←
AI for Government
Aware · M21 · lesson 21 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Recognizing AI-Generated Threats
📖
now learning

Recognizing AI-Generated Threats

10 min

On a Tuesday morning, Diane Okafor, a benefits caseworker at a state unemployment agency, got a voicemail that sounded exactly like her division director. The voice told her to expedite a flagged claim before the auditors flag us. It had his cadence, his slight stammer, even his habit of saying appreciate you. Diane almost did it. What stopped her was small: the director never called her cell, and the claim number had one too many digits. She forwarded the voicemail to security. Three other caseworkers got the same call that week, and none of them caught it.

That voicemail was not a recording of a real person. It was synthetic audio, generated from roughly thirty seconds of the director's voice scraped from a public budget hearing on the agency's video channel. This is the new shape of the threat, and it changes who is a target. You do not need to be a cybersecurity specialist. You need to be someone with access to money, data, or a decision, which describes most of the people reading this.

Why the old tells stopped working

For twenty years, government employees were trained to spot fakes by looking for mistakes. Misspelled words. Broken English. Blurry logos. A stranger with an improbable inheritance. Those tells existed because scams were cheap and made by humans cutting corners, and the corners were where the evidence lived.

Generative AI removed the corners. A phishing email written by a language model has clean grammar, your agency's tone, and a plausible reference to a real policy. A convincing fake video of an official can be produced in an afternoon. The cost of making a persuasive fake collapsed, which raised the volume and the quality at the same time, and those two things together are what makes this different from every previous wave of phishing training.

So the detection job changed underneath everyone. You can no longer ask whether this looks sloppy. You have to ask whether it makes sense, and whether you can confirm it through a channel that does not depend on the message itself. The question is no longer whether something is well made. It is whether it really came from who it claims, and whether you can establish that without trusting the thing you are trying to check.

It is worth being clear about where this leaves you, because the framing determines whether the rest of this lesson helps. Spotting these threats before you act on them is critical to security, and the first line of defense is human judgment and awareness rather than a filter. That is not a comforting statement about how capable people are. It is a statement about where the decision sits: somewhere in the chain, a person reads the message and either does the thing or does not. Diane was that person, three of her colleagues were also that person, and the difference between the outcomes was a habit rather than a tool.

The three families of AI fakes

You will mostly meet three kinds. Knowing the family tells you roughly where to look, with the important caveat that looking is the weaker half of the job.

AI-written text: phishing and pretext

This is the most common and the most dangerous because it scales. An attacker can send 50,000 tailored emails as easily as one. The writing will be clean, so the danger signs have moved out of the prose and into the ask and the route.

  • It creates urgency and supplies a reason not to check, such as asking you not to loop in finance because the matter is sensitive.
  • It asks you to move money, reset credentials, share data, or click a link to verify something.
  • The sender's display name is right but the actual address is off by a character, or it arrives from a free email domain.
  • It references a real project but asks for something slightly outside the normal process for that project.

There are also textual tells, and they are worth knowing while acknowledging they are fading. AI-generated text is often slightly off in ways that are hard to pinpoint: unusual word choices in formal emails, grammar that is technically correct but phrased awkwardly, a tone that does not match the person it claims to come from, and inconsistent formatting. Register is a common miss in both directions. A colleague who would normally write "can you send me the Q3 report" appears as "I am writing to request that you transmit the quarterly report for Q3," or in the other direction adopts a chatty tone that has never appeared in a work email. Requests that do not quite make sense for the context belong here too, such as being asked to confirm your password and recent transactions, which nobody legitimate has ever needed. And links that are subtly misspelled or routed through a shortening service, which hides where you are actually going.

Synthetic voice: the deepfake call or voicemail

Voice cloning needs only a short sample, and senior officials have hours of public audio online from hearings, webinars and recorded meetings. The fake call typically impersonates someone with authority over you and asks you to bypass a step. It avoids video, pushes urgency, discourages you from confirming, and requests an action that normal process would route through a system rather than a phone call.

The audio tells that people are taught are real and shrinking: unnatural pacing or rhythm, no natural breathing between sentences, a slightly synthetic quality, missing verbal fillers such as um and uh, and unusual emphasis or intonation. Every one of these has improved noticeably in the time this training has existed, and the ones that remain are the ones you would only notice if you were already suspicious.

Synthetic video and images

A fake video of a public figure, a fabricated screenshot of an internal memo, a forged signature on a PDF. The video indicators people look for are unnatural eye movement, inconsistent lighting between the face and the background, subtle jittering in movement, thin or simplified background detail, unnaturally smooth transitions, lip sync that is off by a frame or two, and inconsistent skin texture.

