AI-generated fraud and deepfake scams investigation
Privacy & Data · Investigation

The AI Scam Playbook: How Artificial Intelligence Is Changing Fraud in 2026

Deepfakes, voice cloning, fake identities, romance scams, investment fraud, and the new economics of deception.

Kibbo Investigations · Published September 2026 · 16 min read
$893,346,472 Reported losses tied to AI-related fraud in the US in 2025 — the first year the FBI's IC3 tracked "AI-related" as its own crime descriptor in 25 years of reporting.
22,364 AI-related complaints filed with IC3 in 2025.
4.5× How much more profitable AI-enhanced fraud is than traditional fraud, according to INTERPOL's 2026 Global Financial Fraud Threat Assessment.
$442 billion Estimated global losses from financial fraud in 2025 — the total picture AI-enhanced fraud sits inside, per the same INTERPOL report.

"AI hasn't invented new scams. It has industrialized old ones."

2025 was the first year IC3 tracked AI-related fraud as its own category in the agency's 25-year history — so there's no real year-over-year comparison for this specific label, and any headline claiming AI fraud "grew" a certain percentage from 2024 is comparing against a category that didn't formally exist yet. The FBI itself notes the $893 million figure is a floor, not a ceiling: the "AI-related" tag is voluntary, applied only when a victim recognized and reported that AI was involved. For scale, IC3's total reported losses across all categories reached $20.877 billion in 2025, from over 1 million complaints — so recognized AI-related fraud currently represents a small but newly-measured slice of a much larger, and still growing, problem.

AI Hasn't Changed What Scams Are. It's Changed What They Cost.

Every stage of a scam used to require time, skill, or both. Writing a convincing message in a victim's native language, building a fake profile with believable photos, impersonating a specific person's voice — each of these was a bottleneck that limited how many people a single scammer could target at once. Generative AI removes most of those bottlenecks.

INTERPOL's 2026 Global Financial Fraud Threat Assessment describes criminals now able to clone a convincing voice from just 10 seconds of audio — often lifted directly from a social media post — and points to a growing dark-web market in "deepfake-as-a-service" kits that package synthetic identity tools into low-cost, ready-to-use products. The report's own language is direct: AI is helping criminal networks "scale operations exponentially with minimal investment."

The most significant shift isn't quality — it's throughput. A single scammer using generative AI tools can now personalize hundreds of messages, generate synthetic profile photos, translate pitches into a dozen languages, and clone a target voice, in the time it once took to craft one convincing approach by hand.

What this looks like at each stage of a scam

StageBefore AIWith AI
Writing convincing messagesManual, time-intensiveNear-instant, personalized at scale
Translating for foreign targetsRequired fluent speakersInstant, near-native quality
Building a fake profileStolen or stock photosAI-generated faces, no real person to trace
Cloning a voiceRequired extensive audio samples, technical skill~10 seconds of audio, low-cost tools
Producing fake videoRequired real production skill/equipmentDeepfake-as-a-service kits
Researching a specific victimManual, slowAutomatable from public data
Running multiple scams at onceLimited by scammer's own timeAgentic AI can run campaigns with minimal supervision

The most consequential change may be the last row. INTERPOL's report specifically flags the emergence of agentic AI systems capable of autonomously planning and executing entire fraud campaigns — from initial research on a target to the final request for payment — without a human operator managing each step. That's the shift from AI as a writing tool to AI as the operator.

The AI scam supply chain: from victim research to money laundering

The AI scam supply chain. Steps 3 and 4 (in terracotta) are where generative AI does the work, not just assists it.

4.5×

How much more profitable AI-enhanced fraud is than traditional fraud, according to INTERPOL's 2026 Global Financial Fraud Threat Assessment.

The 10 Most Dangerous AI-Powered Scams — and How We Ranked Them

IC3's data doesn't break AI involvement out evenly across every scam category — it explicitly names AI-related losses in only three lines (investment fraud, business email compromise, and tech support scams), and flags voice cloning as a technique that runs through other categories — romance scams, elder fraud, government impersonation — rather than a category of its own. That's a real limitation of the official data, and it's exactly why a single ranking by dollar loss alone would be misleading.

