To protect yourself from AI scams, put passkeys on your email and bank, agree on a family safe phrase, and make “hang up and call back” a rule you never break. Those three steps do the most. Nine smaller settings close most of the remaining gaps: alerts, card locks, virtual cards, a credit freeze, and a review of which AI tools can see your money.
Items run in order of impact, each with why, how and time needed. The summary table fits on one printed page. Facts checked on September 24, 2026.
How we checked this
We used security guidance from CISA, the UK’s National Cyber Security Centre (NCSC), the FBI’s IC3 and the FTC, plus official help pages from Chase, Capital One, OpenAI and Google. Facts checked on September 24, 2026. Time estimates are rough figures for one person doing each step once.
The checklist at a glance
| # | Step | Why it matters | Time (est.) |
|---|---|---|---|
| 1 | Passkeys on email, phone carrier and bank | A fake login page cannot capture a passkey | 10–20 min |
| 2 | Family safe phrase | Defeats cloned voices | 5 min |
| 3 | Hang up and call back, always | Defeats every impersonation script | 0 min, a habit |
| 4 | Transaction alerts on every account | You see fraud within minutes | 10 min |
| 5 | Treat Zelle and payment apps like cash | Sent payments often cannot be reversed | 5 min |
| 6 | Freeze your credit at all three bureaus | Blocks new accounts in your name | 20–30 min |
| 7 | Virtual card numbers for online and agent purchases | Limits damage from one leaked number | 10 min |
| 8 | Know where your card lock is | Stops new purchases in seconds | 2 min |
| 9 | Review AI tools connected to your finances | Removes access you forgot you gave | 10 min |
| 10 | Review apps connected to your Google account | Closes old doors into your email | 10 min |
| 11 | Make social profiles private | Less voice and video for cloning | 15 min |
| 12 | Learn the payment red flags and where to report | Stops the final step of most scams | 5 min |
The three changes with the biggest effect
1. Put passkeys on the accounts that control everything else.
Why: Your email is the reset button for every other account, including your bank. AI makes convincing phishing pages cheap, so we want a login a fake page cannot capture. The NCSC says passkeys “are resistant to phishing, as they can’t be intercepted, reused or stolen like passwords”, and that passkeys are always as secure as, or more secure than, two-step verification with the strongest password. CISA ranks the options: a code sent by text or email is the simplest form of multifactor authentication, an authenticator app is stronger, and phishing-resistant methods such as a FIDO security key are “the gold standard.” A CISA advisor puts the reason plainly: people will fall for a good con, and phishing-resistant login means the attacker still fails.
How: Open the security settings of your email account first, then your bank, then your mobile carrier. Look for “passkey” and create one. The NCSC notes that your phone’s built-in credential manager (Apple Passwords, Google Password Manager and similar) creates, stores and syncs it. Where a service offers no passkey, choose an authenticator app over text codes.
Time: 10–20 minutes for the three most important accounts.
2. Agree on a family safe phrase.
Why: The FTC warns that with “a short audio clip — maybe from content posted online — and a voice-cloning program, a scammer could call you and sound just like your family member.” The FBI lists the fix first in its December 2024 alert on AI-enabled fraud: “Create a secret word or phrase with your family to verify their identity.”
How: Pick a phrase that never appears online, share it in person, and agree that anyone asking for money in a hurry must say it. The FTC’s backup, when there is no phrase, is to ask something only the real person would know.
Time: 5 minutes at the dinner table. Our 60-second check for the deepfake family emergency call walks through the whole call.
3. Hang up and call back on a number you already know.
Why: Almost every AI scam needs you to stay on the line. The FBI advises you to verify callers “by hanging up the phone, researching the contact” and calling back. The FTC says the same: use a phone number you know is right.
How: For your bank, use the number on the back of your card or in the official app. For family, use the number saved in your contacts, never one the caller gives you. A real bank will not object to you hanging up.
Time: None to set up. It only works if you do it every time.
Bank settings most people never turn on
4. Turn on transaction alerts for every account.
Why: An alert turns a fraud you would find on next month’s statement into one you see within minutes, while there may still be time to act. Chase, for example, offers alerts “by text or email for low balances, large transactions, account activity, payments and more.” Most major banks offer something similar, though the exact options vary.
How: In your bank app, find Alerts (often under Profile or Settings). Turn on alerts for every card purchase or for purchases above a low amount, for outgoing transfers and payments, for new payees, and for password or contact-detail changes. Repeat for each card and account.
Time: About 10 minutes across a typical set of accounts.
5. Treat Zelle and payment apps like cash.
Why: Chase states that once you send money to someone already enrolled with Zelle, “you can’t cancel it,” and “you most likely will not get it back.” It also says Zelle and Chase “do not provide protections if you make a purchase for goods using Zelle.” Its list of common scams on the same page includes bank impersonators and fake emergencies, the two scripts AI voices make more convincing.
How: Only send to people and businesses you know. Check the “Enrolled with Zelle as [name]” confirmation before you send. For purchases, use a card, which may carry purchase protection. Transfer limit settings vary by bank, so ask yours whether you can view or lower your limits in the app.