For documents, the tell is rarely visual any more. It is provenance: can you find the same document in the official system of record, and does its date make sense against everything else you know? A leaked memo that nobody can locate in the records system is a claim about a memo rather than a memo.

What an indicator list is actually for

Here is the correction that matters more than any item on those lists. Deepfakes are improving rapidly. What was obviously fake two years ago is convincing now, and in a few years these things might be indistinguishable from real. That trajectory has one direction, and every indicator above sits on it.

Which means an indicator list is a way of catching the careless attacker, not a test of authenticity. Finding a tell is informative: something is wrong. Finding no tells tells you almost nothing, because the absence is equally consistent with a competent fake, a good tool, and a real message. Passing your visual inspection only means whoever made it was not sloppy. Treating absence of evidence as evidence of authenticity is the single most reliable way to be fooled by the next generation of these, and it is a mistake that gets more expensive every year.

One specific belief is worth dismantling because it inverts the truth. It is often taught that AI-generated phishing shows generic personalization, using your name and little else, while a well-researched message referencing your actual work is more likely to be genuine or at least a more sophisticated attack. Treat specific personal detail as no signal of legitimacy whatsoever.

Council minutes, agency newsletters, conference programmes, press releases and professional networking profiles publish precisely the details that make a message feel researched. A language model can now produce the researched version at the same volume as the generic one, which means the economic reason generic phishing existed has gone. A message that opens by praising your infrastructure bill analysis from last week's briefing is not thereby safer than one that says hello. It only means the attacker read your agency's website, and public bodies publish more about their staff and their work than almost any other kind of organisation.

The same applies to the surface markers of legitimacy generally. A clean sender address, a correct signature block, a familiar tone and an accurate reference to a live project are all things an attacker can obtain or reproduce. Each one you check is a hurdle they had to clear. None of them is a verification, and stacking four of them does not add up to one.

Verification through a second channel

Because trying to spot fakes is a losing race, verification through independent channels is the more reliable approach. It is the one habit that does not degrade as the technology improves, because it does not depend on the artifact being imperfect.

For written communication: if an email asks you to do something unusual, call the person on a phone number you already know is correct, taken from your directory rather than from the message. Ask something only the real person would know. Confirm through a different medium than the one the request arrived in.

For video or audio: if you receive video of a public official, verify it through official channels or established news organisations. If you receive audio of someone, call that person and ask whether they said it. Check official websites and accounts for an authentic version of the same material.

For factual claims: if the communication asserts something, verify it independently against official agency sources, and never use the communication itself as its own evidence. A message that supplies a phone number to call for confirmation has supplied you with the attacker's phone number.

Be clear about the limits, because out-of-band verification is regularly described as the defense that beats nearly all of these, and it is not. It confirms whether a particular person sent a particular request. It does nothing when the attacker is inside a legitimate account, because the message genuinely did come from your colleague's real mailbox and calling them may confirm exactly that. It does nothing about an attachment you already opened or a link you already clicked, since the harm there occurred before you had a question. And it does nothing about a message you never doubted. Verification is the strongest habit available, which is a different claim from being sufficient, and the difference is where the remaining incidents live.

There is one more reason to prefer verification over inspection, and it is practical rather than philosophical. Inspection has to be done well every single time, by a tired person, on a message designed to discourage exactly that. Verification is a fixed procedure that produces the same answer whether or not you were paying attention when the message arrived. Habits that survive fatigue are worth more than skills that require concentration, and the attacks that succeed are almost always the ones that arrive at the end of a difficult week.

A detection drill you can run in 90 seconds

Diane did not have special tools. She had a habit. Build the same habit with a check you run on anything that asks you to act. Call it the PAUSE check.

  • P for pressure. Is someone rushing me or telling me not to verify? Urgency is the single most common ingredient in an attack, and manufactured urgency is the cheapest thing to fake.
  • A for ask. What exactly is being requested? Money, credentials, data, or a bypass of normal process? The larger the ask, the larger the check it deserves.
  • U for unusual route. Did this arrive through a channel I would not expect for this kind of request? A wire approval by voicemail is unusual. A password reset by text is unusual.
  • S for source check. Verify through a separate, known channel. Hang up and call back on the number in the directory. Do not reply to the email; start a new one to the address you already had.
  • E for escalate. If anything fails the check, report it. Reporting a real message by mistake costs five minutes. Acting on a fake can cost the agency far more.

Notice that not one of the five asks you to judge whether the artifact looks real. That is deliberate, and it is why the check keeps working as the fakes get better. An attacker can perfect the voice and cannot easily make a wire approval by voicemail into a normal thing at your agency.

Running PAUSE on the voicemail

Pressure: yes, before the auditors flag us. Ask: expedite a flagged claim, which moves money. Unusual route: yes, the director never used her cell. Source check: she called his desk line from the directory and he had not called her. Four signals, in about a minute. Escalate: she forwarded it to security, who warned the team, which is what turned one caseworker's caution into protection for the three who had already received the same call.

