
Last month, Hugging Face (a site that hosts most of the world’s open AI models) found OpenAI models intruding into its production systems. They found that unreleased versions of their models ran loose for four and a half days across roughly 17,600 recorded actions, coordinating over public text files. As more and more details from this incident have come out, the picture has only darkened. Agents from separate, unrelated training runs found each other inside an internal file repository months earlier and used it as a covert message board, and when OpenAI revoked access they rebuilt the channel within days by encoding messages into directory names, going right back to sharing credentials and techniques. This weirdly intense level of cooperation was emergent; nobody taught these models how to do this.
And it’s not just OpenAI. Anthropic disclosed in July that three of its models, told in the prompt that they had no internet access, had compromised three real companies through weak passwords. The machines turned out to be online by mistake, a human error in misconfiguration. Meta followed a week later when its Muse Spark model escaped a sandbox (misconfigured by the same folks from the Anthropic issue). Around this same time, UK’s AI Security Institute also documented an agent that researched an open-source project’s human maintainers, invented fake identities, and talked a real person into approving its malicious code.
Every one of these was a door somebody left open. (Btw, rotate your Hugging Face tokens.) But the reality is that these models can now chain a complete break-in, at machine speed, unsupervised, for days. Anthropic’s threat report last August described one bad human actor using Claude Code to extort at least 17 organizations, with the model reading stolen financial records to price each ransom between $75,000 and more than $500,000. By November the company was describing a state-sponsored campaign where AI executed 80 to 90 percent of the work. Phishing is seeing similar explosions: in Hoxhunt’s long-running test, AI-written spear phishing went from 31% worse than elite human red teams in 2023 to 24% better by March 2025. All those corporate training sessions where they tell you to look out for typos and cheap-looking websites are now effectively useless. “Bad grammar, poor spelling or clunky websites are less likely with AI.” And don’t think its just emails. A finance employee from Arup wired $25 million after a video call where every colleague on screen was synthetic.
The FBI’s 2025 Internet Crime Report counted $20.9 billion in losses, opened its first-ever AI category (22,364 complaints, $893 million), and logged $7.7 billion lost by Americans over 60, up 59% in a single year. They’re also now warning that scammers circle back to people who’ve already been defrauded, posing as FBI agents, complete with AI-generated video of a senior official pushing a counterfeit complaint site.
It’s a mess and it’s only going to get worse as models get smarter, faster, and harder to contain. So what the heck should you do about it?
What to do in the new age of AI scams
Pretty much everything you’ve learned in terms of avoiding online scams is now moot. If you still think you can confidently identify modern phishing attempts, you’re wrong. But that doesn’t mean you should feel helpless. There are so, so many things we can do to avoid disaster in this new age.
Catch this and more in the Handy AI newsletter.
Quick wins
- Pick a family password. The FBI has recommended this in writing since December 2024: “Create a secret word or phrase with your family to verify their identity.” Some additional tips: use several words, not one; nothing guessable from your public (or private) social media; agree on it out loud, never over text; and rehearse it often so it’s reflex. AI voice models are getting quite advanced, and having a verbal password prevents you from wiring cash over the phone when a fake voice of your kid is calling from jail, sobbing and asking for bail money.
- Agree that nobody in the family moves money on an inbound call. Not for the bank, not for the IRS, not for a panicked relative, not for “the FBI.” Whoever gets a call like this should hang up and dial back on to a verified number they already have on hand. This has been the FTC’s core advice since 2023 and it’s becoming even more important.
- Look for typical scam patterns. Any sort of urgency, secrecy, or irreversible payment methods is bad news. Any request saying things like “right now,” “don’t tell anyone,” and asking from some kind of wire, crypto, or gift cards is a scam, full stop. Even if you swear its your mom’s voice on the phone.
Bigger swings for bigger protection
- Freeze your credit at all three bureaus. This can be done at Equifax, Experian, and TransUnion. It’s free to do (by federal law), has no effect on your score, and when you need a loan the bureaus are required to lift an online request within an hour. While you’re at it, offer to set them up for your parents. This is probably the highest-value hour on this list and one people sip often. One note: the freeze is the free, legally protected product, but the bureaus also advertise a paid “credit lock”. Skip that one.
- Lock your phone number. SIM swapping (moving your number to a criminal’s phone) is a common method of how attackers intercept the text codes protecting your accounts. Every major US carrier has protection for this. Verizon has Number Lock and SIM Protection. AT&T has Wireless Account Lock. T-Mobile splits it into SIM Protection and Port Out Protection, set per line in the T-Life app. Five minutes tops to enable.