Time: 5 minutes to check your limits and payees.
6. Freeze your credit at all three bureaus.
Why: A freeze stops anyone, including a scammer using your stolen details, from opening new credit in your name. The FTC confirms it is free to place and lift, lasts until you lift it, and does not affect your credit score. A fraud alert is weaker: it asks lenders to verify your identity but does not block new accounts.
How: Contact Equifax, Experian and TransUnion separately. A freeze at one does not cover the others. Keep the PINs or logins somewhere safe, and lift the freeze temporarily when you apply for credit yourself.
Time: 20–30 minutes for all three.
7. Use virtual card numbers for online shopping and AI agents.
Why: If you give a merchant or a shopping agent a virtual number instead of your real one, a leak exposes only that number. At Capital One, a virtual card is a unique number tied to your account, and a merchant-specific version works at only one store. You can lock or unlock virtual cards “at any time without affecting your ability to make other purchases.”
How: At Capital One, create one in the mobile app, on the website, or through Google Pay in Chrome. Note the limits: eligibility depends on the card, virtual cards work only for online purchases in the U.S., and they cannot be added to Apple Pay or Google Wallet. Deleting a virtual number declines any recurring charges on it. Other issuers offer similar tools under different names. Pair this with the controls in our guide to spending limits for AI agents in ChatGPT, Gemini and your card.
Time: About 10 minutes to set up your first one.
8. Know where your card lock is before you need it.
Why: A lock stops new purchases in seconds, and you can undo it if the card turns up. In the Chase app, the steps are: select the card, swipe up to “Account services,” tap “Lock & unlock card,” and flip the toggle.
How: Find the lock in each of your card apps now, when you are calm. Note one caution from Capital One: if the physical card is locked, purchases on its virtual cards won’t go through either.
Time: 2 minutes per card.
How to review which AI agents and apps can touch your money
9. Review AI tools connected to your finances.
Why: Every connection you approve is a door, and it stays open until you close it. Know what each one can do. OpenAI’s help page for Finances in ChatGPT says ChatGPT can see transactions, balances, subscriptions, investment holdings and credit information. It also says ChatGPT cannot move money, pay bills, change account settings or make trades. Finances is available in the U.S. to Plus and Pro users.
How: In ChatGPT, open the Finances page and its Accounts tab to see each connected account and remove any you no longer want. To cut everything, disconnect Finances in Settings. OpenAI says synced data is deleted from its systems within 30 days. Past conversations are not removed automatically, so delete those separately. Our walkthrough of connecting your bank to ChatGPT through Plaid covers the details. For shopping agents that can spend, check the spending controls and cancellation steps in our Amazon “Buy for Me” guide.
Time: About 10 minutes.
10. Review apps connected to your Google account, and close old ones.
Why: Every “Sign in with Google” click leaves a small route into the account that resets everything else.
How: Google’s help page points to myaccount.google.com/linkedapps. There are three kinds of connection: Sign in with Google, linked accounts, and apps with access to your Google account. Open each, choose the app, and use “Stop using Sign in with Google,” “Delete link” or “Remove access.” Google warns that removing a link does not delete data the other service already holds, so close accounts you no longer use with the service itself. Amazon offers a similar review for apps using Login with Amazon; check Amazon’s own help pages for the steps.
Time: About 10 minutes, longer if your list is long.
Two habits that finish the job
11. Make your social profiles private.
Why: Voice cloning needs a sample. The FTC notes a short clip, “maybe from content posted online,” can be enough. The FBI recommends making social media accounts private and limiting followers to people you know.
How: Switch profiles to private, prune followers you don’t know, and think twice before posting videos of family members talking.
Time: About 15 minutes.
12. Learn the payment red flags and where to report.
Why: Every scam ends with a request for money in a form that is hard to get back. The FTC lists the usual forms: a wire through a company like Western Union or MoneyGram, cryptocurrency, a payment app, or gift card numbers. The FBI adds: “Do not send money, gift cards, cryptocurrency, or other assets to people you do not know.”
How: Any request that combines urgency with one of those payment methods is a scam until proven otherwise. Report scams at ReportFraud.ftc.gov and to your state attorney general, as the FTC advises. If money has already left, go straight to our guide for the first hour after your money is stolen.
Time: 5 minutes to read, and a copy on the fridge.
What to watch out for
- Voice verification at your bank. The FBI notes that criminals clone voices to get into bank accounts. If your bank uses your voice to confirm your identity on the phone, ask whether you can switch to another method.
- Losing your phone. Passkeys live on your devices. Before relying on them, check that they sync to a second device or keep a backup method so you are not locked out.
- Fake “security” calls. A caller posing as your bank’s fraud team who asks you to move money or read out a code gets the same answer: hang up and call back (item 3).
- Settings differ by bank. We used Chase and Capital One as examples because their help pages are public. Your bank’s menus and limits will differ. For legal questions about liability after a loss, talk to your bank and, if needed, a consumer-protection attorney.
For the full list of scam patterns these steps defend against, see our catalog of AI scams that steal money in 2026.




