Skip to content

alphaPlan · Cybersecurity · Cheat-sheet 06

AI-Powered Scams

AI makes scams fluent, personal and convincing, so judge the request instead of the polish and confirm anything sensitive on a channel you chose.

Ideas to remember

  1. 01AI writes scam messages that are fluent, personalised and mass-produced, so bad grammar is no longer a tell.
  2. 02A face can be faked in real time on a video call, so a familiar face is a claim, not proof of identity.
  3. 03A few seconds of public audio is enough to clone a voice, which powers the panicked 'relative in trouble, send money now' call.
  4. 04A synthetic identity is a person who never existed, built from real and fake details that all point at each other.
  5. 05Every one of these scams needs you to accept a claim of identity without checking and to act fast, so one habit defeats them all.
  6. 06Urgency plus money equals verify: that pressure is the attack, not a detail of it.

Words

Deepfake
Video or audio that AI has generated or altered to show a real person saying or doing something they never did.
Voice cloning
An AI copy of someone's voice made from a short recording, able to say anything the attacker types.
Synthetic identity
A fabricated persona with a profile, activity and references that are all part of the same set of lies.
Separate, trusted channel
A route you chose and already trust, never the contact details supplied in the suspicious message.
Safe word
A word or phrase agreed in advance that only your family or team knows; a clone cannot guess it.

Do this

  • Judge what a message asks and whether the request makes sense, not how well it is written.
  • Before acting on a sensitive request made over video or phone, hang up and call back on a number you already have.
  • Pick a family safe word today and make sure everyone who might be called knows it.
  • Treat a new contact you cannot check independently as unproven: a profile is not proof of a person.
  • Never use the contact details supplied in the suspicious message itself.

Watch out

  • A well written, personalised message asking for something sensitive deserves more suspicion, not less.
  • Betting on spotting a visual glitch, odd blinking or mismatched lips, is a weak plan because the technology keeps improving.
  • Calling back the number that just rang you, or letting the caller 'prove' it on the same call.

From the lessons: AI-written phishing, Deepfake video, Voice cloning, Synthetic identities, The verification playbook. codeforalbania.com/en/learn/cybersecurity/06-ai-powered-scams

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement