Deepfake voice and video scams

Also called: voice cloning · AI voice scam · synthetic media fraud · deepfake CEO fraud

Deepfake scams use AI-generated voice or video to impersonate a specific real person — a relative in distress, an executive authorising a payment, a job candidate. The FBI recorded 22,364 AI-related fraud complaints in 2025 with $893 million in losses. A callback on a number you already had defeats every version of it.

Key facts

Category
Impersonation
First documented
2019
Typical loss
$2k–$250k USD, per victim
Main channels
phone call, video call, voicemail, social media video ads, online interviews, messaging apps
Who is targeted
Finance staff authorising payments, for the executive-impersonation version; Parents and grandparents, for the voice-cloned distress call; Anyone whose voice appears in a public video — seconds of audio is enough; Employers hiring remote workers, for the AI-assisted interview version; Followers of public figures used in fabricated investment endorsements
Documented origins
Nigeria, Myanmar, Cambodia, India, Russia, United States
Main targets
United States, United Kingdom, Canada, Australia, Singapore, Germany, Netherlands, Hong Kong
Case files
6 documented cases
Last reviewed
2026-09-06
Anatomy of a synthetic-media scamAnatomy of a synthetic-media scam. AI did not create a new scam. It removed the tells that used to give the old ones away. 1. Reference material is gathered: Seconds of audio from a social video, or photographs from a public profile. 2. A voice or face is generated: Cloned audio for a distress call; a synthetic face for a video meeting or interview. 3. Contact, in a familiar voice: A relative in trouble, an executive authorising a payment, a candidate in an interview. 4. The old checks fail: Fluent writing, a real-sounding voice and a live video are no longer evidence of anything. 5. The ask arrives: A wire transfer, bail money, or access to a system for a newly hired remote worker. 6. The residual tells: Lip movement out of step with audio; coughs and sneezes that do not match the picture. The diagram marks stage 4 as the point where the scheme can still be stopped: A callback on a number you already had defeats every version of this, because a cloned voice cannot answer a phone the operator does not control. A family code word does the same for distress calls. Both cost nothing and neither depends on spotting anything.Anatomy of a synthetic-media scamAI did not create a new scam. It removed the tells that used to give the old ones away.1Reference material isgatheredSeconds of audio from asocial video, orphotographs from a publicprofile.Minutes2A voice or face isgeneratedCloned audio for a distresscall; a synthetic face fora video meeting orinterview.Minutes3Contact, in afamiliar voiceA relative in trouble, anexecutive authorising apayment, a candidate in aninterview.Minutes4The old checks failFluent writing, areal-sounding voice and alive video are no longerevidence of anything.Minutes5The ask arrivesA wire transfer, bailmoney, or access to asystem for a newly hiredremote worker.Minutes to hours6The residual tellsLip movement out of stepwith audio; coughs andsneezes that do not matchthe picture.During the callWhere it can still be stopped — stage 4A callback on a number you already had defeats every version of this, because a cloned voice cannot answer a phone the operator does not control. A family codeword does the same for distress calls. Both cost nothing and neither depends on spotting anything.Stages and indicators documented in the FBI's 2025 Internet Crime Report and its December 2024 advisory on generative AI in financial fraud.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

A deepfake scam uses generated audio or video to impersonate a specific real person. Three forms account for nearly all documented harm.

The distress call. A relative’s voice, crying, in trouble. It is the family emergency scam with the one weak point repaired — the voice no longer has to be explained away by a bad line or a broken nose.

The executive. A chief executive or finance director on a call or a video meeting, authorising an urgent transfer. This is business email compromise with a verbal confirmation attached, which defeats the control most organisations added first.

The candidate. An AI-assisted job interview to get a synthetic person hired into a remote role. The FBI’s assessment is that the objective here “generally appears to be gaining access to private computer networks” rather than immediate money.

The scale needs stating carefully, because the coverage runs ahead of the data. IC3 recorded 22,364 AI-related complaints and $893 million in losses in 2025. Within that, voice-cloned distress scams accounted for over $5 million — real, and small. AI-linked business email compromise was over $30 million; romance and confidence scams with a likely AI nexus, over $19 million.

The bigger effect is not dramatic at all. The FBI’s own advisory names generative AI being used “to limit grammatical or spelling errors for foreign criminal actors targeting US victims.” Thirty years of advice about spotting bad English described a real signal that has now been engineered away.

How it actually works

  1. Reference material is gathered

    Seconds of audio from a social video, a voicemail greeting, a conference talk. Photographs from a public profile. Nothing here requires access to anything private.

  2. A voice or a face is generated

    Cloned audio for a phone call, or a synthetic face for a video meeting. The FBI notes the technology is “becoming increasingly difficult to detect and easier to make”.

  3. Contact, in a voice you know

    A relative in trouble. An executive with an urgent payment. A candidate in an interview. The pretext is old; only the verification barrier has changed.

  4. The checks people were taught stop working

    Fluent writing, a familiar voice, a live video call. All three were reasonable proxies for identity. None of them is any longer.

    Where it could have stopped

    A callback on a number you already had defeats every version of this, because a cloned voice cannot answer a phone the operator does not control. For families, a code word agreed in advance does the same and — crucially — works when the person answering is frightened. Neither depends on your ability to detect anything.

  5. The ask

    A wire transfer, bail money, a change of payment details, or system access for a newly hired remote worker.

  6. Residual tells, for now

    IC3 lists lip movement that does not fully coordinate with the audio, and sounds like coughs or sneezes that do not align with what is shown. Useful, but not something to rely on.

Why it works

It attacks verification rather than persuasion. Most scams have to talk you into something. This one repairs the step where you would have checked, which makes an old and otherwise unconvincing story survive contact with scrutiny.

Voice was the last intuitive proof. People will doubt an email and still trust a phone call, because recognising a voice feels like direct knowledge rather than inference. That intuition is now wrong and has not caught up.

Distress destroys discrimination. Voice cloning is used most against people who are frightened, and a crying voice on a bad line is hard to identify even when genuine.

Inside organisations, it exploits the fix. Firms that added “call and confirm” as a BEC control have a process that a cloned voice walks straight through — unless the callback goes to a number the firm already held.

And the quiet uses are the widespread ones. Better-written phishing, plausible profiles at volume, convincing fake trading platforms. None of it makes headlines, and it accounts for most of the money.

Where it comes from

Synthetic media has no geography of its own. It is a capability, added to whatever operation already exists — which is why the FBI reports it appearing inside BEC, romance, distress and employment fraud rather than as a category of its own.

What the data does show is uneven adoption. The largest AI-linked losses attach to schemes that were already the largest: business email compromise and confidence fraud. Compound-based operations in Southeast Asia use it for profile generation and translation at scale; West African BEC networks use it for correspondence; the distress-call version turns up wherever family emergency scams already run.

The most under-discussed variant is the employment one. Synthetic candidates interviewing for remote roles is not consumer fraud at all — it is an intrusion technique wearing a job application, and it sits closer to state-linked and organised network compromise than to anything else on this site.

Real cases

Scammers impersonating the FBI's own fraud-reporting centre

2026 US Ongoing

In July 2026 the FBI updated a warning first issued in April 2025 about an ongoing scheme in which criminals impersonate FBI personnel and the Internet Crime Complaint Center itself in order to re-victimise people who have already been scammed. The scheme uses AI-generated video, spoofed websites that harvest personal data, and fake FBI profiles on social media, and it is triggered precisely when a victim announces they intend to report the fraud.

Read the case file · 1 source

Canada's emergency scam: a spike, then a collapse

2025 CA Ongoing $8.6m

The Canadian Anti-Fraud Centre files grandparent scams under "Emergency (Jail, Accident, Hospital, Help)", and its open dataset shows a category that rose fast and then fell just as fast. Reported losses went from C$2.5 million in 2021 to C$11.6 million in 2023, then dropped to C$3.3 million in 2024 and C$1.5 million in the first nine months of 2025. It is one of the clearest examples in any national dataset of a scam category being pushed back.

