What you'll learn
- Why AI has changed the economics of deceiving people, not the tactics
- What a synthetic persona is, and why photographs no longer prove anything
- The pattern that befriending attacks follow, and where it always leads
- Why "they knew things about me" is the weakest reason to trust somebody
- Why a familiar voice is no longer identification
- Out-of-band verification: the one habit that defeats nearly all of this
- Why urgency and secrecy are the two reliable warning signs
- What to do when you realise something is wrong — and why it is never your fault
Key terms and definitions
| Term | Meaning |
|---|---|
| Synthetic persona | An invented identity built with generated text, images and detail |
| Grooming | Building trust with somebody in order to exploit or abuse them |
| Social engineering | Manipulating a person into giving access, money or information |
| Pretext | The false reason given for a request |
| Out-of-band verification | Checking a request through a different channel you already trust |
| Voice cloning | Reproducing somebody's voice from a short sample |
| Phishing | Messages designed to obtain credentials, money or access |
| Isolation | Separating somebody from the people who would notice |
| Escalation | Moving step by step from harmless to harmful requests |
| Payment fraud | Deception whose goal is getting money transferred |
Core concepts
What actually changed
None of the tactics in this topic are new. Pretending to be somebody else, building false trust, inventing an emergency — all of it is older than the internet.
What AI changed is the cost. Three things used to limit this kind of harm:
- Effort. Maintaining a convincing fake relationship took real time. One person could run only a few.
- Language. Clumsy writing and obvious errors gave attackers away.
- Depth. A fake identity fell apart under questioning, because inventing consistent detail is hard.
All three limits have weakened. Generated text is fluent in any language. A persona can hold hundreds of conversations at once, never gets tired, never gets bored, and never slips out of character. Convincing photographs cost nothing.
So the right conclusion is not "there are new tricks to learn". It is that the old tricks now arrive polished, in volume, and aimed at people who would previously never have been targeted — including people whose language made them hard to reach before.
Synthetic personas
An invented identity can now come complete: a face that belongs to nobody, a plausible history, interests that match yours, photographs that pass a reverse image search because the image has never existed anywhere else.
Which retires several checks people still rely on:
- A photograph proves nothing. Nor do several, nor does one holding a handwritten sign.
- Good English, or good Spanish, proves nothing. Fluency was a filter; it has stopped being one.
- Consistency proves nothing. A system can keep a story straight indefinitely.
- A video call proves less than it did, and will prove less still.
What does still carry weight is independent existence: a person with a history you can reach through channels they do not control — a school, a workplace, a mutual friend you knew first, a family member you can phone on a number you already had.
How befriending attacks run
This is a pattern, not a list of tricks, and recognising the shape is what protects you. It is also worth knowing because it is deliberately slow — slowness is what makes it feel unlike an attack.
Contact. Often from a plausible adjacent place: a game, a shared interest, a group chat, a friend-of-a-friend request.
Attention. Unusually interested, unusually available, unusually kind. This is the part that works, because being listened to is genuinely pleasant and genuinely rare.
Alignment. They happen to share your interests, your sense of humour, your frustrations. AI makes this trivial — the persona can be shaped around what you reveal.
Isolation. Gently, this becomes something separate. Our thing. They wouldn't understand. Don't mention it yet. A move to a different app, one with fewer people in it and less history.
Escalation. Small steps that each seem reasonable given the last one: a photograph, then another, a secret, a favour, money, a meeting.
Pressure. Once something exists to lose, the tone changes — guilt, obligation, or a threat.
Two things follow. First, every stage before the last is pleasant, which is exactly why it works and why nobody in it feels foolish. Second, isolation and secrecy are the signature. Someone with good intentions does not need you to keep them hidden, and does not need to be the only person you talk to.
"They knew things about me"
People often explain their trust by saying how much the other person knew. That is backwards, and it is worth seeing clearly.
Information about you can be assembled: from your own posts and old accounts, from friends' public profiles, from a leaked database, from what you said earlier in the same conversation and have now forgotten mentioning. None of it indicates goodwill — only effort, and effort is now cheap.
The same logic covers the convincing message that appears to come from somebody you know. Knowing details is not identity. The question is never "do they know things about me?" but "have I confirmed who this is through a channel they do not control?"
A familiar voice is no longer identification
A short sample of somebody's speech — a voice note, a video, a few seconds of a livestream — is enough to reproduce their voice.
The common form this takes is a call or message, apparently from a family member or friend, in distress and needing money or a code urgently. It is effective because it bypasses thinking: the voice is right, the fear is real, and the urgency is the point.
The rule is simple and should be agreed in advance, before it is needed:
Hang up. Call back on the number you already have.
Not a number given to you in the call. Not a reply to the message. A number you already had, or a different route entirely. If they are fine, you have lost a minute. If the call was fake, you have lost nothing at all.
Some families agree a spoken code word for emergencies. That works, provided it is something never written down online.
Out-of-band verification
One habit defeats nearly everything in this topic, so it is worth naming properly.
Out-of-band verification means checking a request through a different channel that you already trusted before the request arrived.
