Deepfakes have moved out of research labs and political disinformation and into everyday fraud. A finance employee in Hong Kong was convinced by a realistic AI video conference call — featuring a convincing simulacrum of his company's CFO — to wire $25 million to criminal accounts[1]. Voice clone technology now requires as little as three seconds of audio to replicate someone's voice convincingly enough[2] to fool people who know them well. AI-generated profile photos are used in romance scams, fake job listings, and corporate impersonation. Knowing what to look for is not optional anymore. It is a basic literacy skill for anyone who interacts with digital media.
This article breaks down the specific tells — visual, audio, and behavioral — that AI-generated content leaves behind, and gives you the tools to verify what you're seeing before you act on it.
This article is about being targeted — a call, a message, a video meeting where someone wants something from you. If instead you have come across a video or photo online and want to know whether it is real before you pass it on, that is a different problem with a different answer, and it is over here.
Start here: you cannot tell by looking, and neither can anyone else
Every version of this advice used to begin with what to watch for. That approach is finished, and the measurements are not close.
A pre-registered study of 1,276 people, published in Communications of the ACM, put ordinary people in front of real and synthetic media[5]. Mean accuracy was 51.2%. On images alone it was 49.4% — slightly worse than a coin toss. People were right 64.6% of the time about genuine material and only 38.8% about synthetic material, because the reflex is to assume things are real.
Familiarity did not help: people who called themselves highly familiar with AI scored 51.9%, the unfamiliar 51.1%. One thing did move the number, and the authors are blunt about it — older participants performed worse, most sharply on audio and audiovisual material. The conclusion is worth quoting exactly:
The tells that used to be taught have expired on their own schedule. Malformed hands are still common but were never evidence of the reverse. Unnatural blinking was solved years ago. And the audio advice aged worst of all: readers were told AI voices don't breathe, while the vendors now document adding breath on request — ElevenLabs' own help page says "you can use audio tags such as [sighs] or [exhales] to add breathing and similar reactions to generated speech."
So this article does not teach you to listen harder. Everything below works whether the voice is real, cloned, or a stranger — because none of it depends on you telling the difference.
The procedure: hang up, then call back on a number they never gave you
One rule, three parts. End the call yourself. Find a number they had no way to control. Call that. Every step below protects one of those three.
1. Hang up first. Don't explain, don't argue, don't verify with them.
You owe a cold caller nothing — not politeness, not an explanation, not one more moment. Staying on the line to "just check something" is the whole trick, and there is no question you can ask that a prepared caller has not already got an answer to. Never let them keep you on while you look something up. Never accept a transfer to the fraud team, the police, or a supervisor.
2. Get a number from something you already own.
Not from the call, the caller ID, a voicemail, an email, a text or a link — those are all things the caller chose for you. The FTC is explicit: "Don't trust your caller ID. Your caller ID might show the government agency's real phone number or name — like 'Social Security Administration.' But caller ID can be faked."[6]
- Your bank — the number printed on the back of your card, or the bank's own app, or its address typed into your browser by hand.
- Police or a government agency — the published number, or your local non-emergency line, looked up independently.
- A relative in trouble — the number you already have saved. Then try somebody else who would know.
3. Take a minute before you dial.
Urgency is the product. The bank, the warrant, the grandchild — every version is built to stop you pausing, because a pause is where it falls apart. Nothing real is ruined by ten minutes.
On a landline, hanging up may not be enough. The caller can hold the line open after you put the handset down, then play a recorded dial tone so your next call seems to connect. You dial your bank and reach the same people. Consumer Protection BC documents them changing voices, or handing you to an accomplice, to sell it[7]. The reason is mundane: "the person who initiates a call on a landline has to end the call for the other person to be able to dial out again."
So on a landline, use a different phone — a mobile, or a neighbour's. If you have no other phone, wait several minutes and call someone you know first; if you reach them, the line is clear. Mobiles disconnect properly and are not affected.
What no real caller ever does
- Asks you to move money to a "safe account." Your bank will never do this. There is no such account.
- Wants gift cards, a wire, crypto or a payment app. The FTC: "No government agency will demand you wire money or pay with gift cards, cryptocurrency, or a payment app."[6]
- Tells you not to tell anyone — especially not bank staff, especially not family.
- Calls out of the blue for money or personal details. "Government agencies will never call, email, text, or message you on social media to ask for money or personal information. Only a scammer will do that."[6]
- Needs it done right now. Urgency is a tactic, not a circumstance.
Behavioral Red Flags — What the Attacker Is Asking You to Do
Technical tells become less reliable as generation quality improves. Behavioral patterns are far more durable — because the goal of a deepfake attack is to get you to do something, and that goal creates predictable behaviors regardless of how convincing the media is.
This script — or close variants — is used in what the FTC calls "family emergency scams,"[4] increasingly paired with AI voice cloning of the supposed family member's voice.
Set this up before you need it
All of this works better if it is already decided, because the moment it matters is the moment you are least able to think.
- Agree a family phrase. A word or question only your people know — never texted, never posted. Starling Bank recommends exactly this. When a panicked voice calls, you ask for it.
- Save the number now. Put your bank's card number in your phone today, so you are not hunting for it while somebody shouts at you.
- Tell the people most likely to be targeted. This works best when somebody already knows that the plan is to hang up and call back.
The institutions that carry this risk professionally have already made the switch. J.P. Morgan states the reason plainly — people identify deepfake video correctly only about 40% of the time — and draws the conclusion that matters: "Verifying a directive, even one that appears to come from the CEO, is not just acceptable but expected."[8] U.S. Bank's guidance contains no perceptual tells at all. After losing $25 million, Arup's chief information officer recommended rehearsing the response rather than training the eye.
What to Do When You're Not Sure
If You've Been Targeted
If you've sent money, shared personal information, or been manipulated by content you now believe was AI-generated, act quickly — not to recover the money (which is often unrecoverable) but to document and report, which helps track and potentially stop the operation targeting others.
Deepfake quality will continue to improve, and some of the specific visual artifacts described here will eventually be resolved by better generation systems. But the behavioral patterns of deepfake attacks — urgency, financial pressure, manufactured reasons to avoid verification — are structural features of the fraud, not features of the technology. Those won't change.
The most durable protection isn't a detection tool. It's the habit of slowing down before acting on anything that arrived unexpectedly, claimed to be urgent, and asked you to do something you'd normally verify. A phone call, a code word, an extra 90 seconds — these are not inconveniences. They are the difference between a close call and a $25 million wire transfer.
scmp.com
mcafee.com
sumsub.com
consumer.ftc.gov
arxiv.org/abs/2403.16760 · doi:10.1145/3729417
consumer.ftc.gov
consumerprotectionbc.ca