Skip to main content

The One Hour Shield: Protect Yourself From AI Scams

How do I protect myself from AI scams?

AI did not invent any of these attacks. It removed the cost of running old ones convincingly, at scale, in your voice. So the defences are old defences, and the reason to do them today is that the attempt rate went up, not that the attacks became clever.

Eight steps, 68 minutes if you do all of them, ordered by how much protection each minute buys. Step one takes three minutes and is the most valuable thing here. If you stop after it, the visit was worth it.

  1. 1. Agree a spoken password with your family

    about 3 min

    Cloning a voice now takes a short sample of someone speaking, and the sample is usually a video they posted themselves. The call that follows is a grandchild in trouble, a child stranded, a spouse in an accident, and it is convincing because the voice is right. A word that was never said online cannot be cloned along with the voice.

    Pick a word or short phrase that has never appeared in any message, post or email. Say it out loud to each person, in person or on a call you started. Never write it down anywhere that syncs, and never type it into a chat. The rule is simple enough for a child and an eighty year old: if the voice cannot say the word, hang up and call back on the number you already have.

    What this does not do. This only works if the word stays spoken. The moment it is texted, it lives in an inbox that can be read.

  2. 2. Put two-factor authentication on your email before anything else

    about 10 min

    Email is not one account, it is the reset key to every other account you own. An attacker who reaches it does not need to break your bank, they ask your bank for a new password. Every other lock on this page is downstream of this one.

    Open your email provider's security settings and turn on two-factor authentication using an authenticator app rather than text messages where the option exists. Then do the same for the account that controls your phone, meaning your Apple or Google account, because it can reset the email.

    What this does not do. Codes sent by text can be intercepted by porting your number to another phone. An authenticator app avoids that entirely, which is why it is worth the extra two minutes.

  3. 3. Freeze your credit at all three bureaus

    about 20 min

    A synthetic identity built from your details is only profitable if someone can open credit in your name. A freeze stops that at the source, and it is free by federal law. This is the longest step here and the one most worth finishing.

    Do all three, because a lender only checks one and the attacker picks which. Create the account, verify your identity, set the freeze, and store the PIN each bureau gives you somewhere you will still have it in five years. Thawing takes minutes when you genuinely need credit.

    EquifaxExperianTransUnion

    What this does not do. A freeze stops NEW accounts. It does nothing about fraud on the cards you already hold, so it is a lock on the front door, not the whole house.

  4. 4. Make one rule about money, and make it unbreakable

    about 5 min

    Every version of this attack, from the cloned voice to the fake video call to the invoice from a supplier you know, ends in the same place: money moving to new details, urgently, quietly. The rule that defeats all of them is indifferent to how convincing the request was.

    No payment, and no change to payment details, ever happens without a call back to a number you already had on file, made by you, after the request. Not the number in the message. Not a number read out on the call. Say the rule out loud to whoever handles money in your household or your business, and give them explicit permission to be slow and to be wrong about it.

    What this does not do. The rule fails the first time someone is allowed to make an exception because the request came from the boss. Build it so that the boss is the person it most applies to.

  5. 5. Find out which of your accounts are already exposed

    about 5 min

    The convincing details in a scam message, an old address, a real order number, a colleague's name, usually come from a breach rather than from surveillance. Knowing which of your accounts are in circulation tells you which passwords to change first.

    Enter your email address at Have I Been Pwned. It tells you which known breaches include it. Change the password anywhere it appears, starting with anything you reused, and treat any account you had forgotten as a live risk rather than a curiosity.

    Have I Been Pwned

  6. 6. Close the reset path

    about 10 min

    Attackers rarely guess a password. They walk the recovery route: a phone number, an old alternate email you no longer read, a security question whose answer is on your public profile. The reset path is usually weaker than the lock.

    In each important account, review the recovery options. Remove alternate email addresses you no longer control. Replace security questions whose answers are public, meaning your mother's maiden name, your first school, your pet, with an answer that is simply another random password stored in your password manager.

    What this does not do. Your mobile carrier is part of this. Ask them to add a port-out PIN to your line, because a number moved to another handset defeats every code sent by text.

  7. 7. Reduce the raw material

    about 10 min

    A convincing clone of your voice or face is built from what you published. This is not an argument for disappearing, it is an argument for knowing what is public and deciding that on purpose rather than by default.

    Set personal social accounts to private, review who can see older posts in bulk where the platform allows it, and pay particular attention to video where you speak at length, which is the most useful material of all. Do the same for accounts belonging to children in your household.

    What this does not do. Anything already public should be assumed to be permanently collected. This step reduces what gets added, and that is still worth ten minutes.

  8. 8. Give the safe word and the money rule to one older relative

    about 5 min

    The grandparent scam works because it targets someone who is alone, who loves the person supposedly calling, and who has been taught to be helpful. All the protection in the world on your own accounts does nothing for them.

    Call them. Agree the same spoken password. Tell them the money rule, and add the line that matters most: nobody who genuinely loves you will ever be angry at you for hanging up and calling back. Write the callback numbers on paper beside the phone, because paper does not get spoofed.

If something has already happened

Report fraud to the FTC

The federal reporting route for scams and attempted scams, including ones that failed.

Identity theft recovery plan

If accounts were actually opened in your name, this builds a step by step recovery plan and the letters that go with it.

FBI Internet Crime Complaint Center

For internet-enabled crime, and the route that matters most when money has already moved.

Your free credit reports

The federally authorised site for the free reports you are entitled to. Check for accounts you did not open.

If a fake image or video of you is circulating

The removal routes that work, including the ones that never require you to upload the image, and the separate path that applies when the person shown is under 18.

Questions people ask

How do I protect myself from AI voice scams?

Agree a spoken password with your family that has never been written down anywhere online, and make a rule that no money moves and no payment details change without a callback to a number you already had. Voice cloning defeats recognition, so the defence cannot rely on recognising the voice. It has to rely on something the caller must know or a channel the attacker does not control.

Does freezing my credit stop AI scams?

It stops one important branch of them. A freeze prevents new credit being opened in your name, which is what a synthetic identity built from your stolen details is for, and it is free by federal law at all three bureaus. It does nothing about fraud on accounts you already hold, and nothing about a scam that persuades you to send money yourself, which is why it is step three here rather than step one.

What is a family safe word and does it actually work?

It is a word or short phrase agreed in person and never typed anywhere, used to confirm identity on a call that claims to be a relative in trouble. It works because it does not depend on the voice, which can now be cloned from a short sample of public video. It stops working the moment it is sent in a message, so it must stay spoken.

Is two-factor authentication by text good enough?

It is much better than nothing and weaker than an app. Codes sent by text can be intercepted by moving your number to another handset, which is why an authenticator app is preferable where it is offered, and why asking your mobile carrier to add a port-out PIN is part of closing the reset path.

How long does this actually take?

About an hour for all eight steps, and the credit freeze is half of it because it has to be done three times. The order here is deliberate: the steps are ranked by protection gained per minute spent, so a reader who stops after step one has still done the single most valuable thing on the page.

Practise the hard part

Most of this page is locks. The part no lock covers is judgement in the moment, and it is worth finding out how good yours is: eight passages, five real and three written by an AI. Most people score near chance, which is exactly why the rules above are written so they work without you having to tell.

This page is information, not legal or financial advice, and it collects nothing. Every link was opened and confirmed on 23 August 2026. The credit bureaus, the FTC and the FBI are independent of GAGE and we receive nothing from them. If a link has changed, tell us and we will fix it the same day.