- A message from your bank → log in the way you normally do, or phone the number on your card
- A message from a teacher → ask at school
- An email about an order → open the retailer's site yourself
- A friend asking for money → phone them
- A new online friend claiming to be a student somewhere → something only a real student there could confirm
What makes it work is that the attacker controls the channel they contacted you on, and nothing else. That is also why "they sent me a link to verify" is never verification: the link is inside the channel they control.
Urgency and secrecy
Of all the warning signs, two are reliable enough to act on by themselves.
Urgency. Right now. Before it closes. Don't wait. Urgency exists to prevent the pause in which you would notice. Almost nothing genuine collapses because you took ten minutes to check — and anything that genuinely cannot wait will survive you confirming it.
Secrecy. Don't tell anyone. They'd be angry. This is just between us. Legitimate requests do not require that the people who care about you be kept out. Secrecy is not a sign of closeness; it is the removal of the person who would have said something.
If a message carries both, treat that as sufficient reason to stop and check, whoever it appears to be from.
Payment fraud
Where the goal is money, the shapes repeat: a relationship that eventually needs a loan; an investment that must be entered today; a fee to release a prize; a refund that requires your details; a charity after a disaster; a payment to an account that has "changed".
Two habits cover nearly all of it.
- Never send money to somebody you have not met in person, however long you have talked.
- Treat any change of payment details as suspicious, and confirm it through a channel you already had.
And a point worth keeping in mind: irreversible payment methods — transfers, cryptocurrency, gift card codes, vouchers — are requested precisely because they cannot be recalled. Being asked for one of those is itself a warning.
If it has already happened
This section matters more than any of the above, because the usual reason people come to harm is not that they were fooled. It is that they were too ashamed to tell anyone, and the pressure continued.
If you realise something is wrong:
- Stop replying. You owe a stranger nothing, and there is no explanation you need to give.
- Do not send money, images, or anything else — complying has never once ended it.
- Keep the evidence. Screenshots, usernames, account links. Do not delete the conversation.
- Tell somebody now. A parent, a teacher, a safeguarding lead, an adult you trust.
- Report the account to the platform, and the bank immediately if money moved.
- Contact the police where money, threats or images of a young person are involved. This is criminal conduct, not an embarrassment.
And the part worth stating plainly: if somebody built a false identity in order to deceive you, the fault is theirs. These attacks are professionally run and designed to work on intelligent, careful people. Being deceived by one says nothing about you. Staying silent is the only thing that keeps it going, and telling somebody early is what ends it.
Where to get help
If somebody is deceiving, pressuring or defrauding you or a friend, these are the routes that exist. Start with a trusted adult or your school's safeguarding lead — everything below is easier with somebody alongside you.
United Kingdom
- Childline — 0800 1111, free and confidential, or chat at childline.org.uk
- CEOP Safety Centre (National Crime Agency) — ceop.police.uk, for somebody online asking a young person for images, or an adult communicating with a child inappropriately. CEOP does not handle bullying, fake accounts or hacked accounts; report those to the platform and your school.
- Action Fraud — 0300 123 2040 or actionfraud.police.uk for fraud and cybercrime in England, Wales and Northern Ireland. In Scotland, report to the police on 101.
- Police — 999 in an emergency, 101 otherwise
Trinidad and Tobago
- Children's Authority — 996 or 800-2014, to report abuse or reach Protective Services
- ChildLine — 800-4321 or 131
- Police — 999
Jamaica
- 211 — the free 24-hour child abuse helpline run by the Child Protection and Family Services Agency through the National Children's Registry. This replaced the old 888-PROTECT number.
- Safe Spot — 888-723-3776
- CISOCA, the police unit for sexual offences and child abuse — 876-926-4079, or WhatsApp 876-224-5352, 24 hours
- Police — 119
Barbados
- FMH Sandy Lane Charitable Trust Children's Helpline — 537-3644, 832-3644 or 266-3644, 24 hours
- Child Care Board — 1-246-535-2800, or childcareboard@barbados.gov.bb
Guyana
- 914 — free, 24 hours, for child abuse, sexual offences and domestic violence
- Childcare and Protection Agency — 613-1811, including by WhatsApp on +592-613-1811
The Bahamas
- National Hotline for Child Abuse — (242) 322-2763, 24 hours
Elsewhere in the Caribbean
- Antigua and Barbuda — Friends Hotline, 1-268-800-4357
- St Kitts and Nevis — Probation and Child Protection Services, 662-6833
- St Lucia — St Lucia Crisis Centre; St Vincent and the Grenadines — MyChild Helpline
- Grenada — Sweet Water Foundation child helpline; Belize — Child Protective Services
- Suriname — Kinder- en Jongerentelefoon, bel123.org; Sint Maarten — Department of Youth Affairs, 542-3718
- Child Helpline International (childhelplineinternational.org) lists child helplines country by country
Caribbean advice worth reading before anything goes wrong
- UNICEF Eastern Caribbean — Think before you click, a cyberbullying handbook for secondary students, at unicef.org/easterncaribbean
- SWIPE SAFE Youths (CARDTP) — cardtpconnect.org/swipesafeyouths, written for 13 to 24 year olds in the region
- OECS Child Online Protection — oecs.int/en/child-online-protection
United States
- NCMEC CyberTipline — missingkids.org, for online exploitation of a young person
Canada
- Cybertip.ca — the national tipline for online sexual exploitation of children
- Kids Help Phone — 1-800-668-6868
Australia
- eSafety Commissioner — esafety.gov.au/report
- Kids Helpline — 1800 55 1800, for anyone aged 5 to 25
Anywhere else
- findahelpline.com lists verified helplines by country, including child helplines
- Your school, a parent or relative, and your local police remain the routes that always exist
If money has moved, contact the bank immediately — speed matters more than working out what happened first.
