By Voung H.
Voung oversees BSA/AML, fraud prevention, and sanctions compliance and is responsible for building data-driven controls and partners across the FIGFCU to safeguard the credit union, its Members, and stop emerging threats.
SUMMARY
- Scammers use AI to clone voices, generate deepfake videos, write flawless phishing messages, and build entire fake websites
- These tactics make scams far harder to detect than they were a few years ago
- Bad grammar or a robotic voice are no longer reliable warning signs
- The best defense is recognizing urgency, verifying independently through a number or channel you already trust, and never sending money or codes based on a call, message, or video alone
A few years ago, scam calls and emails were easy to spot — bad grammar, a robotic voice, an offer too good to be true. Not anymore. Today’s scammers have AI, and it’s changed the game entirely.
How AI scams are happening.
Here’s a review of tactics scammers are using most right now and how each one works.
Voice cloning: Scammers only need a few seconds of audio pulled from a TikTok, a voicemail greeting, or a public Instagram video to generate a convincing clone of your voice. In several reported cases, parents have received calls where their “child’s” voice was sobbing, saying they’d been in an accident and needed money wired immediately. It wasn’t their child. It was AI, built from clips scraped off social media. The FBI has reported that Americans lost more than $893 million last year to AI-related scams, including voice cloning.*
Deepfake video calls: This isn’t limited to individuals. In one widely reported 2024 case, a finance company employee was tricked into wiring $25 million after joining a video call where the CFO and several colleagues were entirely AI-generated deepfakes.**
Hyper-personalized phishing: AI has also erased the old warning signs of a scam email or text; the typos, the broken formatting. Scammers now generate messages with perfect grammar and professional design that mirror real bank or company communications, often personalized using details scraped from your own online presence.
Fake job offers and “processing fees”: AI-generated recruiters reach out with a job offer, move the conversation to a messaging app, and eventually ask for a “processing fee” or personal information to complete onboarding for a job that never existed.
AI scams aren’t just phone calls; they’re reshaping online scams too.
The phone is only one entry point. AI has changed the game just as much on social media, dating apps, and online marketplaces, arguably with even more room to manipulate people over time.
Romance scams with AI-generated faces and chatbots: Dating profiles now often feature deepfake photos and videos, sometimes built by face-swapping a stolen photo, sometimes generated entirely from scratch. In one widely reported case, a woman lost more than $80,000 and her home after scammers used deepfake video and cloned audio of a soap opera actor to build a fake romantic relationship over months; starting on Facebook, then moving to WhatsApp, before the requests for gift cards and cryptocurrency began. Some scammers now use AI chatbots to carry on these conversations around the clock, responding instantly and convincingly enough that victims believe they’re talking to a real, attentive person.†
Deepfake celebrity investment scams: Fabricated video clips of public figures such as CEOs, financial personalities, and even public officials are used to promote fake “investment opportunities” or crypto giveaways. The video looks and sounds real, but no legitimate company or public figure runs a “send money, get double back” promotion.
AI-generated fake websites and marketplace listings: Scammers can now spin up entire fake storefronts, complete with professional design and product photos, that mimic real retailers almost perfectly. Shoppers pay for items that never ship or unknowingly hand over card details to a site built purely to harvest them.
AI chatbot impersonation: Some scams now use AI-powered chat “customer service” agents on fake or spoofed websites to walk victims through providing personal or financial information, all while sounding exactly like a legitimate support interaction.
Warning Signs to Watch For
- Urgency and panic: Scammers rely on you reacting before you think. Any call or message demanding immediate money or information is a red flag, no matter how real it sounds.
- A request for unusual payment: Wire transfers, gift cards, or cryptocurrency are commonly used by scammers because funds can be difficult or impossible to recover once sent.
- A request for your PIN, password, or one-time verification code: Be suspicious of any unexpected call or text asking for your PIN, password, or one-time verification code. Never provide these credentials in response to an unsolicited request. Instead, contact the organization directly using a trusted phone number or its official website or app.
