AI Changes Credibility, Not the Need for Verification
Generative AI can make an impersonation more persuasive through cloned audio, synthetic images or video, personalized text, translated scripts, and rapid variation. It does not make the underlying identity, emergency, invoice, investment, romantic claim, or payment instruction true. Treat media as one piece of evidence rather than proof of who created or sent it.
The FBI has described malicious campaigns using text and AI-generated voice messages to impersonate trusted people and obtain access or information. The safest first test is independent contact: use a previously known number, established company directory, verified account, or another trusted person. Do not use a callback number, link, or new platform supplied by the suspicious sender.
Preserve the Original Message and Transaction Trail
Save the original email or message where the platform permits it, including headers, sender identifiers, profile URL, username, telephone number, timestamp, attachments, audio, video, payment instructions, and the full conversation. Keep original files and make separate working copies. Record the device and account that received the material, when it was exported, and every action taken afterward.
For payments, preserve invoices, bank or card references, wire instructions, beneficiary names, wallet addresses, gift-card information, shipment details, receipts, and communications about changes. Contact the financial institution immediately when money is at risk; evidence preservation should not delay an attempt to stop or recall a transfer. NIST identifies audio, video, images, and computer information as digital and multimedia evidence and emphasizes methods and tool testing rather than visual guesswork.
Use OSINT to Develop and Test Identifiers
Open-source intelligence, or OSINT, uses lawfully available sources to develop and corroborate leads. For an AI-enabled scam, useful identifiers may include usernames, domains, email addresses, telephone numbers, company names, filing numbers, profile creation dates, reused text, image provenance, payment recipients, wallet addresses, and shipment or contact locations.
Build an identifier table and record the source, URL, search terms, retrieval date, and confidence for each association. Check company claims against official registries, professional claims against the appropriate licensing body, and public-company claims against SEC filings. Look for contradictions in dates, geography, corporate relationships, contact methods, and payment instructions. A reverse-image result, shared avatar, IP-derived location, domain registration, or database association is a lead—not automatic attribution to a human actor.
Use HUMINT for Independent, Attributable Confirmation
Human intelligence, or HUMINT, means information obtained from people. In scam verification, its strongest use is independent confirmation through a person or organization with direct knowledge: the family member whose voice was imitated, the vendor whose invoice was altered, the employer allegedly requesting gift cards, the bank receiving a transfer, or a witness to a claimed event.
Document who was contacted, the independently sourced contact method, how identity was established, when the conversation occurred, what the person directly knew, and whether statements are exact quotations or summaries. Avoid disclosing more sensitive information than necessary. The FTC's fake-emergency guidance advises calling the supposed family member or friend through a known number rather than trusting the voice presented by the caller.
Report Loss Quickly and Label Conclusions Carefully
Route active financial loss to the bank, card issuer, payment platform, exchange, or gift-card company immediately. Report consumer fraud at ReportFraud.ftc.gov and internet-enabled crime through the FBI's Internet Crime Complaint Center. Use local law enforcement or 911 where threats, immediate danger, or crimes in progress are involved. Preserve report numbers and copies.
A verification report should separate confirmed facts, source records, witness statements, technical observations, OSINT leads, inferences, and unresolved questions. Claims such as “AI-generated,” “deepfake,” “same actor,” or “located in Florida” require evidence appropriate to that conclusion. Consumer detection tools can be wrong, and output alone should not become the case theory.
For account containment and prevention, review the Florida cybersecurity checklist. A PI may document identities and public evidence but cannot hack accounts, compel platform records, or guarantee recovery.
