AI Scam Defense
Scammers now have access to the same AI tools as everyone else, and they're using them to run fraud that would have been science fiction three years ago. Cloned voices that sound exactly like your mother. Deepfake video calls from your "boss." Phishing emails with zero typos and perfect personalization. Fake job interviews conducted entirely by AI. This skill covers the new generation of AI-powered scams — how they work, how to spot them, and what to do if you've already been hit.
``agent-adaptation
# Localization note — AI scam tactics are global. Reporting agencies are jurisdiction-specific.
# Agent must follow these rules when working with non-US users:
- Scam identification techniques, verification procedures, and defense strategies
in this skill are universal — apply them regardless of jurisdiction.
- Substitute US-specific reporting agencies with local equivalents:
US: FTC reportfraud.ftc.gov, FBI IC3 ic3.gov
UK: Action Fraud actionfraud.police.uk
Australia: ACCC Scamwatch scamwatch.gov.au
Canada: Canadian Anti-Fraud Centre antifraudcentre.ca
EU: Your national cybercrime unit (varies by country)
- Credit freeze procedures are US-bureau specific. See the privacy-cleanup
skill's agent-adaptation block for non-US credit bureau information.
- FINRA/SEC references are US-only. For investment scam verification:
UK: FCA register register.fca.org.uk
AU: ASIC moneysmart.gov.au
CA: CSA securities-administrators.ca
- If scam involves banking fraud: always direct to local bank's fraud line
FIRST (before any other step), as rapid reporting can stop transfers.
CODEBLOCK0
AI SCAM CATEGORIES:
A. VOICE CLONING — A call from someone who sounds like a person you know
B. DEEPFAKE VIDEO — A video call where the person isn't who they appear to be
C. AI PHISHING — Highly personalized, perfectly written emails or messages
D. FAKE JOB OFFERS — AI-generated job postings, interviews, or recruiters
E. AI ROMANCE SCAMS — Dating profiles with AI-generated photos and conversation
F. AI INVESTMENT SCAMS — Fake pitches with AI-generated decks, sites, and testimonials
CODEBLOCK1
HOW TO SPOT IT:
-> The call creates extreme urgency ("I need money RIGHT NOW")
-> They ask you not to call anyone else to verify
-> They request unusual payment: wire transfer, gift cards, crypto
-> The story involves arrest, accident, kidnapping, or hospitalization
-> If you ask a personal question they should know, they deflect
VERIFICATION PROTOCOL:
1. Hang up. No matter how real it sounds. Hang up.
2. Call the person directly on their known number.
3. If they don't answer, call another family member who can verify.
4. Establish a family safe word — a code word that proves identity.
Pick something obscure that would never appear in public posts.
5. Never act on urgency alone. Real emergencies can wait 5 minutes
for you to verify.
CODEBLOCK2
HOW TO SPOT IT:
-> Lighting on the face doesn't match the background
-> Slight lag between lip movement and audio
-> Unnatural blinking patterns (too much or too little)
-> The person avoids turning their head to the side
-> Hair edges look blurry or shimmer unnaturally
-> They resist or deflect requests to do something spontaneous
(hold up a specific number of fingers, turn sideways)
VERIFICATION PROTOCOL:
1. Ask them to do something unpredictable:
"Hold up three fingers on your left hand"
"Turn your head to the right and back"
"Hold a piece of paper with today's date written on it"
2. Deepfakes struggle with sudden lateral movement and hand gestures.
3. For any financial request over video, ALWAYS verify through a
separate, established communication channel.
4. Call them on a known phone number to confirm the request.
5. Company policy should require multi-person authorization for
transfers — never rely on one video call.
CODEBLOCK3
HOW TO SPOT IT:
-> Check the sender's ACTUAL email address (not the display name).
