A photo, a video, a phone call: how to tell whether AI made it
An employee in Hong Kong sent HK$200 million after a video call in which every colleague was fake. Spotting flaws is getting harder; checking through another channel still works.

In January 2024 an employee in the Hong Kong office of the engineering firm Arup got a message from someone posing as the company's UK-based chief financial officer, about a transaction that had to stay confidential. Then came a video conference. The CFO and several colleagues on screen looked and sounded right, so he made 15 transfers to five Hong Kong bank accounts, HK$200 million in all, about US$25 million. Everyone else on that call was fake, and Arup later confirmed that fake voices and images were used. Once a forgery can hold up through a live group call, trusting your eyes and ears is a losing game. The visual tells below are worth knowing as an early warning. What actually protects the money is checking through a channel you control before anything is sent.
What your eyes can still catch
The FBI's announcement lists the imperfections worth looking for: distorted hands or feet, unrealistic teeth or eyes, indistinct or blurred faces, odd accessories such as glasses and jewelry, shadows that don't fit, watermarks, lag in video, a voice that doesn't match the lips, and movements that look unnatural. With a suspicious image, it helps to go from small details to the whole frame.
Hands, ears and teeth come first. They are complicated shapes and are often half hidden, which is where image generators tend to slip: a sixth finger, fingers merging into a cup, a row of teeth rendered as one white band. Then read the background. Shop signs, license plates, book spines and printed T-shirts often come out as shapes that look like writing but spell nothing. Last, check the light. A face lit from the left should throw its shadow to the right, and people standing together should cast shadows in the same direction.
In video, watch what happens when something gets in the way. Real-time face swapping lays a fake face over a real one, and the fit is weakest when a hand passes in front of the face, when the head turns to the side, or when the person leans toward the camera. Edges flicker and features jump for a moment. A caller who stays perfectly front-on and still, on a conveniently blurry feed, deserves a second thought. For audio, the FBI suggests listening to tone and word choice. A cloned voice can match the sound of someone you know, but the nickname they use for you, their usual phrases and their rhythm of speech have to be imitated by the scammer, and that is where it often falls apart.
The trouble is that this list keeps getting shorter. The FBI wrote it at the end of 2024, and newer image models have since fixed many of the old giveaways, including hands and lettering. Finding no flaw only means you didn't find one; it says nothing about whether the picture is real. The reverse happens too: heavily compressed photos and selfies run through beauty filters get mistaken for AI all the time. Use visual tells to decide whether to keep digging, never to reach a verdict.
Check where it came from: Content Credentials and labels
A sturdier approach than squinting at pixels is to ask whether the file carries a record of its own origin. In February 2021, Adobe, Arm, the BBC, Intel, Microsoft and Truepic founded the Coalition for Content Provenance and Authenticity (C2PA). Its standard lets cameras, editing software and AI generators write into the file how the image was made and what was done to it, with a cryptographic signature that breaks if the content is altered. Products that support it call this record Content Credentials. If you have the original file, you can upload it at verify.contentauthenticity.org; when a record exists, the page shows which tool created or edited the image and what changes were recorded.
Two limits matter. The record is fragile: a screenshot, a forward through a messaging app or a platform's re-compression usually strips it. And a missing record proves nothing. Most genuine photos have none, and anyone making a fake on purpose will not add one. A credential you find is real evidence; finding nothing means this check simply didn't work and you need another one. If what you have is a screenshot, or a video forwarded through WhatsApp, Telegram or social media, it is almost certainly not the original file, so skip this step and go straight to the reverse image search below.
Some platforms add their own "AI-generated" or "Made with AI" labels, and China has made labeling mandatory: since September 1, 2025, AI services there must attach both a visible label and a hidden one in the file's metadata, and platforms must check for them. Labels help in one direction only. A labeled post can be treated as synthetic; an unlabeled one cannot be treated as genuine, because the people using fakes for fraud are exactly the ones who won't follow the rules.
Find the earliest copy
Plenty of so-called AI fakes are old photos with new captions, and plenty of AI images are passed off as on-the-scene shots. The same method catches both: reverse image search. Google Lens, Bing Visual Search and TinEye all work, and on a phone the easiest route is to save the image to your photos first, or pause a video on a clear frame and take a screenshot, then open Google Lens or the Bing app and pick the picture from your gallery. For a video, search three or four different frames; a clear front view of a face, or a frame with captions, signs or logos, tends to lead to the source fastest.
