AI Safety & Trust

How to Spot AI Scams and Deepfakes at Work (The Old Red Flags Are Dead)

Date Published

Person shielding a laptop from a suspicious mask and fishing hook with an AI guard, Alvora teal illustration

The tells you were taught to look for are gone. Scam emails used to announce themselves with broken English and strange formatting; AI writes them fluently now, in your company's tone, referencing your real projects. Voice cloning needs seconds of audio from any webinar or voicemail. And video calls can now contain a face that is not the person wearing it.

This is not a reason to panic; it is a reason to change what you check. The old defense was spotting bad craftsmanship. The new defense is verifying requests through a second channel, and it works against every version of this attack, human or AI.

Why the scams suddenly got good

A fishing hook dangling a suspiciously perfect email, AI written phishing

Generative AI removed the two costs that kept scams sloppy: language and scale. Security researchers tracking AI-driven scams describe phishing that is personalized from your LinkedIn and your company's press releases, sent in fluent local language, at volumes only automation reaches. The infamous case that defined the category: a finance worker in Hong Kong transferred 25 million dollars after a video call where every colleague on screen, including the CFO, was a deepfake. The craftsmanship test is dead. Suspicion has to attach to the request, not the writing quality.

The new red flags: pressure, secrecy, and channel switches

What AI cannot fake is a legitimate process. The flags that survive: urgency that punishes verification ("must happen before the auditors see it"), secrecy ("keep this between us"), a request to move to a different channel ("reply on my personal number"), payment detail changes of any kind, and first-time requests that skip normal procedure, however plausibly explained. One of these deserves attention; two together deserve a phone call.

The one rule that defeats all of it

Pausing an urgent request and verifying through a separate phone call

Verify out-of-band: confirm the request through a channel the requester did not choose. The email asks you to pay; you call the number you already had, not the one in the signature. The CEO voice-notes you for gift cards; you message the CEO on the internal system. The video call approves a transfer; the transfer still waits for the workflow. This single habit beats fake emails, cloned voices, and deepfaked calls simultaneously, because the attacker controls their channel and cannot control yours. Teams make it stick by agreeing it in advance: any money or credential request gets a call-back, no exceptions, and nobody gets in trouble for the five-minute delay.

On a suspicious video call

A video call face with a faint mask edge under a magnifying glass, spotting a deepfake

Live deepfakes are improving fast, so treat visual tells as hints, not proof: lighting that does not match the room, edges that shimmer near hair and jaw, lip-sync drifting on hard consonants. Better than staring: interact. Ask about something only the real person knows that is not on any public profile, or ask them to turn their head fully sideways, which still strains many live face swaps. And if the call itself made the request, the out-of-band rule already applies regardless of how real anyone looked.

Check your own shadow

Attackers personalize from what you publish. Worth five minutes: what does your LinkedIn plus your company's website tell a stranger about who approves payments, who is traveling, and who reports to whom? You do not need to go dark; just notice that the org chart in your bios is the scammer's script. Then make sure the basics are boring and solid: password manager, two-factor everything, and updates on time.

If you already clicked or paid

Speed beats shame. Tell IT or your bank immediately: transfers can sometimes be recalled in the first hours, and credentials can be rotated before they are used. The person who reports in ten minutes is the hero of the story; the one who sits on it for a day out of embarrassment is how small incidents become large ones.

Defending against AI is, fittingly, also a skill of using it well: the habits of verifying what AI tells you and handling data carefully are the same muscle. Build the whole set with our free courses, starting from zero.

Frequently asked questions

How can I tell if an email was written by AI?

Increasingly, you cannot, and it no longer matters: fluent language now proves nothing either way. Judge the request instead: urgency, secrecy, channel switches, and payment changes are the signals that survive AI.

What is a deepfake scam at work?

A cloned voice or synthesized video of a real colleague, usually senior, used to authorize payments or extract credentials. In the best-known case a finance worker paid out 25 million dollars after a video call where every participant was fake.

How do I verify a suspicious request?

Out-of-band: use a contact channel you already had (the saved phone number, the internal chat) rather than anything provided in the request itself. The attacker controls their channel and cannot control yours.

Can I detect a deepfake on a live video call?

Sometimes: mismatched lighting, shimmering edges near hair and jaw, drifting lip-sync, and trouble with full profile turns. But treat detection as a hint; any request for money or credentials made on a call still gets out-of-band verification.

What should I do if I fell for a phishing email?

Report to IT and your bank immediately: transfers can sometimes be recalled within hours and credentials rotated before use. Speed is everything, and the fast reporter is the hero of the incident, not the culprit.

Sources