AI Scams in 2026: How to Spot Deepfakes, Voice Clones & Fake Agents
On this page
Scams are not new. What’s new is that artificial intelligence has made them cheaper to run, faster to scale, and dramatically more convincing — a cloned voice, a deepfaked video call, a flawless phishing message, all generated in seconds. In 2026 the question is no longer “could I be fooled by a scam?” but “would I recognize one built by AI?” This guide breaks down how the major AI scams actually work, the real cases that show their reach, and — most importantly — the simple, low-tech habits that defeat even a perfect fake.
Key Takeaways
- Fraud hit record highs. Americans reported $16 billion in fraud losses to the FTC in 2025, up ~25% (FTC, 2026), and $20.9 billion to the FBI’s IC3 (FBI IC3, 2026).
- AI got its own line in the FBI’s report for the first time ever: ~$893 million in AI-linked losses — and the FBI says the real total is far higher (FBI, 2026).
- Deepfakes already drain real money. Engineering firm Arup lost ~$25 million to a deepfake video-call scam (CNN, 2024).
- The defense is low-tech. A family safe word and a callback to a known number beat any deepfake or voice clone, no detection skills required.
- Don’t rely on your eyes. Visual “tells” are fading as AI improves; verification through a separate channel is what actually protects you.
How big is the problem, really?
Big, and growing fast — though it’s worth being precise about the numbers, because scaremongering helps no one. Two government sources set the baseline. The Federal Trade Commission reported that people lost a record $16 billion to fraud in 2025, roughly a 25% jump from the year before, with imposter scams the #1 category for the fifth straight year at $3.5 billion (FTC, 2026). The FBI’s Internet Crime Complaint Center (IC3) logged even more — $20.9 billion in losses across more than a million complaints, up 26% year over year (FBI IC3, 2026).
The telling detail: in 2025, for the first time in its roughly 25-year history, the IC3 report added a dedicated section for AI-enabled fraud, tallying about $893 million in losses where AI was specifically identified (FBI, 2026). The FBI is careful to note that figure reflects only the cases where AI’s role was recognized — the true number is “far higher,” because a well-made fake often isn’t spotted as AI at all.
Why AI changed the scam game
Old scams had natural limits. A con artist could only make so many calls, write so many emails, and a bad accent or broken English gave the game away. AI erased those limits at once. To understand why, it helps to know what generative AI can now do — our plain-English guide to what AI is covers the basics — but the short version is that three things changed:
- It’s cheap and infinite. One scammer can now generate thousands of personalized, fluent phishing messages an hour, in any language, with no typos to give them away.
- It’s convincing. AI can clone a voice from a few seconds of audio and fake a video face in real time. The “tells” people learned to spot — bad grammar, robotic speech — are gone.
- It’s personal. Scrape someone’s social media, and AI can impersonate their writing style, reference real friends, and use a photo of their actual house. Generic scams became tailored ones.
The result isn’t a brand-new category of crime. It’s the same scams — impersonation, romance, investment, tech support — supercharged. So let’s go through the main types and, for each, exactly how to spot it.
Scam type 1: Deepfake video scams
A deepfake is AI-generated video or imagery of a real person. The landmark case is sobering: in 2024, the global engineering firm Arup lost about $25 million when an employee in Hong Kong was invited to a video call, saw and heard the company’s CFO and several colleagues, and followed their instructions to make 15 transfers. Every person on that call except the victim was a deepfake, built from publicly available video and audio (CNN, 2024).
The consumer versions are everywhere now. Deepfaked videos of Elon Musk promoting crypto giveaways have cost individuals dearly — one Ontario man lost $1.7 million to such a scheme (Yahoo Finance, 2025). Fake celebrity endorsements, fake “news clips,” and fake CEO announcements all follow the same script: a trusted face tells you to act fast with money.