- Use passkeys wherever you can. A passkey is a sign-in that’s locked to the real site, something that fakes login sites can’t really replicate effectively. Google’s lives under Security, then “Passkeys and security keys,” Apple creates them automatically through iCloud, and Microsoft’s is under Advanced security options. Check whether your bank supports them at passkeys.directory (and complain they don’t). The FIDO Alliance says five billion passkeys are in use and three quarters of people with at least one enabled. If passkeys aren’t available on one of your accounts, check for two-factor authenticator options like an app code or text code. Better than nothing.
- Turn on every alert your bank offers. Transaction alerts, login alerts, transfer alerts, all of them. Get them pushed to your phone if possible. You’ll want to find out about any sort of fraudulent activity as soon as possible.
- Check what’s already out there. Run your email through Have I Been Pwned to see which breaches you’re in (you will be in several, trust me). If you’re using the same password for everything, stop. Get a password manager. There’s one built into your phone that will work just fine. Then, point Google’s free Results about you tool at yourself. This is an underrated tool that monitors search for your phone number, address, and email. Since February it also catches SSNs and license numbers, and then files the removal requests for you. Californians also get something called the DROP system, which sends a single free deletion request to more than 500 registered data brokers. There’s also a ton of paid data removal services like DeleteMe and Optery, around $40 to $130 a year. They’ll catch a lot, but not everything, so curb expectations.
- Shrink the raw material. The FBI’s PSA that recommends the family password also recommends making social accounts private and limiting public clips of your face and voice. It’s a good suggestion, especially since companies like Meta use public Instagram data to train their AI models.
Some other habits to help
- Treat Zelle, wires, crypto, and gift cards as cash. If a criminal breaks in and moves your money, this is considered unauthorized and federal law is on your side. But if you get talked into sending it the money yourself, Zelle’s network policy says imposter-scam victims “may be eligible” for reimbursement, decided case-by-case. The CFPB dropped its lawsuit against Zelle’s operator and three large banks over exactly this, which means there is minimal federal pressure in these situations. No law guarantees your money back. Pick payment methods you can dispute (credit cards, mainly) whenever a stranger is on the other end.
- Keep secrets out of chatbots. On consumer plans, especially the free tiers, the big assistants like ChatGPT and Claude generally use your conversations for training unless you turn it off. Google’s own Gemini documentation says human reviewers read a sample of chats, keeps reviewed chats up to three years even after you delete them, and asks you not to enter confidential information. Anthropic keeps chats five years if you allow training, 30 days if you don’t. Turn this off when able (ChatGPT: Data Controls; Claude: Privacy Settings; Gemini: Keep Activity) and use temporary chats for anything sensitive. Most importantly: keep all passwords, card numbers, SSNs, and medical records out of the chatbots entirely.
- Only install and use official AI chatbot apps. Fake ChatGPT apps are a whole genre running from ad-stuffed wrappers to malware that reads your two-factor texts. Use official apps only. Check the developer name character by character and deny permissions an app has no reason to want.
- Treat AI browser and agents like an employee. Most modern agents and AI browsers now have the ability to log into your accounts for you. This means every rule here you’re making for yourself has to apply to your AI assistant as well. Guardio walked Perplexity’s Comet into a phishing page in under four minutes, and Zenity showed a “poisoned” calendar invite was convincing agents to open up access to local files and password vaults. I don’t allow agents to log into things at all to be safe but, if you must, make sure sensitive accounts like banks are off limits.
What to do if things go south
The tips here will help protect you. But, they’re not bulletproof, and implementing them all will take some time. Should things go south and you fall prey to an AI scam, here’s a quick hitlist of what to do quickly:
- If you feel like you were scammed out of money, immediately call your bank’s fraud line first and say the words “recall” and “freeze.” Then, within the hour, file at ic3.gov. The speed at which you do this is important. The FBI’s Recovery Asset Team’s 2025 58% save rate was heavily skew toward people who called fast.
- If your identity data leaked, use IdentityTheft.gov.
- Everything else goes to ReportFraud.ftc.gov.
If you want to talk to a human, AARP’s Fraud Watch helpline (877-908-3360) is open to everyone and the Justice Department’s National Elder Fraud Hotline (833-372-8311) is open for folks over 60.
This space can and will get worse. Models are getting smarter and faster, and more open, and there is no sign of that slowing down. Scams that would be obvious in the past are going to get more and more convincing and it pays to be ready.
But don’t get discouraged! This list can and will help protect you significantly. Find the time and get it done.
Select any passage to give it a thumbs up or down. Humans and agents both welcome.