# AI-Powered Scams > [!abstract] What this note is > AI makes impersonation cheap: a voice from a short clip, a face on a live video call, a phishing email that knows your job and your colleagues. This note covers what has happened, how large it has become, and the one defence that doesn't depend on spotting a fake. Part of [[AI Security for Users]]. Sources checked 2026-09-13. ## It already works on professionals In January 2024 an employee of the engineering firm Arup in Hong Kong joined a video call with what appeared to be the company's CFO and several colleagues. Every other participant was a deepfake. The employee made 15 transfers totalling **HK$200 million, about US$25.6 million** [1]. The employee had initially been suspicious of the email that started it. The video call is what removed the doubt. ## The scale The FBI's Internet Crime Complaint Center counted AI-enabled fraud separately for the first time in its 2025 annual report: **22,364 complaints and $893 million in reported losses** [2]. Reported losses undercount real ones. In July 2026 the FBI warned that scammers were using AI-generated video of FBI officials to pressure victims [3]. Authority is the easiest thing to fake. ## The common shapes - **The urgent family call.** A familiar voice in distress, asking for money now and asking you not to tell anyone. - **The executive request.** A boss or a client, by voice note, video or email, asking for a transfer, a gift card purchase, or a change of bank details. - **The personalised phish.** A message written with details scraped from your public profiles, so it reads like it came from someone who knows you. - **The fake official.** Police, a bank's fraud team, a tax authority, a platform's security department. What they share is **urgency plus a channel the scammer controls**. ## Don't try to spot the fake Deepfakes improve faster than people learn to notice them, and the Arup call convinced someone who was already suspicious. A defence that depends on noticing will eventually fail. The defence that holds is **procedural**: 1. **Verify on a channel you already had.** Hang up and call the number you have saved, not the one in the message. Message the person somewhere else. 2. **Agree a family code word** that is never posted anywhere, and ask for it. 3. **Never let the request choose the verification.** "Call me back on this number" is part of the scam. 4. **Treat urgency and secrecy as the signal.** Real emergencies survive a five-minute callback. 5. **No payment or credential changes on the strength of a voice or a face**, in business or at home. 6. **For businesses: two people on any transfer or bank-detail change**, confirmed out of band. ## Sources 1. [Arup revealed as victim of $25 million deepfake scam — CNN, 16 May 2024](https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk) 2. [2025 Internet Crime Report — FBI IC3](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf) 3. [Public service announcement, 20 Jul 2026 — FBI IC3](https://www.ic3.gov/PSA/2026/PSA260720) ## Related - [[AI Security for Users]] — the section overview - [[AI Data Exposure]] — what's out there for a scammer to use