A worked scenario: the video nobody can verify

You receive a video that appears to show a city council member accepting a bribe. It is high definition and looks professionally shot. The council member denies it. You now hold something that is either a serious matter of public interest or a serious attack on a public official, and you cannot tell which by watching it again.

Do not share it yet, because forwarding potential synthetic media is how it acquires credibility, and every forward makes the correction harder. Check official sources: has any established news organisation reported it, and has the council member responded through an official channel? Look for the indicators, knowing they only ever produce a positive result and never a clean bill of health. Verify independently, because if this is genuinely significant, news organisations with forensic resources will investigate it. And wait for credible verification before acting on it or passing it on.

The discipline here is tolerating an unresolved question for longer than feels comfortable. The attack works on the interval between receiving something inflammatory and knowing what it is, and the only defense in that interval is not to act. That is responsible handling of potentially AI-generated media, and it is harder than any technical step in this lesson.

What to do when you spot one

Detection only matters if it turns into action. Three rules cover it.

  1. Do not engage and do not delete. Do not click, reply, or call back the number in the message. Keep it, because security needs the original to warn others and trace the source.
  2. Report through your agency's channel immediately. Most agencies have a phishing report button or a security mailbox. If you do not know yours, find out today rather than during an incident.
  3. Warn your team if it is targeted. These attacks arrive in waves against many people at once, and your report can protect the colleague who is about to receive the next one.

One reassurance to finish on. You are not expected to be a forensic analyst, and the fact that fakes will eventually be undetectable by eye is not a statement about your competence. Your job is to notice, pause, verify through a second channel, and report. Technical attribution belongs to someone else. The catch belongs to you, and Diane's catch came from knowing her director never called her cell, which is not a technical skill at all.

Anti-Patterns to Avoid

Each of these is a habit that felt like vigilance right up until it failed.

  • Relying on your ability to spot deepfakes. You believe you are good at this, so you accept video evidence without verifying it. The material is improving faster than anyone's eye, and confidence in this skill is inversely related to how recently you tested it. The correct posture is that you will eventually be fooled and your process has to work anyway.
  • Assuming an important fake would be obviously fake. The reasoning goes that if something really mattered, you would be able to tell. Sophisticated fakes are not obviously fake, and effort scales with the value of the target. The more consequential the message, the more resources went into making it convincing.
  • Treating a clean surface as a pass. Correct sender address, right signature block, familiar tone, accurate project reference. These are hurdles the attacker cleared, not evidence they are legitimate. Passing a surface check only means they were not careless.
  • Treating personalization as legitimacy. A message that references your actual work feels researched and therefore real. Public minutes, newsletters and professional profiles supply exactly those details, and a model can write the researched version at scale.
  • Trusting the source because it looks official. Phishing that appears to come from your own IT department is common precisely because it works, and attackers spoof official addresses and reproduce internal branding convincingly.
  • Verifying through the message. Calling the number in the email, replying to the thread, or clicking the confirmation link uses the attacker's channel to check the attacker's claim. Verification has to start from information you already had.
  • Treating out-of-band verification as complete. It is the strongest habit here and it does not cover a compromised legitimate account, an attachment already opened, or a message you never questioned.
  • Forwarding to ask what people think. Sharing suspected synthetic media to solicit opinions spreads it and lends it credibility. Report it up rather than circulating it sideways.

Practice Prompts

These take an afternoon between them and they are worth more than reading this lesson twice.

  • Re-read your inbox. Look at the last week of messages and apply the ask-and-route indicators to them. Note any that you acted on without checking, and what made them feel safe.
  • Rehearse the video question. Write down exactly what you would do if you received a video of a senior official making a controversial statement, in order, including who you would contact first.
  • Find the official process. Establish how your agency verifies a communication that claims to come from leadership, and confirm you could execute it today without asking anyone how.
  • Build your known-good list. Make sure the directory numbers for the people most likely to be impersonated to you are somewhere you can reach without going through email.
  • Study a known fake. Find an educational example of synthetic media, watch it closely, and note both what gives it away and what is genuinely convincing. Do this to calibrate how good these are, not to train yourself as a detector.

Reflection

The point of these is to find the specific gap between your intentions and your Tuesday morning.

  • If my director left me that voicemail today, what would I actually do, and would I check?
  • What request would I carry out without verifying, purely because of who appeared to be asking?
  • How much of my own voice and image is publicly available, and how much of my supervisor's?
  • When I last decided a message was legitimate, what was that decision actually based on?
  • Do I know my agency's reporting channel well enough to use it in the next five minutes?

