AI Scams & Deepfakes in 2026:
How to Protect Yourself
I've been fixing computers for over 30 years, and in all that time I've never seen anything quite like what's happening right now. The scams coming through in 2026 aren't the sloppy Nigerian prince emails you could spot from a mile away anymore. They're polished, personalized, and powered by artificial intelligence — and they're fooling people who are far from naive. I've had clients in my shop this year who lost thousands of dollars because a phone call sounded exactly like their son. Others got emails that looked so legitimate, even I had to look twice. This article is the guide I wish I could hand every person who walks through my door.
1 Voice Cloning: The Scariest Scam of 2026
This one gives me chills. AI can now clone someone's voice from as little as three seconds of audio — a voicemail greeting, a TikTok clip, a snippet from a video call. The scammer types whatever they want, and the AI speaks it in your loved one's voice.
The typical scenario: you get a frantic phone call at 2 a.m. from what sounds exactly like your child or grandchild. They say they've been in an accident, they're in trouble, they need money wired immediately. And they beg you not to tell anyone else. It hits all the emotional buttons at once — urgency, fear, authority, and isolation — and it's working. Voice phishing attacks surged over 400% in late 2024 and haven't slowed down since.
Set up a family code word — a simple, private word or phrase that only your family knows. If someone calls claiming to be a family member asking for money, ask for the code word. No code word, no money, no exceptions. It sounds old-school, but it's the single most effective defense against voice cloning. Also: always hang up and call them back on the number you have saved for them — not the number they called from.
2 Deepfake Video Calls: Seeing Is No Longer Believing
If you think voice cloning is scary, deepfake video calls are terrifying. In one well-documented case, an employee at a major engineering firm was tricked into wiring $25.6 million after joining a video call where every other participant — including the company's CFO — was a deepfake generated from publicly available footage. The employee had actually suspected the initial email was phishing, but seeing the faces on video convinced him it was real.
You don't need to be a Fortune 500 company to be targeted. Scammers are now using deepfake video in romance scams, fake job interviews, and even fake tech support calls. If there's enough publicly available video or photos of someone (think social media), their face can be used in real time.
If something feels off on a video call — especially if money, passwords, or sensitive information comes up — verify through a completely separate channel. Hang up and call the person directly. Text them on a number you already have. Walk to their office. The key is: never verify through the same channel the request came from, because that's the channel the attacker controls. Also watch for visual tells: unnatural blinking, slight audio-lip mismatches, and faces that look "too smooth" can all be signs of a deepfake.
3 AI-Powered Phishing Emails: The Typos Are Gone
Remember when you could spot a phishing email because it was full of bad grammar and weird formatting? Those days are over. AI tools let scammers generate perfectly written, highly personalized emails in seconds. They can scrape your LinkedIn profile, your company website, even your social media posts to craft a message that references your job title, your recent projects, or your boss's name.
Bank impersonation texts alone are up nearly 20x since 2019. And it's not just banks — I've seen fake shipping notifications from Canada Post, fake password reset emails from Microsoft, and fake invoice emails that look exactly like they came from a real supplier.
Always check the sender's actual email address — not just the display name. Hover over links before clicking them (or long-press on mobile) and look at the actual URL. Watch for subtle character swaps like using a zero instead of the letter O, or a 3 instead of an E. And if an email asks you to click a link to "verify your account" or "confirm a payment," don't click it — open your browser and go to the website directly by typing the address yourself. For more on spotting infection signs after clicking a bad link, see our guide on 7 Signs Your Computer Has Malware.
4 Fake Browser Extensions: The Trojan Horse on Your Toolbar
This one hits close to home for me as a technician because I'm pulling these off client machines constantly. Malicious browser extensions are disguising themselves as popular AI tools — just this month, a fake version of the Perplexity AI search tool was caught in the Chrome Web Store stealing browsing data and intercepting search traffic.
These extensions ask for broad permissions when you install them — access to all your browsing data, ability to read your tabs — and most people just click "Allow" without thinking. Once installed, they can see every website you visit, capture form data (including passwords), and redirect your searches to scam sites.
