AI scams are familiar frauds, such as fake emergencies, fake bosses and fake investments, made more convincing with cloned voices, deepfake video and flawless writing. In 2025, the FBI received 22,364 complaints that mentioned AI, with more than $893 million in reported losses. It was the first year the FBI’s annual report included a section on AI.
The good news: the defenses that work do not depend on spotting the fake. A family code word, a callback on a number you already know, strong sign-in and a refusal to be rushed beat even a perfect clone.
- The FBI logged 22,364 complaints mentioning AI in 2025, with more than $893 million lost. The real figure is likely higher.
- Losses keep climbing: in 2025, internet crime complaints to the FBI reported $20.9 billion lost, and fraud reports to the FTC about $16 billion.
- Four AI scams matter most: voice-clone emergencies, deepfake video calls, sharper phishing and fake investment endorsements.
- The best defenses are procedures a fake cannot pass: a code word, a callback, passkeys and a pause.
- If money has moved, call your bank at once, then report to IC3 or the FTC.
How big is the AI scam problem?
Big, and almost certainly undercounted. These are the official US figures for 2025.
Read the AI figure carefully. The FBI counts a complaint as AI-related only when the report mentions AI, and many victims never find out. The FBI makes the point itself: investment complaints with a reported AI link cost $632 million, while all investment scams cost more than $8 billion. The FBI and FTC also count differently, so do not add their totals together.
Here is where the AI-linked losses landed:
| Scam type | Losses in complaints mentioning AI, 2025 |
|---|---|
| Investment | $632 million |
| Business email compromise | $30 million |
| Tech and customer support | $19.5 million |
| Romance and confidence | $19 million |
| Fake jobs | $12.6 million |
| “Distress” calls from a fake relative (part of romance and confidence) | over $5 million |
The four AI scams to know
Voice-clone emergency calls
A relative calls in a panic: an accident, an arrest, a kidnapping. They need money now, and they beg you not to tell anyone. The voice sounds right because it is a clone. The FBI calls these distress scams, and says they are evolving to imitate other relatives and close friends, not just grandchildren.
The same trick works on organizations. In May 2025, the FBI warned that criminals were sending AI-generated voice messages that impersonated senior US officials. The goal was to build trust, then send a link to “move” the chat to another platform and take over accounts.
Deepfake video calls
In early 2024, an employee of the engineering firm Arup in Hong Kong joined a video call with people who looked and sounded like senior colleagues. Following their instructions, the employee made 15 transfers totaling HK$200 million, roughly US$25 million. Arup later confirmed that fake voices and images were used.
Video fakes also show up in hiring. The FBI has seen fake job interviews where a candidate’s lips do not match the audio. The goal generally appears to be access to company networks.
Phishing without the typos
Bad spelling used to give scams away. Not anymore. In a 2024 study with 101 participants, spear phishing emails written entirely by AI got clicks from 54% of recipients, the same rate as emails written by human experts. Generic phishing got 12%.
The study is a preprint, but it matches what the FBI describes. Chatbots can quickly produce an official-sounding email from a CEO or official, complete with wiring instructions or a phishing link.
Fake investment endorsements
Investment fraud is the costliest scam of all, and AI gives it famous faces. The FBI describes investment “clubs” that use AI-generated video and voices of celebrities, CEOs and other trusted figures, with fake endorsements on social media and in video calls. AI chat tools also let scammers generate thousands of conversations quickly, each one different for its target.
Defenses against AI scams that actually work
Every case above follows the same pattern: urgency, secrecy, and a request for money, codes or access. You do not need to detect the fake. You need habits that a fake cannot pass.
Why these work:
The code word and the callback defeat any clone, however good. The scammer does not know the word and cannot answer the real person’s phone. The FBI recommends both.
Passkeys are built to resist phishing. There is no password to steal, and a passkey only works on the site it was made for, so a fake login page gets nothing useful.
The pause breaks the pressure, which is the scammer’s real tool. The FBI’s advice is to “Take a Beat” before handing over money or personal details.
For businesses, add two controls. Any payment, or change to a supplier’s bank details, needs a second person’s approval and a callback on a number already on file. That is exactly the check a deepfake call is designed to skip.
An AI assistant can give you a quick second opinion on a message that feels off. Remove names, account numbers and other personal details first, for the reasons in our AI privacy guide.
I received the message below. Do not visit or open anything in it. List any warning signs of a scam you can see, such as urgency, secrecy, payment requests, mismatched sender details, or links that do not match the company they claim to be from. Then tell me how to check it independently, using contact details I already have rather than any in the message. Message: [paste the message with personal details removed]
Treat the answer as a second opinion, not a verdict. A clean result does not make a request safe, and the callback rule still applies.
What to do if you’ve been scammed
Call your bank or payment provider now
Use the number on your card or in the official app, and ask them to stop or recall the payment. Speed matters: the FBI says complaints filed quickly give its Recovery Asset Team a better chance to help.
Report it
In the US, file at ic3.gov and ReportFraud.ftc.gov. Include the scammer’s name or company, how and when they contacted you, how you paid, and where the money went. Elsewhere, use your national fraud reporting service or the police.
Lock down your accounts
Change any password you shared, turn on passkeys or an authenticator app, and check the recovery email and phone number on each account. If you build software, scammers phish for API keys and cloud tokens too, and our guide to keeping API keys safe covers the first hour after a leak.
Warn the people around you
If your voice or face was used, tell family, friends or colleagues so they are not the next target. Save the evidence before you block anyone.
FAQ
Can scammers really clone a voice?
Yes. The FBI recorded more than $5 million in 2025 losses to distress scams that used voice cloning to imitate a loved one. Treat any urgent call asking for money as unverified until you call back on a number you know.
How can I tell if a video call is a deepfake?
Sometimes you can, from lips that do not match the audio or oddly timed coughs. But good fakes pass a visual check. End the call and ring back on a known number, or ask something only the real person would know. Our guide on how to spot a deepfake has a full routine.
Are older people the main targets?
They lose the most: people over 60 reported $7.7 billion in losses to the FBI in 2025. But AI scams also hit businesses, job seekers and investors of every age.
What is the single best defense against AI scams?
A callback on a number you already had. It beats cloned voices, fake video and spoofed caller ID, because the scammer cannot answer the real person’s phone.
Where do I report an AI scam?
In the US, report to the FBI at ic3.gov and to the FTC at ReportFraud.ftc.gov. If money moved, call your bank first. Outside the US, use your national fraud reporting service or the police.
Next, learn how to spot a deepfake before you share one, or give your team a one-page AI use policy with a money rule built in.
- Cryptocurrency and AI scams bilk Americans of billions, FBI, April 2026
- 2025 IC3 annual report, FBI, April 2026
- FTC data show people reported losing $3.5 billion to imposter scams in 2025, FTC, June 2026
- Criminals use generative artificial intelligence to facilitate financial fraud, FBI Internet Crime Complaint Center, December 2024
- Senior US officials impersonated in malicious messaging campaign, FBI Internet Crime Complaint Center, May 2025
- UK engineering firm Arup falls victim to £20m deepfake scam, The Guardian, May 2024
- Evaluating large language models’ capability to launch fully automated spear phishing campaigns, arXiv, November 2024
- Passkeys, FIDO Alliance




