Scams, privacy, and AI-generated deception
The digital defense checklist
Nine checkpoints across three fronts — the manipulation tactics that ask for money, the settings that leak your data quietly, and the synthetic media built to fool the people you trust. Work through what applies, then keep the last tab bookmarked for the day you need it.
FTC / CISA social engineering defense framework
NIST SP 800-63B / GDPR privacy by design
ISO/IEC 42001 (AI management) / C2PA standards
This field isn’t saved or sent anywhere — it clears when you leave the page. Write the real one down somewhere private instead.
What to do in the moment — not a checklist, a script
Suspected deepfake or cloned-voice call
- Hang up immediately.
- Don’t say “yes” or confirm any personal detail before you do.
- Call back on a number you already had saved — never one they just gave you.
- Ask for the pre-agreed safe word before discussing anything further.
Credential or financial compromise
- Freeze the affected card or account immediately through your bank’s app or hotline.
- Revoke active sessions from every account’s security dashboard.
- Change every password that was shared or reused, and replace it with a unique passkey where you can.
Reporting it
Reporting doesn’t usually recover funds already sent, but it’s what feeds the databases that get scam numbers, domains, and account details blocked for the next person.