July 27, 2026 ยท by David Gilbert ยท 3 min read ยท Cyber Security
Across talks, radio segments, client meetings, and a fair few conversations at the shop counter that started as something else entirely, one cyber security question comes up more than all the others combined: "How do I know if a message or call is actually real?" It's a great question precisely because there's no single, satisfying, one-line answer โ but there is a genuinely useful framework I give people.
Why This Question Is So Hard Now
It used to be easier to answer. Look for poor spelling, generic greetings, obviously wrong logos, a sender address that's clearly off. Those tells haven't disappeared completely, but they're far less reliable than they used to be โ AI-generated scam content increasingly reads as polished and personalised as anything legitimate, and voice and video cloning have removed the "it just sounded a bit off" instinct a lot of us used to lean on without even realising we were doing it.
The Framework I Actually Give People
Instead of trying to spot a fake by how it looks or sounds โ increasingly unreliable โ I tell people to focus on three structural questions that don't depend on production quality at all:
- Is it creating urgency? Genuine requests from genuine banks, bosses, and family members can almost always tolerate you calling back in ten minutes on a number you already had. Pressure to act "right now, don't think about it" is one of the most consistent fingerprints across scam types, regardless of how convincing the rest of the message is.
- Is it asking for something unusual through an unusual channel? A password reset request by phone call. An invoice payment change via a casual text message. A request for sensitive information through a channel that organisation doesn't normally use for that purpose. The channel mismatch is often a bigger tell than anything about how the message itself sounds or reads.
- Can I verify it independently, without using any contact details provided in the message itself? This is the single most important one. Don't call the number in the suspicious text. Don't click the link in the email to "verify your account." Go find the organisation's real number yourself, separately, and check that way instead.
Why I Lead With Structure, Not Spotting
The structural questions work regardless of how good the fake gets, because they don't depend on noticing a flaw in the production โ they depend on a behaviour pattern that's hard for a scammer to avoid entirely, no matter how convincing the audio or video becomes. As the fakes keep improving, and they will keep improving, I'd rather hand people a framework that still works in two years than a list of "tells" that'll quietly stop working as the technology moves on without most people noticing.
The Answer People Don't Always Want to Hear
Sometimes the honest answer is "you can't be completely certain just by looking or listening, so don't try to be โ verify independently instead." That feels less satisfying than a confident "here's exactly how you spot a fake," but it's the more accurate, more durable answer, and it's served the clients who've actually adopted it well, including at least one I know of who avoided a genuinely convincing impersonation scam purely by following step three and calling back on a number they already had.
The Real Takeaway
You don't need to become a forensic expert at spotting fakes. You need a habit of independent verification for anything involving money, access, or sensitive information, applied consistently, regardless of how legitimate something looks or sounds. That one habit will outlast every specific scam technique that comes and goes after it.