Voice, video, and flawless writing no longer prove identity. These habits still do.
Every identity signal you grew up trusting is now forgeable: the voice on the phone, the face on the video call, the writing style in the email, even the caller ID. Stronger verification starts with contact details you already trust and approval processes that do not depend on any one call, message, or appearance.
This guide is the defensive playbook the other guides point to. None of it requires technology or skill. It requires deciding, before the adrenaline hits, that identity gets verified through channels you control — because every impersonation scam, human or AI, depends on you skipping that step.
The three principles
1
Start from a known channel
End the incoming contact and initiate a new one using a saved number, an official directory, an internal company system, or an in-person route. This is stronger than trusting voice, video, caller ID, or a supplied callback number.
2
Use approval controls for consequential requests
Money, credential, vendor, and sensitive-data changes should require the normal documented process and, where appropriate, a second authorized approver. Apparent identity on one channel never replaces those controls.
3
Treat shared knowledge as supplementary
A code word or personal question can add context, but answers can leak, be researched, or be guessed. Shared knowledge is a secondary signal, not proof and never sole authorization for payment or access.
When to run verification
!
Money is requested through any remote channel
Call, text, email, video — if it asks for money, gift cards, crypto, or a wire, it triggers verification. No exceptions for how real it sounds or how well it knows you.
!
Credentials or codes are requested
Passwords, one-time codes, seed phrases. The answer is no to everyone, and verification if the requester claims to be someone you trust.
!
Urgency plus secrecy appears
"Right now" and "don't tell anyone" — together, that's the signature of every emergency scam ever run, with or without AI.
!
The contact channel is new
A new number, a personal email for business matters, a DM instead of the app. Channel switches are how impersonators avoid the real person's territory.
!
Something is off, even slightly
A word choice, an odd hour, a request out of character. Your unease costs one phone call to resolve. Suppressing it is what every scammer needs you to do.
The playbook
✓
Hang up and initiate a known-channel call-back
Use a number already saved or obtained from an official source, not one supplied by the incoming caller. For organizations, use an official app, directory, or internal system and ask the relevant team to confirm the request.
✓
Keep approval controls in the loop
Families can require an independent call-back before sending money. Companies should retain dual approval for payments and documented verification for vendor, credential, and access changes, regardless of urgency or seniority.
✓
Use code words only as a secondary check
A private family code word can supplement a known-channel call-back, but it is not proof and can be learned, leaked, or guessed. Never let a code word alone authorize money, credentials, or sensitive information.
✓
Treat personal questions as weak signals
A lived-experience question may expose a poor script, but a correct answer can come from public posts, breaches, or another person. Use the response only as supplementary context and still complete known-channel verification.
✓
Switch channels carefully
On a suspicious video call, contact the person through a pre-established company system or known number. A second channel is useful only if you selected it independently and the required approval process still occurs.
✓
Make it policy, personal and corporate
Families: money requests get a call-back, always. Companies: no payment, vendor change, or credential reset on the strength of any single call or message, regardless of apparent seniority. Policy removes the pressure decision the scam depends on.
Frequently asked questions
Isn't all this overkill for a call from my own mother?
You'll verify perhaps twice a year — the rare occasions when 'mom' urgently needs money through an odd channel. That's precisely the scenario voice cloning targets, and real mom will be glad you called her back. The habit is nearly free; the failure mode isn't.
What makes a good family code word?
Something memorable to you, meaningless to outsiders, and absent from social media — a defunct family joke, a childhood object's nickname. Avoid pet names, birthdays, and anything guessable from your public life. Share it in person or on a call you initiated.
How do companies handle this without slowing everything down?
One rule covers it: instructions that move money or credentials require confirmation through a second, pre-established channel. It adds minutes, not days — and it's exactly the rule that would have stopped the $25M deepfake meeting fraud.
Scambook's AI checker analyzes suspicious messages, numbers, and links against a live scam database — including the machine-generated ones. Free, in seconds.