- Pressure to bypass a callback: If a “loved one” or “bank representative” discourages you from hanging up and calling back on a known number, that’s a signal something’s wrong.
- A relationship that escalates fast and stays online-only: If an online romantic interest avoids video calls, seems oddly perfect, or gets emotionally intense quickly, be cautious — especially if a request for money follows.
- Any request for money from someone you’ve never met in person: This applies to romantic interests, “investment opportunities,” and job recruiters alike. It’s a near-guaranteed red flag.
- A deal or return that sounds too good to be true: Crypto “giveaways” that promise to double your money, or unbelievable deals on a retailer site you’ve never heard of, are almost always fake.
How to protect yourself from AI scams.
- Hang up and call back: If you get an urgent call from a family member or your bank, hang up and call them directly using a number you already have saved — not one given to you during the call.
- Set a family safe phrase: Agree on a word or phrase with close family members that only you would know, to use in a genuine emergency.
- Limit what’s public: Set your videos and voice notes on social media to private or friends-only. The less audio of your voice available publicly, the harder you are to clone.
- Verify independently: If you get a message from your bank or credit union, don’t click the link or call the number provided. Go directly to the official website or app, or call the number on the back of your card or paper statement.
- Keep new relationships on the platform, and off your wallet. Be wary if someone you’ve met online pushes to move to a private messaging app quickly, or asks for money, gift cards, or crypto — no matter how real the relationship feels.
- Double-check unfamiliar retailers: Before buying from a site you don’t recognize, search for reviews, check for a real physical address or return policy, and be skeptical of prices that seem far below market value.
- Slow down: Scammers are counting on your urgency. Taking even thirty seconds to pause and verify can be the difference between a close call and a real loss.
- Treat email as an insecure channel: Expect to receive fraudulent messages by email. Avoid sending personal information, such as Social Security numbers or banking details, over email.
- Don’t click links or scan QR codes in unexpected emails: Doing so can install malware, including viruses or ransomware, onto your device.
- Let your password manager and browser warn you: If your password manager won’t autofill your login on a site, the domain is likely fake. Pay attention to browser security warnings, too.
- Enable multi-factor authentication (MFA): If you receive an unexpected prompt or code, someone may be trying to access your account.
- Never grant remote access to your computer: Doing so gives a scammer direct access to everything on your device. Don’t grant access unless you’re 100 percent certain the person asking for access is legitimate.
- Don’t open unexpected, shared files: If you receive shared access to files from an unknown source, stop and verify with the sender using a phone number you trust before opening anything.
Final thoughts: Play it safe.
AI hasn’t just made scams more common; it’s made them more convincing. The best defense isn’t spotting a bad script anymore. It’s building habits: verify independently, never act on urgency alone, and know that if someone is pressuring you to skip a callback, that pressure is the scam.
We will never contact you by phone, text, or email and ask you to provide your password or a one-time security or verification code. If you receive an unexpected request for sensitive personal or account information, do not respond. Contact the Credit Union directly using a trusted phone number or our official website or mobile app.
If you receive a call from any number or person claiming to be an employee of the Credit Union asking for this information—no matter how urgent or convincing they may be—hang up and call us directly at 800.877.2345.
If you receive an email stating that your username, password, phone number, or email address has been changed and you did not initiate this change, please contact us immediately.
To learn more about scams and tips to help keep you safer, visit our Current Scams page and Security Center.
This article is provided for educational purposes only and is not intended as financial, legal, or tax advice. Information is general in nature and may not apply to your individual circumstances. Consider consulting an appropriate financial, legal, or tax professional regarding your specific situation.
*Arntz, Pieter, “Americans lost nearly $900 million to AI-powered scams, FBI says.” Malwarebytes.com. Posted 8 June 2026. Accessed 2 September 2026.
**Chen, Heather and Magramo, Kathleen, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’ CNN.com. Posted 3, February 2024. Accessed 2 September 2026.
†Chow, Vivian, “California woman loses home after being scammed by AI deepfake posing as actor.” KTLA.com. Posted 28 August 2025. Accessed 2 September 2026.