How to spot it: Visual tells still exist — unnatural blinking, lips slightly out of sync, blurry edges around the face, lighting that doesn’t match, skin that’s too smooth. But treat these as weak signals, because they fade with every model upgrade. On a live video call, ask the person to turn their head fully sideways or wave a hand in front of their face — actions current deepfakes handle poorly (Consumer Reports, 2025). The reliable rule: any video that pressures you to send money or crypto is a scam until you verify it through a separate, trusted channel.
Scam type 2: Voice clones and the “family emergency” call
This is the AI scam most likely to reach an ordinary family. Scammers need only a few seconds of someone’s voice — pulled from a social video, a voicemail greeting, or a short “wrong number” call — to produce a convincing clone (CNN, 2026). Then comes the call: your grandchild, child, or sibling, panicked, saying they’ve been in an accident or arrested and need money right now. The voice is unmistakably theirs. The caller ID may even be spoofed to match.
The emotional hijack is the whole point — panic short-circuits skepticism. A 2023 survey by security firm McAfee found that 1 in 4 adults had experienced an AI voice scam or knew someone who had, 77% of targets who received a clone message lost money, and 70% weren’t confident they could tell a cloned voice from the real one (McAfee, 2023). (That’s a vendor survey, but the pattern matches what the FTC and FBI now warn about.)
The single best defense, from the FTC: Don’t trust the voice. Hang up and call the person back on a number you know is theirs. And set up a family “safe word” — a private word or phrase that any real emergency caller must say. A cloned voice can sound perfect; it can’t know your secret word (FTC, 2023).
Scam type 3: AI romance and “pig butchering” investment scams
Romance scams were devastating before AI; now they’re industrialized. Generative tools let a single operator run dozens of fake personas at once — complete with AI-generated profile photos, AI-written messages with no language tells, and even AI “video selfies” to defeat a video-chat request. Many of these evolve into “pig butchering” schemes, where the scammer slowly builds trust, then steers the victim into a fake crypto investment that looks profitable until the money vanishes.
The scale is staggering. The FBI’s IC3 counts crypto investment fraud as its single largest loss category, and of the $893 million in specifically AI-linked losses in 2025, investment fraud accounted for about $632 million (FBI via SecureWorld, 2026). One widely reported case shows the human cost: a French woman was manipulated over months by a scammer using AI-generated images and videos of actor Brad Pitt, ultimately losing around €830,000 ($850,000) — and then enduring public mockery as a victim of a uniquely cruel deception (NBC News, 2025).
How to spot it: A new online connection who professes strong feelings quickly, never manages to meet in person, and eventually mentions an “amazing investment” is following the script almost exactly. Reverse-image-search their photos, be deeply skeptical of anyone introducing crypto, and remember that a willingness to video chat is no longer proof — AI can fake that too.
Scam type 4: AI phishing and impersonation
The everyday workhorse of AI fraud is impersonation — of your bank, a government agency, a delivery service, or your employer. AI writes flawless, personalized messages at massive scale, which is why imposter scams remain the FTC’s top category, with government impersonators alone accounting for about $920 million in 2025 losses (FTC, 2026). The old advice to “watch for spelling mistakes” is officially dead.
A fast-growing workplace variant targets job seekers: fake recruiters, AI-generated interviewers, and deepfaked candidates. The FBI attributes roughly $13 million in 2025 AI-linked losses to employment and interview deepfakes (FBI via SecureWorld, 2026) — a phenomenon we explore from the hiring side in our guide to AI interview questions and fake candidates.
How to spot it: Any unexpected message creating urgency around money, passwords, or personal data deserves suspicion — regardless of how polished it looks. Never click links in such messages; instead, go directly to the organization’s official site or app, or call the number on the back of your card. Legitimate institutions don’t demand gift cards, crypto, or wire transfers.
Scam type 5: Fake AI agents — and where this is heading
The newest frontier is “agentic” AI — systems that don’t just chat but take actions: browsing, messaging, transacting on their own (our beginner’s guide to agentic AI explains the concept). The same autonomy that makes agents useful makes them a powerful tool for fraud. Security analysts at Sumsub explicitly warn that agentic AI scams are poised to surge in 2026, with fraud shifting toward complex, multi-step automated schemes (Sumsub, 2026).
