the habit of a second verification channel is a stronger defence than any paid product.