EMERGING THREATUpdated 23 September 2026

AI can imitate a voice or face. Verify the request independently.

The FBI’s 2025 report records more than 22,000 complaints containing AI-related information and over $893 million in associated reported losses. Those reports do not establish that AI alone caused each loss. This guide explains the forms of impersonation and the checks that reduce reliance on appearances.

$893M+
Losses in FBI AI-related reports (2025)
Voice
Audio can be imitated
Video
Appearance is not authentication
22,000+
AI-related FBI reports (2025)
The short answer

AI scams use artificial intelligence — voice cloning, deepfake video, and AI-written messages — to impersonate people you trust, often using just seconds of audio or a few photos. The defence: verify any urgent request through a separate, known channel, and agree on a private "safe word" with family for emergencies.

Voice cloning: the family emergency scam

Illustrative scenario, not a documented case: a caller sounds like a relative, claims to be in trouble and asks for urgent money. A cloned voice could support the deception, but the same request can also come from an ordinary impersonator. Independently contact the relative before paying.

The FBI documents voice cloning and other synthetic media in its generative-AI fraud warning. Quality and required audio vary; a single minimum clip length is not a universal rule. Our family-impersonation guide gives a verification plan.

The defense

Create a family safe word — a phrase that only family members know, never posted online, that must be spoken during any urgent phone call requesting money. Keep it private and rotate it if exposed. It adds a check, but does not replace independent contact.

Sources:FBI IC3 2025 Internet Crime Report ↗

Deepfake video calls

Video can support impersonation of a colleague or authority. Before acting on a financial instruction, use your organization’s verified approval process and a separate contact route. Our business-fraud guide explains payment controls.

Visual and audio defects can prompt further checking, but their absence is not authentication. Ordinary bandwidth or lighting problems can also look suspicious. There is no reliable universal head-turn or hand-gesture test for deciding whether a financial request is safe.

Protection

Verify any video-call financial instruction through a separate channel. Never authorize transactions based solely on video calls.

FROM THE FIELD

Synthetic media has legitimate uses as well as fraudulent ones. A useful safety check addresses the claimed identity and requested action instead of assuming that every use of AI is malicious.

AI-generated phishing at scale

Phishing can be mass-produced or individually targeted. Generative AI can help an operator write and adapt messages, but older techniques remain in use:

Good grammar does not establish a genuine sender. Use technical protections and independent verification together.

Sources:FBI IC3 2025 Internet Crime Report ↗

How to protect yourself from AI scams

Use verification procedures alongside account and device protections:

  1. 1.

    Agree a private family phrase as an additional check; replace it if exposed and still verify unusual requests independently.

  2. 2.

    Never authorize financial transactions based solely on phone or video calls — verify through a separate channel.

  3. 3.

    Be skeptical of any urgent request for money, regardless of who appears to be asking.

  4. 4.

    Limit personal audio and video on public social media — scammers mine these for cloning material.

  5. 5.

    For businesses: implement verbal verification protocols for wire transfers. No amount should be authorized by voice or video alone.

  6. 6.

    Keep your voicemail greeting generic — detailed greetings provide more audio for cloning.

Why the check matters more than the tell

AI can make a false identity more convincing, but appearances are only part of the claim. A real person can also lie. The practical objective is to verify who is making the request, what authority they have and whether the proposed action belongs to a genuine process.

Use visual clues as reasons to investigate, not as a pass/fail test. A family safe word adds a private check; independent contact reduces reliance on the caller’s presentation. Neither is a guarantee if the word or account has been compromised.

Move verification outside the request

End the unexpected contact and reach the person or organization through a previously verified channel. If that account may be compromised, use another independent route. Do not let the caller provide the contact who verifies them.

Resistance to verification is a warning, but willingness to wait is not proof of legitimacy. Confirm the specific request through the real organization or person, then use the appropriate payment or approval controls.

Secrecy, pressure to remain on the line and instructions not to contact anyone else are reasons to stop and seek independent confirmation. A scammer can also be patient. The useful safeguard is the verification process, not the emotional reaction to your request.

Visual clues remain useful, but do not let a convincing voice or face authorize a payment. Verify the person and the financial request separately. Our AI romance-scam guide explains why a real face cannot establish honest intentions.

What people actually ask AI assistants about scams

There is a second AI story on this page, and it runs the other way. People now ask AI assistants whether a message, an app or a person is a scam, and the assistant answers by reading pages like this one. We publish the questions Microsoft's AI sent to the Bing index when it cited our pages as the AI Scam Query Index: 180 distinct questions in the first release, weekly since July 2026, with our share of each answer. Most of them are comparisons, which payment app is safer, which dating app checks identity, whether a bank alert is real. Almost none of them are about AI scams by name. The people being targeted by cloned voices are asking about the payment rail and the platform, not the technology.

That is why the guide above stays on behaviour rather than detection, and why each AI technique has its own breakdown built on a real case:

If an AI scam has already cost you money, act fast with our recovery guide, then see where to report it in your country.

P
Written by Peter
Founder, Tutela Digitalis • Updated 23 September 2026

Research and educational guidance by Peter. Sources and material corrections are linked on this page.

Frequently Asked Questions

What are AI scams?
These are frauds in which AI supports deception, for example through written messages, synthetic identities, cloned audio or manipulated video. The technology can make an impersonation convincing, but not every polished message or scam uses AI.
Is a video call a reliable identity check?
It can provide information, but it does not establish honest intentions or authority to request a payment. Visual glitches are not a reliable pass/fail test. Verify the person and specific request independently.
How can I reduce the risk?
Use a separate, independently verified contact route before sharing money or access. A private family phrase can add a check, but may be exposed. Follow established payment approval procedures rather than relying on a voice or face.
What does the FBI AI-loss figure mean?
In 2025, the FBI received more than 22,000 complaints containing AI-related information, with associated adjusted losses exceeding $893 million. That reporting descriptor does not prove AI alone caused each loss.

Reviewed 23 September 2026. We corrected overbroad verification and recovery claims during our launch-content review. See the corrections log for the material changes.

Sources & References

Every statistic in this guide is sourced from verified organizations. Click to verify any claim.

FBI IC3 2025 Internet Crime Report ↗

Worried about AI-powered fraud?

Get expert assessment of your vulnerability and practical protection steps.

Book a Consultation →

Continue reading

PHISHING

Phishing is the #1 reported cybercrime

BUSINESS

Business email compromise and invoice fraud

RECOVERY

I've been scammed — the first 24 hours