There’s also a more technical threat aimed at developers rather than consumers, worth knowing about because it signals the direction of travel. In June 2026, security firm Tenet Security disclosed an attack class it calls “Agentjacking,” in which attackers plant fake error reports that AI coding agents read and act on — executing the attacker’s instructions. Tenet reported a roughly 85% success rate in testing and 2,388 organizations with exposed credentials (Tenet Security, 2026; The Next Web, 2026). To be clear: Agentjacking targets software developers, not everyday users — you don’t need to defend against it personally. But it illustrates the broader 2026 lesson — as we hand AI agents more power to act, “tricking the agent” becomes a new category of attack.
How to spot it (as a consumer): Be wary of any “AI assistant,” chatbot, or browser extension that asks for payment details, account access, or permission to act on your behalf, especially if you didn’t seek it out. Stick to official apps from known companies, and never grant an AI tool access to your bank, email, or passwords unless you fully trust and recognize the provider.
Your anti-scam playbook
Here’s the reassuring part: you don’t need to become a deepfake detective. A handful of habits neutralize nearly every AI scam, because they bypass the fake entirely and verify through a channel the scammer doesn’t control.
| Habit | Why it works |
|---|---|
| Set a family safe word | A cloned voice can’t know a private phrase you agreed on in advance. |
| Hang up and call back | Verifying on a known number defeats spoofed caller ID and cloned voices. |
| Slow down | Urgency is the scammer’s main weapon; almost no real emergency needs money in minutes. |
| Never pay in gift cards, crypto, or wire | These are the payment methods of fraud; legitimate institutions don’t demand them. |
| Don’t click; navigate directly | Go to the official app or site yourself instead of trusting a link or number you were sent. |
| Lock down social media | Less public voice and video means less raw material to clone you or your family. |
| Verify on live video | Ask them to turn their head or wave a hand — and still confirm separately if money’s involved. |
The throughline is a mindset, not a gadget: treat any unexpected, urgent request involving money or access as a scam until you’ve verified it independently. That single reflex protects you against fakes far better than any visual inspection — and it works even against the perfect deepfake that no human eye could catch.
If you think you’ve been targeted or scammed
Act quickly and don’t be embarrassed — these scams fool careful, intelligent people by design.
- Stop sending money and cut contact with the scammer.
- Call your bank or payment provider immediately. Fast reporting improves the odds of stopping or recovering a transfer.
- Report it. File with the FBI’s Internet Crime Complaint Center at IC3.gov and the FTC at ReportFraud.ftc.gov, and notify local police.
- Preserve evidence — screenshots, phone numbers, transaction details, and messages.
- Warn the people around you, especially older relatives, who are frequently targeted by voice-clone calls.
Reporting matters even when recovery isn’t possible: it feeds the data that helps the FTC and FBI track these schemes and warn others.
The honest bottom line
AI hasn’t invented new crimes; it has industrialized old ones and stripped away the clues we relied on to catch them. Spelling mistakes, robotic voices, and obvious fakes are no longer your safety net. But the flip side is genuinely encouraging: the defenses that work best in 2026 are old-fashioned and free. A safe word. A callback. A deep breath before you act. Scammers are betting on speed and emotion; your strongest move is to be the person who slows down and verifies. Do that consistently, teach it to the people you love, and even a flawless AI fake has nowhere to go.
Frequently Asked Questions
How do AI voice cloning scams work?
Scammers grab a few seconds of someone’s voice — from a social media video, voicemail, or a quick “wrong number” call — and use AI to clone it. They then call a relative pretending to be that person in a crisis (“I’ve been in an accident, I need money now”), often spoofing the real caller ID. The voice sounds genuinely like your loved one. The defense is simple and powerful: hang up and call the person back on their real number, and agree on a family “safe word” in advance that any real emergency caller must say.
What is a deepfake scam?
