How AI Scams Keep Getting Harder to Spot
Why the Old Advice Doesn't Cut It Anymore
I used to tell people to watch for bad spelling and clumsy phrasing as a giveaway sign of a scam. That advice is fading fast. AI tools now write cleaner, more convincing messages than most legitimate businesses manage, and the old checklist of red flags is quietly going out of date. I still teach the basics, but I've had to add a lot more to the list this year. It's not just about better grammar either, AI tools can now mimic a specific person's writing style if a scammer has enough of your public posts or emails to learn from, which makes even a message that "sounds like" someone you know worth a second look rather than an instant reason to trust it.
Voice Cloning Is the One That Worries Me Most
A scammer only needs a few seconds of someone's voice, often lifted from a social media video, to generate a convincing clone. I've heard about calls where a "grandchild" or "colleague" asks for urgent money, and the voice sounds exactly right because in a sense it is. My advice hasn't changed much here, if a call asks for money or account details urgently, hang up and call the person back on a number you already have saved. A few seconds is genuinely all it takes now, pulled from a video call recording, a podcast clip, or even a voicemail greeting. I'd recommend agreeing a code word with close family that you'd only ever share in person, since it cuts through the panic of a convincing voice far faster than trying to spot something "off" about the call itself.
AI-Written Emails That Actually Read Well
Phishing emails used to trip themselves up with strange grammar and mismatched logos. Now they can be generated to match a company's actual tone of voice, complete with correct branding pulled from public websites. I've written before about how I spot phishing attempts, and the honest answer is I rely far less on writing quality these days and far more on checking the sender address and the link destination. Branding used to be a giveaway too, a slightly wrong logo or an odd font, but that's trivial to copy accurately now. The sender's actual email address is one of the few things that's still genuinely hard to fake convincingly, which is why I keep coming back to it as the first thing worth checking.

Fake Job Offers and Investment Scams
AI has also made its way into scams that don't look like scams at all on the surface. I'm seeing fake job offers built around an AI-generated recruiter persona, complete with a professional-sounding video introduction, designed to get someone comfortable enough to hand over bank details for a supposed "onboarding" payment. Investment scams have had the same treatment, dressed up with fabricated testimonials, fake news screenshots, and a chatbot "advisor" that answers questions instantly and convincingly. The common thread is a fabricated sense of legitimacy that would have taken real effort to fake even a couple of years ago.
Fake Video Calls and Deepfakes
This is the newest one and it still catches people off guard. Video deepfakes convincing enough to fool a quick glance are now within reach of ordinary scammers, not just well funded operations. If a video call asks you to authorise a payment or share sensitive information, treat it the same as an unexpected phone call and verify through a separate channel first. I don't think this is something to panic about day to day, most people will never encounter a deepfake video call, but knowing it's technically possible now changes how much weight I'd put on "I saw them, it must be real" as proof on its own.
The One Habit That Cuts Through All of It
I don't think the answer is learning to spot every new trick as it appears, since the technology moves faster than any checklist can keep up with. What actually works is a habit: verify through a channel you already trust, not one the message itself gives you. That means calling a number you already have saved rather than one in the email, or messaging someone on a platform you know they use rather than replying to the account that contacted you. It's the one thing that stays effective regardless of how convincing the fake gets.
What Still Works Against All of This
The fundamentals hold up better than you'd expect. Two factor authentication stops a cloned voice or a convincing email from being enough on its own, and a password manager like NordPass means even a leaked password doesn't unlock everything else. If something feels off, it's always worth reporting to Action Fraud, and if you want a second opinion on anything suspicious, get in touch and I'll take a look. None of this requires you to become a technical expert. It's a short list of habits, run consistently, rather than a constant effort to stay ahead of whatever's newest.
