The complete guide to spotting AI-generated scams in 2026
Kate Hernandez
September 15, 2026•5 min read

Scams used to look like scams. Strange grammar. A slightly-off website. A "bank" that wrote in a way your bank never would.
That advice hasn't disappeared, but you can't count on it anymore.
Generative AI can write a polished email in seconds, clone a voice, and build a convincing fake website. The result is a shift in how we need to think about scams in 2026: instead of asking "does this look fake," start asking "what is this person asking me to do?" That question matters more than any spelling check ever did.
How did we get here: AI enters the scam toolkit
AI didn't invent phishing or fake shopping sites. It just made them easier to fake convincingly.
The old mass-phishing email was generic, typo-ridden, and easy to spot. Now imagine that same scam written specifically for you, using your name, in professional language, referencing a detail pulled from your social media. That's AI-generated phishing, and it's doing what legitimate marketing does: personalizing at scale, just with bad intent.
The FBI's 2025 Internet Crime Report tracked AI as its own category for the first time, logging 22,364 complaints and nearly $893 million in losses tied to fake profiles, voice clones, and fabricated videos. That number is probably a floor, since AI-tagging on complaints is voluntary.
The scammer doesn't need to convince you something impossible is real. They just need an ordinary situation to look believable long enough for you to act.
The behavioral red flags that still work
AI can change how a scam looks or sounds, but scammers still need you to do something: send money, share a password, click a link, give up a code.
Manufactured urgency. "Pay today or face arrest." "Your account closes in 30 minutes." The FTC warns urgency and fear are used deliberately, to keep you from checking the story. Stop. A real problem will still be there after you verify it.
Requests for secrecy. "Don't tell your parents." "Don't call the bank." Secrecy exists because someone else might recognize the scam. AI voice cloning makes this worse, since the voice asking for silence may sound genuinely familiar. Tell someone anyway.
Payment that's hard to trace. Gift cards, crypto, wire transfers. The FTC is clear: legitimate businesses never demand gift cards.
Requests for remote access or codes. "Let me connect to your computer and fix that." "Tell me the code we just sent to your phone." No legitimate company verifies your identity this way. Giving someone remote access or a one-time code hands them the keys to your accounts.
Contact through an unexpected channel. Your boss texts from a new number. Your bank messages you on WhatsApp. Could be real, but it's a reason to verify. Don't use the contact info given to you; use an authorized number or app you already trust.
What this looks like in real life
AI-written phishing: polished, error-free messages from your credit card company claiming, "unusual activity" and a countdown to act. Don't grade the writing. Check whether it's unexpected, urgent, and pushing you toward a link.
Deepfake voice calls: your "child" or "boss" calling, upset, needing money fast, asking you to keep quiet. Hang up and call the person back on a number you already have. Some families agree on a safe word in advance, which sounds strange until it saves you money.
Fake retail sites: You click an ad for a designer bag at 70% off, land on a website of a store you've never heard of but looks real and even has fake reviews. Check the URL, search elsewhere for reviews, and verify the business exists before you pay.
Fake job offers: a recruiter from a generic firm reaches out, offers you a too good to be true job, then a request for banking details or a check to "buy equipment" before you've started. Verify through the company's own site, not the recruiter's link.
The 30-second gut check
Before responding to an unexpected request, ask:
- Stop: Is someone pushing me to act immediately?
- Check: Did this arrive through a new number, email, or platform?
- Question: Am I being told to keep this secret?
- Protect: Are they asking for money, gift cards, crypto, passwords, or device access?
- Verify: Can I confirm this through a channel I already trust?
- Act: Only proceed once you've verified independently.
How Webroot Total Protection can help
Skepticism is the first layer of defense, but you shouldn't have to rely on instinct alone.
Webroot Total Protection adds antivirus defense, phishing protection, dark web and identity monitoring, a secure VPN, and password management, depending on your plan. AI makes scams more convincing, but the underlying risks haven't changed: a bad link is still a bad link, a fake site still wants your login.
Technology can catch a lot of that. The rest is a habit: stop what you're doing, leave the website or call, verify using a trusted number or app, then decide.
Additional resources

Kate Hernandez
Kate Hernandez is a senior marketing manager for OpenText Cybersecurity.