Also called: voice cloning · AI voice scam · synthetic media fraud · deepfake CEO fraud
Deepfake scams use AI-generated voice or video to impersonate a specific real person — a relative in distress, an executive authorising a payment, a job candidate. The FBI recorded 22,364 AI-related fraud complaints in 2025 with $893 million in losses. A callback on a number you already had defeats every version of it.
What it is
A deepfake scam uses generated audio or video to impersonate a specific real person. Three forms
account for nearly all documented harm.
The distress call. A relative’s voice, crying, in trouble. It is the
family emergency scam with the one weak point
repaired — the voice no longer has to be explained away by a bad line or a broken nose.
The executive. A chief executive or finance director on a call or a video meeting, authorising an
urgent transfer. This is business email compromise with a verbal
confirmation attached, which defeats the control most organisations added first.
The candidate. An AI-assisted job interview to get a synthetic person hired into a remote role.
The FBI’s assessment is that the objective here “generally appears to be gaining access to private
computer networks” rather than immediate money.
The scale needs stating carefully, because the coverage runs ahead of the data. IC3 recorded 22,364
AI-related complaints and $893 million in losses in 2025. Within that, voice-cloned distress scams
accounted for over $5 million — real, and small. AI-linked business email compromise was over $30
million; romance and confidence scams with a likely AI nexus, over $19 million.
The bigger effect is not dramatic at all. The FBI’s own advisory names generative AI being used “to
limit grammatical or spelling errors for foreign criminal actors targeting US victims.” Thirty years
of advice about spotting bad English described a real signal that has now been engineered away.
How it actually works
Reference material is gathered
Seconds of audio from a social video, a voicemail greeting, a conference talk. Photographs from a
public profile. Nothing here requires access to anything private.
A voice or a face is generated
Cloned audio for a phone call, or a synthetic face for a video meeting. The FBI notes the
technology is “becoming increasingly difficult to detect and easier to make”.
A relative in trouble. An executive with an urgent payment. A candidate in an interview. The
pretext is old; only the verification barrier has changed.
The checks people were taught stop working
Fluent writing, a familiar voice, a live video call. All three were reasonable proxies for
identity. None of them is any longer.
Where it could have stopped
A callback on a number you already had defeats every version of this, because a cloned voice cannot answer a phone the operator does not control. For families, a code word agreed in advance does the same and — crucially — works when the person answering is frightened. Neither depends on your ability to detect anything.
The ask
A wire transfer, bail money, a change of payment details, or system access for a newly hired
remote worker.
Residual tells, for now
IC3 lists lip movement that does not fully coordinate with the audio, and sounds like coughs or
sneezes that do not align with what is shown. Useful, but not something to rely on.
Why it works
It attacks verification rather than persuasion. Most scams have to talk you into something. This
one repairs the step where you would have checked, which makes an old and otherwise unconvincing story
survive contact with scrutiny.
Voice was the last intuitive proof. People will doubt an email and still trust a phone call,
because recognising a voice feels like direct knowledge rather than inference. That intuition is now
wrong and has not caught up.
Distress destroys discrimination. Voice cloning is used most against people who are frightened,
and a crying voice on a bad line is hard to identify even when genuine.
Inside organisations, it exploits the fix. Firms that added “call and confirm” as a BEC control
have a process that a cloned voice walks straight through — unless the callback goes to a number the
firm already held.
And the quiet uses are the widespread ones. Better-written phishing, plausible profiles at volume,
convincing fake trading platforms. None of it makes headlines, and it accounts for most of the money.
Where it comes from
Synthetic media has no geography of its own. It is a capability, added to whatever operation already
exists — which is why the FBI reports it appearing inside BEC, romance, distress and employment fraud
rather than as a category of its own.
What the data does show is uneven adoption. The largest AI-linked losses attach to schemes that were
already the largest: business email compromise and confidence fraud. Compound-based operations in
Southeast Asia use it for profile generation and translation at scale; West African BEC networks use
it for correspondence; the distress-call version turns up wherever family emergency scams already run.
The most under-discussed variant is the employment one. Synthetic candidates interviewing for remote
roles is not consumer fraud at all — it is an intrusion technique wearing a job application, and it
sits closer to state-linked and organised network compromise than to anything else on this site.
Real cases
2026 US Ongoing
In July 2026 the FBI updated a warning first issued in April 2025 about an ongoing scheme in which criminals impersonate FBI personnel and the Internet Crime Complaint Center itself in order to re-victimise people who have already been scammed. The scheme uses AI-generated video, spoofed websites that harvest personal data, and fake FBI profiles on social media, and it is triggered precisely when a victim announces they intend to report the fraud.