Hover over it. Look for subtle misspellings:
support@amaz0n.com, hr@company-careers.net
-> The email creates urgency: "Your account will be closed in 24 hours"
-> It asks you to click a link or download an attachment
-> The link URL doesn't match the real company's domain
-> They reference real details about you (scraped from public profiles)
but get small things wrong
-> The request bypasses normal processes ("Don't go through the usual
channel, just handle this directly")
DEFENSE PROTOCOL:
1. NEVER click links in unexpected emails. Go directly to the website.
2. Check the full email header for the actual sending domain.
3. If it claims to be from a colleague, verify via Slack/Teams/phone.
4. Enable multi-factor authentication on EVERYTHING.
5. Use a password manager — it won't autofill on fake domains.
6. When in doubt, forward the email to the real company's
abuse/phishing address (e.g., phishing@company.com).
CODEBLOCK4
HOW TO SPOT IT:
-> The job was not posted on the company's actual careers page
-> Interview is text-only or on an obscure video platform
-> They "hire" you unusually fast with minimal vetting
-> They ask for SSN, bank details, or payment before your start date
-> The salary is significantly above market rate for the role
-> Communication comes from a free email domain (gmail, outlook)
rather than a corporate one
-> They send you money before you've done any work
VERIFICATION PROTOCOL:
1. Search the company name + "scam" or "fake job"
2. Go to the company's REAL website and find their careers page.
Is the job listed there?
3. Look up the recruiter on LinkedIn. Check their profile age,
connections, and activity history.
4. Call the company's main phone number and ask to speak to
the hiring manager or HR department.
5. NEVER pay anything to get a job. Legitimate employers never
charge for training, equipment, or background checks.
6. NEVER share your SSN until you have a verified, signed offer
from a confirmed real company.
CODEBLOCK5
HOW TO SPOT IT:
-> Their photos look perfect but have no online presence elsewhere
-> Reverse image search returns zero results (real people have
digital footprints; AI-generated faces don't)
-> They can never video call, or calls are brief and low quality
-> The relationship progresses unusually fast emotionally
-> They're always overseas, military, or working on an oil rig
-> After weeks of connection, a financial need emerges
-> They get defensive or guilt-trip you when you ask for verification
VERIFICATION PROTOCOL:
1. Reverse image search their photos (Google Images, TinEye)
2. Look for AI generation artifacts: asymmetric earrings,
blurred backgrounds where hands meet objects, inconsistent
teeth, warped text on clothing
3. Ask for a live video call where they hold up a specific object
4. NEVER send money to someone you haven't met in person
5. Ask a trusted friend to review the conversation objectively --
isolation from outside perspective is the scammer's main tool
CODEBLOCK6
HOW TO SPOT IT:
-> Guaranteed returns (no legitimate investment guarantees returns)
-> The "platform" or "fund" isn't registered with the SEC
-> Celebrity endorsements (almost always fake — verify independently)
-> Initial small investment shows amazing returns (to hook you)
-> Withdrawal requires an additional "fee" or "tax" payment
-> Pressure from a friend or online community (who are also victims
or in on the scam)
-> The pitch deck and website look polished but the company has
no verifiable history
VERIFICATION PROTOCOL:
1. Check SEC EDGAR database: sec.gov/cgi-bin/browse-edgar
2. Search FINRA BrokerCheck: brokercheck.finra.org
3. Search the platform name + "scam" or "review"
4. Verify any celebrity endorsements on the celebrity's official channels
5. If it's crypto: check the token on CoinGecko/CoinMarketCap.
No listing = red flag.
6. NEVER invest money you can't afford to lose based on social
media recommendations or unsolicited messages.
CODEBLOCK7
IMMEDIATE ACTIONS (do these NOW):
