A caller sounds like someone you know. They are frightened, rushed, and asking you to act immediately. You may be tempted to listen harder for an artificial accent or a strange pause. But the more useful question is whether the request can be confirmed independently. You do not have to become an expert deepfake detector to create a better verification process.
What has changed, and what has not
Google's June 2026 fraud and scams advisory discusses evolving scam tactics and the use of AI. It is a provider's account of observed threats, not a census of every fraudulent call. The technology matters, but the familiar mechanisms of urgency, impersonation, and payment pressure still matter too.
The FTC's advice on AI family-emergency scams recommends contacting the supposed caller through a known number. That changes the source of evidence. Instead of asking the suspicious message to prove itself, you ask a channel established before the message arrived.
Separate identity, story, and requested action
A convincing voice does not prove a payment request is authorised. Even a real account or real colleague can be compromised, confused, or relaying somebody else's claim. Check three things separately: who is communicating, whether the story is accurate, and whether the requested action follows the normal process.
This distinction helps with messages as well as calls. A familiar logo, an existing conversation thread, or a plausible invoice is evidence about appearance. It is not enough to justify changing bank details or sharing a verification code. If a request bypasses the procedure that usually protects the action, the bypass itself deserves attention.
Why looking for one giveaway can fail
The signal detection experiment shows the tradeoff between missed threats and false alarms. Moving the threshold changes both. A rule that marks every unfamiliar message as fraudulent catches more suspicious cases but also blocks ordinary communication. A permissive rule makes communication easy but can miss harmful requests.
The point is not to calculate a perfect threshold for your family. It is to match verification to the consequences. A routine scheduling message and an urgent request to transfer money should not need identical evidence. A separate callback may be a modest inconvenience compared with an irreversible action.
A worked example: an urgent change of payment details
Imagine a small business receiving a message that appears to come from a regular supplier. It says the bank account has changed and today's invoice must be paid immediately. This is an invented scenario, not an allegation about a particular supplier. The safest useful response is a process, not an argument with the sender.
- Pause the payment and identify the unusual element: new account details plus pressure to skip the usual check.
- Contact the supplier using the number already stored in your records, rather than a number supplied in the suspicious message.
- Have the normal authorised person confirm the change and record the result. If the request cannot be verified, keep the payment paused and follow the organisation's fraud procedure.
Use base rates without turning them into reassurance
In base rate neglect, change the frequency of the underlying event while holding the signal's accuracy fixed. Notice how the meaning of a positive signal changes. A message being unusual is not the same thing as it being fraudulent; the surrounding context affects how much weight to give the clue.
You usually do not know a reliable numerical fraud rate for a specific incoming call. Do not invent one or assume that a low average risk makes a high-consequence request safe. The practical lesson is to avoid judging the entire situation from a single vivid cue, whether that cue is a familiar voice or a frightening warning.
Make verification easy before an emergency
Keep trusted contact details accessible. Agree that an unusual financial request can be paused without anyone taking offence. In a team, decide who can approve a changed account and how the check is documented. A family can agree to call back through an existing number rather than relying on a voice alone. A shared phrase can be an additional check, but should not be the only one.
Try value of information to compare the cost of a check with how much it can improve a decision. A verification step earns its place when it provides independent evidence that could change the action. Re-reading the same message many times may feel like checking while adding little new information.
- Pause pressure-driven or unusual requests.
- Use contact details established independently of the request.
- Do not share account verification codes with an unsolicited caller.
- Keep normal approval and payment controls in place.
If you already acted, switch from judging to responding
If money or account access may have been exposed, contact the relevant bank or service through its official channel promptly and follow its incident process. Preserve messages and transaction details. Reporting routes depend on your country; the FTC guidance linked here describes the US context. The important habit is to seek practical help quickly rather than spending the first hour debating how convincing the message sounded.
No checklist catches every attack. A verified callback can still encounter a compromised account, and a rushed colleague may make a mistake. Layer checks around actions that are hard to reverse. Good processes also make it easy to admit uncertainty: people should be able to say 'I need to verify this' without being punished for slowing down.
Try the ideas for yourself.
These are teaching models. Follow the assumptions in each experiment; the results are not real-world forecasts.
Sources & further reading
Current-event context was checked on October 7, 2026. Follow the original source for newer updates. Worked scenarios are illustrative unless explicitly identified as reported data.
- Google — June 2026 frauds and scams advisory ↗
June 2026 · First-party account of observed scam tactics.
- FTC — Scammers use AI to enhance family emergency schemes ↗
2023 · Independent callback guidance; US reporting context.