AI Scam Defense: training for the scams AI made easier
4 short lessons, about 23 minutes: Deepfake CEO voice and video calls, Fake invoices and business email compromise, QR code phishing, AI-written phishing. Then a 12-question quiz and a certificate you can print. Free, and it all runs in your browser.
Training a whole team? The AI Literacy Training Pack ($149 for up to 50 staff) has a presentable deck, a quiz with answer key, certificates and a completion log.
- Deepfake CEO voice and video calls (6 min)
- Fake invoices and business email compromise (7 min)
- QR code phishing (5 min)
- AI-written phishing (5 min)
1. Deepfake CEO voice and video calls (6 min)
A call, voice note or video meeting that sounds and looks like your CEO, finance director or a supplier, asking for an urgent payment, gift cards or sensitive data.
The FBI warns that criminals use AI-generated audio to impersonate people victims know, and AI-generated video for real-time video chats with supposed company executives, law enforcement or other authority figures. Source: FBI Internet Crime Complaint Center (IC3): Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (Alert I-120324-PSA) (3 December 2024).
How it works
- Criminals clone a voice from short clips: a conference talk, a podcast, a social media video or a voicemail greeting.
- They call or leave a voice note, often from a new number, sometimes after an email that sets up the story (a deal, an acquisition, an overdue supplier).
- Some join a video call with a face that moves and talks like the executive, with the camera 'breaking up' to hide flaws.
Warning signs
- An unexpected request for a payment, a change of bank details, gift cards or confidential data.
- Pressure and secrecy: 'I need this done in the next hour', 'don't mention this to anyone yet'.
- A new or withheld number, a personal messaging app, or a reason why the person can't be called back.
- The request skips your normal approval steps. Don't rely on hearing a glitch: good clones sound right.
What to do
- Hang up and call back on a number you already have for that person, never one given in the call or message.
- Agree a verification phrase or a callback rule for payment requests before you need it.
- Require a second approver for new payees, bank-detail changes and any payment over a set amount, with no exceptions for seniority.
- Report the attempt to your security contact, even if you didn't pay: someone else in the company may be next.
Sources
- FBI Internet Crime Complaint Center (IC3): Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (Alert I-120324-PSA) (3 December 2024)
- CISA, with the NSA and FBI: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats (Contextualizing Deepfake Threats to Organizations) (12 September 2023)
Sources checked 30 September 2026.
2. Fake invoices and business email compromise (7 min)
An email from a real supplier, a lookalike of their domain, or a hacked colleague's mailbox, saying the bank details have changed or an invoice is overdue.
The FBI's IC3 counted 305,033 business email compromise incidents worldwide and $55,499,915,582 in exposed dollar losses between October 2013 and December 2023. Source: FBI Internet Crime Complaint Center (IC3): Business Email Compromise: The $55 Billion Scam (Alert I-091124-PSA) (11 September 2024).
How it works
- Criminals break into a supplier's or colleague's mailbox, or register a lookalike domain such as acme-invoices.com or acrne.com.
- They read real threads, then reply at the right moment with a genuine-looking invoice and 'our new bank details'.
- They set a different Reply-To address, so your questions go to them and they can confirm their own fraud.
Warning signs
- Any change of bank details, new account, or 'please use this account instead', sent by email.
- A sender domain that's almost right, or a Reply-To that doesn't match the From address.
- Urgency ('overdue', 'final notice', 'today') and a reason not to call ('I'm travelling').
- An invoice attached as a web page (.html, .htm) or behind a sign-in link instead of a normal PDF.
What to do
- Verify every bank-detail change by phone, using the number in your supplier records, before the next payment.
- Use two-person approval and a waiting period for new payees and changed accounts.
- Turn on multi-factor authentication for email, so a stolen password isn't enough to take over a mailbox.
- If money has gone, call your bank immediately to try to recall it, then report it (FBI IC3 in the US, Action Fraud in the UK).
Sources
- FBI Internet Crime Complaint Center (IC3): Business Email Compromise: The $55 Billion Scam (Alert I-091124-PSA) (11 September 2024)
- UK National Cyber Security Centre (NCSC): Business email compromise: defending your organisation
Sources checked 30 September 2026.
