A phone rings. The voice on the other end sounds exactly like a grandchild in distress, asking for money before anyone finds out. The voice is not real. It is software, trained on a short audio clip found online, operated by a stranger working through a list of phone numbers. This is not a hypothetical. It is one of the most common AI-enabled scams circulating today, and it is costing Americans hundreds of millions of dollars a year.
The conversation about AI and security has long centered on corporate networks and government infrastructure. That framing misses where the actual financial damage is accumulating: in household accounts, at kitchen tables, among ordinary people making ordinary decisions under extraordinary pressure.
The Numbers Behind the Threat
In its 2025 annual report, the FBI’s Internet Crime Complaint Center tracked AI-connected fraud complaints for the first time. Americans filed more than 22,000 such cases and reported roughly 893 million dollars in losses. Investment fraud alone accounted for 632 million dollars of that total. Americans over 60 accounted for 352 million dollars in losses.
Those figures represent only victims who reported to the FBI and only cases where AI’s involvement could be identified. The consulting firm Deloitte projects that actual AI-driven fraud losses across the United States could reach 40 billion dollars by 2027, up from 12.3 billion dollars in 2023. The gap between what gets reported and what actually happens is, by any measure, enormous.
None of the underlying scams are new. What AI changed is the cost and the quality of the deception.
What AI Actually Changed About Fraud
Cloning a voice now requires only a few seconds of audio and inexpensive consumer tools. Research cited in the source found that listeners could identify an AI-generated voice only about 60% of the time. That is a coin flip with worse odds. Video is following the same trajectory. In 2024, a finance employee at the architecture and design firm Arup was deceived into wiring approximately 25 million dollars to fraudsters after attending a video meeting populated by deepfakes of the company’s chief financial officer and several colleagues.
Phishing emails have improved in parallel. Clumsy grammar and odd formatting once served as reliable warning signs. Language models now produce clean, fluent, personalized messages at scale, drawing on details scraped from social media. Deepfake videos of recognizable business figures are used to promote fraudulent trading platforms.
The pattern extends to business losses as well. The cyber insurer Resilience reported that more than 85% of the losses in its claims portfolio in the first half of 2026 stemmed from attacks targeting people rather than systems. The human layer, not the technical one, is where the vulnerability now lives.
This is what most coverage misses. The sophistication of these attacks is not primarily technical. It is psychological. Scams are engineered around fear and urgency: a panicked grandchild, a boss demanding a same-day transfer, an investment window closing tonight. Stress narrows attention and pushes people toward fast, intuitive decisions at exactly the moment when slow, deliberate ones are needed. Fraudsters also exploit authority, whether a CFO’s face on a video call or a government agency’s letterhead, because most people defer to it. Fluency matters too: a message with no typos, in a voice that sounds exactly right, bypasses defenses that a clumsy fake would have triggered.
What Individuals and Regulators Can Actually Do
Several practical defenses follow directly from understanding how these scams work. When a suspicious call arrives, the right response is to hang up and dial a number already known, such as a bank’s fraud hotline, never one supplied by the caller. A cloned voice cannot answer a real person’s phone. Families can agree on a code word for emergencies and treat any urgent money request that lacks it as fraudulent. A self-imposed 24-hour delay before any large payment removes the urgency that scammers manufacture. Two-factor authentication on financial accounts, transaction alerts, and a credit freeze add further layers of protection that cost little or nothing.
The regulatory picture is more complicated. In the United States, victims of instant-payment fraud often recover little, because banks frequently classify losses as “authorized” when a customer was deceived into approving a payment. The Consumer Financial Protection Bureau sued Zelle’s operator and three major banks over their response to alleged fraud in late 2024, then dropped the case in March 2025. New York’s attorney general has since filed her own lawsuit, which a judge allowed to proceed in July. Zelle’s operator denies the allegations and says it will appeal.
The United Kingdom has taken a different approach. Since late 2024, UK banks have been required to reimburse most scam victims up to 85,000 pounds, roughly 115,000 dollars, with costs split between sending and receiving institutions. The regulator’s own data shows that 88% of money lost to eligible scams has been returned to victims since the rules took effect. An independent evaluation found that scam losses fell by roughly a fifth in the rule’s first year. The logic is straightforward: when banks bear the financial cost of fraud, they deploy their security capabilities more fully.
In Short
AI has not invented financial fraud. It has made fraud faster, cheaper, more convincing, and harder to detect. The 893 million dollars reported to the FBI in 2025 is almost certainly a fraction of the real total. The most effective defenses combine personal habits, such as callback verification, code words, and deliberate delays, with institutional accountability of the kind the UK has begun to build. Speed and convenience in payments are genuine benefits. The question is who bears the cost when that speed is exploited.
Based on reporting from The Conversation AI.