Skip to content
How-to Beginner 25 min read by Rajat Jain Updated August 13, 2026

How to Protect Yourself from AI Scams

Voice cloning, deepfakes, AI phishing, and fake AI tools: recognize the schemes, verify before you pay, and report - FTC, FBI IC3, and SEC verified.

Note

Techniques and reporting channels verified 13 August 2026 against official sources: the FTC consumer alert 'Scammers use AI to enhance their family emergency schemes' (March 2023), FBI IC3 public service announcements I-120324-PSA (December 2024) and I-072026-PSA (July 2026), and the SEC/NASAA/FINRA Investor Alert on AI and investment fraud (January 2024). Scam techniques evolve quickly - re-check the official pages when patterns feel new.

Before you start

  • 10 minutes to set up a family code phrase and review your social media privacy settings
  • A phone where you trust saved contact numbers of family and your financial institutions
  • Bookmark the three official reporting pages: ReportFraud.ftc.gov, www.ic3.gov, and sec.gov/tcr
Jump to section
  1. 1

    Know the five AI scam families

    Voice cloning, deepfakes, AI-generated phishing, fake AI tools and services, and AI-powered investment fraud - each with the official warning behind it.

  2. 2

    Spot the red flags

    FBI-tested imperfections in synthetic media, payment-method tells, and the SEC's guaranteed-returns alarm bell.

  3. 3

    Verify before you act

    Hang up and call back on a number you already trust, use the family code phrase, and confirm .gov sites by typing them yourself.

  4. 4

    Shrink what scammers can copy

    Your voice and face are the raw material - limit public audio and video, lock down accounts, and harden the accounts money moves through.

  5. 5

    Report it to the right agency

    FTC for consumer scams, FBI IC3 for cyber-enabled fraud, SEC for investment fraud - and never pay a 'recovery' service that finds you first.

AI scams work because synthetic media removes the tells you were taught to trust: the voice on the phone, the face on the video, the polish of the email. In 2026 the FTC, FBI, and SEC all warn that scammers clone voices from short online clips, generate deepfake videos of officials and executives, mass-produce believable phishing, and wrap it all in fake AI investment schemes - with the FBI noting generative AI also corrects the spelling and grammar errors that used to give frauds away. This guide walks through the five scam families, the red flags, the verification steps that defeat them, and exactly where to report - every claim verified against the official FTC, FBI IC3, and SEC sources today. We cover the frontier of this problem in our news coverage of a rogue open-source agent and white-hat red-team breaches - the same tooling is being weaponized by scammers.

Before you start

  • Print or bookmark the three reporting pages: ReportFraud.ftc.gov, www.ic3.gov, and sec.gov/tcr.
  • Agree on a family code phrase - a word or short phrase no public post or voicemail contains.
  • Update two settings: make your social media accounts private, and keep your financial apps on multi-factor authentication (MFA).
  • Set a rule with yourself: any request for money or secrets over the phone, video, email, or DM gets verified through a channel you initiated before anything moves.

Step 1: Know the five AI scam families

All five are documented in official federal warnings - this is not speculative:

1. Voice cloning (family emergency scams). The FTC’s March 2023 alert explains it plainly: a short audio clip of your loved one - harvested from content posted online - plus a cloning program, and the scammer sounds exactly like them. The script is the classic grandparent fraud: “I’m in jail / a wreck / in trouble, send money fast, don’t tell anyone.”

2. Deepfakes (video and image impersonation). The FBI IC3 documents AI-generated videos of executives, law enforcement, and even senior FBI leaders - including, per the July 2026 PSA, AI-generated videos of a senior FBI official directing victims to a spoofed IC3 website. Deepfakes also power fake celebrity endorsements, fake charity appeals after disasters, and real-time video calls where the face is synthetic.

3. AI-generated phishing. The FBI warns generative AI removes the linguistic tells - scammers now mass-produce believable spear-phishing, romance-bait profiles, and even embed AI chatbots into fraudulent websites that walk victims toward malicious links or credential theft.

