
한국어 안내: 이 가이드를 한국어로 읽기
A frantic call in a relative’s voice, a video meeting that appears to show your boss, or a caller who sounds like a bank security representative can feel convincing. Voice and video alone, however, are no longer reliable proof of identity. Generative AI can imitate a person from short audio clips or public images, and scammers can combine those imitations with names, workplaces, travel plans, and family details found online.
The most useful defense is not becoming an expert at spotting every deepfake. It is having a routine that makes you pause the request and verify the person through an independent channel. This guide explains how individuals, families, employees, and small businesses in the United States can respond to suspected AI voice cloning, synthetic video calls, and impersonation messages.
This article provides general consumer, financial-safety, and cybersecurity information. It is not individualized legal, financial, or security advice. If money has been lost, someone is being threatened, or immediate safety is at risk, contact the appropriate financial institution, law-enforcement agency, or qualified professional promptly.
Why AI impersonation scams can look convincing
Older phishing attempts were often exposed by awkward grammar, an unfamiliar accent, or a poor-quality profile photo. Generative AI can produce smooth messages, imitate a familiar voice, create realistic profile images, and support video that resembles a live call. The FBI’s Internet Crime Complaint Center warns that criminals use generative AI to make romance, investment, family-emergency, and authority-impersonation fraud more believable and easier to conduct at scale.
You do not need to distrust every call. Instead, watch for the structure of the request. Impersonation scams typically create fear or surprise, take away your time to think, isolate you from other people, and demand an unusual form of payment or access. The behavior surrounding the request is usually more useful than the apparent quality of the voice or video.
- Artificial urgency: “Do it right now,” “Stay on the line,” or “This must be completed today.”
- Isolation: Instructions not to tell relatives, coworkers, bank staff, an attorney, or police.
- Unusual payment: Gift cards, cryptocurrency, cash pickup, wire transfers, or a payment app’s friends-and-family option.
- Credential requests: One-time security codes, passwords, remote-access software, or screen sharing.
- Manufactured authority: A supposed police officer, court official, tax agency, bank, or executive demanding immediate obedience.
The first 10 minutes: what to do before sending anything
- Stop the interaction. Say, “I will verify this separately,” then end the call or stop replying. A legitimate emergency does not require you to remain in a potentially compromised conversation.
- Write down the request. Record who the caller claimed to be, the requested action, payment method, account or wallet details, phone number, username, and time of contact.
- Do not use the link or callback number in the message. The number may lead back to the same fraud operation, even when caller ID appears familiar.
- Use a number you already trust. Call a relative from your saved contacts, a company through its internal directory, or a bank using the number on the back of your card or in its official app.
- Bring in another person. Read the request to a relative, coworker, manager, or other trusted person. A second person helps break the pressure created by the scammer.
If your relative does not answer immediately, that does not make the emergency call authentic. Try two or more independent routes: a text to the usual number, another relative, a school, a workplace, or an official facility number. Do not send money while waiting. If you believe someone faces immediate physical danger, call 911 or the appropriate official emergency number instead of paying the caller.
The strongest rule: switch channels and verify independently
Asking more questions inside a compromised call may not help. A scammer may have gathered personal information in advance or may continue using a synthetic voice. Verification must begin outside the conversation controlled by the caller. The following four-step routine works for family emergencies, bank calls, workplace payment requests, and government impersonation.
Step 1: Leave the incoming channel
End the phone call, video meeting, text conversation, or social-media direct message. Do this even if caller ID matches a relative or company. Caller ID can be spoofed, and a familiar profile may be compromised.
Step 2: Find a trusted contact independently
Use a saved contact, the phone number on a physical card, an official mobile app, an agency’s verified .gov website, or an established employee directory. Avoid calling the first number in a search advertisement without checking the domain and source.
Step 3: Use a family safe word or private question
Choose a short safe word that cannot be guessed from birthdays, addresses, pet names, or public posts. If no safe word exists, ask about a recent shared experience that was never posted online. A private question is an extra check, not a replacement for calling back through a trusted number.
Step 4: Confirm the transaction separately
If the caller claims to be a bank, open the official app yourself and review transactions and alerts. If an executive requests a wire or a vendor changes payment instructions, call the established vendor number and obtain approval through the company’s normal system.

