AI has made scam messages far more polished. Security researchers say old advice — "watch for typos" — is now outdated. Here's what actually gives them away. Try guessing each one:
Judge messages by what they're asking you to do, not how well they're written. Urgency, generic greetings despite claiming to know you, and requests for money, codes, or passwords matter far more than grammar ever did.
For twenty years, bad grammar was the giveaway. Large language models ended that: today’s scam messages are fluent, personalised, and context-aware — they reference your actual neighbourhood, recent purchases, or job title scraped from the web. The tells have moved from how a message is written to what it asks you to do.
Whatever the message says, never use the link or number it provides. Open the official app or type the official address yourself. This one habit neutralises AI-written scams, cloned websites, and spoofed sender IDs all at once.
For twenty years the standard advice for spotting a scam message was to look for bad English. That advice has now expired. Generative writing tools produce fluent, idiomatic, correctly punctuated text in dozens of languages at effectively no cost, and fraudsters adopted them immediately. A scam message today can read better than a real one from your bank.
Three things changed at once. Scams became cheap to write at scale. They became personalised, because the same tools can weave in details scraped from your public profiles. And they became conversational — a fraudster can now run hundreds of simultaneous chats, each one patient and responsive, without speaking the victim's language.
What did not change is the underlying structure. Every scam still needs you to do something: send money, hand over a code, install something, or click a link. The polish sits on the surface. The shape underneath is the same as it ever was, and the shape is what you should learn to recognise.
Ask what the message actually wants. Gift cards, cryptocurrency, bank transfers to a new account, a one-time code read out loud, remote access to your computer — these requests are fraudulent essentially every time, whoever appears to be asking and however well they write.
Scams almost always try to move you: from a marketplace to WhatsApp, from a dating app to private messaging, from email to a phone call. The move takes you away from a platform that monitors for fraud and keeps records. Notice it happening.
Real organisations give you time. Deadlines measured in minutes or hours, threats of immediate account closure, warnings not to discuss it with anyone — all of these exist to stop you checking. Secrecy in particular is a hallmark: no legitimate process requires you to keep it from your family or your bank.
AI-written scams are often rich in confident detail — reference numbers, case IDs, officer names, exact amounts. The detail feels like proof. Ask whether any of it can actually be verified independently. Usually the only way offered is to ask the sender, which is no verification at all.
In romance and friendship scams, the emotional pace is the tell. Declarations of deep feeling within days, constant availability, an uncanny sense that this person understands you. Language models are very good at sustained, attentive warmth, and that is precisely what is being used.
Cloning a voice now takes a short sample, easily taken from a social media video. The classic version is a distressed call from a family member — an accident, an arrest, a lost phone, an urgent need for money — in a voice you recognise. Video calls with synthetic faces are further behind but no longer theoretical, and have already been used in large corporate frauds.
The defence does not require detecting the fake. Agree a family code word now, while nobody is under pressure, and use it to verify any urgent request for money. Then hang up and call the person back on the number you already have. A real relative will not mind. Our family check word tool helps you set one up, and the AI voice call checker walks through what to listen for.
Verify through a channel you chose, not the one that contacted you. Hang up and dial the number on your card. Open the bank's app rather than the link. Message your daughter on the number already in your phone. Type the company's address yourself.
This works because it does not depend on spotting anything. It does not matter how good the writing is, how accurate the voice clone is, or how much the sender knows about you. If verification runs through a channel the attacker does not control, the attack fails. It is the one habit worth teaching to everyone you know.
Often you cannot, and detection tools are unreliable. That is why the advice has shifted from spotting the writing to examining the request, the urgency, and whether you can verify it through a channel you chose yourself.
No. They are the same scams delivered more cheaply, more fluently and at greater scale. The goals are unchanged, which is why the old defences based on verification still work while the ones based on spotting bad English do not.
Yes, from a short sample of ordinary speech. This is why a family code word matters, and why any urgent request for money should be verified by calling the person back on a number you already have.
Contact the person or organisation through a channel you chose, not the one that reached out to you. Hang up and dial the number on your bank card. That one habit defeats almost every version of this.
No. Replying confirms your number or address is active and being read, which makes you a higher-value target. Block and report instead.