AI-powered scams now use cloned voices (from just seconds of audio), deepfake videos of trusted public figures, and flawless phishing messages — the old advice to spot bad grammar no longer works. The defence is process, not appearance: slow down, hang up and call back on a known number, agree a family safe word, and never trust urgency, secrecy, or unusual payment demands.
For years, the advice on spotting a scam was reassuringly simple: look for the bad grammar, the odd spelling, the blurry logo, the website that just looks wrong. That advice is now dangerously out of date. Artificial intelligence has handed scammers tools that produce flawless, natural English, convincing fake videos of people you trust, and — the part that genuinely unsettles people — cloned voices built from just a few seconds of audio. The National Anti-Scam Centre's Scamwatch service puts it plainly: scammers use AI to fake voices, videos and websites, personalise messages, spoof phone numbers and build entire platforms to steal money and personal information (Scamwatch, https://www.scamwatch.gov.au/stop-check-protect/help-to-spot-and-avoid-scams/how-scammers-use-technology-and-ai). Older Australians are squarely in the sights of these new scams, both as targets of "family emergency" calls and of fake investment ads. The good news is that while you can no longer trust how something looks or sounds, there's a small set of habits that still keeps you safe. This article is general information only, not personal advice.
Why did the old warning signs stop working?
The reason scams used to be catchable is that they were made by people working at scale, often in a second language, using crude tools. The tell-tale mistakes gave them away. AI has erased all of that. A scam email or text can now be written in perfect, personalised English that mimics the tone of your real bank. Fake websites carry polished logos and professional design. And video and audio can be fabricated convincingly enough to fool a quick glance or a short phone call.
So the single most important shift to make is this: stop trying to judge whether something is genuine by how convincing it looks or sounds. That instinct, which served you well for years, now works against you — because the fakes are designed to pass exactly that test. The defence has to move from spotting mistakes to following a process.
What about the call that sounds exactly like your grandson?
The most distressing of the new scams uses voice cloning. From a few seconds of someone's voice — scraped from a social media clip, a voicemail greeting, or even a quick "hello?" — scammers can generate speech in that person's voice saying whatever they type. Scamwatch confirms the mechanism directly: with only a short recording, scammers can create an AI clone of a voice and use it to call you pretending to be a friend or family member in distress (Scamwatch, https://www.scamwatch.gov.au/stop-check-protect/help-to-spot-and-avoid-scams/how-scammers-use-technology-and-ai).
The script is engineered to overwhelm your judgement. The phone rings and it's your grandchild, or your son or daughter, sounding frightened and upset: there's been an accident, or they've been arrested, or they're stranded overseas and their phone is gone. They need money right now, and they beg you to keep it quiet — "please don't tell Mum." The voice is right. The panic is real. And that combination is exactly what makes it so effective.
Notice the pattern underneath the emotion, because the pattern is the giveaway, not the voice: urgency, secrecy, and an unusual way to pay — a transfer to an unfamiliar account, gift cards, or cryptocurrency. Real emergencies rarely demand all three at once. The defence is simple and it works: hang up and call the person back yourself, on the number you already have for them. A cloned voice can't survive that. Better still, agree a family "safe word" now — a word or phrase only your real family would know — and make a rule that any genuine emergency call must include it. It feels almost too simple, but a pre-agreed code word defeats a voice clone completely.
What about the famous face that "endorses" an investment?
The second new scam works on greed and trust rather than fear. Scammers use AI to create fake videos in which a well-known Australian business figure, TV presenter or public official appears to spruik a "can't-lose" investment or cryptocurrency platform. The person never said any of it — their likeness was faked without their knowledge or consent — but the video looks real enough to be persuasive, and it's usually wrapped in a slick fake news article or a professional-looking trading platform. Scamwatch has issued specific alerts about exactly this "fake celebrity online investment" pattern.
These almost always surface as social-media ads or messages, promising high, "guaranteed" returns. Here the rule is refreshingly absolute: no legitimate celebrity endorses get-rich investment schemes, and no genuine investment guarantees high returns. Both are hallmarks of a scam, full stop. Before you act on any investment you've seen advertised — especially on social media — check the promoter against the warnings on the Government's MoneySmart website and treat anything that arrived via an ad or a direct message with deep suspicion (ASIC MoneySmart, https://moneysmart.gov.au/check-and-report-scams/how-to-spot-a-scam).
What about the perfect message from "your bank"?
The third vector is everyday impersonation, now polished to a shine. A text or email that appears to come from your bank, myGov, Centrelink, the ATO, a delivery company or a utility — flawless, personalised, and often followed up by a phone call from someone claiming to be the fraud team, walking you through "securing" your account.
Two habits neutralise almost all of it. First, never click a link in an unexpected message — instead, reach the organisation yourself through its official app or by typing the address you know; Scamwatch's own advice is to always type web addresses directly into your browser rather than clicking links in emails, messages or social-media ads (Scamwatch, https://www.scamwatch.gov.au/stop-check-protect/help-to-spot-and-avoid-scams/how-scammers-use-technology-and-ai). Second, never trust an inbound call that claims to be your bank or a government agency; caller ID can be faked, so hang up and phone them back on a number you look up for yourself. Remember the underlying truth: a genuine bank or government body will never rush you, and will never ask you to move your money to "keep it safe."
What is the one defence that still works — process, not appearance?
Pull the threads together and you get a handful of habits that hold up no matter how good the fakes become. The first is to slow down, because urgency is the scammer's single most powerful weapon — real emergencies and legitimate organisations both survive a pause while you check. The second is to verify independently: hang up, close the message, and re-establish contact through a channel you choose, such as a known phone number or the official app. The third is to watch for the signature — urgency plus secrecy plus an unusual payment method is the fingerprint of a scam, whatever voice or face is attached to it. The fourth is to assume it can look and sound real, and not wait to "spot the flaw," because there may not be one. And the fifth is to have a plan before it happens: agree a family safe word, and pick one trusted person to run any pressured "opportunity" or urgent demand past before you act.
What do the worked examples show?
These show the two most common AI scams in action — the voice-clone emergency call and the deepfake investment ad. They are illustrative only, not personal advice, and the figures are illustrative.
Consider Norma, 74, who answers the phone to what sounds exactly like her grandson, in tears: he's been in a car accident, he's in trouble with the police, and he needs $4,000 transferred to a lawyer's account tonight — and please, please don't tell his mother. The voice is unmistakably his. On these facts the emotion is the trap, and the pattern beneath it is the tell: urgency, secrecy and an unusual, immediate payment, all at once (Scamwatch, https://www.scamwatch.gov.au/stop-check-protect/help-to-spot-and-avoid-scams/how-scammers-use-technology-and-ai). On these facts it is generally rational for Norma to do the one thing a cloned voice cannot survive — hang up and call her grandson straight back on his own saved number, or ask for the family safe word — before moving a single dollar. Nine times out of ten the real grandson answers, safe and puzzled.
Now consider Frank, 68, who is scrolling social media and sees a slick video of a well-known Australian TV finance presenter enthusiastically backing a cryptocurrency platform "guaranteeing" 20% monthly returns, wrapped in what looks like a real news article. On these facts the endorsement is fabricated and the promise is impossible: no legitimate public figure endorses get-rich schemes, and no genuine investment guarantees high returns (ASIC MoneySmart, https://moneysmart.gov.au/check-and-report-scams/how-to-spot-a-scam). On these facts it is generally rational for Frank to treat the ad as a scam on its face, resist the "limited-time" pressure to sign up, and check any investment against MoneySmart's warnings before parting with a cent — rather than trusting a face on a screen that AI can now fake at will.
What should you do if it happens to you?
If you think you've been caught, move quickly and don't waste a second on embarrassment. Contact your bank immediately — if a transfer is fresh, they may be able to stop or recall it — and change any passwords that may be exposed. Then report it to the National Anti-Scam Centre's Scamwatch, and, for anything involving hacked accounts or cybercrime, to ReportCyber (Scamwatch, https://www.scamwatch.gov.au/report-a-scam). If your identity may have been compromised, IDCARE — Australia and New Zealand's free national identity and cyber support service — can help you build a plan to limit the damage, on 1800 595 160. Reporting won't always get your money back, but it helps the authorities disrupt the operation and protect the next person. (Our companion piece on recovering after a scam walks through the steps in detail.)
And please, set the shame aside. These fakes are engineered to fool intelligent, careful people — being targeted says nothing about you except that you have a phone. The people who stay safest aren't the ones who think they'd never be fooled; they're the ones who've decided, in advance, to verify everything and never act in a hurry.
Sources
- Scamwatch — How scammers use technology and AI
- Scamwatch — Report a scam
- ASIC MoneySmart — How to spot a scam
- eSafety Commissioner — Deepfakes
Key takeaways
- AI has made scams sound and look flawless — cloned voices from just a few seconds of audio, deepfake videos of trusted public figures, and perfectly written phishing messages.
- The old advice to spot bad grammar or a blurry logo no longer works — the defence has to shift from spotting mistakes to following a verification process.
- A voice-clone "family emergency" call combines urgency, secrecy, and an unusual payment method — the pattern is the tell, not the voice; hang up and call the person back on a known number.
- No legitimate celebrity endorses get-rich investment schemes, and no genuine investment guarantees high returns — both are hallmarks of a deepfake investment scam.
- A pre-agreed family "safe word" that only real family members know defeats a cloned-voice scam completely, because a scammer has no way to produce it.
Frequently asked questions
How does AI voice cloning scam work?
Scammers can generate a convincing clone of someone's voice from just a few seconds of audio — scraped from a social media clip or voicemail greeting — and use it to call a family member pretending to be in distress, asking for urgent money while begging them to keep it secret.
How can I protect myself from a voice-clone scam call?
Watch for the pattern rather than trying to judge the voice: urgency, secrecy, and an unusual payment method (transfer, gift cards, or cryptocurrency) together are the giveaway. Hang up and call the person back on a number you already have for them, or ask for a pre-agreed family "safe word" that only real family would know.
Are celebrity-endorsed investment videos on social media real?
Almost certainly not if they promise high or "guaranteed" returns. Scammers use AI to fake videos of well-known public figures appearing to endorse investment platforms without their knowledge or consent. No legitimate celebrity endorses get-rich schemes, and no genuine investment guarantees high returns.
What should I do if I think I've been scammed?
Contact your bank immediately — a fresh transfer may be able to be stopped or recalled — and change any exposed passwords. Report it to Scamwatch and, for hacked accounts or cybercrime, to ReportCyber. If your identity may be compromised, IDCARE (1800 595 160) can help you build a plan to limit the damage.