Realistic scenarios and words you can use
Scenario 1: A relative’s voice asks for bail money
You hear a crying voice that resembles a child or grandchild. Another person takes the phone, claims to be an attorney or police officer, and asks for cash, a wire, or gift cards. Do not spend the call trying to prove whether the voice is synthetic. Hang up and call the relative’s normal number. Contact another family member at the same time. If custody is a genuine concern, call the relevant agency using its independently published public number.
Response: “I am not sending money during this call. I will verify through the number I already have and the agency’s official number.”
Scenario 2: A company executive orders an urgent transfer on video
The face and voice may look like an executive, but the meeting is short, one-way, and designed to bypass ordinary controls. End the call and confirm through at least two established routes, such as the existing company chat thread, a registered extension, or a separate approver. Never treat a video appearance as sufficient authorization to change vendor banking details or release a payment.
Response: “Urgent requests still require our normal two-person approval. I will confirm through the registered extension and payment system.”
Scenario 3: A bank security caller asks for a one-time code
The caller says your account is under attack and asks you to read a code sent by text. That code may be the final step the scammer needs to reset your password or authorize a transfer. Do not share it. End the call, open the bank’s official app, and call the number on the back of your card. Decline requests to install remote-support software or share your screen.
Response: “I do not share authentication codes. I will check the account in the official app and call the number on my card.”
Scenario 4: Wiring instructions change during a home purchase
A compromised online account can also send impersonation messages from a relative’s or coworker’s real profile. Protect important accounts with a strong sign-in method and a recovery route you have tested before an emergency. Smartor’s passkey and account-recovery guide can help you review recovery contacts, backup devices, and security keys so an impersonation attempt is less likely to turn into a lasting account takeover.
Visual and audio clues are secondary signals
Synthetic media may show small mismatches between lips and speech, unusual blinking, changing fingers or jewelry, unstable edges around a face, inaccurate shadows, sudden audio changes, or unnatural pacing. The FBI suggests looking for distortions in faces, hands, accessories, shadows, movement, and voice synchronization.
Those clues are not a final test. Better synthetic media may contain none of them, while an ordinary call can freeze or blur because of network conditions. Do not conclude that a smooth video is authentic or that a glitchy one is fake. Use visual and audio anomalies as a reason to pause; make the actual decision through an independent callback, account review, and normal approval process.
Create a family AI-impersonation response plan
Fifteen minutes of preparation can prevent a rushed decision later. Write down the following information in a secure place. Keep the safe word out of public social-media posts and broadly shared documents.
- One family safe word and a plan for changing it
- Each person’s primary and backup contact method
- Official numbers for schools, workplaces, care facilities, and other likely emergency contacts
- A designated second person who must be consulted before emergency payments
- A family rule that gift cards, cryptocurrency, and cash pickup are not emergency-verification methods
- A rule to verify through at least two independent channels, even when the caller says not to hang up
A memorable two- or three-word phrase is usually more practical than a long sentence. Change it if anyone outside the family may have heard it. For children and older relatives, practice the action instead of giving a technical lecture: “Hang up, call the saved number, and tell another family member.”
Payment controls for employees and small businesses
AI video does not change the fundamentals of accounting controls. It makes clear that a face and voice cannot serve as the only approval method.
- Confirm new bank accounts, payees, and payroll changes by calling an established contact.
- Separate the person requesting a large transfer from the person approving it.
- Do not waive procedures for a “confidential acquisition,” “CEO request,” or other claim of secrecy.
- Require a ticket, purchase order, or approval-system record instead of authorizing payment solely in a call.
- Keep a history of vendor contact changes and add extra verification to the first payment after a change.
- Train employees with the exact refusal language they may use and the name of the internal reporting contact.
If you already sent money or information
Do not lose time out of embarrassment or continue negotiating with the caller. Fast action may improve the chance of stopping a transaction and can limit further harm.
- Contact the payment provider immediately. Tell the bank, card issuer, payment app, gift-card company, or cryptocurrency exchange that the transaction was fraudulent. Ask whether it can be canceled, frozen, recalled, or flagged. Find contact information in an official app or on the physical card.
- Secure affected accounts. If you shared a password or allowed remote access, use a clean device to change the password and enable multifactor authentication. Change other accounts that reused the same password.