Read the case file · 2 sources

$2.95bn lost to impersonation, and a rule with a $53,088 price tag

2025 US Ongoing $3.0bn

The FTC's Impersonation Rule took effect in April 2024 and makes it illegal to falsely pose as a business or a government body, or to misrepresent an endorsement, with civil penalties of up to $53,088 per violation. In its first-year review the FTC recorded $2.95 billion in impersonation losses in 2024 and warned that AI-generated deepfakes threaten to turbocharge the problem.

Read the case file · 3 sources

$893 million in AI-involved fraud, and where it actually shows up

2025 US Ongoing $893.3m

The FBI received more than 22,000 complaints reporting AI-related information in 2025, with adjusted losses of $893,346,472. Its breakdown is more useful than the headline: over $30 million in AI-linked business email compromise, over $19 million in romance and confidence scams with a likely AI nexus, over $5 million in voice-cloned distress scams, and almost $13 million in employment scams where voice spoofing was used in interviews.

Read the case file · 2 sources

Japan counts the ads that use a famous face, and names the faces

2025 JP Ongoing $294.7m

Japan's National Police Agency counts SNS-type investment fraud by how the victim was first reached, and the largest single route is a banner advertisement using a celebrity's name — 3,202 cases and ¥44.09 billion through November 2025. The NPA's response was to run counter-campaigns alongside the named public figures whose likenesses had been used.

Read the case file · 2 sources

The FBI's catalogue of how generative AI gets used in fraud

2024 US Ongoing

In December 2024 the FBI published an itemised account of how criminals use generative AI across text, images, audio and video. The most consequential entries are the mundane ones: AI used to correct grammar and spelling for foreign actors targeting US victims, to produce fictitious social media profiles at volume, and to generate the content of fraudulent investment websites.

Read the case file · 1 source

Red flags

  • A distressed call from a relative on an unfamiliar number. The number is the tell, not the voice.
  • Any urgent payment request confirmed only by voice, however familiar the voice is.
  • A video call where lip movement lags the audio, or where coughs and other sounds do not match the picture.
  • An executive authorising a transfer outside the normal process, particularly while travelling.
  • A candidate who avoids turning the camera on, or whose video behaves oddly during an interview.
  • A public figure endorsing a specific trading platform in a social media advert.
  • Pressure not to hang up and call back. This is the point of the whole exercise.
  • A request that arrives with a plausible reason why the usual channel is unavailable.
  • Perfect, fluent, well-structured writing from a source that used to be sloppy.

If it’s happening to you

On a call now. End it and call back on a number you already had. Not a number given to you on the call, not a number in a message — one from your own contacts, a card, or an official website. If the caller resists, that resolves it.

For a family emergency, call the person directly, then call another family member. Ask the code word if you have one.

In a business context. Do not act on a voice or video instruction alone. Confirm through a pre-existing channel with a second person, and treat any change of payment details as a stop condition regardless of who appears to be asking. See business email compromise.

If money has gone. Call your bank immediately and ask for a recall; report it the same day. See where to report. In a business case, preserve the call records, the meeting invitation and any recording.

Preventing it.

Agree a family code word. Not guessable, never posted anywhere. Tell older relatives what it is for. It is the cheapest and most effective countermeasure available for the distress variant.

Make callbacks a rule, not a suspicion. In a family and in an organisation, the framing that works is “this is simply what we do”, because it removes the social cost of appearing to doubt someone.

Reduce what is available. Public voice and video is training data. This is not a reason to disappear from the internet, but it is a reason to think about what a voicemail greeting in your own voice, or a public video, is now worth.

Stop treating fluency as evidence. Well-written, correctly branded and confidently delivered are no longer signals of legitimacy, and continuing to teach them as such is now actively harmful.

Where the money goes

Deepfakes do not change the money. A voice-cloned distress call ends in cash handed to a courier or a transfer to a mule account, exactly as the non-cloned version does. A deepfaked executive instruction ends in a wire to a receiving account that empties within hours, exactly as BEC always did.

