The New Phishing: How AI Imitates Trust and What to Do Next
An unexpected financial message gives you an immediate choice: follow the contact path it supplies, or verify the request through a path you already trust.
A text appears to come from your bank. It uses your name and mentions a transaction you do not recognize. The logo may look right, and the writing may be polished. A later call may even sound familiar. Artificial intelligence can improve each of those surface signals. Your verification path helps you decide what deserves a response.
Why can a false message feel so convincing?
AI helps criminals imitate the language and appearance of a person or institution you recognize. It can support polished emails and cloned voices. It can also produce false documents and realistic videos. The FBI recorded 22,364 AI-related complaints in 2025, with reported losses nearing $893 million. Those figures reflect complaints received, rather than every attempted scam.[1]
Grammar and visual polish can still offer clues, yet they cannot establish who sent the message. CISA specifically cautions that AI-generated phishing emails may now have correct spelling and grammar.[2] Independent consumer guidance reaches the same practical conclusion: AI can make trusted brands and people easier to imitate.[3]
The scam still needs something from you. It may ask you to click a link or reveal a password. Other requests seek a verification code or a transfer. Urgency narrows the time available to compare the story with another source. Secrecy may isolate you from the person who could challenge it.
Where does independent verification change the path?
A convincing message supplies its own route and its own evidence. Verification works by leaving that closed path. The difference is easier to see when the two routes are compared on the same questions.
Question | Inside the message | Outside the message |
|---|---|---|
Who chose the contact path? | The sender supplied the link, number, or reply address. | You open the official app, use a saved bookmark, or call a known number. |
What counts as evidence? | A polished logo, familiar voice, urgent story, or matching personal detail. | The official account, a known person, or an independently located professional record confirms the request. |
Who controls the next action? | The sender sets the pace and keeps the response inside the same story. | You decide whether any response, account change, or transfer is warranted. |
Dovetail Principle: Information Should Show What Changes for You
A phishing message tries to control the route, the evidence, and the timing. A short pause lets you choose the source you will trust and decide what happens next. That preserves your authority even when the imitation is convincing. This same commitment to decision authority is reflected in the Dovetail Principles.
How can you build a verification path before you need it?
Start with the institutions and people whose requests could lead to money movement or account access. Save the official phone numbers for your bank, custodian, and advisor. Use bookmarks you created from sites you located independently. FINRA also recommends checking investment professionals and firms through official registration records because imposters may misuse real names and credentials.[4]
For family requests, call the person at a number you already know. If the person is unavailable, contact someone else who can confirm the story. A family code word can add friction for a scammer, although the separate callback remains the stronger check. Voice cloning can make a caller sound like someone familiar.[5]
Protect email and financial accounts with unique passwords and multifactor authentication. Where available, passkeys or security keys provide phishing-resistant protection. Microsoft describes passkeys as a stronger replacement for methods such as SMS or voice codes.[6] Set alerts for unusual logins and transactions. Enter a verification code only in an official app or website that you opened yourself.
What should you do if you already responded?
The next action depends on what the scammer may have reached. If you entered a password, change it and update any other account that used the same one. Begin with email because it often receives password-reset links for other accounts. Review recent sign-ins and recovery information.
If you shared financial information or sent money, call the institution through a verified number. Ask about securing the account, disputing a charge, or attempting to reverse a fraudulent transfer. The available remedy depends on the payment method and timing. If identifying information was exposed, use IdentityTheft.gov or a qualified identity-recovery resource to build the appropriate recovery steps.[7]
Keep the original message, screenshots, and contact details. Save payment records and a short timeline too. Those records can help the institution or investigator understand what happened. The Identity Theft Resource Center also offers individual recovery guidance for account compromise and identity theft.[8]
What routine should your family keep close?
Agree that any unexpected request involving money, account access, or sensitive information will be verified separately. The rule should apply even when the voice sounds familiar and the story could be true.
AI can imitate the surface of trust. Your verification path supplies something different: a source chosen outside the message. Pause, leave the message, verify the story, and then decide what the situation actually calls for.
Related Reading: Keep, Scan, or Shred? A Simple Path to Paper Control in Retirement. This article explains how secure recordkeeping supports identity protection and makes important information easier to locate.