AI literacy · Staying safe · Lesson 2 of 4
AI scams
Voice clones, phishing and fake profiles.
10 minute read
Scams are not new. What is new is that AI has removed most of the old warning signs and made every scam cheaper to run at scale. The scams below are the ones most likely to reach you or your family, and each one has a defence that still works.
Voice cloning
AI can copy a person's voice from a few seconds of audio, which is less than most people have posted publicly without thinking about it. The classic attack is a phone call that sounds exactly like a family member in distress: an accident, an arrest, a stolen wallet, and an urgent need for money. The voice is real enough to bypass your instincts, which is exactly the point. Grandparents are targeted most, but nobody is immune.
Why is a few seconds enough? Because the model has already learned what human voices are like in general from enormous amounts of recorded speech. Your voice is a particular setting of pitch, pace, accent and habit laid over patterns the model already knows, so a short sample is all it takes to fit those settings, in the same way a good impressionist needs only a little listening before the impression starts working. And the phone is the perfect place to use the result, because phone audio is compressed and slightly muffled for everyone, which hides the small flaws that might give a clone away through a good speaker.
Phishing without the typos
For years, the advice was to watch for bad grammar and clumsy wording in scam messages. AI has ended that. A scammer anywhere in the world can now produce flawless, personalised messages in perfect Australian English, styled exactly like your bank, your uni or your workplace. The old tells are gone, so the defence has to move from how a message reads to what it asks you to do.
Walk through one illustrative example line by line. A text arrives: your parcel could not be delivered, a small redelivery fee of $2.99 is owing, tap the link within 24 hours or the parcel returns to sender. Every element is engineered. The parcel is plausible because most people are waiting on something. The fee is tiny because $2.99 feels far too small to be a scam, however the link leads to a fake payment page, and the real target is the card details you type into it. The 24 hour deadline manufactures urgency so you act before you think. And the link itself is the payload, because the message exists only to get your thumb onto it. Notice that nothing here depends on bad grammar, and everything depends on what the message asks you to do.
So the modern defence is to judge messages by their asks. There are only a few things a scammer can want from you: a code, a password, a payment, or a click through to a page that collects one of those. A one time code deserves special respect, because it exists precisely to prove that you are you, so anyone who asks you to read one out is asking to become you. Your bank will never ask for a code or a password on a call or message it started, and neither will any legitimate service, so that ask alone identifies the caller.
Fake people
AI generates convincing profile photos, life stories and endless patient conversation, which makes fake profiles and romance scams far easier to run. The pattern is a stranger who builds trust over weeks, then needs money or asks you to invest. A close cousin is the deepfaked celebrity investment ad: a well known face appearing to endorse a trading platform that promises easy returns. Those endorsements are fabricated, and the platforms take money in and give nothing back.
Why scams reach everyone
A misconception to drop early: scams happen to gullible people. They do not. Scam scripts are refined against thousands of victims, they are timed to catch people when they are tired, rushed or worried, and the people caught by them include professionals, teachers and, in the case of the fake celebrity ads, experienced investors. Australians lose billions of dollars to scams every year, and reports to Scamwatch, the reporting service run by the ACCC, consistently show investment scams causing the largest losses of any category. The question is never whether you are smart enough to avoid scams. It is whether a scam happens to arrive on your worst day, which is why the defence has to be a habit rather than cleverness.
And the scams find their way into a teenager's week in specific shapes: a text that seems to come from your manager at your casual job asking you to quickly buy gift cards for a client, a buyer on a marketplace app who overpays for your old textbooks and asks you to refund the difference, concert tickets resold by a stranger who wants a bank transfer, and follow up scams that contact past victims claiming to recover their losses for a fee. Each one is the same skeleton in new clothes: an unexpected ask, a reason to hurry and a payment path that cannot be reversed. Once you can see the skeleton, the costume stops mattering.
The defence that still works
- Verify through a second channel. If a call or message asks for money or codes, hang up and contact the person or organisation through a number you already have or find yourself. Never use contact details supplied by the message.
- Agree on a family safe word. A word or phrase only your family knows, asked for on any distressed call. A voice clone knows the voice, not the word.
- Slow down when anything is urgent. Manufactured urgency is the engine of every scam, because rushed people skip checking. Real emergencies survive a two minute pause.
- Watch the payment path. Gift cards, crypto and instant transfers to strangers are scam rails, because they cannot be reversed.
- Report it at scamwatch.gov.au, whether or not money was lost. Reports help Scamwatch warn others and spot new patterns early.
This lesson leans on the previous one, because voice clones and deepfaked endorsements are simply synthetic media pointed at your wallet. And it sets up the two that follow: the data lesson explains where scammers get the raw material that makes an attack personal, and the verification lesson turns the checking instinct you are building here into a general habit. The case study at the end of this topic reconstructs a voice clone scam in full, and it rewards a close read, because watching one being built step by step is the best inoculation available.
Check your understanding
8 questions. Pick an answer for each, then check.
1. How much audio does a scammer typically need to clone a voice convincingly?
2. Why is bad grammar no longer a reliable scam warning sign?
3. A family safe word defeats voice cloning because
4. A caller claiming to be your bank asks you to act immediately. The safest response is to
5. You spot a video of a famous Australian endorsing an investment platform with guaranteed returns. The most likely explanation is
6. According to the lesson, scams succeed mainly because
7. Why do phishing texts often ask for a very small fee, such as $2.99?
8. A caller asks you to read out a one time code your bank just texted you. This means