Could you tell whether an urgent call from a relative was genuine—or generated using AI?
About eight in ten Britons report having received an impersonation attempt from someone posing as a trusted person or organisation. Yet fewer than one in ten have agreed a family safe word to verify an unexpected request.
Only 14% of Britons are very confident they could recognise AI-generated or manipulated communications, according to research released for Cyber Security Awareness Month.
The Institution of Engineering and Technology (IET) is urging households to adopt a private safe word as AI makes it increasingly easy to imitate familiar voices and create convincing messages, images, videos and documents using personal information gathered online.
The IET warns that a familiar voice, image, telephone number or piece of personal information should no longer be treated as proof of identity, although 45% have some confidence in telling .whether a message, call, image or video had been created or manipulated using AI.
Phone remains the primary channel for impersonation attempts. Nearly three in ten (29%) people who have experienced them receive suspicious calls every day, and those targeted report receiving an average of 26.5 impersonation attempts a month by phone, more than by text message (22.8) or email (21.2).
More than one in five (22%) would be more likely to believe an approach was genuine if the sender knew information they expected only a real person or organisation to know. A fifth would be influenced by a familiar-looking telephone number, email address or account, while 13% would be more likely to trust somebody who knew about their recent activities. These are precisely the cues people have traditionally relied on to judge authenticity, yet they are increasingly easy for scammers to fake using AI.
A fraudster could imitate a relative’s voice, mention a genuine holiday or house move discovered online and use exposed contact or account details to support an urgent request for money.
The voice could be generated using AI, while personal information might come from social media, a compromised account or an earlier data breach. Each element may appear authentic even when the overall approach is fraudulent. A familiar voice, face, account or telephone number should therefore no longer be treated as sufficient proof of identity on its own.