Only install extensions from the official developer — check the publisher name and look for the "Featured" or "Established publisher" badges in the Chrome Web Store. If an extension has very few reviews or was just published recently, be cautious. Regularly audit your installed extensions by going to chrome://extensions in your address bar and removing anything you don't recognize or no longer use. And never install an extension that a website pop-up tells you to install.
5 QR Code Scams ("Quishing")
QR codes are everywhere now — restaurant menus, parking meters, event tickets, store windows. Scammers know this, so they've started placing fake QR codes over legitimate ones, or printing convincing-looking flyers and stickers with malicious QR codes in public places. When you scan one, it takes you to a phishing site designed to steal your login credentials or payment information.
This is especially effective because your phone's camera app doesn't show you the full URL before you tap — and on a small screen, a fake site can look nearly identical to the real thing.
Before scanning any QR code in a public place, take a close look at it — does it look like a sticker placed over something else? Is it on a random flyer taped to a lamp post? If so, don't scan it. When you do scan a code, check the URL preview before tapping through. If the domain looks unfamiliar, misspelled, or overly long, don't open it. And never enter payment information on a page you reached via QR code unless you're certain it's the legitimate site.
6 The "Safe Account" Scam
Here's one I've been hearing about more and more. You get a call or text claiming to be from your bank, the CRA (or IRS), or even the police. They tell you your account has been compromised and you need to move your money to a "safe account" immediately to protect it. The voice sounds professional. The caller ID might even show your bank's real phone number (spoofed). They create intense urgency — and the "safe account" is, of course, the scammer's.
Your bank will never ask you to transfer money to protect it. The CRA will never call you demanding immediate payment over the phone. No legitimate organization will pressure you to make a financial decision in minutes.
Hang up immediately. Then call your bank using the number on the back of your card — not any number the caller gave you. Tell them what happened. If it was a real fraud alert, they'll know about it. If it wasn't, you just saved yourself from becoming a victim. The golden rule: any time someone creates urgency around money, slow down. That urgency is the weapon.
7 Your Defence Checklist: 7 Things to Do Today
You don't need to be a tech expert to protect yourself. Here are the most important steps you can take right now — they'll defend against the vast majority of AI-powered scams:
1. Set up a family code word — agree on it in person, and use it to verify emergency calls.
2. Turn on two-factor authentication (2FA) — on your email, your bank, and your social media. Even if someone steals your password, 2FA stops them at the door. Use an authenticator app instead of text messages when possible.
3. Keep your devices updated — those software updates you keep ignoring often patch the exact security holes scammers are exploiting.
4. Audit your browser extensions — go to chrome://extensions right now and remove anything you don't actively use.
5. Lock down your social media — the less public information available about you, the harder it is for AI to personalize an attack. Review your privacy settings and limit who can see your posts, friends list, and personal details.
6. Use strong, unique passwords — a password manager makes this painless. Reusing the same password across sites is one of the biggest risks most people take without realizing it.
7. Install reputable antivirus software — a good security suite catches phishing sites, malicious downloads, and sketchy extensions before they do damage. Not sure which one? Check out our Best Antivirus Software 2026 guide.
Stop all communication with the scammer immediately. Contact your bank or credit card company right away to freeze or reverse any transactions. Change your passwords — starting with your email, since that's the gateway to resetting everything else. Report the scam to the Canadian Anti-Fraud Centre (1-888-495-8501) or the FTC at reportfraud.ftc.gov if you're in the U.S. The sooner you act, the better your chances of recovering lost money.
Think Your Computer's Been Compromised?
If you clicked a suspicious link, installed a sketchy extension, or your computer is suddenly acting strange after any kind of scam attempt, don't wait — the sooner you act, the less damage gets done.
If you're in the Nanaimo, BC area, BigMike Computer Services can do a full security check, remove any malware, and make sure your system is locked down. Over 30 years of fixing computers — and cleaning up after scammers is unfortunately a growing part of the job.
Visit BigMike Computer Services →— BigMike | Computer Repair Technician, Nanaimo BC
📧 BigMikeNanaimo@gmail.com