The Rise of AI Scams in 2026: How Criminals Are Fooling Millions Online
A finance employee at the engineering firm Arup joined what looked like a routine video call with the company’s CFO and several colleagues. Every face on the screen was a deepfake. By the time the call ended, the employee had wired $25.6 million to the scammers behind it.
That single transaction is the clearest illustration of what’s changed. AI scams in 2026 no longer rely on broken English and obvious red flags. They use cloned voices, synthetic video, and language models that write better than most native English speakers. The FBI’s Internet Crime Complaint Center logged this shift formally for the first time this year, introducing “AI-related” as a standalone fraud category in its 2025 Internet Crime Report, released in April 2026. The category recorded 22,364 complaints and $893.35 million in adjusted losses — and investigators openly call that number a floor, not a ceiling, since most victims never realize AI was involved.
Why AI Scams in 2026 Look Nothing Like Old Phishing Emails
The old tells are gone. Spelling errors, awkward phrasing, and generic “Dear Customer” openers used to be the first line of defense against phishing. Large language models erased that advantage. Cybersecurity firm Vectra AI found that AI-generated phishing emails now achieve click-through rates more than four times higher than human-written ones, and reported that AI-enabled fraud overall surged 1,210% during 2025.
Three capabilities are driving the surge:
- Voice cloning that needs almost no source material — McAfee researchers found that three seconds of audio is enough to produce a clone with roughly 85% accuracy.
- Real-time deepfake video, the technology used in the Arup call, now cheap enough to run on consumer hardware.
- Automated conversation, where chatbots run romance scams or tech-support cons across thousands of victims at once, adjusting tone and language on the fly.
How Much Money Are People Actually Losing?
The numbers vary depending on who’s counting and what they count, which is itself worth understanding before citing any single figure.
The FBI’s $893.35 million covers only complaints filed with US law enforcement that explicitly referenced AI. The Global Anti-Scam Alliance, surveying 46,000 adults across 42 countries, put worldwide scam losses — AI-assisted and otherwise — at $442 billion, a figure that captures unreported losses the FBI data misses entirely. Deloitte’s Center for Financial Services projects generative-AI-enabled fraud losses in the US alone will reach $40 billion by 2027, up from $12.3 billion in 2023.
Deepfake fraud specifically has a documented trajectory. Losses in the US reached roughly $1.1 billion in 2025, according to threat-intelligence firm Keepnet — nearly triple the $360 million recorded the year before. Separately, blockchain analytics firm Chainalysis found that crypto scam operations with visible ties to AI vendors generated 4.5 times more revenue per operation than those without, and estimated at least $14 billion flowed into identified crypto scam addresses in 2025 alone.
Why Can’t People Just Spot the Fakes?
Because, increasingly, they can’t. A study by identity-verification firm iProov found that only 0.1% of people could reliably identify AI-generated deepfakes when tested directly. Detection rates for video deepfakes specifically sit around 24.5%, according to threat research firm DeepStrike — barely better than a coin flip.
Even automated detection struggles outside the lab. Tools that hit 96% accuracy under controlled conditions drop to 45–50% accuracy in real-world deployment, where lighting, compression, and network quality vary. That gap matters because it means the burden of catching these scams is shifting away from individual vigilance and toward institutional process — verification callbacks, second-channel confirmation, multi-person sign-off on large transfers.
That’s precisely what saved two other major companies. When Ferrari and the advertising giant WPP faced their own deepfake CEO-impersonation attempts, employees stopped the fraud not with detection software but by asking one unscripted, personal question the AI voice couldn’t answer.
The Romance Scam Playbook, Rebuilt With AI
Romance fraud predates AI by decades, but generative tools have made it far more convincing. Dating platforms now show a 6.3% fraud rate — more than double the rate seen in financial services, according to fraud-trend research published by FF News in mid-2026.
The mechanics are simple and brutal. A scammer builds a profile using AI-generated or deepfake photos, sometimes adding video calls with a face-swapped identity to build trust faster. Once the emotional hook is set, the request follows: a medical emergency, a “guaranteed” crypto opportunity, help covering a wallet transfer. In October 2024, Hong Kong police arrested 27 people running a deepfake romance ring that used face-swapping and voice-changing software to pull victims into fake crypto investments over live video, with losses reaching into the millions of dollars.
Who’s Actually Behind These Scams?
Not lone hackers in basements. Chainalysis’s 2026 Crypto Crime Report found that scams impersonating government officials using deepfaked imagery grew more than 1,400% during 2025, pointing to organized, well-funded operations rather than opportunistic individuals. Much of this activity traces back to industrialized scam compounds in Southeast Asia, where trafficked workers are forced to run AI-assisted fraud operations at scale — a labor and human-rights crisis running parallel to the financial one.
What Regulators Are Doing About It
Legislation is catching up, unevenly. Forty-seven US states have now passed some form of deepfake law, totaling 169 statutes since 2022, according to tracking firm MultiState. The federal TAKE IT DOWN Act, which requires platforms to remove non-consensual deepfake content within 48 hours of a valid request, has been in force since May 19, 2026. In the European Union, the AI Act’s content-labeling requirements take effect in August 2026, carrying penalties of up to €35 million or 7% of a company’s global revenue.
Whether enforcement can keep pace with generation speed is an open question. Deepfake creation tools iterate in weeks; legislation takes years.
How to Protect Yourself From AI Scams
Security researchers and law enforcement converge on a short list of defenses that don’t depend on spotting a fake in real time:
- Verify through a second channel. If a call, text, or email demands money or credentials urgently, hang up and call the person back on a known number.
- Establish a family or company codeword for financial emergencies — something an AI clone won’t know to say.
- Slow down urgent requests. Scammers manufacture time pressure because hesitation is their biggest enemy.
- Treat unsolicited romantic or investment contact with default skepticism, especially if the relationship moves toward a money request within weeks.
- Assume video and voice can be faked. The technology is no longer expensive or rare.
None of these require special software. They require friction — the one thing AI-generated fraud is specifically engineered to remove.
The scammers didn’t get smarter. They got a better tool. The defense has to start there.