- Preserve evidence. Save phone numbers, messages, email headers, usernames, transaction records, gift-card receipts, and cryptocurrency wallet addresses. Do not reopen attachments or continue engaging with the scammer.
- Report the incident. Internet-enabled financial fraud can be reported to the FBI’s IC3. Consumer fraud can be reported through FTC ReportFraud. Contact local police for immediate threats or safety concerns.
- Respond to identity exposure. If you provided a Social Security number, identification document, or financial login, review the recovery steps at IdentityTheft.gov and consider whether a credit freeze or fraud alert is appropriate.
You do not need to prove that AI was used before reporting. Focus on facts you can document: how contact began, whom the person impersonated, what was requested, the payment method and time, account or wallet details, and what information you disclosed.
Prevention checklist
- Set social-media profiles to an appropriate privacy level and review public followers or friend lists.
- Reduce public exposure of phone numbers, travel dates, schools, workplaces, and family relationships.
- Use a unique password and multifactor authentication for important accounts.
- Check whether your wireless account supports an account PIN or number-transfer lock.
- Create a family safe word and designate a second verifier.
- Save official bank, employer, school, and care-facility contacts before an emergency.
- Agree never to share gift-card numbers, one-time codes, or passwords by phone.
- Require two-person confirmation for large payments and changes to receiving accounts.
Seven common mistakes
- Trusting a familiar voice: A voice that sounds right is not identity proof.
- Calling back the displayed number: Caller ID may be spoofed or controlled by the fraud operation.
- Using the caller’s link or search instructions: Those directions can lead to a fake help center or sponsored impersonation page.
- Feeding the caller more personal information: Asking “Is this my son Daniel?” supplies a name and relationship the scammer can reuse.
- Keeping the requested secret: Claims of an investigation or confidential deal are often designed to prevent verification.
- Sending a small test payment: The first payment can trigger larger demands and additional data collection.
- Trying to make a perfect technical diagnosis: Ending the call, stopping payment, and verifying independently are faster and safer than analyzing the media alone.
Frequently asked questions
If the face moves during a live video call, doesn’t that prove it is real?
No. Real-time manipulation, prerecorded footage, account compromise, or a combination of a real person and synthetic elements may be involved. End the call and verify through an established contact method regardless of how natural the video appears.
Is one family safe word enough?
It is helpful but should not stand alone. A safe word can leak or be overheard. Combine it with a callback to a saved number, confirmation from another relative, and review of official records when applicable.
Would a bank or government agency ever demand gift cards or cryptocurrency?
An unsolicited demand for immediate payment by gift card, cryptocurrency, cash pickup, or similar hard-to-reverse method is a major warning sign, especially when framed as taxes, bail, a fine, or account protection. Do not pay. Contact the organization through its official website, app, or previously established number.
Should I reply to a suspicious audio message to test the person?
You do not need to continue the conversation to verify identity. Avoid links and attachments, preserve the evidence, and contact the person through a separate trusted route. If the message reached a work device, follow your organization’s safe reporting procedure.
Can I report an attempt even if I did not lose money?
Yes. Attempted fraud can still be reported with the phone number, account, requested payment method, and other details. Review FTC ReportFraud for consumer scams and IC3 for internet-enabled financial fraud.
Can I rely on an AI-detection app?
Treat detection tools as supporting information only. They can produce false positives or miss sophisticated manipulation. Do not delay a payment recall, password change, or official report while waiting for a detection result.
The response sequence at a glance
Pause → end the conversation → call a saved number → involve a second person → review the transaction in an official app → refuse payments, codes, and remote access → preserve evidence → contact the financial institution and official reporting services.
AI impersonation can be technically sophisticated, but the safest response remains straightforward. Do not use a voice or face as final proof. Switch channels when a request is urgent, and do not let anyone bypass established payment or verification controls. Practicing this routine with family members and coworkers makes it much easier to recover your judgment when a convincing call arrives.
Official sources consulted
- FBI Internet Crime Complaint Center: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud
- Federal Trade Commission: Scammers use AI to enhance their family emergency schemes
- Cybersecurity and Infrastructure Security Agency: Recognize and Report Phishing
- Federal Trade Commission: ReportFraud.ftc.gov
[…] English guide: Read this guide in English […]