1. STOP ALL CONTACT with the scammer. Block them everywhere.
2. SECURE YOUR ACCOUNTS:
-> Change passwords on all financial accounts
-> Enable multi-factor authentication everywhere
-> If you shared login credentials, change them on every site
where you used that password
3. CONTACT YOUR FINANCIAL INSTITUTIONS:
-> Credit card: Call issuer, dispute charges, request new card
-> Bank transfer/wire: Call bank immediately — wires can sometimes
be recalled within 24 hours
-> Crypto: Likely unrecoverable, but report to the platform
-> Payment apps (Zelle, Venmo, CashApp): Report unauthorized
transaction through the app AND your bank
-> Gift cards: Call the gift card company with the receipt
4. FREEZE YOUR CREDIT (free, do all three):
-> Equifax: 1-800-525-6285 or equifax.com/personal/credit-report-services
-> Experian: 1-888-397-3742 or experian.com/freeze
-> TransUnion: 1-800-680-7289 or transunion.com/credit-freeze
5. DOCUMENT EVERYTHING:
-> Screenshot all messages, emails, call logs, transaction records
-> Save the scammer's profile, phone number, email, website URLs
-> Write a timeline while your memory is fresh
CODEBLOCK8
REPORTING CHECKLIST:
1. FTC (Federal Trade Commission):
-> Go to reportfraud.ftc.gov
-> Select the category that matches your scam
-> Provide all details: dates, amounts, contact info, method
-> You will receive a reference number — save it
2. FBI Internet Crime Complaint Center (IC3):
-> Go to ic3.gov
-> File a complaint (especially for scams involving internet,
email, social media, or cryptocurrency)
3. Identity Theft (if personal info was compromised):
-> Go to identitytheft.gov
-> Follow the step-by-step recovery plan
-> This generates an Identity Theft Report (an official document
that gives you specific legal rights)
4. State Attorney General:
-> Search "[your state] attorney general consumer complaint"
-> File online
5. Local Police:
-> File a report and get a report number
-> You may need this for insurance claims or bank disputes
6. Platform-Specific Reporting:
-> Report the scam profile/listing on the platform where it occurred
-> LinkedIn, job boards, dating apps, social media all have
fraud reporting tools
CODEBLOCK9
IDENTITY THEFT RECOVERY STEPS:
1. File an Identity Theft Report at identitytheft.gov
-> This creates your official FTC Identity Theft Report
-> This gives you legal rights: extended fraud alerts,
blocking fraudulent debts, preventing debt collection
2. Place an Extended Fraud Alert (7 years):
-> Call any one credit bureau (they notify the others)
-> Requires the Identity Theft Report from step 1
3. Review your credit reports:
-> Free at annualcreditreport.com
-> Check all three bureaus for accounts you don't recognize
4. Close any fraudulent accounts:
-> Call each company where fraud occurred
-> Send them your Identity Theft Report
-> They must close the account and stop collecting the debt
5. Monitor ongoing:
-> Sign up for free credit monitoring
-> Check your credit reports every 4 months (rotate bureaus)
-> Watch for tax fraud: file your taxes early each year
-> Watch for medical identity theft: review Explanation of
Benefits statements from your health insurance
6. Consider an IRS Identity Protection PIN:
-> irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin
-> Prevents someone from filing a tax return using your SSN
CODEBLOCK10 yaml
defense:
scam_encountered:
type: null
date_discovered: null
date_occurred: null
amount_lost: null
payment_method: null
personal_info_exposed: []
scammer_contact_info: []
evidence_saved: false
recovery_actions:
accounts_secured: false
credit_frozen: false
ftc_reported: false
ftc_reference_number: null
ic3_reported: false
identity_theft_report_filed: false
police_report_filed: false
police_report_number: null
platform_reported: false
financial_institutions_contacted: []
fraudulent_accounts_closed: []
prevention:
family_safe_word_set: false
mfa_enabled: false
password_manager_in_use: false
credit_monitoring_active: false
irs_pin_set: false
follow_up:
credit_review_dates: []
next_check_in: null
CODEBLOCK11 yaml
triggers:
- name: immediate_financial_response
condition: "scam_encountered.amount_lost > 0 AND recovery_actions.financial_institutions_contacted IS EMPTY"
action: "You reported a financial loss but haven't contacted your financial institutions yet. This is time-sensitive — calling your bank or card issuer now gives you the best chance of recovering funds. Let's do that first."
- name: credit_freeze_reminder
condition: "scam_encountered.personal_info_exposed IS NOT EMPTY AND recovery_actions.credit_frozen IS false"
action: "You shared personal information with the scammer. Your credit should be frozen at all three bureaus to prevent identity theft. This is free and takes about 10 minutes. Ready to walk through it?"
- name: reporting_follow_up
condition: "scam_encountered.date_discovered IS SET AND recovery_actions.ftc_reported IS false AND days_since(scam_encountered.date_discovered) >= 1"
action: "It's been a day since you discovered the scam. Filing your FTC report helps law enforcement track these operations and may help others avoid the same scam. Let's file at reportfraud.ftc.gov."