Read the case file ·
1 source
2025 CA Ongoing $8.6m
The Canadian Anti-Fraud Centre files grandparent scams under "Emergency (Jail, Accident, Hospital, Help)", and its open dataset shows a category that rose fast and then fell just as fast. Reported losses went from C$2.5 million in 2021 to C$11.6 million in 2023, then dropped to C$3.3 million in 2024 and C$1.5 million in the first nine months of 2025. It is one of the clearest examples in any national dataset of a scam category being pushed back.
Read the case file ·
2 sources
2025 US Ongoing $3.0bn
The FTC's Impersonation Rule took effect in April 2024 and makes it illegal to falsely pose as a business or a government body, or to misrepresent an endorsement, with civil penalties of up to $53,088 per violation. In its first-year review the FTC recorded $2.95 billion in impersonation losses in 2024 and warned that AI-generated deepfakes threaten to turbocharge the problem.
Read the case file ·
3 sources
2025 US Ongoing $893.3m
The FBI received more than 22,000 complaints reporting AI-related information in 2025, with adjusted losses of $893,346,472. Its breakdown is more useful than the headline: over $30 million in AI-linked business email compromise, over $19 million in romance and confidence scams with a likely AI nexus, over $5 million in voice-cloned distress scams, and almost $13 million in employment scams where voice spoofing was used in interviews.
Read the case file ·
2 sources
2025 JP Ongoing $294.7m
Japan's National Police Agency counts SNS-type investment fraud by how the victim was first reached, and the largest single route is a banner advertisement using a celebrity's name — 3,202 cases and ¥44.09 billion through November 2025. The NPA's response was to run counter-campaigns alongside the named public figures whose likenesses had been used.
Read the case file ·
2 sources
2024 US Ongoing
In December 2024 the FBI published an itemised account of how criminals use generative AI across text, images, audio and video. The most consequential entries are the mundane ones: AI used to correct grammar and spelling for foreign actors targeting US victims, to produce fictitious social media profiles at volume, and to generate the content of fraudulent investment websites.
Read the case file ·
1 source
Red flags
- A distressed call from a relative on an unfamiliar number. The number is the tell, not the voice.
- Any urgent payment request confirmed only by voice, however familiar the voice is.
- A video call where lip movement lags the audio, or where coughs and other sounds do not match the picture.
- An executive authorising a transfer outside the normal process, particularly while travelling.
- A candidate who avoids turning the camera on, or whose video behaves oddly during an interview.
- A public figure endorsing a specific trading platform in a social media advert.
- Pressure not to hang up and call back. This is the point of the whole exercise.
- A request that arrives with a plausible reason why the usual channel is unavailable.
- Perfect, fluent, well-structured writing from a source that used to be sloppy.
If it’s happening to you
On a call now. End it and call back on a number you already had. Not a number given to you on the
call, not a number in a message — one from your own contacts, a card, or an official website. If the
caller resists, that resolves it.
For a family emergency, call the person directly, then call another family member. Ask the code word if
you have one.
In a business context. Do not act on a voice or video instruction alone. Confirm through a
pre-existing channel with a second person, and treat any change of payment details as a stop condition
regardless of who appears to be asking. See business email
compromise.
If money has gone. Call your bank immediately and ask for a recall; report it the same day. See
where to report. In a business case, preserve the call records, the meeting
invitation and any recording.
Preventing it.
Agree a family code word. Not guessable, never posted anywhere. Tell older relatives what it is
for. It is the cheapest and most effective countermeasure available for the distress variant.
Make callbacks a rule, not a suspicion. In a family and in an organisation, the framing that works
is “this is simply what we do”, because it removes the social cost of appearing to doubt someone.
Reduce what is available. Public voice and video is training data. This is not a reason to
disappear from the internet, but it is a reason to think about what a voicemail greeting in your own
voice, or a public video, is now worth.
Stop treating fluency as evidence. Well-written, correctly branded and confidently delivered are
no longer signals of legitimacy, and continuing to teach them as such is now actively harmful.
Where the money goes
Deepfakes do not change the money. A voice-cloned distress call ends in cash handed to a courier or a
transfer to a mule account, exactly as the non-cloned version does. A deepfaked executive instruction
ends in a wire to a receiving account that empties within hours, exactly as
BEC always did.
That is worth holding onto, because it means the defences at the money end are unchanged and still
work. The recall window, the second approver, the pre-existing callback number and the bank’s fraud
line all operate identically whether or not synthetic media was involved.
What has changed is only the point of verification — which is why every recommendation on this page is
about how you confirm a request rather than about how you detect a fake.
By the numbers
No published dataset breaks this scheme out as its own category yet, so there is no chart to show.
The data page explains which agency categories exist and why some schemes are
invisible in official statistics.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.