4. Fake AI tools, services, and “AI-washing” businesses. The FTC has sued companies that promised AI-driven riches they never delivered - the Air AI business-opportunity case and the “AI-powered Ecommerce Empire” scheme both cost consumers millions. Working as an onboarding mini-guide: if a business’s only product is its AI hype, treat it as hostile.

5. AI-powered investment fraud. The SEC’s joint alert with NASAA and FINRA is explicit: bad actors lean on the hype around AI and crypto to promote unregistered platforms, guaranteed returns, and pump-and-dump “AI company” stories - and use deepfake videos of CEOs and cloned voices to sell them.

The through-line in every official warning

Every one of these schemes needs the same three things from you: urgency (act now), secrecy (don’t tell anyone), and an irreversible payment method (wire, gift card, or crypto). Remove any one of the three and the scam collapses.

Step 2: Spot the red flags

Synthetic media tells (FBI, IC3 PSA I-120324-PSA):

  • Distorted hands or feet, unrealistic teeth, eyes, or irregular faces
  • Unrealistic accessories - glasses or jewelry that don’t sit right; inaccurate shadows
  • Video lag or watermarks; audio that doesn’t match the lip movements
  • A voice with odd tone, word choice, or robotic pacing on a call that claims to be a loved one
  • An unexpected “it’s me” call from a number you don’t recognize - spoofed caller ID is trivial

Pressure tells (FTC and SEC):

  • Payment demanded via wire transfer, gift card (with the PIN), or cryptocurrency - all nearly impossible to reverse
  • “Don’t tell anyone” and “act immediately” - the FTC calls urgency the scammer’s most powerful tool
  • “Guaranteed returns with little or no risk” or “your money doubles” - the SEC lists these as classic signs of investment fraud
  • An unregistered platform or unlicensed salesperson pushing an “AI” trading system
  • A “government official” contacting you on WhatsApp, Telegram, or Facebook - the FBI confirms the real IC3 never works that way

Step 3: Verify before you act

The single verified counter-measure for every family in this guide:

  1. Never trust the voice or the face on an unsolicited call. The FTC’s own words: “Don’t trust the voice. Call the person who supposedly contacted you and verify the story. Use a phone number you know is theirs.” Do not call back the number on your screen - scammers control it.
  2. Use the secret code phrase. The FBI recommends a secret word or phrase with your family to verify identity. Ask for it. A real loved one knows it; a clone doesn’t.
  3. Call your loved one through a different channel - a partner, sibling, or their voicemail on a saved number - if you can’t reach them directly.
  4. For institutions: hang up and call the number on the back of your card, or type the official website yourself. Contact them directly using the information on their website - the SEC’s official advice for verifying any regulator communication. Independently search for contact information rather than clicking links or calling numbers in the suspicious message (SEC/NASAA/FINRA alert).
  5. For official websites: type www.ic3.gov directly into the address bar; verify the URL ends in .gov; avoid sponsored search results, which the FBI says are usually paid imitators.
  6. For videos of public figures promising investments or recovery: check the figure’s official account and official announcements; the SEC warned deepfake CEO videos are an active manipulation technique.
  7. For investment platforms: check whether the firm is registered on your state or national securities regulator’s lists, and research the platform beyond the name - search the URL and screenshots, not just the brand (FBI guidance).

The recovery-scam trap (FBI, July 2026 PSA)

If someone contacts you promising to recover money you already lost - to an official-looking “IC3,” an “FBI agent,” or a “recovery firm” - that is itself a scam. The FBI’s PSA is definitive: the IC3 has no social media presence, never contacts individuals directly via phone, email, social media, or chat, and never asks for payment to recover funds. A “government official” who wants a fee, a gift card, or crypto before returning your money is the scam.

