How to do it

AI has stripped scammers of their old flaws (shaky grammar, garbled sentences), but it hasn't changed the skeleton of the deception. Learn to see that.

  1. Ignore writing quality as a clue. A well-written message is no longer a sign of trustworthiness: today scams are polished, personalized, with your name and real details. Formal perfection absolves no one.
  2. Look for pressure and urgency. "Act within an hour," "your account will be blocked," "your child is in trouble": haste serves to stop you from thinking and verifying. Legitimate requests almost never force you to decide on the spot.
  3. Look at the final request. Every scam, under any disguise, wants one of two things: for you to pay, or for you to hand over data and credentials. If an unexpected message aims at one of these, it's a serious suspect regardless of how it's written.
  4. Check the requested payment method. Gift cards, cryptocurrencies, instant transfers, peer-to-peer payment apps: these are the rails of scams because they can't be reversed. No real entity (bank, tax authority, courier, police) asks you to pay this way.

Check: if a message combines urgency, a request for money or data, and a channel that pushes you not to verify, it's almost certainly a scam, even if it seems to come from a known sender and even if it's beautifully written.

A concrete example

Marco gets an email from "his bank": the right logo, perfect Italian, his name spelled correctly, a notice of suspicious access and a button to "verify your identity now or the account will be suspended." No errors, no awkward phrasing: the email looks authentic. But Marco doesn't click. He notices the three signals: urgency, the threat of being blocked, the request to enter credentials. Instead of following the link, he opens the bank app he normally uses and checks there: no notice, no suspicious access. The email was a fake built with AI on the model of the bank's real communications. Marco recognized it from the structure, not the form.

When it does NOT work (and how to fix it)

If the message seems to come from a trusted contact

Scams exploit hacked accounts or spoofed senders to look like your bank, a colleague, a friend. The "right" sender is no guarantee. The remedy is to verify through a different channel: don't reply to the suspicious message, but contact the person or entity through a contact you already know (the number in your contacts, the official app, the website typed by hand).

If they called you pretending to be a company or an institution

AI makes it possible to clone voices and handle very credible calls. A convincing voice proves nothing. Hang up and call the entity back at the official number you find on its website or on your card, never at the number they called from. No real operator takes offense if you call back to be safe.

If you've already clicked or provided data

Act immediately. Change the password of the affected service right away (and of every other one where you used the same one), enable two-step verification, and if you gave out banking data, alert your bank to block cards or operations. Report the message as phishing and, for financial damage, file a report keeping all the evidence.

A tip from someone who really uses it

Adopt a single rule, valid for everything: no important action (paying, entering credentials, giving codes) starts from a link or a number received in a message. You always start from the official channel that you reach yourself: the app you've already installed, the website you type by hand, the number printed on your card. This habit neutralizes nearly all scams, including the ones AI will make ever more polished.

Frequently asked questions

If there are no grammar errors, can I trust the message?

No, and this is the most important change to understand. Perfect Italian was a reassurance that no longer holds: AI writes better than many real offices. Judge the message by what it asks of you and with how much urgency, not by how it's written.

Can I ask the AI itself whether a message is a scam?

Yes, and it's a smart use: paste the text of the suspicious message (without your personal data) into an AI and ask it to assess the scam signals. It often spots urgency, abnormal requests and disguised links well. Treat it as a useful second opinion, not as a final verdict: verifying through the official channel remains the decisive move.