3. QR code phishing (5 min)
A QR code in an email, a letter, a parking sign or a poster that leads to a fake sign-in or payment page, usually opened on a phone.
How it works
- An email says your multi-factor authentication or a shared document needs you to scan a code, so the link never appears as text a filter can read.
- A sticker is put over a real QR code on a parking meter, a restaurant table or a poster.
- The page that opens copies a real sign-in or payment page, on a phone where the address bar is small.
Warning signs
- A QR code you didn't expect, in an email or text, especially one about your account, a delivery or a document.
- A sticker on top of a printed code, or a code that looks added.
- The address shown in the preview is misspelled, very long, or not the organisation's normal domain.
- The page asks you to sign in or pay straight away.
What to do
- Don't scan codes from unexpected emails or texts. Contact the organisation through its website or a number you know.
- Before opening, read the address in the scanner's preview. If it's not what you expect, don't open it.
- Pay for parking and services through the official app or website rather than a code on a sign.
- Report QR emails the same way as any phishing email.
Sources
- FBI Internet Crime Complaint Center (IC3): Cybercriminals Tampering with QR Codes to Steal Victim Funds (Alert I-011822-PSA) (18 January 2022)
- Federal Trade Commission (FTC): Scammers hide harmful links in QR codes to steal your information (6 December 2023)
Sources checked 30 September 2026.
4. AI-written phishing (5 min)
Phishing emails and messages written with AI: fluent, personal, free of typos, and able to reference your real projects, colleagues and suppliers.
The NCSC assessed in January 2024 that generative AI lets criminals write convincing lures without the spelling and grammar mistakes that often gave phishing away. Source: UK National Cyber Security Centre (NCSC): The near-term impact of AI on the cyber threat (24 January 2024).
How it works
- Attackers feed public information (your website, LinkedIn, press releases) into AI tools to write messages that fit your role and company.
- The message reads naturally in any language, so the old advice to look for spelling mistakes no longer works.
- The same tools produce thousands of personalised variations, so no two messages look alike.
Warning signs
- Judge the request, not the writing: a sign-in, a payment, a download, a gift card or sensitive data.
- Check the sender's real address and any Reply-To, not just the display name.
- Hover over links: does the address match the organisation? Is it a shortener or an IP address?
- Look for pressure, secrecy, or a move to a new channel.
What to do
- Never sign in from an email link: open the app or type the address yourself.
- Use multi-factor authentication, so a stolen password alone doesn't open your account.
- Use your mail app's Report phishing button, or forward the message to your security contact.
- Check a suspicious email with the free email check on this site: it explains every warning sign it finds.
Sources
- UK National Cyber Security Centre (NCSC): The near-term impact of AI on the cyber threat (24 January 2024)
- FBI Internet Crime Complaint Center (IC3): Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (Alert I-120324-PSA) (3 December 2024)
- UK National Cyber Security Centre (NCSC): Phishing attacks: defending your organisation
Sources checked 30 September 2026.
Runs locally · nothing uploaded
Quiz: 12 questions, pass mark 80%
Your certificate
Pass the quiz (80% or more) to create a certificate with your name.
Certificate of completion
has completed AI Scam Defense: Deepfake CEO voice and video calls, Fake invoices and business email compromise, QR code phishing, AI-written phishing.
Free training module from securityawarenesskit.com by Agent Trust Cloud. Self-assessed; not an accredited qualification.
Train the whole team, and keep the record
Questions
Is the quiz or my name sent anywhere?
No. The quiz is graded in your browser, and the certificate is made on your screen from the name you type. The page is blocked from sending data anywhere, and nothing is stored.
Is the certificate an accredited qualification?
No. It records that you completed this free module and passed its quiz (pass mark 80%). Keep a list of who completed it as a record of your training.
Who is it for?
Everyone, and especially anyone who can pay invoices, approve payments, change bank details, or reset passwords and multi-factor authentication.
Checked a suspicious message lately? Try the free "Is this email a scam?" check. Running October's Cybersecurity Awareness Month? Here's a four-week plan.