# AI-Powered Scams
> [!abstract] What this note is
> AI makes impersonation cheap: a voice from a short clip, a face on a live video call, a phishing email that knows your job and your colleagues. This note covers what has happened, how large it has become, and the one defence that doesn't depend on spotting a fake. Part of [[AI Security for Users]]. Sources checked 2026-09-13.
## It already works on professionals
In January 2024 an employee of the engineering firm Arup in Hong Kong joined a video call with what appeared to be the company's CFO and several colleagues. Every other participant was a deepfake. The employee made 15 transfers totalling **HK$200 million, about US$25.6 million** [1].
The employee had initially been suspicious of the email that started it. The video call is what removed the doubt.
## The scale
The FBI's Internet Crime Complaint Center counted AI-enabled fraud separately for the first time in its 2025 annual report: **22,364 complaints and $893 million in reported losses** [2]. Reported losses undercount real ones.
In July 2026 the FBI warned that scammers were using AI-generated video of FBI officials to pressure victims [3]. Authority is the easiest thing to fake.
## The common shapes
- **The urgent family call.** A familiar voice in distress, asking for money now and asking you not to tell anyone.
- **The executive request.** A boss or a client, by voice note, video or email, asking for a transfer, a gift card purchase, or a change of bank details.
- **The personalised phish.** A message written with details scraped from your public profiles, so it reads like it came from someone who knows you.
- **The fake official.** Police, a bank's fraud team, a tax authority, a platform's security department.
What they share is **urgency plus a channel the scammer controls**.
## Don't try to spot the fake
Deepfakes improve faster than people learn to notice them, and the Arup call convinced someone who was already suspicious. A defence that depends on noticing will eventually fail.
The defence that holds is **procedural**:
1. **Verify on a channel you already had.** Hang up and call the number you have saved, not the one in the message. Message the person somewhere else.
2. **Agree a family code word** that is never posted anywhere, and ask for it.
3. **Never let the request choose the verification.** "Call me back on this number" is part of the scam.
4. **Treat urgency and secrecy as the signal.** Real emergencies survive a five-minute callback.
5. **No payment or credential changes on the strength of a voice or a face**, in business or at home.
6. **For businesses: two people on any transfer or bank-detail change**, confirmed out of band.
## Sources
1. [Arup revealed as victim of $25 million deepfake scam — CNN, 16 May 2024](https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk)
2. [2025 Internet Crime Report — FBI IC3](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)
3. [Public service announcement, 20 Jul 2026 — FBI IC3](https://www.ic3.gov/PSA/2026/PSA260720)
## Related
- [[AI Security for Users]] — the section overview
- [[AI Data Exposure]] — what's out there for a scammer to use