Worked examples
Example 1: Identifying the pattern (4 marks)
Over two months, somebody a student met in a game has become their closest friend, moved the conversation to a private app, and asked them not to mention it at home. Identify the concerns.
- The move to a separate app with fewer people and less history is isolation (1 mark)
- Asking that it be kept from family removes the people who would notice (1 mark)
- The pattern is slow and pleasant by design, which is why it does not feel like an attack (1 mark)
- Somebody with good intentions does not need to be hidden, so secrecy alone is reason to tell an adult (1 mark)
Example 2: Voice cloning (3 marks)
A student gets a call in a relative's voice, upset, asking them to send money immediately. State what they should do and why.
- Hang up and call the relative back on a number they already have (1 mark)
- A voice can be reproduced from a few seconds of recording, so it is no longer identification (1 mark)
- Urgency exists to prevent the pause in which the student would check, so acting slowly is the defence (1 mark)
Example 3: Evaluating a judgement (4 marks)
A student says their online friend must be genuine, because they have sent photographs and know a lot about the student's school and family. Evaluate this reasoning.
- Photographs of a person who does not exist cost nothing and pass a reverse image search (1 mark)
- Information can be assembled from posts, friends' profiles and the conversation itself (1 mark)
- Knowing details shows effort, which is cheap, rather than goodwill (1 mark)
- Genuine confirmation needs a channel the other person does not control, such as a mutual friend known first (1 mark)
Common mistakes and how to avoid them
- Thinking the tactics are new. They are old; AI made them cheap, fluent and scalable.
- Treating photographs as proof. Faces can be generated, including with handwritten signs.
- Treating fluent language as proof. Fluency has stopped being a filter.
- Trusting somebody because they know things about you. That shows effort, not goodwill.
- Trusting a familiar voice. A few seconds of audio is enough to clone it.
- Verifying through the channel the request came from. Use one you already trusted.
- Clicking "verify" links sent with the request. The attacker controls that channel.
- Treating urgency as a reason to hurry. It is a reason to slow down.
- Treating secrecy as closeness. It removes the person who would have warned you.
- Sending money to somebody never met in person. However long the conversation has run.
- Staying silent out of embarrassment. Silence is what lets it continue.
Using this in practice
When a message asks you for anything — money, images, information, secrecy:
- Who does this appear to be from, and how do I know?
- Which channel did it arrive on, and who controls that channel?
- Can I confirm it out of band — a number I already had, in person, a site I opened myself?
- Is there urgency? Then slow down deliberately.
- Is there secrecy? Then tell somebody, which is exactly what it is designed to prevent.
- Is this payment irreversible? Transfers, crypto and gift cards cannot be recalled.
- Have I met this person in real life?
- Who would I least want to know about this conversation? That is usually who should.
Quick revision summary
- The tactics are old; AI removed the limits of effort, language and depth that used to contain them
- A synthetic persona can supply faces, history and consistency, so photographs and fluency prove nothing
- Befriending attacks run contact, attention, alignment, isolation, escalation, pressure — and feel pleasant throughout
- Isolation and secrecy are the signature: good intentions never require being hidden
- "They knew things about me" shows effort, not goodwill; details are not identity
- A familiar voice can be cloned from seconds of audio — hang up and call back on a number you already have
- Out-of-band verification through a channel you already trusted defeats nearly all of this
- Urgency removes the pause in which you would check; nothing genuine fails because you took ten minutes
- Never send money to somebody not met in person, and treat changed payment details as suspicious
- Irreversible payments are requested because they cannot be recalled
- If it has happened: stop replying, send nothing, keep evidence, tell an adult, report it — and know the fault is the deceiver's
A note on legal advice
Nothing in this topic is legal advice, and it should not be used as a substitute for it.
Laws differ considerably between countries, they change, and how a law applies depends on facts this material cannot know. Where this topic says something is unlawful or an offence, it is describing the general position in many jurisdictions so that you understand why the rules exist — not telling you what the law is where you live.
What this material is for is helping young people use technology, including AI, appropriately, lawfully and safely, and knowing where to go for help. For anything that has actual consequences, ask somebody qualified: a teacher, your school's safeguarding lead, a solicitor or attorney, your exam board, or the police. If something is happening to you now, do not wait for advice before telling a trusted adult.