Updated July 24, 2026 · Phishy team
Scammers can now clone a voice from a few seconds of audio and fake a live video call. A panicked call in your daughter's voice, a video message from a CEO, a celebrity promising to double your crypto — all generated by AI. The technology is new, but the con is old: create panic or greed so you act before you think. Here is how deepfake scams actually work, the tells that still give them away, and the one habit that defeats almost all of them.
1. The family emergency: a call in your child's or grandchild's voice, crying, saying they had an accident or were arrested and need money now. The voice is cloned from a video they posted online. 2. The CEO / colleague transfer: a video call or voice note from your boss asking you to urgently pay an invoice or buy gift cards. Common against employees in finance roles. 3. The celebrity investment: a polished video of a famous person or a well-known bank endorsing a crypto or trading platform that promises guaranteed returns.
A real voice or face switches off your suspicion instantly — that is the whole point. The scammer pairs it with urgency (act in the next five minutes) and secrecy (don't tell anyone). When you recognise the voice, your brain stops checking. The defence is not to detect the fake perfectly; it is to refuse to act on any voice or video alone.
• Urgency plus secrecy: money is needed now and you are told not to call anyone else. • The request is always money, gift cards, crypto or a code — never something harmless. • Odd video artefacts: blurring around the face or hairline, mismatched lip-sync, unnatural blinking, flat lighting. • Voice that is slightly robotic, oddly paced, or never quite answers a personal question. • A new or unknown number, or a request to move the chat to WhatsApp or Telegram.
Never act on a voice or video alone. Hang up and call the person back on their real, saved number. Agree a family safe-word for real emergencies. At work, verify any urgent payment on a second, known channel before sending a cent. A ten-second callback undoes a perfect fake, because the real person picks up — puzzled — and the illusion collapses.
Deepfakes rarely travel alone: there is usually a link to a fake investment site, a payment page, or a message setting up the call. Paste that text or link into the free Phishy checker on this page — it follows the link to its real destination and reads the message with AI, and tells you in seconds whether it is safe, suspicious or a scam. No signup. With Family Mode you can also get an alert if a dangerous message reaches an elderly parent, without reading their private chats.
Yes. A few seconds of audio from a social-media video is enough to clone a voice convincingly. That is why you should never send money based on a voice alone — always call back on their real number.
Look for blurring around the face, poor lip-sync, unnatural blinking and flat lighting, and notice the classic combo of urgency plus secrecy. When unsure, end the call and verify on a known channel.
Stay calm, hang up, and call the person back on their saved number. Use a pre-agreed family safe-word. Do not send money, gift cards or crypto based on the call alone.
Phishy checks the messages and links that come with the scam — the fake investment site, payment page or setup text — and flags them in seconds, free, so you catch the con around the deepfake.