Step 4: Shrink what scammers can copy

Your voice and face are the raw material for cloning - the FBI’s advice is to limit the supply:

  • Limit online content of your voice and image. Make social media accounts private, restrict followers to people you know, and think twice before posting clear-audio videos or voicemail-style clips that could be harvested.
  • Review privacy settings on every platform that hosts your audio or video - closing off public noise is the cheapest defense.
  • Hardening the accounts money moves through: enable MFA on banking and payment apps, and tell family that an unexpected money request triggers the code-phrase check regardless of channel.
  • Avoid the amateur leak: answering unknown callers or responding to scam texts lets scammers record your voice and confirm your number is active - screenshots of “health” reads and clicks make you a hotter target.

Step 5: Report it to the right agency

You do not need to be sure, and you do not need to have lost money - all three agencies accept reports precisely because patterns connect cases:

  • FTC (consumer scams - voice cloning, phishing, fake products): report at ReportFraud.ftc.gov. The FTC uses reports to open investigations and bring cases.
  • FBI IC3 (cyber-enabled fraud - romance, investment, deepfake, recovery): file at www.ic3.gov with as much as you have - names, contacts, websites, emails, phone numbers, bank account or crypto wallet details, screenshots, and a description of how contact started (the FBI’s own reporting checklist). Victims aged 60+ can call the DOJ Elder Justice Hotline at 1-833-FRAUD-11 for filing help.
  • SEC (investment fraud): report securities fraud to the SEC at sec.gov/tcr, to FINRA via its complaint form, or to your local state securities regulator - the contact list is on NASAA’s website.
  • Your financial institution: always start here if money moved - call the number on your card before anything else, since transfer timing determines whether anything can be frozen or clawed back.

Report even if you didn't lose money

The FTC and IC3 both emphasize that reports from people who spotted a scam - not just victims - are what let them track patterns and warn others. If you caught it in time, your report makes the next person’s defense easier.

How to verify it worked

  • Your family has an agreed code phrase, and everyone knows the ask-for-it rule
  • You can list the three payment-method tells without looking (wire, gift cards, crypto)
  • You can name at least three synthetic-media imperfections from the FBI’s list
  • You know the correct move for an urgent “family emergency” call: hang up, call the saved number
  • You know no government agency contacts individuals via WhatsApp, Telegram, or social media
  • Your three reporting pages are bookmarked, and someone in your family knows where they are

Troubleshooting

My bank called and the voice really sounded like my banker

Voice synthesis has reached the point where it can fool people who know the speaker well - the FTC documented this for family voices, and the FBI warns institutions are impersonated the same way. No skill at recognizing voices will reliably beat that. The invariant defense is not listening harder: it is hanging up and calling the verified number on your card or official site, then confirming the request through that line before any data or money moves.

A family member received a video call that looked like me

Real-time deepfakes during video calls are documented by the FBI (generated for video chats with alleged executives, law enforcement, or family). The silver bullet is the code phrase - ask for it in a way that can’t be scripted, e.g., a follow-up question whose answer is in no public post. If they can’t produce it, end the call and alert the real person through a channel you initiate: direct message, text, or in person.

I clicked a link in a suspicious text and entered a password

Act fast, in order: change that password everywhere it is reused (get a password manager if you don’t have one), enable MFA on the affected accounts, contact the real institution using the number on your card if financial data was entered, and report the message to the FTC at ReportFraud.ftc.gov. The FBI notes malicious links in scam messages can deliver malware - if you typed banking credentials into the fake page, consider calling the bank’s fraud line and freezing cards.

Someone posted an AI video of me endorsing a product

Synthetic content of you is being used for a fake-endorsement or non-delivery scheme - the FBI documents AI images of celebrities and personas promoting counterfeit products. Report the content to the platform (impersonation takedown), report to the FTC at ReportFraud.ftc.gov, and if the video involves financial products, add a report to the SEC at sec.gov/tcr. If it’s sexual in nature, report it at takeitdown.ftc.gov, the FTC’s dedicated tool for non-consensual intimate imagery.

An investment group promised me “AI-powered guaranteed returns”

The SEC, NASAA, and FINRA jointly flag exactly this: unregistered platforms and promoters using AI buzzwords, guaranteed returns, and deepfake endorsements to lure investors. Check registration status with your state securities regulator (NASAA’s contact-your-regulator page), review disclosures using the SEC’s EDGAR database, and if the pitch is high-pressure or “risk-free,” treat it as the red flag it is - then report at sec.gov/tcr.