What you want is the earliest place the picture appears. If the same image was online years ago under a different story, it has been recycled. If a dramatic "breaking news" photo is circulating only among a handful of new accounts, and no news outlet, police force or official account on the scene has published it, treat it with suspicion. Look at who posted it, too: how old the account is, what it posted before, and whether its name and profile picture changed recently.
Celebrity videos deserve their own warning. The FBI notes that criminals generate images of celebrities and social media personalities to promote counterfeit products and fraudulent schemes. If an ad shows a famous investor or entrepreneur recommending a coin or a trading platform, check that person's verified accounts to see whether they ever said it, and check the project on its own merits. Our three-question crypto project check is a quick way to do that.
Can an AI detector settle it?
Many websites promise to tell you in one click whether something was made by AI, and they usually answer with a percentage. Treat that number as a hint at best. In January 2023, OpenAI released a classifier for spotting AI-written text and said at launch that, on a test set of English texts, it correctly flagged only 26% of AI-written text, while labeling 9% of human writing as AI. On July 20 of the same year OpenAI withdrew it, citing its low rate of accuracy. If the company building the models could not make this work, a detector advertising 99% accuracy is probably quoting results on its own test set, and those results drift when the content comes from newer models.
Image, video and voice detectors face the same problem. They are useful for sorting a large pile of content so that people can take a closer look at the suspicious part. A score of 90% AI on a screenshot is not evidence to accuse anyone, and a score of 3% is no reason to trust the sender. Screenshots, compression and cropping all move the result, and two or three detectors often disagree about the same picture.
When a familiar face or voice asks for money
This is the step where money is actually lost. The Federal Trade Commission warned in 2023 that a scammer needs only a short audio clip of a family member's voice, which can come from content posted online, to clone it and call you pretending that person is in trouble and needs money fast. The FBI's announcement describes the same thing, along with real-time video calls from people posing as company executives or law enforcement.

The defense is short. The hard part is remembering it while someone you love sounds terrified on the line:
- Hang up and call back on the number already saved in your phone. Don't redial the incoming number or use one the caller gives you, because caller ID can be faked.
- If you can't reach them, ask around. Call another family member, a coworker or a friend and find out where the person actually is.
- Ask for the family code word. The FBI recommends agreeing on a secret word or phrase with your family in advance and asking for it whenever someone claims to be a relative in trouble. Pick something that isn't findable on social media, like a birthday or a pet's name, and set it in person rather than in a group chat.
- Look at what they want. The FTC names the typical demands: wire a transfer, send cryptocurrency, buy gift cards. Add "don't tell anyone", "it has to be now" and "stay on the line", and you are almost certainly dealing with a scam.
If it is a video call and you can't simply hang up, test it on the spot. Ask the person to turn their head to the side, or to wave a hand slowly in front of their face, and ask something only the two of you would know that isn't findable online, such as what you ate the last time you met. The first checks whether a face swap breaks when the face is covered or in profile; the second asks for something a scammer cannot look up. Even if both go fine, hang up and call back as above, because a good fake may not slip in a few seconds.
At work, process has to carry the weight. The Arup employee was facing what looked like a whole meeting of colleagues, and personal alertness rarely survives that. Rules set in advance work better: payments above a set amount need a second person to approve them, every payment instruction is confirmed by calling the requester on the number in the company directory, and any request to skip those steps because the deal is confidential or urgent is treated as a red flag in itself.
You can also give scammers less to work with. The FBI suggests limiting the photos and recordings of your voice that are publicly available, making social media accounts private and accepting only people you know. If older relatives post voice notes and videos often, help them adjust their privacy settings, and set up the code word while you're there.
Three things can be done today. Agree on the code word with your family in person. Ask your bank what it can do to slow a payment down, such as holds on large or first-time transfers, a delay before money leaves, or an extra confirmation step; options differ from bank to bank, and every hour between a request and the money leaving gives you a chance to catch it. And save your bank's fraud line in your phone, so you are not searching for it in a panic.