- name: identity_recovery_check
condition: "recovery_actions.identity_theft_report_filed IS true"
schedule: "monthly for 12 months"
action: "Monthly identity theft recovery check-in: Have you reviewed your credit reports? Any unfamiliar accounts or inquiries? Any unexpected Explanation of Benefits from your health insurance? Any IRS notices?"
- name: prevention_setup
condition: "recovery_actions.credit_frozen IS true AND prevention.family_safe_word_set IS false"
action: "Now that the immediate crisis is handled, let's set up prevention. A family safe word is the single best defense against voice cloning scams. Have you picked one and shared it with your family?"
``
AI 诈骗防御
如今,诈骗者也能像其他人一样使用相同的AI工具,并且他们正利用这些工具实施三年前还属于科幻小说的欺诈行为。克隆出的声音听起来和你母亲一模一样。来自你老板的深度伪造视频通话。没有拼写错误且个性化程度完美的钓鱼邮件。完全由AI进行的虚假求职面试。本技能涵盖新一代AI驱动的诈骗——它们如何运作、如何识别,以及如果你已经中招该怎么办。
agent-adaptation
本地化说明 — AI诈骗手段是全球性的。举报机构因司法管辖区而异。
代理在处理非美国用户时必须遵循以下规则:
具有普遍性——无论司法管辖区均可应用。
美国:FTC reportfraud.ftc.gov,FBI IC3 ic3.gov
英国:Action Fraud actionfraud.police.uk
澳大利亚:ACCC Scamwatch scamwatch.gov.au
加拿大:加拿大反欺诈中心 antifraudcentre.ca
欧盟:您所在国家的网络犯罪部门(因国家而异)
- - 信用冻结程序是美国信用局特有的。非美国信用局信息请参见
privacy-cleanup技能的agent-adaptation部分。
- - FINRA/SEC引用仅适用于美国。对于投资诈骗验证:
英国:FCA register register.fca.org.uk
澳大利亚:ASIC moneysmart.gov.au
加拿大:CSA securities-administrators.ca
- - 如果诈骗涉及银行欺诈:始终首先引导用户联系当地银行的
欺诈热线(在任何其他步骤之前),因为快速报告可以阻止转账。
来源与验证
何时使用
- - 用户接到一个听起来完全像家人的人打来的电话,要求汇款
- 收到一封写得过于完美、定位精准,不像是垃圾邮件的电子邮件
- 进行了一次视频通话,感觉对方有些不对劲
- 申请了一份工作,面试过程看起来奇怪或过于自动化
- 在网上匹配到一个人,其照片看起来过于完美
- 收到一个投资推介,附带制作精良的AI生成材料
- 想了解当前AI欺诈的现状
操作说明
安全检查 — 如果钱已经汇出,请立即行动
停下。 在对诈骗进行分类之前,代理必须询问:
您是否已经汇款、分享了财务信息,或让任何人访问了您的账户?
