The Aigentic logo
Subscribe

Deep Dive

Scammers have an AI assistant, too

AI is making fraud cheaper to run, easier to personalize and harder to spot. Here are the identities scammers borrow — and how to check who’s really contacting you.

· The Aigentic

Scammers have an AI assistant, too

The same tools that help a business draft a note, summarize a file, or clone a voice for a demo also help a scammer. Microsoft’s 2026 threat research describes AI moving into criminal operations as a force multiplier: drafting phishing lures, translating messages, summarizing stolen data, and reducing the friction of running a convincing con. Human operators still set the target. The software makes the work cheaper to scale.

What the FBI can count

The FBI’s 2025 Internet Crime Report is the first IC3 annual report with a dedicated section on artificial intelligence (pages 39–41). Complainants filed 22,364 reports that mentioned AI, with about $893 million in associated losses. The bureau’s own summary puts the same figures next to a much larger total: more than a million complaints and nearly $21 billion in reported losses of every kind.

Those AI numbers are a floor, not a census. IC3 applies the AI descriptor only when a filer mentions artificial intelligence. Many victims have no way to tell that a message, a voice, or a profile was generated. The report itself notes the gap on investment fraud: AI-nexus losses in that category topped $632 million, while investment fraud overall exceeded $8.6 billion.

Why the economics changed

The incentive is straightforward. Convincing deception used to take time, language skill, and a plausible backstory for each target. Generative tools lower that cost. A scammer can produce more messages, in more languages, with fewer of the spelling and tone mistakes that once gave a pitch away.

That does not make every fake undetectable. It does mean a mediocre operation can look more professional than it used to, and a practiced one can reach more people without hiring a larger crew.

Personalized phishing, at machine scale

A 2024 study of 101 participants tested that shift in email. Researchers compared four groups: generic phishing, messages written by human experts, fully automated personalized emails, and AI drafts with a human in the loop. The generic control emails drew a 12% click-through rate. The fully automated personalized messages reached 54% — the same rate as the human-expert emails. Human-assisted AI drafts reached 56%.

The study is one experiment, not a universal click rate. The sample is small, the participants were recruited, and a click is not the same as a loss. It still shows the practical point: once personalization is cheap, a machine-written note can perform like an expert-written one.

How AI strengthens a scam

The FBI has warned that generative tools strengthen familiar schemes in three ways that show up again and again.

Personalized messages. Models can draft volume: romance and investment chats, spear-phishing notes, and fictitious social profiles that look consistent over time.

Cloned voices. Short audio of a relative, a boss, or a public figure can be turned into a call that asks for money now. The bureau’s advice is to hang up and reach the real person or institution on a number you already trust.

Manufactured evidence. Fake IDs, staged video calls, celebrity endorsements, and doctored “proof” can be generated to support the story. FTC impersonation data show the same pattern on the consumer side: a message that looks like a security alert, followed by a request to move money, share a code, or stay on the line.

The identities scammers borrow

Brand phishing works because the name on the message is one you already use. Check Point’s Q2 2026 ranking puts the concentration in plain numbers. The top five brands accounted for more than half of the brand-phishing attempts the company tracked that quarter.

Rank Brand Share of brand-phishing attempts
1 Microsoft 22.6%
2 LinkedIn 11.6%
3 Google 6.7%
4 Apple 5.8%
5 Amazon 5.2%
6 Adobe 3.8%
7 Facebook 1.9%
8 WhatsApp 1.4%
9 PayPal 1.3%
10 ChatGPT 1.1%

ChatGPT entered the top 10 for the first time. Check Point cites a fake ChatGPT Plus billing notice — a payment-failure email built to look like OpenAI’s, leading to a page meant to capture card details. The share is small. The signal is that an AI product is now familiar enough to impersonate.

Banks, Social Security, and the FTC itself

The brands are only part of the costume. The FTC also sees impersonations of banks, the Social Security Administration, and the FTC. A common sequence starts as a fake bank or company alert and then “transfers” you to a supposed government agent who says the only way to protect the money is to move it.

The real Social Security Administration will not suspend a number over the phone and demand gift cards or crypto. The real FTC will not threaten you, tell you to withdraw cash or buy gold, or ask you to transfer funds for safekeeping. A bank’s fraud department will not ask you to share a one-time verification code so it can “secure” the account.

Age changes the pitch, not the risk

FTC analyses of Consumer Sentinel reports find that adults 18–59 report higher rates of job, shopping, and investment scams. The Commission’s 2024 report to Congress on older consumers finds that people 60 and older are about five times as likely as younger adults to report losing money to a tech-support scam.

Older adults report losses less often overall. When they do report a loss, the median amount is higher. The 2024 Consumer Sentinel data book makes the same point in a later year of data: people in their twenties report a loss in a larger share of filings; people 70 and older report much higher median losses when money is gone.

Kids and fabricated images

Children are in a different category. The FBI has warned that ordinary photos — a school picture, a social-media post, a still from a video chat — can be altered into fabricated explicit images and used for extortion. The victim does not have to have sent a nude photo. The threat is the fake, plus a demand for money or for real images.

The bureau’s later notice on AI-generated child sexual abuse material is blunt: realistic computer-generated sexual images of minors are illegal. Families who need takedown help can use NCMEC’s Take It Down service. Reporting goes to IC3 and to NCMEC.

If something feels suspicious, interrupt

A request that arrives with urgency, secrecy, or an unusual payment method is asking you not to check. Give yourself the pause.

  1. Verify independently. Hang up or close the message. Look up the company, bank, school, or agency yourself — on a number or site you already have, not the one in the pitch.
  2. Contact the payment provider. If you sent money, shared a card, or used a transfer app, wire service, gift card, or crypto ATM, tell that provider immediately and ask whether the transaction can be reversed.
  3. Secure access. Change passwords on any account you may have exposed. Turn on multi-factor authentication. Check for new devices, forwarding rules, or recovery-email changes. If someone had remote access to a computer, run a scan with software you trust.
  4. Keep evidence and report. Save emails, texts, phone numbers, usernames, and receipts. Report to the FTC at ReportFraud.ftc.gov and to the FBI at IC3.

After a loss, a second contact often arrives offering to recover the money — for a fee, a “processing charge,” or your bank details. That is a recovery scam. Neither the FTC nor a legitimate agency will charge you to get a refund. Ignore the helper. Use the channels above.

AI makes a request easier to believe. It does not make the request real. Give yourself permission to pause — and verify the person making it.

Back to Deep Dive · Hands On · Subscribe

the aigentic

Know what matters in AI.

The stories shaping AI, the tools worth trying, and what they mean for your work.

Morning Brief + Closing Time. Two emails every weekday.

Free. Unsubscribe anytime.