Deepfake Scams: Can You Still Trust a Phone Call?

Mr. Ali Haji
Deepfake Scams: Can You Still Trust a Phone Call?

How AI-generated voices, videos and documents are rewriting the rules of financial fraud in Bahrain and the GCC—and what consumers and banks can realistically do to stay ahead.

Introduction

The phone rings late in the evening. The voice on the line is your son’s—the same voice, the same nervous laugh—and he is in trouble and needs money, right now. There is just one problem. Your son is asleep in the next room.

For years, most of us carried a quiet confidence that we would never be fooled. We would spot the clumsy grammar, the odd link, the caller who could not answer a simple question. Scams were easy to catch because they were badly made.

That confidence has quietly expired. Artificial intelligence has erased nearly every warning sign we used to rely on. The message now reads perfectly. The website looks exactly right. And the voice on the phone belongs to someone you love.

As banking in Bahrain grows faster and more digital—instant transfers, remote onboarding, biometric logins—the question shifts underneath us. It is no longer whether you are sharp enough to spot a scam. It is whether spotting one is still realistically possible.

What Is a Deepfake Scam?

In plain terms, a deepfake scam is fraud that uses AI-generated audio, video, images or documents to impersonate a real person or organisation.

It wears many faces:

  • A cloned voice of a relative in distress
  • A video call with someone who appears to be a manager or colleague
  • AI-generated identity documents used to open accounts
  • Flawlessly written messages that seem to come from a bank or ministry
  • Fake endorsements from public figures pushing an investment

The crucial point is that none of this is a new crime. It is an old crime in a far better disguise. The aim has not shifted an inch: to make you move your money willingly.

Why It Is Growing So Fast

Three things changed at once. The tools grew cheap, the raw material grew easy to find, and money started moving instantly.

Cloning a voice no longer needs a studio. A few seconds of audio lifted from a social media clip can be enough. Anyone who posts a voice note, a story or a short video has already handed over the raw ingredient.

The figures tell the story:

  • Deepfakes are now thought to feature in roughly one in nine fraud cases worldwide
  • Deepfake attempts in the United Kingdom rose by around ninety-four per cent in a single year
  • Cases of highly sophisticated identity fraud have climbed steeply year on year
  • Reported global fraud losses passed 12.5 billion dollars in 2024, about a quarter more than the year before

And with instant payment systems, the money is often long gone before the doubt even arrives.

An AI-cloned voice deceiving a phone user

Why It Works on Careful People

This is the part most people badly underestimate.

In one voice-cloning study, listeners correctly judged whether a voice was real only about a third of the time—and that was in calm laboratory conditions, with no pressure at all. On a tense phone call at nine in the evening, the odds sink further.

Successful scams also pull several psychological levers at once:

  • Urgency, so there is no time to check
  • Authority, with the caller claiming to be from a bank, a ministry or the police
  • Emotion, usually a loved one in trouble
  • Familiarity, because spoofing can make a number or a sender name look genuine

Banks in Bahrain have warned customers about exactly this pattern, noting that fraudsters clone numbers and sender IDs to pose as banks, government bodies, telecom operators and the police. Authorities have issued repeated alerts about waves of scam text messages carrying links that mimic official websites almost perfectly.

None of this asks the victim to be careless. It only asks them to be human.

The Hidden Risk for Banks

Consumers are the visible target. The deeper trouble is that verification itself is under attack.

Banks spent years shifting toward face and voice recognition as proof of identity, precisely because passwords were weak. The timing proved cruel. Artificial intelligence learned to imitate faces and voices at almost the very same moment.

Business surveys capture the unease. Around two-thirds of organisations expect biometric fraud to rise, and a large share brace for more AI-driven attacks, forged identity documents and AI-generated fake profiles. Financial services keeps turning up among the sectors hit hardest by identity fraud.

The result is a verification problem with no tidy answer. If a face and a voice can both be manufactured, what exactly still counts as proof that someone is who they claim to be?

