Every identity signal you grew up trusting is now forgeable: the voice on the phone, the face on the video call, the writing style in the email, even the caller ID. What can't be forged is control of channels and knowledge of shared life — and that's exactly what modern verification is built on.
This guide is the defensive playbook the other guides point to. None of it requires technology or skill. It requires deciding, before the adrenaline hits, that identity gets verified through channels you control — because every impersonation scam, human or AI, depends on you skipping that step.
The three principles
1
Channels beat signals
A scammer can fake what you hear and see on their call. They cannot answer the real person's phone. Contact initiated by you, through an address or number you already had, is the strongest identity proof that exists.
2
Shared knowledge beats biometrics
A code word, an inside joke, what you actually did together last Tuesday — AI trained on public data can't answer what was never public. One good question breaks a script.
3
Time beats urgency
Every impersonation scam manufactures a countdown, because verification takes only minutes and destroys them. Any request that can't survive a ten-minute delay has told you what it is.
When to run verification
!Money is requested through any remote channel
Call, text, email, video — if it asks for money, gift cards, crypto, or a wire, it triggers verification. No exceptions for how real it sounds or how well it knows you.
!Credentials or codes are requested
Passwords, one-time codes, seed phrases. The answer is no to everyone, and verification if the requester claims to be someone you trust.
!Urgency plus secrecy appears
"Right now" and "don't tell anyone" — together, that's the signature of every emergency scam ever run, with or without AI.
!The contact channel is new
A new number, a personal email for business matters, a DM instead of the app. Channel switches are how impersonators avoid the real person's territory.
!Something is off, even slightly
A word choice, an odd hour, a request out of character. Your unease costs one phone call to resolve. Suppressing it is what every scammer needs you to do.
The playbook
✓Hang up, call back on the number you already have
The master move. It works against voice clones, spoofed caller ID, fake fraud departments, and panicked-relative scripts alike. Practice saying: "I'll call you right back on your number."
✓Set code words now, before you need them
One for family emergencies, one for any business that moves money on verbal instructions. Two minutes to set up; beats every deepfake ever made. Never use it except to verify — and if it's ever guessed at, that's a red flag itself.
✓Ask a question only the real person can answer
Not public facts (AI has those) — lived ones. "What did we eat when you visited?" A stalling, deflecting, or 'why are you testing me, hurry' response is your answer.
✓Switch channels to verify
On a suspicious video call? Text their known number: "Are you on this call?" Suspicious email from the boss? Walk over, or message them on the internal system. The scammer controls one channel; they almost never control two.
✓Make it policy, personal and corporate
Families: money requests get a call-back, always. Companies: no payment, vendor change, or credential reset on the strength of any single call or message, regardless of apparent seniority. Policy removes the pressure decision the scam depends on.
Frequently asked questions
Isn't all this overkill for a call from my own mother?
You'll verify perhaps twice a year — the rare occasions when 'mom' urgently needs money through an odd channel. That's precisely the scenario voice cloning targets, and real mom will be glad you called her back. The habit is nearly free; the failure mode isn't.
What makes a good family code word?
Something memorable to you, meaningless to outsiders, and absent from social media — a defunct family joke, a childhood object's nickname. Avoid pet names, birthdays, and anything guessable from your public life. Share it in person or on a call you initiated.
How do companies handle this without slowing everything down?
One rule covers it: instructions that move money or credentials require confirmation through a second, pre-established channel. It adds minutes, not days — and it's exactly the rule that would have stopped the $25M deepfake meeting fraud.
Fight AI with AI.
Scambook's AI checker analyzes suspicious messages, numbers, and links against a live scam database — including the machine-generated ones. Free, in seconds.