I lost money and now someone on social media offers to recover it

Walk away - the FBI’s July 2026 PSA describes this as an active scheme that targets past victims, sometimes using AI-generated videos of FBI officials and spoofed ic3.gov copies. Real law enforcement never contacts you this way and never charges fees to return your money. Report the recovery attempt itself to the genuine www.ic3.gov - those reports are how the FBI tracks the ring - and if you’re 60+, call the DOJ Elder Justice Hotline at 1-833-FRAUD-11 for help filing.

You did it

  • You know the five scam families and one real-world example of each
  • You can spot synthetic-media imperfections and the three payment-method tells
  • Your family has a code phrase and the hang-up-and-call-back rule in place
  • Your social media accounts are private, and you think before posting clear audio or video
  • You know exactly where each kind of report goes (FTC, IC3, SEC, your bank)
  • You know the one thing no official organization ever does: contact you first and charge you to help
  • You’ve shared this guide with the least-technical person you love - they’re the target, and now they’re the defense
Official sources

All fetched 13 August 2026. Scam techniques evolve; check the official pages when something feels new.

Next: defense is easier when you understand the attacker - read our stories on the rogue open-source agent incident and white-hat red-team breaches to see how far AI tooling has come, then make sure your own setup follows security basics from our MCP safety guide if you run agentic tools.

Questions, answered first

Can a scammer really clone my family's voice?

Yes - and the FTC says it takes surprisingly little: a short audio clip of the person, which scammers harvest from content posted online (social videos, voicemail greetings), plus a voice-cloning program. The cloned call can sound just like your loved one. That's why the FTC's official advice is blunt: 'Don't trust the voice. Call the person who supposedly contacted you and verify the story' using a phone number you know is theirs.

I already sent money to a scammer. What do I do?

Act fast: contact your bank or card issuer using the number on the back of your card (never the number the scammer gave you) to try to stop the transfer, then file a complaint with the FBI's IC3 at www.ic3.gov with all identifying and transaction details, and tell the FTC at ReportFraud.ftc.gov if it involved their reporting remit. IC3 explicitly notes victims aged 60+ can call the DOJ Elder Justice Hotline at 1-833-FRAUD-11 (833-372-8311) for help filing. Reporting matters even when money is gone - it helps investigators connect cases.

Are AI-generated images or videos themselves illegal?

Not inherently - the FBI IC3 states creation or distribution of synthetic content is not illegal by itself. It becomes criminal when it facilitates fraud, extortion, identity theft, or stock manipulation, which is why law enforcement's focus is the scheme wrapped around the media, not the media alone. Treat a realistic image or video as a claim to verify, not as proof of anything.

Someone on WhatsApp says they can recover my lost crypto for a fee. Legit?

Almost certainly a recovery scam - the FBI's July 2026 PSA describes exactly this: scammers impersonating FBI personnel and the IC3 to re-victimize people who already lost money, using AI-generated videos of officials and spoofed ic3.gov lookalikes. The IC3 has no social media presence, never contacts individuals directly, and never asks for payment to recover funds. Block the contact and report it to the real www.ic3.gov.

I got a call that sounded exactly like my bank's support line. What now?

AI voice synthesis has reached the point where banks and government agencies can be impersonated convincingly. Never share account details with an inbound caller. Hang up, call the number on the back of your card or the official website (typed by you), and verify the contact. A legitimate institution will never pressure you to act immediately, keep it secret, or demand gift cards, wire transfers, or crypto - those are the FTC's official scam tells.

You did it

  • You can name all five AI scam families and one real example of each
  • Your family has a code phrase that no AI voice or video could know
  • You know the three payment-method tells: wire, crypto, gift cards
  • You know not to call back numbers from a suspicious message - you call the saved number instead
  • You type official URLs yourself instead of clicking links, and check for .gov
  • You have bookmarked ReportFraud.ftc.gov, www.ic3.gov, and sec.gov/tcr
Official sources