A deepfake scam uses AI-generated video or images of a real person to deceive a victim. The most famous case is engineering firm Arup, which lost about $25 million in 2024 after an employee joined a video call where the “CFO” and colleagues were all AI deepfakes. Consumer versions include fake celebrity investment videos (deepfaked Elon Musk promoting crypto) and romance scams using AI-generated photos. If a video pressures you to send money or crypto, treat it as a scam until verified through a separate, trusted channel.
How can you tell if a video call is a deepfake?
Visual tells still exist — unnatural blinking, lips slightly out of sync with audio, odd lighting, blurry edges around the face, or skin that looks too smooth — but they’re getting less reliable as the technology improves. A better test on a live call is to ask the person to do something deepfakes struggle with: turn their head fully sideways, wave a hand in front of their face, or stand up. The strongest defense isn’t your eyes at all — it’s verification: call them back on a known number before acting.
What should I do if I think I’ve been targeted or scammed by an AI scam?
Stop sending money immediately. Contact your bank or payment provider right away — fast reporting improves the chance of recovering funds. Report the incident to the FBI’s Internet Crime Complaint Center at IC3.gov and to the FTC at ReportFraud.ftc.gov, and tell local law enforcement. Preserve evidence: screenshots, phone numbers, transaction records, and any messages. Reporting also helps investigators spot patterns, even when your own money can’t be recovered.
Are AI scams really increasing in 2026?
Yes. Americans reported a record $16 billion in fraud losses to the FTC in 2025, up about 25% year over year, and the FBI’s IC3 logged $20.9 billion in losses. For the first time in its roughly 25-year history, the FBI’s 2025 report added a dedicated AI section, tallying about $893 million in losses where AI was specifically identified — and noting the true figure is far higher, since AI’s involvement often goes unrecognized.
Sources
- FTC, “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025,” retrieved 2026-06-29, https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
- FBI IC3, “2025 Internet Crime Report,” retrieved 2026-06-29, https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- FBI, “Cryptocurrency and AI Scams Bilk Americans of Billions,” retrieved 2026-06-29, https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
- SecureWorld, “AI-enabled fraud topped $893M, FBI says,” retrieved 2026-06-29, https://www.secureworld.io/industry-news/ai-enabled-fraud-topped-893m-fbi
- CNN Business, “Finance worker pays out $25 million after video call with deepfake CFO,” retrieved 2026-06-29, https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
- NBC News, “AI Brad Pitt dupes French woman out of $850,000,” retrieved 2026-06-29, https://www.nbcnews.com/news/world/ai-brad-pitt-woman-romance-scam-france-tf1-rcna187745
- Yahoo Finance, “Ontarian loses $1.7M to crypto scam using AI Musk video,” retrieved 2026-06-29, https://ca.finance.yahoo.com/news/ontarian-loses-1-7m-crypto-130800904.html
- FTC Consumer Advice, “Scammers use AI to enhance their family emergency schemes,” retrieved 2026-06-29, https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes
- CNN, “AI voice-cloning scams: how to protect yourself,” retrieved 2026-06-29, https://www.cnn.com/2026/05/29/tech/ai-voice-cloning-scams-protect-yourself
- McAfee, “Beware the Artificial Imposter,” retrieved 2026-06-29, https://www.mcafee.com/content/dam/consumer/en-us/resources/cybersecurity/artificial-intelligence/rp-beware-the-artificial-impostor-report.pdf
- Sumsub, “Agentic AI scams poised to surge in 2026,” retrieved 2026-06-29, https://sumsub.com/newsroom/sumsubs-annual-report-fraud-shifts-to-complex-multi-step-schemes-in-2025-agentic-ai-scams-poised-to-surge-in-2026/
- Tenet Security, “Agentjacking: coding agents with fake Sentry errors,” retrieved 2026-06-29, https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/
- The Next Web, “Agentjacking: AI coding agents and Sentry,” retrieved 2026-06-29, https://thenextweb.com/news/agentjacking-ai-coding-agents-sentry
- Consumer Reports, “Don’t get caught by a deepfake scam,” retrieved 2026-06-29, https://www.consumerreports.org/money/scams-fraud/dont-get-caught-by-a-deepfake-scam-a1121081735/