Fraud, now that language is cheap
What changed, precisely
Fraud did not become possible because of AI. What changed is the cost structure, and three specific costs collapsed.
Fluency. The classic advice to spot a phishing email — look for bad grammar and odd phrasing — worked because the attacker was writing in a second language at volume. That signal is gone. It was never a good signal, and it is now no signal at all.
Personalisation. Writing a message tailored to one person's employer, role, recent post and colleagues used to take a human twenty minutes, which meant it was reserved for high-value targets. It now costs a fraction of a cent, so the tailored version is available for everybody.
Voice and video. Voice cloning from a few seconds of audio has been demonstrated in research since 2023 and is available commercially. Live video calls with synthetic participants have been used in real thefts.
The consequence is not a new attack. It is that the highly targeted attack, formerly reserved for chief executives, is now economic against ordinary people.
The cases
The Hong Kong video call, 2024. A finance employee at the local office of an engineering firm transferred roughly US$25 million after a video conference in which the chief financial officer and several colleagues appeared. Every other participant was synthetic. The employee had been suspicious of the initial email; the video call resolved the suspicion, which is exactly what it was built to do.
Family emergency calls. A relative's voice, distressed, needing money immediately — bail, an accident, a kidnapping claim. Consumer protection agencies in several countries now list this as a top-reported scam. The audio is typically taken from social media video.
Romance and investment fraud, sometimes called pig butchering. Long-running relationships built over weeks, moving to a fake trading platform. AI reduces the labour cost of maintaining many conversations at once and removes the language barrier. Investigations have documented these operations running from compounds in Southeast Asia, staffed in part by trafficked workers — which places the harm at both ends of the transaction.
Business email compromise. The largest category by money lost in most national statistics, and it does not require any synthetic media at all — just a convincing message about a change of bank details, sent at the right moment in a real transaction.
What actually defends
The useful defences share a structure: they do not depend on detecting the fake.
Switch channels. Hang up and call back on a number you already have. Message the person on a different application. This defeats voice cloning completely, because the attacker controls one channel and not the second. It is the single most effective habit in this lesson.
Agree a code word. With family, now, before it is needed. A word that would never appear in a public post. When the distressed call comes, ask for it. This costs one conversation at dinner.
Impose a delay on money. Almost every one of these frauds requires urgency, because urgency prevents verification. A personal rule — no transfer to a new recipient within an hour of first being asked — converts most of these attacks into failed attacks. For businesses, the equivalent is a callback on a stored number for any change of bank details, no exceptions for seniority, which is the control the Hong Kong case lacked.
Reduce the raw material. Voice cloning needs your voice; face swapping needs your face. Public video of you speaking is the input. This is not a reason to withdraw from the internet, but it is a reason to think about whether a child's school performance needs to be public.
Doubt the direction of authority. These attacks work by invoking someone you would not question: a boss, a bank, a police officer, a parent. The rule that survives is that legitimate authorities do not lose anything if you verify, and fraudulent ones lose everything.
Two things not to rely on
Artefact-spotting. Counting fingers and watching for blink rates. It worked in 2020, it is unreliable now, and it will be worse next year. It also produces false confidence, which is worse than no defence.
Detection tools. They exist, they are useful in forensic contexts with the original file, and they degrade badly on the compressed, re-encoded, screen-recorded media that actually circulates. Do not build a personal defence on a detector's verdict.
The durable defences are procedural. They work whether the fake is crude or perfect, which is the property you want as the fakes improve.
The one thing to keep
AI collapsed the cost of fluency, personalisation and voice cloning, so the defences that survive are procedural rather than perceptual — switch channels, agree a code word, and impose a mandatory delay on any urgent money request.
Before you move on
Why is "hang up and call back on a number you already have" more robust than trying to detect that a voice is cloned?
Pick the one you would defend. Nobody sees your answer.