The Role of AI

Artificial intelligence is also the main line of defence—which is why this is an arms race rather than a problem with a solution.

Banks and payment providers increasingly rely on AI for:

  • Liveness detection, checking whether a face is physically present
  • Behavioural biometrics, such as typing rhythm and how a device is held
  • Real-time transaction monitoring for unusual patterns
  • Scanning documents for signs of generation or tampering
  • Warning prompts that surface before a risky transfer is confirmed

That last one is worth dwelling on. Rather than blocking a payment outright, some providers now interrupt it with a pointed warning, handing the customer a moment to reconsider without stripping away their control.

The uncomfortable truth is that both sides sharpen at a similar pace—and the attackers only need to get lucky now and then.

When the Money Is Already Gone

Recovery is where this turns genuinely painful.

There is an important line between money taken from an account without permission and money the customer was talked into sending. In the second case the transfer was technically authorised, even though the consent was won through deception. That line often decides whether anyone is ever repaid.

Local reporting in Bahrain has described victims of online banking fraud struggling to recover their money, with customers, banks and wallet providers trading blame over who is responsible. Cross-border transfers make recovery harder still, because the money is usually shuffled through several accounts within minutes.

This is why prevention gets so much of the attention. Once the money has moved, the options run thin.

Why Regulation Matters

Consumer protection is a core duty of the Central Bank of Bahrain, which issues consumer alerts, publishes guidance, and tracks complaints against licensed institutions. Bahraini banking rules also require boards to oversee electronic banking risks—secure authentication, audit trails, incident response, and customer fraud awareness.

But AI-driven fraud raises thornier questions:

  • Who should shoulder the loss when a customer is deceived rather than hacked?
  • Should banks be required to refund victims of authorised transfers made under deception?
  • Should AI-generated audio and video be labelled or watermarked?
  • What should replace voice authentication now that voices can be cloned?
  • Should high-value transfers to new recipients carry a mandatory delay?

Different jurisdictions are landing on different answers, and those answers will decide how much of the risk sits with the customer and how much with the institution.

So, How Worried Should You Be?

The honest answer is: worried enough to change your habits, but not so worried that you abandon digital banking altogether.

Most of the effective defences are simple and unglamorous. Verify through a channel you chose, not the one that reached out to you. Call back on a number you already have. Agree a family code word for emergencies. And treat urgency itself as the warning sign—because urgency is the one ingredient every scam cannot do without.

Technology will keep improving on both sides. Habits are the part you actually control.

Conclusion

Artificial intelligence did not invent a new kind of fraud. It industrialised an old one, sanding away the small flaws that used to protect us.

For Bahrain and the wider GCC—where digital banking is widespread and payments increasingly instant—the real challenge is a change of mindset. The old advice was to look for the thing that seemed wrong. That advice no longer works, because more and more, nothing does.

The new advice is simpler, and harder: verify independently, every single time, no matter how convincing the request feels.

Because the most dangerous scam is not the one that sounds fake.

It is the one that sounds exactly like someone you trust.

FAQs

1. What is a deepfake scam?

It is fraud that uses AI-generated voice, video, images or documents to impersonate a real person or institution in order to obtain money or information.

2. How much audio does a voice clone need?

Very little. A few seconds pulled from a public video or a voice note can be enough for today’s tools.

3. Can people tell a real voice from a cloned one?

Usually not. In one study, listeners judged voices correctly only about a third of the time—and that was without any emotional pressure.

4. Are banks in Bahrain warning customers about this?

Yes. Banks and authorities have issued repeated warnings about spoofed numbers, fraudulent text messages, and callers impersonating banks, ministries and the police.

5. What is the single most effective protection?

Independent verification. End the call and reach the person or institution yourself using a number you already have—never one supplied during the call or message.

DeepfakesFinancial FraudArtificial IntelligenceCybersecurityDigital BankingConsumer Protection
AH

Mr. Ali Haji

College of Administrative and Financial Sciences — Gulf University, Bahrain

Last Updated: July 2026