Glossary

  • Deepfake. AI-generated synthetic media made to appear authentic, most often video or audio of a real person.
  • Synthetic media. Audio, video or images created or manipulated by AI, whether or not they impersonate anyone.
  • Voice cloning. Generating speech in a specific person's voice from a short sample of their real speech.
  • Lip sync. The synchronisation between audio and lip movement in video, which in fakes can be off by a frame or two.
  • Spoofing. Forging the source of a communication so it appears to come from a legitimate sender.
  • Pretext. The false but plausible story a message supplies to explain why it is asking for something unusual.
  • Out-of-band verification. Confirming a request through a separate channel whose contact details you already held, rather than through the message itself.
  • Provenance. The traceable origin of a document or file, such as being locatable in the official system of record.

This lesson is about what arrives. These cover what surrounds it.

Closing

Recognition matters and verification matters more. The indicators in this lesson are real and they are on a timer, so use them to catch the careless attacks and do not build your defense on them. Build it instead on habits that do not depend on the fake being imperfect: notice what is being asked, notice how it arrived, and confirm through a channel you already trusted before the message existed.

Diane caught hers on two details that had nothing to do with audio quality. The director never called her cell, and the claim number had one too many digits. That is what detection looks like now. It is not expertise in synthetic media. It is knowing your own process well enough to feel it when something is slightly outside it, and being willing to spend five minutes on a phone call to find out.

Key Takeaways

  • The old tells are dead. Bad grammar and blurry logos no longer signal a fake, because AI makes scams clean, personalized and high-volume at almost no cost.
  • Watch the ask and the route, not the polish. Judge a message by what it requests and how it arrived, since those are the parts an attacker cannot easily make normal.
  • Indicator lists catch the careless. Finding a tell means something is wrong. Finding no tells means almost nothing, and absence of evidence is not evidence of authenticity.
  • Personalization is not legitimacy. Minutes, newsletters and profiles supply the researched details that make a message feel real, and a model can produce them at scale.
  • Voice and video clone from public audio. A short clip from a hearing or webinar is enough, so authority on a call is not proof of identity.
  • Verify through a second, known channel. Never confirm a request using contact details inside the suspicious message, and start from information you already held.
  • Verification is the strongest habit, not a complete one. It does not cover a compromised legitimate account, an attachment already opened, or a message you never doubted.
  • Run the PAUSE check. Pressure, ask, unusual route, source check, escalate, and note that four of the five are about the request rather than the artifact.
  • Report, do not delete, and do not forward. Keep the original for security, report it fast, warn your team, and never circulate suspected synthetic media to ask what people think.
  • Detection is your job; attribution is not. You are expected to notice and report rather than trace the attacker, so a false alarm is always cheaper than a missed one.

Frequently Asked Questions

The email came from a real internal address. Does that settle it? No, for two separate reasons. Attackers spoof official addresses convincingly, and a legitimate address can be genuinely compromised, in which case the message really did come from your colleague's mailbox and every technical check will confirm it. A correct sender address is one hurdle cleared. If the request is unusual for that person or that process, verify by voice on a number from the directory, and if the answer is that they did not send it, that is now an account compromise rather than a phishing attempt and security needs to hear it that way.

I called the number in the message and someone confirmed the request. Am I fine? You verified the attacker's claim using the attacker's channel, which confirms nothing. Contact details supplied inside a suspicious message are part of the message. Verification has to start from a source you held before the message arrived: your agency directory, a number already in your phone, or an internal system. If you have already done this and acted, treat it as an incident and report it now rather than waiting to see whether anything happens.

How am I supposed to spot a deepfake if they are going to become undetectable? Increasingly you are not, and the lesson is not asking you to. That is exactly why the check is built around the request and the route rather than the artifact. An attacker who perfects the voice still has to ask you for something, and still has to reach you through some channel. A wire approval arriving by voicemail is anomalous regardless of how good the voice is, and that anomaly is what you are trained to notice.

What if I report something and it turns out to be genuine? That is the expected outcome a good share of the time and it costs about five minutes of someone's attention. The asymmetry is the whole argument: a false alarm is a short conversation, while acting on a real fake can move money, expose data, or push a wrongful decision onto a citizen. Agencies that see plenty of false positives are agencies whose staff will also report the real one. If reporting feels expensive at your agency, that is a process problem worth raising on its own.

Someone sent me a video of an official that looks damaging. Can I forward it to a colleague to get a second opinion? Do not. Forwarding it circulates potential synthetic media and lends it the credibility of having come from you, and every additional copy makes a correction harder to land. Send it to security or your communications office instead, which is a report rather than a share. Check whether established news organisations have reported it and whether the official has responded through an official channel, and hold the question open until somebody with forensic capability answers it.