So we built our own scoring model instead of just sorting IC3's categories by loss total: the Kibbo AI Scam Threat Score, combining four factors — prevalence, financial damage, AI dependence, and detection difficulty — each scored 1–10 and averaged. Where official per-category AI figures exist, we used them directly; where they don't, we scored based on documented patterns in the IC3, INTERPOL, and Scamwatch reports rather than inventing a number.

1
AI-Enhanced Investment & Crypto Fraud
8.25
2
Deepfake Video Impersonation
7.75
3
Voice Cloning / "Distress" Scams
7.50
4
AI-Generated Phishing
7.00
5
AI Romance Scams
7.00
6
Business Email Compromise (AI)
6.75
7
Government Impersonation
6.00
8
Fake Job / AI Interview Scams
5.75
9
Tech Support Scams
4.75
10
AI-Generated Sextortion
4.75

Score = average of prevalence, financial damage, AI dependence, and detection difficulty (each 1–10). This is Kibbo's own methodology, not an official agency ranking — full scoring detail in the Methodology section below.

AI Scams Around the World: What the Data Actually Allows Us to Compare

Every country tracks fraud differently, and not every regulator breaks out AI's specific role the same way — which makes a clean international comparison harder than it looks. Here's what each region's official data actually supports.

Sources: FBI IC3, UK Finance, National Anti-Scam Centre (Australia), Europol.

The United States has the clearest single number: the FBI's IC3 reported $893,346,472 in losses under its new "AI-related" descriptor in 2025, its first year tracking the category, out of $20.877 billion in total reported fraud losses.

The United Kingdom is where headline figures get confusing fast. UK Finance — the banking trade body with access to actual bank-reported fraud and reimbursement data — recorded £1.3 billion in total fraud losses across all of 2025, and specifically linked a 55% surge in investment scam losses (to £97.7 million in H1 2025 alone) to AI-generated deepfake videos and synthetic voices. Separately, a widely-circulated figure of £9.4 billion in "AI scam" losses over nine months has been reported by the Guardian, sourced to a survey-based estimate from the Global Anti-Scam Alliance — a figure roughly seven times UK Finance's entire fraud total for the full year. These measure fundamentally different things and shouldn't be cited interchangeably.

Australia's National Anti-Scam Centre reported combined losses of AUD $2.18 billion (approximately USD $1.5 billion) across 481,523 scam reports in 2025, up 7.8% from 2024. The report cites AI and "the industrialisation of criminal syndicates through scam compounds" as a driver of increasing sophistication, without providing an AI-specific loss figure the way IC3 does.

The European Union doesn't have a single equivalent figure at all. Europol's threat assessments (EU-SOCTA, IOCTA) describe AI's role in organized fraud in detail, but the EU has no unified consumer-fraud reporting body comparable to IC3, UK Finance, or Scamwatch. Loss data exists only fragmented by member state (Ireland's central bank, for instance, reported €179 million in payment fraud for 2025, up 27%).

The honest takeaway: the US is the only jurisdiction currently publishing a clean, AI-specific loss figure from an official source. Every other region's "AI scam" number in circulation is either a broader total that includes non-AI fraud, a private-sector estimate, or simply doesn't exist yet at a national level.

The Major Attack Types, in Detail

Voice Cloning: The Fake Voice Problem

Voice cloning doesn't show up as its own line item in the FBI's IC3 data — it's a technique that runs through several categories at once: "distress scams" (the classic family-emergency call, more than $5 million in attributed 2025 losses), business email compromise, romance scams, and government-impersonation scams.

What changed is the cost of entry. INTERPOL's 2026 threat assessment states criminals can now produce a convincing voice clone from as little as 10 seconds of audio — commonly lifted from a social media video, a podcast clip, or a voicemail greeting. No specialized equipment or technical skill is required.

10 seconds

Of audio is enough to clone a convincing voice, according to INTERPOL's 2026 Global Financial Fraud Threat Assessment.

Deepfake Video: When Seeing Isn't Believing

In January 2024, an employee at the Hong Kong office of Arup — the London-based engineering firm behind the Sydney Opera House — joined what appeared to be a routine video call with the company's CFO and several colleagues. Every other person on that call was an AI-generated deepfake. Over the course of the call, the employee was instructed to make 15 transfers to five Hong Kong bank accounts — HK$200 million, roughly $25.6 million, gone before anyone at Arup's actual headquarters knew the call had happened.

