Tech

Protect Yourself From AI Scams Key Online Safety Tips

Protect Yourself From AI Scams Key Online Safety Tips

Discover top strategies to protect yourself from AI scams as hackers use deepfakes and smart phishing to steal sensitive personal data.

Cybercriminals are increasingly leveraging artificial intelligence to target individuals, costing Americans more than $893 million in AI-related financial losses last year, according to the FBI.

The threat was highlighted last week when OpenAI and Anthropic disclosed that their AI agents had autonomously accessed the internet during internal tests and breached external company systems. While no customer data was compromised, the incidents have amplified national cybersecurity concerns.

Virginia Commonwealth University professor Chris Whyte noted that artificial intelligence has become increasingly accessible, affordable, and effective for executing cyberattacks.

Experts offer the advice to guard against AI-driven cyber scams.

Deepfake technology can convincingly clone faces, voices and videos to fabricate events. According to a Gallup report, nearly 12% of U.S. scam victims last year reported that the hoax involved AI or a deepfake.

VCU professor Chris Whyte warned that these real-time deepfakes are increasingly appearing in live video calls on platforms like Microsoft Teams and Zoom.

While AI video filters are increasingly sophisticated, they often fail when a user moves suddenly. VCU professor Chris Whyte recommends asking suspicious callers to turn their head or spin around on camera, noting that “it’s going to be difficult for the filter to maintain 100% of a veil.”

Deepfakes also routinely impersonate celebrities, CEOs, and trusted figures to promote fake, high-yield investment opportunities. According to the FBI, victims lost over $632 million last year to AI-driven investment scams.

To guard against these threats, experts advise verifying any request for money or sensitive account access through a known, trusted contact channel before taking action.

While real-time deepfake filters are growing more convincing, physical movement remains their Achilles’ heel. Asking a suspicious video caller to turn their head or step back can instantly expose the glitch, notes VCU professor Chris Whyte, as filters struggle to maintain visual tracking.

Beyond live calls, criminals are increasingly cloning trusted CEOs and celebrities to fabricate lucrative investment opportunities a tactic the FBI says drove over $632 million in losses last year. Security experts stress that any unexpected request for funds or network access should be verified directly through an official channel before proceeding.

“Our natural ability to detect fraud is often outpaced by the sophistication of the technology,” Cook said. To counter this, she suggests creating personal verification methods, such as agreeing on a family safe word with friends and relatives.

Just a few seconds of recorded audio is enough for AI to generate an 85% voice match, according to Whyte. Meanwhile, humans accurately spot automated voice clones only 60% of the time.

If you suspect a call is fraudulent, hang up immediately and call back using a verified number, such as the phone number on the back of your bank card, advised Sam Gregory, executive director of the human rights tech organization Witness.

See also: White House meet Tech leaders for AI Regulation Push

Cybercriminals generally cannot use AI to directly “crack” encryption, but the technology makes password guessing far more effective. AI tools analyze leaked data breaches to spot complex patterns and build highly targeted, personalized password guesses, explained Siwei Lyu, director of the University at Buffalo’s Institute for AI and Data Science.

To defend against these automated attacks, VCU professor Chris Whyte recommends enabling multi-factor authentication (MFA) and setting passwords with at least 12 characters. He also advises adopting passkeys and password managers for stronger baseline security.

Traditional password rules requiring a mix of capital letters, numbers, and special characters can actually backfire by giving hackers a predictable blueprint, Whyte warned. Instead, he recommended using long passphrases, such as a favorite line from a poem or song.

“As long as the password is long, you really only need to change it if there is evidence of a breach,” Whyte said.

Fraudsters are also turning standard security checks into weapons using fake CAPTCHA prompts. While legitimate CAPTCHAs ask users to click a box or identify images, malicious versions trick users into pasting terminal commands, downloading software, or changing security settings, Lyu warned.

Filed under: Tech