News2026.07.30 08:00

AI-powered scams appear in Lithuania: how not to fall victim

Grėtė Ubartaitė, LRT.lt 2026.07.30 08:00

Even calls from a close relative should be treated with caution, as AI-powered scams are now taking place in Lithuania. A Vilnius resident, Domantas (his surname is known to LRT but has been withheld), shared his experience with LRT.

"My sister called me. Her photo, name and phone number all appeared on my screen. I answered, and I heard my sister asking for help because she was in an accident. It immediately struck me as strange because my sister doesn't drive," he said.

Realising the call might be a scam, he ended the conversation and immediately rang his sister. She told him she was at home watching TV and had never called him.

After hearing what had happened, she remembered receiving a phone call some time earlier from a company whose name she could no longer recall. The caller had tried to sell her a product or service. The conversation lasted several minutes before she firmly told the salesperson she was not interested.

Domantas said he had heard about similar scams before, but until it happened to him, he had assumed they were more myth than reality. He described the trick as highly convincing.

How does it work?

Šarūnas Grigaliūnas, head of the Cyber Security Competence Centre at the Kaunas University of Technology (KTU), told LRT that scammers posing as relatives, bank employees, police officers or other trusted figures over the phone was nothing new.

"However, generative artificial intelligence has changed one crucial thing: fraudsters no longer have to convincingly imitate a person themselves. They can use a voice that sounds like a real family member.

According to Grigaliūnas, this type of scam usually consists of several stages.

First, fraudsters gather information about their target in advance, including their name, phone number, family relationships, social media profiles, photographs, videos, comments, workplace, place of residence and other publicly available information.

Some of this information comes from social media, some from leaked databases and some from previous scam attempts.

He stressed that criminals do not need lengthy recordings or extensive personal information. By publicly sharing relatives' names, birthdays, schools, pets' names and other personal details, people can unknowingly provide material for social engineering attacks.

Likewise, a short audio or video clip posted on social media may be enough for criminals to clone someone's voice.

"In some cases, fraudsters deliberately call a person, ask a few harmless questions and use the conversation to obtain natural voice samples.

"In the simplest scenario, they prepare AI-generated phrases in advance. More sophisticated attacks use real-time voice conversion, where the fraudster's speech is processed so it sounds like someone else's voice.

"In even more advanced schemes, AI can be combined with scripted conversations, automated dialogue and personal information about the victim," he said.

Grigaliūnas also pointed out that seeing the name of someone you know on your phone does not necessarily mean the call is coming from their device.

"If fraudsters spoof the caller ID, your phone may display the contact exactly as it is saved in your address book. The technology itself is not the attack. It simply creates the illusion of trust.

"The real mechanism is social engineering: creating a sense of urgency, fear or shame, asking the victim not to tell anyone, urging them to transfer money immediately, hand over a bank card, approve a transaction or reveal a PIN, Smart-ID code or login credentials," he said.

He also warned that even if people realise they are speaking to a scammer, they should avoid prolonging the conversation. The goal is not only to avoid losing money, but also to avoid giving away additional personal information.

"The longer someone talks, the more the fraudster learns: how they react, the names of family members, the nature of their relationships, which details seem believable and which questions cause stress. A longer conversation also provides more voice samples.

"We should not exaggerate and think that a single word is enough to steal someone's identity. But longer, more natural speech helps criminals capture a person's intonation, speaking pace, emotional reactions and characteristic expressions. That information can be used in future attacks," Grigaliūnas said.

How can you tell it's a scam?

According to Grigaliūnas, the most important thing to understand is that a familiar voice or recognised phone number is no longer enough to verify someone's identity. Instead, people should assess the situation as a whole.

The cybersecurity expert said several warning signs may indicate that the person on the phone is not a loved one but a scammer.

Such calls are often unexpected and emotionally charged. The caller, posing as a relative, may claim to have been in a car crash, arrested, admitted to hospital or hit by another emergency.

They then urge the victim to transfer money immediately, hand over cash, buy gift cards, provide security codes or open a link.

Scammers also frequently insist that the victim keep the conversation secret, avoid contacting the police and not call back to verify the story. They may refuse to provide a family-agreed security phrase and try to keep the victim on the phone.

Other clues include inconsistencies in the caller's story.

Although the voice may sound familiar, they may phrase sentences differently, get family events wrong, confuse places, names or dates, or display technical oddities such as unnatural pauses, delays, unusual background noise, a monotone voice, overly perfect speech or repetitive phrases.

"However, relying solely on technical signs is risky because AI-generated voices are improving rapidly," Grigaliūnas warned.

He advised people to verify a caller's identity through an independent channel by finding a trusted phone number themselves and calling back. He also recommended paying close attention to the caller's tone of voice, choice of words and the possibility that AI voice cloning may be involved.

Families can also agree on a secret security phrase to use if someone ever claims to be a relative and asks for help. He stressed that people should never make financial decisions based on a single phone call.

"It can be a short sentence or question that only close family members know the answer to. But it should not be a child's name, a pet's name, a date of birth or any other information that could be found on social media. It should be artificial, non-intuitive and never made public," he said.

Grigaliūnas also advised limiting the amount of personal information shared online.

Police: scammers have already stolen more than €21m this year

The use of AI in fraud is not yet widespread, but criminals are increasingly incorporating the technology into their scams, according to Ramūnas Matonis, head of communications at the Lithuanian Police Department,

"As AI continues to develop, fraudsters are likely to exploit it more frequently. There is a strong possibility they will increasingly use AI to send voice messages, generate videos and deploy other AI-powered tools. The public must remain critical.

"If there is even the slightest doubt about whether a call is genuine, end the conversation and contact your relative through another communication channel that you normally use. People should also avoid making hasty decisions," Matonis told LRT.

He said there are currently no statistics showing how often AI is used in fraud cases. However, broader fraud figures illustrate the scale of the problem.

Police recorded 4,003 fraud cases in 2023, rising to 4,739 in 2024 before falling to 4,398 in 2025. Between January and May this year, 1,918 cases were recorded, 9.4% fewer than during the same period last year.

"This year alone, fraudsters have stolen more than €21m from victims. Last year, they stole more than €34m over the course of the year," Matonis said.

LRT has been certified according to the Journalism Trust Initiative Programme