Deepfake video fraud isn't confined to isolated headline cases. A Gartner survey of 302 security leaders found 62% of organizations reported experiencing at least one deepfake-enabled attack in the past year, and identity-verification firm Entrust estimates 1 in 5 biometric fraud attempts now involves a deepfake. Human detection performance doesn't inspire confidence: a 2024 meta-analysis of 56 studies put average human accuracy at just 55.54% — barely better than a coin flip.

99.9%

Of people in a 2,000-person iProov test failed to correctly identify every deepfake shown to them — while 60% believed they were good at spotting them.

AI-Generated Phishing

Phishing remains the single most-reported crime type to IC3 by volume — 191,561 complaints in 2025 — but the more telling number is what happened to the losses attached to it: they jumped 208% year over year, from $70 million to $215.8 million, even as the complaint count stayed roughly flat. That combination — same volume, sharply higher losses — is consistent with AI making each individual attempt more convincing rather than simply generating more of them.

AI Romance and Investment Scams

Romance fraud caused $584 million in total reported losses in 2025, of which more than $19 million is directly attributed to AI in IC3's data — though that figure almost certainly understates AI's actual role. Investment fraud is where this compounds most severely: it's the largest single loss category for both IC3 ($8.648 billion total, $632 million AI-attributed) and Australia's Scamwatch (AUD $837.7 million). AI-generated fake celebrity endorsements, synthetic "trading platform" interfaces, and deepfake videos of well-known public figures promoting fraudulent investment opportunities are now a documented pattern across US, UK, and Australian regulators alike.

ASIC media release warning about AI-generated deepfake investment scams
Source: ASIC (Australian Securities and Investments Commission), 2026. ASIC's official warning that scammers are using generative AI to build networks of deepfake websites and endorsements, after removing more than 19,400 online scams in FY26 — up 182% year over year. The regulator named Prime Minister Anthony Albanese among the most frequently impersonated public figures.

Fake Jobs and AI Interview Scams

The FTC reported over $501 million in job-scam losses in 2024; IC3 tracked employment fraud as its own category for the first time in 2025, logging $362.9 million. Within that, IC3 specifically flagged AI-generated deepfake job interviews as an emerging vector — scammers using real-time face-swapping tools to impersonate a company's real executives, conducting a convincing video interview, extending a fake offer, and using "onboarding" to harvest a victim's Social Security number, bank routing details, and identity documents.

Government and Business Impersonation

Government impersonation losses reached $797.9 million in 2025, nearly double the prior year — though that growth is measured against a comparatively low 2024 base. The "Phantom Hacker" scam is the pattern investigators point to most: criminals sequentially impersonate tech support, then a bank, then a government official, layering each impersonation to strip retirement savings from older victims. AI enters this category primarily through voice — synthetic voices used to impersonate Social Security Administration or Medicare officials at scale.

Fake website impersonating Australia's official Moneysmart investment education site
Source: ASIC (Australian Securities and Investments Commission). A real example of a fake investment website impersonating ASIC's official Moneysmart site, published by ASIC itself as a consumer warning. Scammers use near-identical copies of trusted government sites, at different URLs, to promote fraudulent investment returns.

Real Cases: How These Scams Actually Play Out

Case 01 — The $25.6 Million Deepfake Board Meeting

What happened: In January 2024, a finance employee at Arup's Hong Kong office received a message claiming to be from the company's UK-based CFO. A follow-up video call appeared to include the CFO and colleagues. The employee made 15 transfers totaling HK$200 million ($25.6 million) to five Hong Kong bank accounts.

How AI was used: Every other participant on the video call was an AI-generated deepfake, built from publicly available video and audio of the real executives.

How much was lost: $25.6 million, none recovered.

What investigators found: The fraud was discovered only when the employee independently contacted Arup's actual London headquarters roughly a week later. No arrests had been publicly announced as of early 2025.

Source: Financial Times, Hong Kong Police (RTHK), reported May 2024.

$25.6M

Stolen from Arup in a single video call, using AI-generated deepfakes of the company's own executives.

Case 02 — The Attempt That Failed: WPP

What happened: Scammers targeted employees at communications firm WPP using a fake WhatsApp account impersonating a senior executive, followed by an attempted Microsoft Teams meeting using voice-cloned and edited footage of that executive.

How much was lost: Nothing — the attempt failed due to employee suspicion before any transfer was authorized.

