← Alle Playbooks
Playbook· security

Protecting yourself from AI fraud — fake calls, phishing and bogus job offers

Voice cloning, deceptively real phishing emails and fake recruiters. How to spot the new AI scams and protect yourself in ten concrete steps. No tech degree required.

The same technology that helps you write and research also helps scammers. A cloned voice takes just a few seconds of audio today, a convincing phishing email is written flawlessly by a model in seconds, and a fake job offer looks just like the real one. The old warning signs, clunky German, an odd salutation, broken logos, no longer work. But that doesn't mean you're powerless. It just means you have to watch for different things than before. That's exactly what we go through here in ten steps.

This isn't fearmongering and isn't legal advice, it's practical orientation. The forms of fraud change fast, the basic principles of protection stay surprisingly stable. If you understand those, you're also armed against the next scam.

Step 1, understand why the old warning signs are no longer enough

The rule of thumb used to be simple. Bad German, strange senders, an impersonal salutation, hands off. That rule is dead. AI writes clean German, often knows your name from leaked data and imitates the tone of real companies. What remains isn't the language, but the intent behind it. Almost every scam wants one of two things: for you to act fast, or for you to hand over something confidential. From now on you watch for this pattern, not for spelling mistakes.

Step 2, treat time pressure as an alarm signal

Fraud thrives on haste. "Your account will be blocked in two hours." "Transfer the money now, or the deal falls through." "The job offer is only valid today." The moment someone pushes you to act fast and without thinking, that in itself is suspicious, no matter how professional the message looks. Real banks, authorities and reputable employers give you time. Make yourself a simple rule: the greater the pressure, the slower you get. Taking a breath and checking costs you almost nothing and stops most scams.

Step 3, expose the cloned call

The most insidious new scam is the call with a familiar voice. A caller sounds like your child, your boss or a colleague and urgently asks for money or data. The voice can be cloned from a few seconds of public audio, for example from a video on social media. Your protection is simple and works: hang up and call back on the number you know and have saved. Not on the number that was shown on the display, that can be faked. Agree on a code word with your family and your closest team for real emergencies. Whoever doesn't know the code word doesn't get through, no matter how real the voice sounds.

Step 4, recognize phishing emails by the destination, not the text

Since the text no longer has any mistakes, you check elsewhere. Hover the mouse over links without clicking, and see where they really lead. If there's a crude address instead of your bank's real domain, it's fraud. Don't even open attachments from senders you don't know for sure. And very importantly, never click the link in the email to log in. Instead, go to the site yourself via your browser or the official app. If there really is something with your account, you'll see it there too. If not, the email was fake.

Step 5, see through fake job offers

Anyone job hunting is a popular target. The scam: a supposed recruiter gets in touch with a well-paid work-from-home job, often via messenger instead of the official platform. Early in the process one of the red flags then comes up. You're supposed to pay in advance for equipment or a training course. You're supposed to forward parcels or move money for the company, that's money laundering, never do it. Or you're supposed to send ID and bank details very early, before there was even a real conversation. A reputable company doesn't ask applicants for money and doesn't push for messenger chats with unknown numbers. Check the company independently, call the official number from the real website and ask for the person.

Step 6, put deepfake videos and fake celebrities in perspective

Videos in which well-known people suddenly promote an investment or a miracle cure are almost always faked. The picture and sound quality is good by now, that alone no longer proves anything. Ask yourself instead: would this person really promote this on this channel. Does the link lead to an official source or to a quickly thrown-together landing page with a countdown and a signup form. For everything that promises money and crypto, the rule is, the bigger the return, the surer the fraud. The German fact-checking site mimikama continuously collects current scams, a look there is worth it if something seems suspicious to you.

Step 7, fake shops and offers that are too good

AI makes it easy to build entire online shops with product images and reviews in minutes. If a brand product is eighty percent cheaper somewhere than everywhere else, the shop is most likely fake. Before you order, search the shop name together with the word reviews. Check whether there's a real legal notice with an address. And if possible pay with a method that offers you buyer protection, not by instant transfer or gift card. Cards and vouchers are the scammers' preferred means, because the money is then gone.

Step 8, secure your accounts technically

The best protection against stolen credentials is two-factor authentication. Even if your password falls into the wrong hands, nobody gets in without the second factor. Turn it on everywhere you can, especially for email, banking and the big platforms. Use a separate password for each service, a password manager takes the remembering off your hands. It sounds like effort, but it's set up once and protects you against the most common form of attack there is, reusing cracked passwords.

Step 9, hand scammers less material

Voice cloning needs your voice, personalized phishing needs your data. Scammers get both from what you share publicly. You don't have to disappear, but it helps to be sparing. Think twice before you post long voice messages or videos publicly. Keep details like date of birth, full address and holiday plans out of open profiles. The less the machine has to feed on about you, the more generic and easily recognizable the attacks against you stay.

Step 10, have a calm emergency plan

If something does happen, a clear head helps more than self-reproach. If you've given away credentials, change the password immediately and activate two-factor authentication. On money matters, call your bank right away, some transfers can still be stopped. Secure evidence, meaning screenshots and messages, and file a report with the police. Also tell the people around you, because the same scam often hits several people in your circle. Talking about fraud is nothing to be embarrassed about, it protects the others.

What's next

Anyone who understands how AI really works falls for its misuse less often. The lesson When the AI hallucinates shows you why AI produces nonsense so convincingly, scammers use the same principle. And how to bring AI into your everyday life safely and sensibly yourself is in AI in everyday life. For the legal side of AI and data, take a look at the playbook DACH Legal, the EU AI Act and GDPR.

Sources

  • Overview of current AI scam methods (deepfake, voice cloning, fake shops), mimikama: https://www.mimikama.org/ki-betrug-maschen-uebersicht/
  • Verbraucherzentrale (German consumer advice centre) on phishing and online fraud: https://www.verbraucherzentrale.de
  • Federal Office for Information Security (BSI), basic protection for citizens: https://www.bsi.bund.de
Protecting yourself from AI fraud — fake calls, phishing and bogus job offers — StudioMeyer Academy