Deepfake Voice/Video Scams
What it is (1-liner)
AI-generated voices or faces used to impersonate loved ones, coworkers, or officials to extract money, data, or approvals—by phone, video, or voicemail.
Red flags (top 5)
Emotional, urgent inbound call: "Mom, I'm in trouble—send money now." (voice clone).
"Boss/CFO" on a video call authorizing a fast payment (BEC via deepfake).
Caller ID/name looks right but asks for crypto/gift cards/wires.
Refuses call-back to a known number; pushes you off official channels.
Pre-recorded political/robocalls with synthetic voices. (AI robocalls are illegal without consent.)
Do this now (60-second checklist)
Treat all inbound calls as untrusted. Hang up and call back using a saved/official number (bank, boss, family).
Agree on family/company code words; ask challenge questions only the real person would know.
If video: ask for a quick liveness check (turn head, unique phrase) and still verify out-of-band.
Never pay via gift cards/crypto/QR at someone's demand.
Report scams to ReportFraud.ftc.gov and FBI IC3; if it's a robocall, also report to FCC.
Report & support
FCC: AI-voice robocalls are prohibited under the TCPA; report spoofing/robocalls.
FBI IC3: file complaints for voice/video imposters.
FBI PSA (May 2025): ongoing AI-impersonation campaigns targeting officials and contacts—mitigations inside.
Mental health & immediate safety
If panic or shame hits, Call/Text 988 (24/7). You didn't "fall for it"—you were targeted by engineered deception.
Scripts you can copy
To a loved one (verification): "I got a call that sounded like you. I'm hanging up and calling your saved number. What's our code word?"
To finance/AP: "Payment approval requires verified callback to known numbers and dual-approval—no exceptions for calls or video."
To the caller: "I don't act on inbound requests. I'll call back on an official number."
Lock down & recover
Turn on Silence Unknown Callers (iOS) or Filter Spam Calls (Android); use carrier scam-blocking.
Establish callback policies at work (no payments or data changes from inbound calls/chats).
If you shared info or sent money, contact your bank/exchange immediately and file FTC/IC3.
Platform-specific steps
Workplace (BEC risk): Require dual control + verified callback for payments and vendor changes; be wary of video invites from new accounts. (Case example: $25M deepfake CFO call in Hong Kong).
Personal: Use voicemail—let unknowns roll to messages; verify via separate channel before responding.
Printable Quick Card (1-page content)
Don't trust inbound voice/video.
Hang up → Call back on saved/official number → Use code word → No gift cards/crypto/wires → Report to FTC + IC3 (AI robocalls are illegal).
FAQs
How common is this now? FBI warns generative AI is accelerating fraud scale and believability.
Are AI robocalls really illegal? Yes—FCC ruled AI-generated voices are "artificial/prerecorded" under the TCPA.
What if the video looks perfect? Deepfakes can fool the eye—verify out-of-band every time (saved/official numbers).
Last updated: Sept 28, 2025 • Reviewed by: ZoraSafe Safety Team