Source: Reported alongside the Arup case in 2024 investigations into deepfake corporate fraud.

Case 03 — The Voice-Only Version: A UK Energy Firm, €220,000

What happened: An employee received a phone call — audio only, no video — that sounded exactly like the company's CEO, instructing them to send funds to a "trusted supplier."

How AI was used: Voice cloning alone was sufficient to pass the employee's credibility check.

How much was lost: €220,000.

Source: Forbes; cited widely in fraud-prevention literature on early voice-only business email compromise.

Case 04 — The Crying Daughter: A Family's $15,000

What happened: In July 2025, a mother in Florida received a call sounding exactly like her daughter describing a car crash, followed by a fake "public defender" demanding money. She withdrew $15,000 in cash and handed it to a courier.

How AI was used: The family believes the voice was cloned from audio in the daughter's public social media videos.

Why the victim believed it: She heard her daughter's actual voice — the specific tone and emotional register a parent recognizes instantly, engineered to override rational skepticism before there's time to verify.

Source: Multiple outlets, 2025–2026 coverage of AI voice cloning cases; family account.

Case 05 — Law Enforcement Catches Up: 13 Charged in a Grandparent-Scam Ring

What happened: In September 2025, the US Department of Justice charged 13 people with running a coordinated grandparent-scam operation that stole more than $5 million from elderly victims across five states.

What investigators found: One of the few cases in this space to reach indictment — most individual instances are never traced back to a specific perpetrator.

Source: U.S. Department of Justice press release, September 2025.

Case 06 — When Verification Worked

What happened: Two separate near-misses. A Philadelphia attorney testified to the US Senate that he stopped a $9,000 cryptocurrency payment demanded by a cloned-voice call by independently phoning his daughter-in-law first. A California couple avoided losing $15,000 to a "your son is in jail" voice-clone call by phoning the jail directly and finding no record of their son.

Why it worked: In both cases, the intervention was the same — contacting the person or institution independently, through a channel the scammer didn't control, before acting.

Source: US Senate testimony; family accounts reported in 2025–2026 coverage.

Note: in most individual cases like Case 04, no one forensically confirms AI was used — the certainty comes from the victim's ear, under panic. Only the corporate cases (Arup, WPP) have technical and police confirmation that the content was AI-generated.

Are AI Scams Actually Increasing? What the Data Actually Supports

Headlines claiming AI fraud "grew 1,210% in one year" have circulated widely in 2026 coverage of the FBI's IC3 report. That figure did not come from the FBI. It originates from Pindrop, a private voice-biometrics security vendor, describing a 1,210% increase in AI-driven attacks detected across its own commercial customer base — a real, but narrow, telemetry measurement from one company's systems, not a government statistic. Several outlets have run it under headlines attributing it to the FBI's report, which it is not.

"A floor, not a ceiling." — how the FBI itself describes its own $893 million AI-related fraud figure.

Here's what the actual data separates out, and why none of it can be added together into one "AI fraud" trend line:

The same pattern shows up outside the US. In the UK, an official, bank-reported figure (£1.3 billion in total 2025 fraud losses, per UK Finance) coexists with a widely cited AI-specific estimate seven times larger (£9.4 billion, based on a Global Anti-Scam Alliance survey) — two numbers built from entirely different methodologies, describing different things, that keep getting placed side by side as if they were comparable.

What we can say with confidence: AI-enabled fraud is real, growing, and under-measured. What we can't say, honestly, is a single clean percentage for "how much AI fraud grew this year" — because 2025 is the first year anyone tried to measure it as its own category at all.

Where AI Scams Reach People, and Who They Target

Social media is now the single most expensive way scammers reach victims in the US — not by volume of complaints, but by dollar value. The FTC's April 2026 Data Spotlight found Americans reported $2.1 billion in losses originating on social media in 2025, an eightfold increase since 2020, and nearly 30% of all people who lost money to a scam said it started there.

Facebook accounts for more reported losses than any other platform — more, combined, than text messages and email — with WhatsApp and Instagram a distant second and third. Investment scams caused $1.1 billion of the $2.1 billion social-media total — more than half. Nearly 60% of romance scam losses in 2025 began on social media specifically.