Common situations and the first move
| What happens | First move | Don't |
|---|---|---|
| A relative calls in tears: a car crash, an arrest, bail money needed | Hang up and call back on the saved number; if they don't answer, call other relatives; ask for the code word | Send money during this call, or call back a number the caller gave you |
| Your boss messages or joins a video call asking for an urgent, confidential transfer | Call them separately on the company directory number and follow normal approval | Skip the checks because it is "confidential" or "urgent" |
| A friend's account sends a video or voice note asking to borrow money | Phone the friend or ask in person; check whether the account has been acting oddly | Pay on the strength of a few seconds of video or audio |
| A celebrity or expert in a video ad recommends an investment or a coin | Check their verified accounts; research the project separately | Download an app or deposit money through a link in the ad |
| Someone claiming to be your bank, a government agency or police starts a video call and asks you to move money | Hang up, look up the official number yourself and call it | Install software they send, share your screen, or move money to a "safe account" |
| A dramatic photo or video of breaking news shows up in your feed | Reverse-search it to find the earliest copy and see whether news outlets or officials published it | Share it straight away |
No real bank or police force will ask you to transfer money into a "safe account" to protect it. That request on its own is reason enough to end the call.
If you have already paid
Speed matters more than anything else. Call your bank or the payment service you used right away, tell them it was fraud, and ask whether the payment can be stopped, recalled or frozen. Keep the messages, call logs and payment receipts, and don't delete the conversation or block the account yet; all of it is evidence.
In the United States, report it to the FBI at ic3.gov and to the FTC at ReportFraud.ftc.gov. In England, Wales and Northern Ireland, Action Fraud was replaced in December 2025 by Report Fraud, at reportfraud.police.uk or 0300 123 2040; in Scotland, report to Police Scotland on 101. Elsewhere, report to the police and to your national fraud reporting service; in mainland China that means calling 110.
If you sent cryptocurrency, write down the transaction hash (TXID) and the receiving address, contact the exchange or wallet you sent from immediately, and put both in your police report. Blockchain transfers can't be reversed, but if the funds reach a centralized exchange, law enforcement may be able to ask that exchange to freeze them, and the odds are better the sooner they hear about it.
Then watch for the second wave. The FBI's report for 2025 notes rising complaints about people posing as fund recovery services. Anyone who contacts you offering to get your money back for an upfront fee is almost always running the second half of the same scam.
If it was your own face or voice that was faked, act as well. Report it to the police and to the platform where it appeared, and tell family and friends exactly how you will confirm any request for money from now on.
FAQ
How can I quickly check on my phone whether a photo is AI-generated?
Zoom in on hands, ears, teeth and any lettering in the background, since those are where generators most often slip. Then long-press the image and run a reverse image search to see where it first appeared. A platform label saying it is AI-made is useful; the absence of one is not. None of these checks settles the question on its own; they tell you whether to keep looking.
An AI detector says 90% AI. Can I trust that?
Only as a hint. The text classifier OpenAI released in 2023 caught just 26% of AI-written text in an English test set and flagged 9% of human writing as AI, and it was withdrawn six months later for low accuracy. Screenshots, compression and cropping change detector results, and a second detector may give a completely different answer, so the number is not evidence.
How much audio does it take to clone someone's voice?
Not much. The FTC says a scammer needs only a short audio clip, and videos, livestreams and voice messages posted online can all supply one. Rather than relying on your family staying offline, agree on a code word in advance and hang up and call back whenever someone calls asking for emergency money.
If there is no AI label, does that mean it is real?
No. Labels depend on the tool and the platform following the rules, and people using fakes for fraud don't. Screenshots and reposts also strip the hidden metadata that labels and Content Credentials rely on. A label or credential you find is useful evidence; not finding one tells you nothing.
What should I do first if I've been scammed?
Call your bank or payment provider immediately to try to stop or recall the payment, keep every message and receipt, then report it: in the US at ic3.gov and ReportFraud.ftc.gov, in England, Wales and Northern Ireland at reportfraud.police.uk, elsewhere to the police. Ignore anyone who then offers to recover the money for a fee.
Sources and further reading
- FBI Internet Crime Complaint Center, public service announcement I-120324-PSA (December 3, 2024), on how AI-generated text, images, audio and video are used in fraud and how to protect yourself
- Federal Trade Commission consumer alert, Scammers use AI to enhance their family emergency schemes (March 20, 2023)
- Dezeen, Arup revealed as victim of deepfake video scam (May 17, 2024), on the HK$200 million transfers from the Hong Kong office
- Cyberspace Administration of China, announcement of the Measures for Labeling AI-Generated Synthetic Content (March 14, 2025, in Chinese), on visible and hidden labels and the September 1, 2025 start date
- OpenAI, New AI classifier for indicating AI-written text (January 31, 2023, archived copy), with the 26% and 9% test results and the note that the tool was withdrawn on July 20, 2023
Updated: First published September 21, 2026. The tools and platform rules mentioned here change quickly; anything that stops applying will be noted here.