- - 如果是:直接跳转到步骤3(立即恢复行动)。 时间对于追回资金至关重要。分类可以稍后再说。
- 如果否,但个人信息已泄露:分类后跳转到步骤5(身份盗窃恢复)。
- 如果两者都否:继续执行步骤1。
代理行动:将损害控制置于教育之上。如果资金已汇出,每一分钟都很重要。
步骤1:识别诈骗类型
询问用户发生了什么。将其归类为以下六大AI诈骗类别之一,然后跳转到该部分。
AI诈骗类别:
A. 语音克隆 — 接到一个听起来像你认识的人的电话
B. 深度伪造视频 — 视频通话中的人并非其表面身份
C. AI钓鱼 — 高度个性化、书写完美的电子邮件或消息
D. 虚假工作机会 — AI生成的招聘信息、面试或招聘人员
E. AI爱情诈骗 — 使用AI生成照片和对话的交友资料
F. AI投资诈骗 — 使用AI生成的演示文稿、网站和推荐信的虚假推介
步骤2:了解每种诈骗的运作方式及识别方法
A. 语音克隆诈骗
运作方式: 诈骗者从社交媒体、语音信箱或公开视频中抓取某人几秒钟的声音。AI工具可以令人信服地克隆该声音。他们打电话给家人——通常是父母或祖父母——假装处于紧急情况。妈,我进监狱了,需要保释金。爸,我出车祸了,请马上汇款。
识别方法:
-> 电话制造极度紧迫感(我现在就需要钱)
-> 他们要求你不要打电话给任何人核实
-> 他们要求非常规付款方式:电汇、礼品卡、加密货币
-> 故事涉及逮捕、事故、绑架或住院
-> 如果你问一个他们应该知道的私人问题,他们会回避
验证协议:
- 1. 挂断电话。无论听起来多么真实。挂断。
- 直接拨打你已知的对方号码。
- 如果对方不接,打电话给其他可以核实的家人。
- 建立一个家庭安全词——一个能证明身份的暗号。
选择一个永远不会出现在公开帖子中的晦涩词语。
- 5. 切勿仅凭紧迫感行事。真正的紧急情况可以等你花5分钟
核实。
B. 深度伪造视频通话诈骗
运作方式: 实时深度伪造软件可以让一个人在视频通话中看起来和听起来像另一个人。这已被用于冒充授权电汇的CEO、虚假的商业伙伴,甚至伪造绑架证据。2024年,一名财务人员在与其假CFO进行深度伪造视频通话后,转账了2500万美元。
识别方法:
-> 面部光线与背景不匹配
-> 嘴唇动作和音频之间存在轻微延迟
-> 不自然的眨眼模式(过多或过少)
-> 此人避免将头转向侧面
-> 头发边缘看起来模糊或异常闪烁
-> 他们拒绝或回避执行自发动作的要求
(举起特定数量的手指、转向侧面)
验证协议:
- 1. 要求他们做一些不可预测的事情:
举起你左手的三根手指
把头转向右边再转回来
拿一张写着今天日期的纸
- 2. 深度伪造难以处理突然的横向移动和手势。
- 对于任何通过视频提出的财务请求,始终通过
独立的、已建立的沟通渠道进行验证。
- 4. 拨打已知的电话号码确认请求。
- 公司政策应要求多人授权才能进行
转账——切勿仅依赖一次视频通话。
C. AI钓鱼邮件
运作方式: AI生成个性化、语法完美且上下文准确的钓鱼邮件。他们抓取你的LinkedIn、社交媒体和公开数据,以编写引用你真实工作、同事和近期活动的消息。不再有带有明显拼写错误的尊敬的客户。
识别方法:
-> 检查发件人的实际电子邮件地址(而非显示名称)。
悬停在上面。寻找细微的拼写错误:
support@amaz0n.com, hr@company-careers.net
-> 邮件制造紧迫感:您的账户将在24小时内关闭
-> 它要求你点击链接或下载附件
-> 链接URL与真实公司的域名不匹配
-> 他们引用了关于你的真实细节(从公开资料中抓取)
但会在小细节上出错
-> 请求绕过了正常流程(不要通过常规渠道,
直接处理这个)
防御协议:
- 1. 切勿点击意外邮件中的链接。直接访问网站。
- 检查完整的邮件头,查看实际发送域名。
- 如果声称来自同事,通过Slack/Teams/电话核实。
- 在所有地方启用多因素认证。
- 使用密码管理器——它不会在虚假域名上自动填充。
- 如有疑问,将邮件转发给真实公司的
滥用/钓鱼地址(例如,phishing@company.com)。
D. 带有AI面试的虚假工作机会
运作方式: 诈骗者在真实招聘网站上创建令人信服的招聘信息。公司拥有专业的网站(AI生成)。招聘人员在LinkedIn上联系。面试通过聊天或单向视频平台进行——有时由AI面试官进行。诈骗以以下方式结束:(a) 收集你的个人数据(用于设置直接存款的SSN、银行详细信息),(b) 给你一张假支票用于购买设备,或(c) 向你收取培训或背景调查费用。
识别方法:
-> 该职位未发布在公司实际的招聘页面上
-> 面试仅限文本或在一个不知名的视频平台上进行
-> 他们异常快速地录用你,几乎不做筛选
-> 他们在你入职前就要求提供SSN、银行详细信息或