That is worth holding onto, because it means the defences at the money end are unchanged and still work. The recall window, the second approver, the pre-existing callback number and the bank’s fraud line all operate identically whether or not synthetic media was involved.

What has changed is only the point of verification — which is why every recommendation on this page is about how you confirm a request rather than about how you detect a fake.

The other half of this story

Our sibling site Clean on Paper explains how the redirected payments move once they leave — the part of the chain that synthetic media does not touch at all.

By the numbers

No published dataset breaks this scheme out as its own category yet, so there is no chart to show. The data page explains which agency categories exist and why some schemes are invisible in official statistics.

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: 22,364 AI-related complaints and $893,346,472 in losses; the BEC, romance, distress and employment splits; the video-interview indicators.
  2. Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: The itemised uses of generative AI in text, images, audio and video, and the note that synthetic content is not inherently illegal.
  3. Canadian Anti-Fraud Centre Fraud Reporting System Dataset. Canadian Anti-Fraud Centre / RCMP. Accessed 2026-09-06. Supports: Canadian emergency and spoofing category volumes, where voice-cloned distress calls are recorded.
  4. Justice Department Highlights Enforcement Efforts Protecting Older Americans from Transnational Fraud Schemes in Recognition of 2025 World Elder Abuse Awareness Day. US Department of Justice. Accessed 2026-09-06. Supports: The grandparent and distress scam structure that voice cloning is applied to.
  5. Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025. National Anti-Scam Centre (ACCC), Australia. Accessed 2026-09-06. Supports: The National Anti-Scam Centre's finding that increased sophistication, including AI, may be making scams harder to recognise and report.

Common questions

How much audio does someone need to clone a voice?

Seconds. A social media video, a voicemail greeting, a podcast appearance or a work presentation is enough. The practical implication is that voice can no longer be treated as identification, which is a bigger change than it sounds — it was the primary check most people used on the phone.

Is this as common as the coverage suggests?

No, and it is worth being precise. The FBI recorded over $5 million in voice-cloned distress scam losses in 2025 — real, but small against $893 million of AI-related fraud overall, and tiny against $8.65 billion of investment fraud. Most 'AI scam' harm is AI improving ordinary fraud rather than deepfaking anyone.

What is the single best defence?

A callback on a number you already had. A cloned voice cannot answer a phone the operator does not control. For families, a code word agreed in advance does the same job and works when the person answering is frightened.

Are there tells in a fake video call?

The FBI names two: lip movement that does not fully coordinate with the audio, and sounds like coughs or sneezes that are not aligned with what is shown. Treat these as useful but not reliable — the technology improves, and a call that shows no tells is not proof of anything.

How does this affect business payments?

It removes the callback-to-the-executive check unless the callback goes to a number you already held. The rule that survives is unchanged: any change of payment details or unusual transfer is confirmed by a second person, on a pre-existing number, before the money moves.

Someone used my likeness in an investment advert. What can I do?

Report it to the platform hosting it — most have specific processes for impersonation — and to your financial regulator, which may add the promoted firm to a warning list. Fabricated endorsements of trading platforms are a documented acquisition channel for investment fraud.

Where deepfake-assisted money goesWhere deepfake-assisted money goes. The synthetic media changes the point of verification. It does not change the money at all. Where deepfake-assisted money goesThe synthetic media changes the point of verification. It does not change the money at all.A person or a companyaccountThe only thing thefake supplies isauthority to askA cloned voice or faceCash to a courier, ora wire — exactly asthe uncloned versionendsA courier, or areceiving accountThe recall window, thesecond approver andthe callback all stillwork hereEmptied within hoursReversibilityA recall is realistically possible only at the first hop, and only in the first hours. After the money is converted it becomes an investigation, not a refund.How the redirected payments move once they leave — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/trade-based-money-laundering/Every defence at the money end is unchanged by synthetic media, which is why the advice on this scheme is about how you confirm a request rather than how you detect a fake.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.