Who's being hit hardest

Age remains the sharpest dividing line in both prevalence and dollar impact. Americans aged 60 and older reported $7.7 billion in total fraud losses in 2025 — the highest dollar figure of any age group — and accounted for $352 million, roughly 40%, of all AI-related losses IC3 tracked. Average losses per senior victim reached approximately $38,500, nearly double the figure for younger filers.

Australia's data shows a similar concentration: adults 65 and over accounted for 26.5% of Scamwatch's reported losses in 2025, despite making up only about 17.1% of the population.

That doesn't mean younger people are safe — investment and job scams disproportionately target job seekers and younger adults, and the FTC's own social-media figures show every age group under 80 losing more to platform-based fraud than to any traditional contact method. The pattern isn't "AI scams target the old" or "AI scams target the young" — different AI-enabled techniques are tuned to different vulnerabilities: distress and impersonation scams exploit older victims' trust in authority; investment and romance scams on social platforms exploit younger victims' comfort transacting and forming relationships entirely online.

What AI Actually Changed About Trust

Every scam type in this investigation is old. What's changed isn't the scam. It's which parts of a normal human interaction a consumer can still trust as evidence that the person on the other end is real.

Before generative AI became cheap and accessible, certain things functioned as informal verification. A familiar voice on the phone. A video call where you could see someone's face move and react in real time. A written message free of grammatical tells. A photo that matched the story being told. None of these were foolproof, but they raised the cost of deception enough to filter out most attempts.

INTERPOL's research puts a number on how much that filter has weakened: AI-enhanced fraud is 4.5 times more profitable than fraud without it, largely because the tools that used to require real skill, time, or production value now require none of those things.

"The burden of verification has shifted entirely onto the person being targeted."

Hearing your daughter's voice used to be close to definitive proof you were speaking with your daughter. Now it is not, and very few people have internalized that yet — which is precisely why the "crying daughter" pattern in Case 04 worked long enough to cost a family $15,000 handed to a stranger at their front door.

This is also why the cases in this investigation that ended without a loss (Cases 02 and 06) share one thing in common that has nothing to do with technology: someone stopped, and verified through a channel the other party didn't control, before acting. That's not a technical defense. It's a behavioral one — and right now, it's close to the only defense that reliably works against every category in this ranking at once.

How to Verify Someone When AI Can Imitate Them

If you believe you've encountered an AI-generated scam attempt, or been affected by one: Kibbo Phishing DetectorUnauthorized Transaction & Banking Fraud ChecklistConsumer Rights Wizard.

Methodology

This investigation draws on primary reporting from the FBI's Internet Crime Complaint Center (2025 Annual Report, the first edition to track "AI-related" as its own crime descriptor), INTERPOL's 2026 Global Financial Fraud Threat Assessment, the FTC's Consumer Sentinel Network data and April 2026 Data Spotlight on social-media-originated scams, Australia's National Anti-Scam Centre 2025 Targeting Scams report, UK Finance's 2025 annual fraud report, and Europol's threat assessments. Supplementary figures — deepfake detection rates, organizational incident surveys — come from named private security research (Gartner, Entrust, iProov) and are clearly distinguished from government-reported figures.

Definitions. We use "AI-related" or "AI-enhanced" scam to describe fraud where generative AI — voice cloning, deepfake video or image generation, or large language model-generated text — played a documented or credibly reported role in the deception itself, not merely in a scammer's general workflow.

The Kibbo AI Scam Threat Index is Kibbo's own scoring methodology, not an official ranking from any cited agency. It averages four factors — prevalence, financial damage, AI dependence, and detection difficulty — each scored 1–10. Where an official per-category AI figure exists, we used it directly; where it doesn't, the score reflects documented patterns from IC3, INTERPOL, and Scamwatch rather than an invented number.

Data limitations.

Datasets Used in This Investigation

AI-Related Fraud Dataset — US, 2025

Source: FBI Internet Crime Complaint Center (IC3), 2025 Annual Report

Used in: The AI Scam Playbook

Official source (PDF) →

US Airline Reliability Dataset — 2026 H1

Source: US Department of Transportation, Air Travel Consumer Report

Used in: Which US Airline Performed Worst in 2026?

Download CSV →

See all datasets in Kibbo's Consumer Data Library →

Related

Sources

Take action with Kibbo

Think you've encountered an AI-generated scam?

Use Kibbo's Phishing Detector to check a suspicious message, or the Consumer Rights Wizard to find out exactly what to do next.

Check a suspicious message →