• Deutsch
  • English
  • WhatsApp is testing a scam warning designed to detect suspicious messages with Artificial Intelligence (AI) directly on your smartphone. It matters to anyone who receives messages, delivery notices, or login codes on a mobile device. The feature arrives as AI makes fraud more convincing and Swiss authorities warn about specific phishing campaigns.

    What is AI changing about digital fraud?

    AI accelerates both fraud and its detection. According to an interview with information security expert Oliver Hirschi, criminals can use it to create professional phishing messages, convincing deepfake voices, and automated attacks at scale. Phishing is an attempt to obtain sensitive information through deceptive messages or websites; deepfakes are artificially generated or manipulated media that imitate real people.

    The objective is not particularly new, but the quality and speed of the deception are changing. Criminals still want login details, credit card information, or approval for payments. AI helps them produce more credible wording and expand a campaign without manually writing every message.

    Attacks are also spreading across multiple channels. Hirschi describes combinations of email, Short Message Service (SMS), phone calls, and fake websites targeting credit and debit cards, Twint, mobile payment services, or online banking. One plausible message therefore proves little: the broader combination of an unexpected contact, urgency, a link, and a payment request often reveals the scheme.

    Defenders can use AI as well. Financial institutions can analyze transaction patterns, identify anomalies—unusual deviations from normal behavior—more quickly, and alert security teams to suspicious activity. That is useful support, but it does not replace human review or customer awareness.

    How is WhatsApp supposed to detect suspicious messages?

    The optional “Scam Alert” feature examines messages from unknown contacts for common signs of fraud. According to Meta, its machine learning model, a detection system trained on examples, runs directly on the smartphone. The company says message content does not leave the device for this assessment and that end-to-end encryption should remain unaffected.

    If the system detects a possible scam, WhatsApp displays a warning. You can then block or report the contact, or continue the conversation. However, the test of WhatsApp’s Scam Alert is beginning as a limited beta, and Meta has not provided a date for a broader release.

    The test does not operate entirely without data transfers. WhatsApp plans to collect aggregated information about how often warnings appear and how people respond. It says it will use differential privacy, a mathematical privacy concept intended to make it harder to draw conclusions about individual users.

    If a legitimate chat is incorrectly flagged, you can voluntarily share the last five received messages with WhatsApp. Meta intends to use this feedback to improve detection and says it will document new model versions in a public registry before release. Model parameters are also expected to be made available to security researchers.

    The reliability of the warning has not yet been independently established. In particular, it remains unclear how many genuine scams it will miss and how often it will flag harmless contacts. People in Switzerland also do not yet know when the feature will be available to them or which language versions will be supported.

    Why are warnings and SMS codes not enough?

    A warning can make you pause, but it cannot deliver a perfectly certain verdict. Criminals adjust their wording, sender identities, and conversations, while detection systems inevitably work with probabilities. A chat without a warning is not automatically safe, and a warning does not prove that the contact is a criminal.

    Microsoft also sees a need to change Two-Factor Authentication (2FA). With 2FA, a second confirmation follows the password, such as a one-time numeric code delivered by SMS. Because of the increase in AI-assisted phishing, the company has reportedly warned administrators about SMS and voice authentication and encouraged a switch to passkeys, Microsoft’s recommended alternative to SMS codes.

    The warning is not an argument against using a second factor. The weakness is that you can still enter an SMS code on a convincing imitation website or disclose it during a fraudulent conversation. AI can improve the bait, but the victim still performs the final approval.

    A campaign involving supposed Planzer deliveries shows how specific this risk can be. Fake emails direct recipients through a button to a website that copies the appearance of the Swiss logistics company. Victims are first asked for their name and address, then told to pay an alleged customs fee of 5.21 Swiss francs and finally prompted to provide full credit card details and approve the transaction through a banking app or SMS code.

    The small fee appears to lower the psychological barrier, while the copied design is meant to create trust. The Zurich Cantonal Police warning about fake Planzer messages demonstrates that a real company name, familiar logo, and functioning verification code do not establish authenticity.

    How can you protect yourself in everyday Swiss life?

    For beginners: Your most useful first step is to pause before clicking a link or approving a payment. Do not follow links in unexpected emails, SMS messages, or other communications, and do not provide personal or financial information without checking the request. If you are uncertain, contact the named service provider directly; with an unexpected delivery notice, first establish whether you are expecting such a shipment at all.

    According to the Zurich Cantonal Police, you can ignore and delete suspicious emails or move them to your spam folder. The police also recommends forwarding potential scam messages to its specified reporting address. If you have already disclosed credit card information, immediately notify your financial institution, block the affected bank or debit cards, and contact your local cantonal police by phone before filing a report in person.

    For advanced users: Review your protective measures across channels rather than treating each one separately. If Microsoft offers passkeys as an alternative to SMS or voice confirmation for an account you use, switching reduces your reliance on codes that a fake website can request. At the same time, treat a WhatsApp alert as one extra signal, not as proof that every unflagged conversation is safe.

    In the workplace, technical controls, training, and rapid information sharing should operate together. Hirschi considers the Swiss financial sector fundamentally well prepared, but says safeguards and awareness among employees and customers must continually adapt to new threats. Cross-channel incidents are easier to recognize when suspicious emails, calls, and payment requests are considered together rather than as unrelated events.

    The reported scale of the threat is substantial, although the figures come from a security vendor. According to Check Point’s report on Switzerland, Swiss companies and organizations recorded an average of 1,489 cyberattacks per week in July 2026, an increase of 35 percent from the same period a year earlier. Check Point identifies phishing and ransomware—malicious software that blocks data or systems for extortion—as common attack techniques; the provider figures in the supplied reports have not been independently verified.

    According to the same vendor data, education was the most heavily attacked sector worldwide, averaging 4,848 attacks per week and organization. Check Point also reports that one in every 36 prompts, meaning an instruction submitted to a generative AI system, carries a high risk of exposing sensitive data. For Swiss schools and companies, the task therefore extends beyond fraud detection to deciding which internal information should be entered into AI tools in the first place.

    Pros and Cons of AI-assisted protection

    Pros:

    • Earlier warnings – An alert inside a chat can stop you before you reply, open a link, or disclose information.
    • On-device analysis – WhatsApp says it will assess messages locally for scams without sending their content to Meta.
    • Faster pattern detection – Banks can identify unusual transactions and suspicious behavior sooner.
    • Protection at scale – Automated systems can examine large numbers of messages or activities and support security specialists.

    Cons:

    • Unknown accuracy – There are no reliable figures yet for missed scams or false alarms from WhatsApp’s new feature.
    • Some data still leaves the device – Aggregated usage information is transferred, and voluntary feedback can include five messages.
    • Risk of false confidence – An unflagged message can still be fraudulent, while a legitimate contact may be incorrectly marked.
    • An ongoing arms race – The same AI that detects patterns helps attackers create convincing text, deepfake voices, and large-scale campaigns.

    AI-assisted protection is a useful additional barrier, but it is not a dependable replacement for verification and restraint. WhatsApp’s local processing approach appears thoughtful from a privacy perspective, yet its accuracy still has to be demonstrated; meanwhile, the Planzer campaign and Microsoft’s SMS warning show how people can be persuaded to authorize a transaction despite technical safeguards. The unresolved risk is the combination of convincing AI-generated deception, several communication channels, and a final action that appears to be genuinely authorized.

    Sources

    AI-FunghiAI-Funghi

    © 2024 - 2026 ai-funghi.com | All Rights Reserved | Impressum | Datenschutz