For everyone

How to Protect Yourself From AI Voice, Video and Impersonation Scams

AI makes it cheaper to imitate a voice, create a plausible photo, translate a scam script and personalize thousands of messages. It does not make a caller, video or message trustworthy. The safest response is not to become a deepfake expert; it is to verify important requests through a channel the requester did not choose.

The rule: verify the request, not the media

If a familiar voice or face asks for money, credentials, a verification code or secrecy:

  1. Pause the conversation. Urgency is part of the attack.
  2. Contact the person or organization independently. Call a number already in your contacts, use the official app, or type the known website yourself. Do not use a number or link supplied in the message.
  3. Ask about something outside the conversation. A private family phrase can help, but the independent callback is stronger.
  4. Check with a second person before sending money or sensitive information.

The US Federal Trade Commission gives the same core advice for cloned-voice emergencies: do not trust the voice; call the person back using a number you know.

Common AI-enabled scam patterns

A relative, executive or official in an emergency

The caller may sound familiar and claim there has been an arrest, accident, confidential business problem or urgent bill. Requests for gift cards, cryptocurrency, wire transfers, passwords or one-time codes are strong fraud signals. End the contact and verify separately.

For workplaces, a request that changes bank details, releases data or bypasses a normal approval should always be confirmed using the existing approval process—even if it appears to come from a senior leader on audio or video.

A convincing video meeting or voice note

Glitches, odd blinking and unnatural speech can occur, but their absence proves nothing. Compression, poor connections and ordinary editing can create similar artifacts. Treat visual clues as reasons to look closer, not as an authentication method.

A synthetic social profile

AI-generated photos and messages can make romance, investment, recruitment and “wrong number” approaches look consistent for longer. Watch the behavior: a rapid move off-platform, refusal to meet, requests for money, unusual payment methods, or pressure to keep the relationship secret.

Personalized phishing

AI can produce polished language and incorporate details scraped from public profiles or a breach. Grammar is no longer a useful filter. Unexpected requests, mismatched destinations, new payment instructions and requests to bypass process are more meaningful signals.

What Content Credentials can—and cannot—tell you

C2PA Content Credentials can attach signed provenance information about a file’s origin and edits. A valid credential can help establish that the recorded provenance was not altered. It does not guarantee that the scene or claim is true. Missing credentials also do not prove that a file is fake; many tools and platforms do not preserve them.

Use provenance as one signal alongside the source, context and independent verification. Do not make a high-stakes decision from an “AI detector” score alone.

If you sent money or information

  1. Call the bank or payment provider’s fraud line immediately and ask whether the transfer can be stopped or recalled.
  2. Change any exposed password and every place it was reused. Revoke exposed sessions or access tokens.
  3. If you disclosed a one-time login code, contact the affected service and check recovery details, forwarding rules and signed-in devices.
  4. Preserve the message, phone number, payment details, profile URL and screenshots. Do not keep engaging the scammer to gather evidence.
  5. Report the fraud to the relevant platform and national authority. In the US, use ReportFraud.ftc.gov and the FBI Internet Crime Complaint Center.

Primary sources and further reading

Related: How to spot phishing, smishing and social-engineering scams.