By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Fraud Team Confirmed My Suspicion
After I reported the call, the bank’s fraud department thanked me for ending the conversation.
The investigator explained that the caller had used a classic voice phishing (vishing) technique, but with a modern twist.
Instead of an obvious scam call with poor audio quality, the criminals used AI-generated speech to sound calm, professional and trustworthy.
The technology had changed.
The objective had not.
They wanted my credit card information.
Why They Wanted My CVV
The investigator explained why the caller insisted on the three-digit security code.
A credit card number by itself isn’t always enough to make online purchases.
Many online merchants also request:
- The card number.
- The expiration date.
- The CVV security code.
If criminals obtain all of those details, they may attempt unauthorised transactions on websites that don’t require additional authentication.
That’s why your CVV should never be shared during an unsolicited phone call.
The AI Wasn’t the Real Threat
Many people assume artificial intelligence is the danger.
The investigator corrected that idea.
The real danger wasn’t the AI voice.
It was the social engineering behind it.
The criminals combined:
- Personal information.
- A convincing story.
- Artificial intelligence.
- A sense of urgency.
Technology simply made the deception more believable.
The scam still depended on one thing:
Getting the victim to trust the caller.
Warning Signs of AI Voice Scams
Looking back, several warning signs stood out.
🚩 Requests for Your CVV
Legitimate banks generally do not ask customers to reveal their CVV during unsolicited calls.
Treat such requests with extreme caution.
🚩 Pressure to Act Immediately
Scammers often claim:
- Your account is under attack.
- Your card will be blocked.
- You must act now.
Urgency reduces careful thinking.
🚩 Discouraging Independent Verification
The caller didn’t want me to end the conversation and contact the bank myself.
That was one of the clearest warning signs.
A genuine representative should not object if you choose to verify the call through official channels.
🚩 Generic Answers
Whenever I asked detailed questions, the caller responded with vague phrases like:
- “It’s standard procedure.”
- “Our system requires verification.”
Specific questions deserve specific answers.
How to Protect Yourself
As AI voice technology improves, recognising scams may become more difficult.
Fortunately, good security habits still work.
- Never share your CVV during an unsolicited phone call.
- If you receive a suspicious banking call, hang up and call your bank using the official number from its website or the back of your card.
- Enable transaction alerts for your accounts.
- Use multi-factor authentication wherever available.
- Be cautious even if the caller sounds professional or knows personal information about you.
Remember:
A convincing voice does not prove a caller is genuine.
Frequently Asked Questions
Can AI really imitate human voices?
Yes.
Modern AI can generate natural-sounding speech that may be difficult to distinguish from a real person.
However, the quality and realism can vary depending on the technology being used.
How did the scammers know my personal information?
Personal information may be obtained through data breaches, phishing attacks, public sources or other criminal activities.
Knowing your name or address does not prove someone is calling from your bank.
What should I do if I accidentally share my card details?
Contact your bank immediately using its official contact information.
The sooner the bank is informed, the sooner it can take steps to help protect your account.
Final Thoughts
Years ago, scam calls were easier to recognise.
Poor audio.
Broken English.
Obvious scripts.
Today, things are different.
Artificial intelligence can make a criminal sound calm, polite and professional.
But one thing hasn’t changed.
Legitimate organisations should not expect you to reveal sensitive information simply because someone sounds convincing.
The safest habit is also the simplest.
Never trust the caller. Verify the caller.
Because in the age of AI, your ears alone may no longer be enough to tell the difference between a real banker and a cybercriminal.
About the Author
Jackson Godwin is a Cybersecurity Consultant specialising in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
Through JacksonTechnology.com.ng, he publishes cybersecurity awareness stories, ethical hacking tutorials, compliance guides, and practical online safety advice to help individuals and organisations recognise cyber threats, prevent financial fraud, and stay secure in an AI-driven digital world.
His mission is to make cybersecurity practical, relatable, and accessible—one cyberstory at a time.






