The AI Scam Techniques I Think Are Getting Harder to Spot

Sep 01, 2026By Jay Kells
Jay Kells

The AI Scam Techniques I Think Are Getting Harder to Spot

I've spent a lot of time telling people what to check for in a scam message, and most of that advice still holds up. But I'd be lying if I said AI hasn't changed the game in the last couple of years. The old tells, the bad grammar, the slightly-off logo, the sender address that doesn't quite match, are quietly disappearing from the scams I see, because the tools scammers now have access to are simply better at faking things convincingly. These are the five specific techniques I think are genuinely getting harder to catch, and what I actually watch for instead of the old checklist.


Deepfake Video Calls That Ask You to "Confirm It's Really Them"


This one still catches me off guard every time I think about it properly. Video call deepfakes used to need serious technical skill and a lot of source footage, and now there are tools that can convincingly mimic a real person's face and voice in something close to real time from a handful of public videos. I've read about cases where someone on a video call, apparently a colleague or a family member, has asked for money or sensitive details, and the call looked and sounded completely normal throughout. My rule now is that a video call asking for money or account access gets verified through a second channel regardless of how convincing it looked, a text to a number I already have saved, not one given to me during the call itself. If someone pushes back on that request, that reaction alone tells me most of what I need to know.


Close-up of advanced humanoid robot's face with metallic features and LED sensors in white studio lighting

AI Chatbots Posing as Customer Support


I've noticed scam sites getting a lot more sophisticated about the "live chat" box that pops up the moment you land on them. It used to be an obvious script with clunky responses, and now some of these bots hold a genuinely natural conversation, answer follow-up questions coherently, and steer you toward entering payment details or personal information without ever feeling like you're talking to something scripted. The tell isn't in how the conversation reads anymore, it's in what the conversation is trying to get you to do. A support chat that pushes hard toward entering card details, remote access software, or a "verification" link outside the platform you started on is worth walking away from, no matter how naturally it's written.


Scam Messages Written With No Grammar Mistakes Left to Spot


For years, bad spelling and clunky phrasing were one of the most reliable signs of a scam email, largely because a lot of them were written by non-native speakers working from templates. AI writing tools have quietly removed that tell almost completely. A phishing email can now read as polished as anything a real company would send, correct grammar, natural tone, even a passable attempt at your bank's usual phrasing. I've stopped using writing quality as a signal at all. What I check instead is where a link actually goes before I click it, whether the message creates unnecessary urgency, and whether I was expecting contact from whoever it claims to be from in the first place. Those three checks work regardless of how well the message is written.


Fake Reviews and Testimonials Generated in Bulk


This one affects online shopping more than anything else I deal with. AI can generate hundreds of plausible-sounding product reviews in minutes, complete with varied writing styles, specific-sounding details, and a spread of star ratings that looks organic at a glance. A shop with nothing but glowing five-star reviews used to be at least mildly reassuring, and now it can be entirely manufactured. I look for reviews that mention specific, checkable details like sizing, delivery timing, or how a fault was resolved, and I'm far more trusting of a site with a realistic mix of ratings, including a few three-stars with reasonable complaints, than one with suspiciously uniform praise.


Hyper-Personalised Phishing Built From Scraped Social Data


The last one is the one I think people underestimate the most. Scammers have always used a bit of personal detail to make a phishing attempt feel credible, but AI tools now make it trivial to scrape someone's public social media activity and generate a message that references real details, a recent holiday, a job change, a family member's name, automatically and at scale. A message that knows something true and specific about you used to be a strong signal it was legitimate. It no longer is. I've become more careful about what I post publicly as a direct result of this, and I treat any message referencing personal detail as needing the same verification as one that doesn't, not less.


None of this means the fight is unwinnable, it just means the checklist has to change. Bad grammar and obviously fake photos were never the real safeguard, they were just an easy shortcut that AI has taken away. What still works is verifying requests through a second channel, checking where links actually lead before clicking, being sceptical of urgency regardless of how well it's written, and not treating personal detail in a message as automatic proof of legitimacy. I use NordVPN to keep my own browsing harder to profile in the first place, since less data scraped about me means less material for this kind of personalised attempt, and my free Safety Toolkit covers the rest of what I'd actually recommend if you want to work through it properly, and Action Fraud has its own guidance on staying ahead of AI-enabled scams if you want a second source alongside mine.