Skip to content

alphaPlan · Desk one-pager

The verification playbook

AI makes scams fluent, personal and convincing, so judge the request instead of the polish and confirm anything sensitive on a channel you chose.

01

Pause

When a request comes with a countdown or a threat, pause, breathe, and verify on a separate, trusted channel.

02

Judge the request, not the polish

Judge what a message asks and whether the request makes sense, not how well it is written.

03

Verify on a channel you chose

Before acting on a sensitive request made over video or phone, hang up and call back on a number you already have.

The one rule to write down

Make 'we always call to confirm a change of bank details' a written rule, not a personal favour.

Confirm any change of bank details by phoning a number you already have on file, never one in the message.

Words

Deepfake
Video or audio that AI has generated or altered to show a real person saying or doing something they never did.
Voice cloning
An AI copy of someone's voice made from a short recording, able to say anything the attacker types.
Separate, trusted channel
A route you chose and already trust, never the contact details supplied in the suspicious message.
Safe word
A word or phrase agreed in advance that only your family or team knows; a clone cannot guess it.

Never

  • Never use the contact details supplied in the suspicious message itself.
  • Treat a new contact you cannot check independently as unproven: a profile is not proof of a person.
  • A face can be faked in real time on a video call, so a familiar face is a claim, not proof of identity.

From The verification playbook and the cheat-sheets for modules 04 and 06 of the cybersecurity course. Practise it with the verification drill.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement