Artificial intelligence has not created financial fraud, but it has made impersonation quicker, cheaper and far more convincing. In 2026, a criminal no longer needs to write a clumsy message or sound believable throughout a long telephone call. A short recording taken from social media can help imitate a relative’s voice; publicly available footage can be altered to show a banker, presenter or financial expert appearing to recommend an investment; and a fake adviser can maintain polished conversations for weeks using generated photographs, documents and messages. The safest response is not to become an expert in detecting every digital manipulation. It is to treat identity, urgency and payment as three separate questions, then verify each one through a contact route that the caller, video or message did not provide.
The most effective AI-assisted scams begin with genuine information. Criminals collect names, family relationships, workplaces, travel plans, hobbies and recent events from public posts, leaked databases, compromised email accounts and earlier scam attempts. They may know what a relative calls you, which bank you use or which investment topics you have searched for. That detail makes a false approach feel personal before any synthetic voice or video is introduced. AI then helps the fraudster turn scattered information into a coherent story, write in the expected tone and respond quickly when the victim asks questions. The result may be technically imperfect, yet emotionally persuasive enough to prevent careful checking.
Most schemes follow a simple sequence. First comes a trigger: an accident, a frozen account, a legal problem, a confidential investment opportunity or a warning that money is already at risk. Next comes borrowed authority. The speaker claims to be a relative, police officer, bank employee, solicitor, investment analyst or recognisable public figure. The third element is pressure. The victim is told to act immediately, keep the matter secret, move money to a supposedly safe account, install remote-access software, share a one-time security code or convert funds into cryptoassets. AI improves the performance, but urgency and isolation still do most of the criminal work.
The financial impact is substantial. UK Finance reported that criminals stole £1.28 billion through payment fraud during 2025, while investment fraud produced the highest authorised push payment losses at £221.5 million, a rise of 40 per cent year on year. In the United States, the FBI’s 2025 Internet Crime Report recorded more than $17.7 billion in reported cyber-enabled fraud losses and identified AI-related complaints as a distinct category for the first time. These figures do not mean every loss involved a deepfake. They show the wider environment in which AI-generated voices, videos, identities and documents are being added to already successful methods of manipulation.
The cloned-relative call is designed to bypass analysis by creating fear. A parent or grandparent may hear a familiar voice saying there has been a road accident, arrest, medical emergency or kidnapping. A second person may then take over, claiming to be a police officer, doctor or lawyer and providing payment instructions. The voice may contain a few convincing phrases rather than a flawless conversation; distress, background noise and a claimed injury can explain any odd pronunciation. The strongest warning signs are not tiny audio defects but the request itself: secrecy, immediate payment, an unfamiliar recipient, gift cards, cash collection, cryptocurrency or refusal to let the recipient call another family member.
The fake banker or financial expert video uses visible authority. A short clip may appear to show a bank executive, television presenter, economist or well-known investor discussing an exclusive opportunity, an automated trading system or an urgent way to protect savings. The video may be placed inside a copied news page, social-media advert or live-looking broadcast. Some manipulations still reveal mismatched lip movement, unnatural blinking, inconsistent lighting or changes in voice quality, but visual inspection is becoming less reliable. A professional face, familiar logo or realistic interview setting proves nothing about who produced the clip or whether the investment exists.
The fraudulent investment adviser usually builds trust more slowly. Contact may begin through an advert, dating conversation, professional networking message, investment group or an unsolicited call. The person may share convincing credentials, a copied company address, a real firm’s reference number and screenshots showing profitable trades. Early withdrawals may even be allowed to encourage a larger deposit. Later, the account appears to grow while every attempt to withdraw produces a new demand for tax, insurance, verification or release fees. The adviser may use video calls, generated identity documents or hired participants, but the essential test remains unchanged: independent regulatory checks, control of the receiving account and the ability to withdraw without paying invented charges.
Begin by stopping the conversation. Do not argue, reveal what made you suspicious or continue answering personal questions. End the call, close the message and give yourself enough time to verify the story. For a family emergency, call the person back on a number already saved in your contacts. If they do not answer, contact another relative, friend, workplace or hospital through details you find independently. A family code word can help, but it should support rather than replace a callback because a password may be overheard, shared or obtained. Ask about the event through a separate route and never use a telephone number, link or account supplied by the person demanding money.
For a supposed bank call, use the number printed on your card, shown inside the genuine banking app or published on the bank’s official site. Caller ID is not evidence because displayed numbers can be spoofed. A real employee should accept that you want to end the call and verify independently. Banks do not need customers to move funds to a new safe account to protect them, disclose a full password, hand over a card, reveal a one-time code for an unexpected transaction or install software that lets another person control the device. If a caller claims fraud is already taking place, use another telephone where possible and check recent transactions only after closing any screen-sharing or remote-control session.
For an investment, verify both the firm and the specific service being offered. In the UK, use the FCA Firm Checker and Financial Services Register, confirm that the business is authorised for the relevant activity, and compare the telephone number, email address and web address with the official record. Search the FCA Warning List as well. A copied firm name or reference number is not enough because clone firms deliberately borrow genuine details. Contact the authorised firm using the number in the regulator’s record and ask whether the named adviser works there. Treat guaranteed returns, secret groups, time-limited access, personal bank accounts, crypto-only payments, remote access and pressure to borrow as reasons to stop.
A dependable routine can be remembered as pause, separate and confirm. Pause before taking any financial action. Separate the request from the communication by ending the call or leaving the chat. Confirm the identity and story using a known person, official record or contact detail found independently. This routine works because it does not depend on spotting visual or audio errors. Even a technically perfect imitation cannot prevent you from calling your relative directly, contacting your bank through its normal number or checking whether an adviser has the correct permissions. The fraudster therefore tries to remove time, privacy and outside help; restoring those three conditions weakens the scheme.
Add practical friction to high-risk payments. Set lower daily transfer limits where suitable, enable transaction alerts and two-step verification, protect email and banking accounts with different strong passwords or passkeys, and keep recovery details current. Households can agree that an unexpected request above a chosen amount requires confirmation by a second trusted person. Never approve a login or payment notification merely because someone on the telephone says it is needed to cancel fraud. Do not share your screen while banking, and do not let an unknown adviser guide you through opening an account or wallet. Security tools help most when they create a pause rather than when they are treated as proof that the other person is genuine.
Use AI-detection tools cautiously. A scanner may flag altered audio, edited images or generated text, but no consumer tool can reliably certify every file as real or false. Compression, poor lighting and ordinary editing can create false alarms, while a well-made deepfake may pass an automated check. Look instead at the complete behaviour around the content. Was the approach unexpected? Is the sender moving the conversation to an encrypted chat? Are you being told not to speak to relatives, the bank or a regulated adviser? Is the recipient account unrelated to the named organisation? Is withdrawal conditional on another payment? A believable face cannot make an unsafe financial process legitimate.

Contact your bank or payment provider immediately using an independently verified number. Explain that the payment was induced by fraud, identify every transaction and ask whether transfers can be stopped, recalled or traced. If card details, security codes or online-banking credentials were shared, request appropriate blocks and new credentials. Speed matters because stolen funds may be moved through several accounts or converted into cryptoassets. Do not wait until you have collected every screenshot before making the first call. Record the time of your report, the name or reference supplied by the bank and the steps it asks you to take.
In the UK, qualifying victims of authorised push payment scams sent through Faster Payments or CHAPS may fall within mandatory reimbursement rules introduced in October 2024. The standard maximum is £85,000 per claim, although the result depends on the payment, customer, circumstances and applicable exceptions, and individual firms may choose to reimburse more. A provider may apply an excess of up to £100 in some cases, but not to a customer assessed as vulnerable under the rules. Submit the claim promptly and provide a clear account of how the fraudster gained trust, what was said, where the money went and when suspicion arose. Reimbursement is an important protection, not a reason to delay reporting.
Preserve evidence without continuing the relationship. Save messages, email headers, account names, payment references, wallet addresses, telephone numbers, adverts, web addresses, documents and screenshots of the alleged investment balance. In England, Wales and Northern Ireland, cyber crime and fraud can be reported to Report Fraud online or by telephone; in Scotland, reports should be made through Police Scotland on 101, while an immediate danger requires 999. Report misleading financial promotions or unauthorised firms to the FCA where relevant. Tell the genuine person or organisation whose identity was copied so they can warn others and secure any compromised account.
A simple family agreement is more useful than a long technical lesson. Decide that no relative will request an urgent transfer, gift card, cash collection or cryptocurrency payment without independent confirmation. Store current telephone numbers for close relatives, banks and other important services. Choose a private family phrase for emergencies and change it if it is ever exposed, while keeping the callback rule as the main safeguard. Discuss how to respond if a caller claims that secrecy is required by police, a bank or a solicitor. The agreed response should be to end the contact, call a known number and involve another trusted person before any money moves.
Reduce the information that makes impersonation easier without blaming the people whose content is copied. Review who can see family names, birthdays, travel updates, workplace details and public voice or video posts. Close unused accounts, remove exposed contact details where practical and use privacy controls for personal posts. Protect email first because access to an inbox can reveal relationships, invoices, financial providers and password-reset links. Turn on two-step verification, preferably using an authentication app or security key where available, and check forwarding rules after any suspected compromise. These steps cannot prevent every imitation, but they can limit the accurate personal detail that makes a fabricated story persuasive.
Finally, practise the response when nobody is under pressure. Run through a sample call once or twice a year: a relative needs bail money, the bank wants a safe-account transfer, or an adviser offers a private opportunity endorsed by a famous person. The goal is not to frighten anyone or test their ability to detect a deepfake. It is to make stopping, calling back and asking for help feel normal. If someone is deceived, respond without ridicule. Shame delays contact with banks and police and leaves victims vulnerable to recovery scams, in which another criminal promises to retrieve the money for an advance fee. Fast action, accurate records and calm support offer the best chance of limiting further loss.