Rosa opens an email that seems to come from her flower supplier. It is warm and clear, with no typos at all.
It says the supplier has a new bank account and that today's order will be held unless she pays now.
Rosa almost reaches for her card. Then she remembers this week's lesson and reads it again, slowly.
Read the example below. It was written for this lesson. It contains several warning signs to find.
Remember: the writing being clean tells you nothing. Look at what the message asks you to do.
| Line in the email | Is it a warning sign? |
|---|---|
| Please send today's payment to a new account. | ? |
| The order will be held unless she pays within two hours. | ? |
| Reply only to this email, because the phone is down. | ? |
| Gift cards are fine too. | ? |
| Thank you for being a loyal customer. | ? |
Rosa wonders whether to paste the email into a chatbot and ask if it is a scam.
NIST notes that generated content may not say when it is unsure. NIST also notes that AI tools can be attacked.
Two named attacks are prompt injection and data poisoning. Both tamper with how a tool behaves.
So a tool's answer is not proof either way. The call back to a known number is still the real check.
Sources: FBI IC3, Criminals Use Generative AI to Facilitate Financial Fraud (2024) Β· NIST AI 600-1, Generative AI Profile (2024)
Tomorrow: what this looks like at home, at school and at work.