AI scams: verify the request, not the face
Our guide to fake crypto projects and rug pulls shows why the evidence behind a presentation matters. AI can make that presentation more credible, but it does not create a right to access your money. An urgent request must be verified even when it appears to come from someone you know.
In a press release published in April 2026, the FBI describes, among other things, the role of AI tools in fraud and impersonation schemes. This does not mean that every suspicious image comes from AI. The nature of the request and the channel used remain more important than the technical label.
Visual clues can help, but they are not enough to keep you safe. A video may contain flaws without being fraudulent, while a fake may show no obvious anomalies. Looking only for strange fingers or a robotic voice misses the main issue.
Ask three questions instead: who is making the request, through which verified channel, and for what action? If the action grants access to an account, discloses a secret or moves funds, obtain independent confirmation before proceeding.
Scenarios that exploit a trusted relationship
A fraudster may impersonate someone close to you and claim that an emergency has occurred. The message may request a change of account details, a quick transfer or a verification code. A familiar voice and knowledge of personal details can increase the pressure.
Call back using a number already saved in your contacts, not one provided in the suspicious message. If the usual channel appears compromised, use another known method. Public information or a memory shared on social media is not a good confirmation secret.
Within a team, a fake instruction may imitate an executive and request an unusual payment. The procedure should verify the beneficiary, amount and authority through an established process. Urgency and hierarchy must not eliminate controls.
An excessive demand for confidentiality may be intended to prevent this verification. “Do not contact anyone” or “do it before the meeting” are signals that require scrutiny. A genuine urgent need can withstand a brief confirmation through an independent channel.
Fake experts, celebrity videos and crypto recommendations
A video may make it appear that a public figure is recommending a token or platform. Images of executives and the names of media outlets can also be copied. The source should be located on official channels, with consistent context and date.
An excerpt taken out of context can mislead viewers even without artificial generation. Check the full announcement, the product and the website involved. An advertisement shown on a social network does not mean that the network endorses the service.
Promises of returns, full reimbursement or privileged access require contractual and regulatory evidence. A familiar face does not turn an offer into a suitable product. The service’s status must still be checked in the relevant country and for the exact activity involved.
Our guide to crypto platforms in Africa distinguishes popularity from authorization. The same method applies to offers presented in a video: the entity’s name, terms, jurisdiction and available remedies must remain clear.
Perfect documents and fake compliance processes
AI can improve the appearance of a message or document, but a fraudster does not need sophisticated technology to copy a logo. An invoice, certificate or professional ID should be verified with its genuine issuer.
A fake support agent may announce an identity check, an account problem or a new rule. The link may lead to an interface resembling a familiar service. Return through your usual access point instead of following a link sent under pressure.
A request for identity documents requires verification of both the channel and the reason for the request. KYC checks and the available remedies covered in our crypto glossary should not become an excuse to collect all your documents without explanation. Limit the information you provide to relevant, official requests.
No administrative check justifies sharing a seed phrase. This information can give someone the power to move assets. A request for a recovery phrase, private key or secret code should end the conversation, regardless of how convincing the document appears.
Investment fraud can build slowly
An interlocutor may build a relationship before presenting an opportunity. Regular messages, calls and apparent proof of gains can gradually create trust. Fraud does not necessarily begin with a dramatic request.
The FBI describes crypto investment fraud built on trust. An initial small withdrawal may be part of the scheme and does not guarantee that the service is legitimate. Verification must focus on the entity, not on a single successful transaction.
A dashboard may display profits without corresponding assets. A number rising on an interface does not prove that the capital exists or can be withdrawn. Successive unlocking fees may then extend the payments instead of releasing the funds.
Do not continue simply because you have already paid. Money already committed can create psychological pressure that encourages another transfer. Seek independent advice and preserve the relevant records before deciding whether to take further action.
Protecting accounts, phones and signatures
A sound process combines human verification with account protections. Secure your email, use appropriate authentication methods and preserve recovery options. A compromised email account can make it easier to impersonate a service or someone close to you.
Our guide to SIM-swap attacks highlights the risk of losing control of a phone number. A familiar voice should never lead you to dictate a code received by SMS. The code may authorize an action you did not initiate.
With a wallet, check the requested action in the application and on the device. A signature does not always have the same effect as a simple connection. The website may be requesting a permission or transaction whose consequences go beyond the stated demonstration.
Our guide to crypto approvals explains these permissions. A reassuring presentation or conversational assistant cannot replace reading the actual request. Keep reserves away from experimental interactions whenever your organization allows it.
Create a family or workplace procedure
For sensitive requests, establish a known rule: call back using a saved number and confirm the beneficiary before making a payment. A family may agree on a private verification detail, but it should remain protected and cannot replace every other control.
In a business, define authorized individuals, internal thresholds and approval steps. A change to bank details should trigger independent confirmation. Instructions must remain accessible even when the executive appears to be in a hurry.
Train users with examples without exposing their secrets. The goal is to recognize a request for authority, not merely to spot a language mistake. A flawless message can be malicious, while an awkward one may come from a legitimate interlocutor.
The procedure should remain short. If it requires steps that are impossible to carry out in everyday life, people may ignore it. A few clear, systematic checks are better than a long checklist used only after an incident.
What should you do if you have already clicked or paid?
Identify the action involved: reading a message, entering credentials, sharing a code, signing or transferring funds. The appropriate response differs in each case. Change affected access credentials through official channels, contact the service provider and seek appropriate help when the level of exposure remains uncertain.
Keep the messages, website addresses, references and dates. Do not publish secrets in a request for help. Useful evidence should show what happened without giving anyone else the means to repeat the attack.
If funds have left an account, contact the relevant services and the competent authorities in your country promptly. A report may help with the case, but does not guarantee recovery. Timelines and available options vary depending on the provider and the circumstances.
Then beware of fake recovery agents. Someone who promises a certain outcome in exchange for an upfront payment or asks for keys may exploit the incident a second time. Verify their identity and role before sharing any information.
The right defense does not depend on a miracle detector
Detection tools can contribute to an analysis, but their result is not absolute proof. A financial process should not authorize a payment merely because a file receives a reassuring score. Independent confirmation remains necessary.
Avoiding AI scams ultimately means reducing the authority granted to an unverified message. The identity, channel and requested action must be confirmed separately. This approach also protects against traditional fraud, even when no artificial intelligence is involved.