Case Library / Agentic AI Attacks (AI-Powered Social Engineering) / FBI IC3's First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)

FBI IC3's First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)

The FBI's 2025 Internet Crime Report introduced IC3's first-ever dedicated AI-fraud tracking section in its nearly 25-year history, logging 22,364 complaints and $893,346,472 in losses from scams using voice clones, deepfake video, fake AI-generated social profiles, and forged identification documents.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In its 2025 Internet Crime Report (covering calendar-year 2025 complaint data, released April 6, 2026), the FBI's Internet Crime Complaint Center (IC3) published, for the first time in the Center's nearly 25-year history, a dedicated section titled "Artificial Intelligence (AI) Used in Cybercrime." That section tallied 22,364 complaints in which AI played a role in the fraud, totaling $893,346,472 in reported/adjusted losses, a new, standalone tracking category distinct from IC3's traditional crime-type breakdowns (BEC, investment fraud, tech support fraud, etc.). The AI figure sits inside IC3's much larger 2025 totals: roughly 1,008,597 total complaints (up from 859,532 in 2024) and total reported losses of approximately $20.877 billion (the FBI's press release rounds this to "nearly $21 billion"), of which cryptocurrency-related complaints alone accounted for over $11 billion and cyber-enabled fraud complaints for over $17.7 billion. By comparison, IC3's prior report (calendar year 2024) recorded $16.6 billion in total losses with no dedicated AI section. The FBI explicitly framed the AI figure as likely an undercount, since many victims may not realize AI (e.g., a cloned voice or a synthetic video) was used against them.

How the Attack Worked

The $893 million is not one incident but an aggregate tally the FBI built for the first time by tagging IC3 complaints in which the victim reported (or investigators identified) some form of AI involvement in the scam. Per the FBI's own description, the underlying techniques folded into that figure include: voice cloning used to impersonate a family member in distress, a company executive authorizing a wire, or a government official demanding payment; deepfake video (believable synthetic video of celebrities, CEOs, or a victim's loved one) used to add visual "proof" to investment pitches, romance scams, or emergency-money requests; fake AI-generated social media profiles used to build long-running romance/confidence relationships; AI-generated or forged identification documents used to pass identity checks in employment and financial scams; and AI-generated conversational scripts that let scammers run persuasive, personalized dialogue (in BEC-style emails, romance chats, and investment pitches) at a scale and polish that would previously have required more manual effort per victim. IC3's report frames the throughline as scammers "deploying fake social profiles, voice clones, identification documents, and believable videos" combined with classic pressure tactics (urgency, secrecy, emotional appeals) to get victims to move money or hand over credentials before they can verify what they're seeing or hearing is synthetic.

The Lure & the Tell

Because this record is an aggregate statistic rather than a single case, there is no single lure. The report's illustrative pattern spans several scam types, unified by AI making the impersonation more convincing than a text-only or voice-only con: a cloned voice claiming to be a grandchild, spouse, or executive urgently needing money; a deepfake video "proving" a celebrity or CEO is personally endorsing an investment; an AI-run chat persona sustaining a months-long romance before requesting funds; or an AI-forged ID clearing a background/identity check in an employment or loan scam. The unifying "tell" IC3 highlights across these is the pressure to act immediately without independent verification: its "Take a Beat" advisory exists specifically because AI-generated audio/video/text is now often good enough that visual or auditory instinct alone no longer reliably catches the fake.

Outcome

The figure was published as part of the FBI's 2025 Internet Crime Report (covering calendar year 2025) and announced via FBI press release on April 6, 2026 under the headline "Cryptocurrency and AI Scams Bilk Americans of Billions." The FBI paired the release with renewed public-awareness messaging (the "Take a Beat" campaign) and pointed to related initiatives, Operation Level Up (proactive crypto-fraud victim notification, launched 2024) and Operation Winter SHIELD (2026, organizational security hardening), as its operational response. Separately and around the same period, DOJ's Fraud Division and Ohio federal/state prosecutors announced a partnership (June 4, 2026 press release) charging 9 defendants in over $42 million of fraud and establishing a data-sharing agreement and an FBI "Most Wanted Fraudsters" list; that Ohio announcement references AI-driven video platforms used in an unrelated romance-fraud scheme but does not itself report or corroborate the $893 million aggregate figure. The two are separate but contemporaneous data points about AI's role in the fraud landscape, not the same claim.

Why It Matters

This is one of the first times a major U.S. law-enforcement body has stood up a dedicated, named tracking category for AI-facilitated fraud inside its flagship annual crime statistics, a signal that AI-enabled social engineering (voice cloning, deepfake video, synthetic profiles/documents, AI-generated persuasive text) has moved from a novel curiosity to a scale problem large enough to warrant its own line item, worth roughly 4.3% of all IC3-reported losses in its debut year. Because the figure is complaint-driven and self-identified by victims/investigators as "AI-involved," the FBI's own caveat that it is likely conservative matters for anyone citing the number: the true scale of AI-facilitated fraud is probably materially higher than $893 million, since much AI involvement (a well-executed voice clone, a convincingly deepfaked video) may go completely undetected by the victim who files the complaint. For an educational/awareness site, this record supports the broader claim that AI-driven impersonation (voice, video, and text) is now a nationally tracked, billion-dollar-adjacent driver of financial fraud in the US, while also illustrating the limits of complaint-based statistics as a way to size the problem precisely.

Defenses

FBI's public messaging around the report centers on its "Take a Beat" campaign: resisting pressure to act quickly and verifying identity/context before sending money or personal/financial information, especially for calls or videos that "sound"/"look" like a known person. The Bureau also points to Operation Level Up (proactive victim notification for crypto-investment fraud, credited with over 8,000 victims notified and >$500M in losses averted since 2024) and the 2026 Operation Winter SHIELD (organizational digital-security hardening) as complementary mitigation efforts. For AI-specific risk, IC3's report implicitly recommends: independent callback verification (not the number/contact provided by the counterparty) before acting on a voice or video request; skepticism toward urgent financial asks from "known" contacts reached only through a single unverified channel; and reporting suspected AI-enabled fraud to ic3.gov promptly (the Bureau notes IC3 receives ~3,000 complaints/day) so patterns can be tracked. IC3 also flags that its own AI figure is likely an undercount, since many victims never realize AI (e.g., a cloned voice) was used against them, a real limitation of complaint-based statistics as an early-warning tool.

Sources
  • 1 2025 IC3 Annual Report. FBI / Internet Crime Complaint Center Primary. Source document containing the AI-fraud section, the 22,364-complaint/$893,346,472-loss figures, and total 2025 loss figures. Verified by direct fetch: the report's 'Descriptors' table lists 'AI Related' complaints = 22,364 and 'AI Related' losses = $893,346,472, an exact match.
  • Cryptocurrency and AI Scams Bilk Americans of Billions. FBI Primary. April 6, 2026 FBI press release announcing the 2025 IC3 report; confirms this is the first AI-dedicated section in IC3's ~25-year history, cites the 22,364 complaints / nearly $893 million figure, total ~$21 billion 2025 losses, and 1,008,597 total complaints. Verified by direct fetch.
  • FBI Releases Annual Internet Crime Report. FBI Primary. Prior-year (2024) IC3 report press release; used for the $16.6 billion 2024 total-loss comparison figure (no dedicated AI category that year). Verified by direct fetch (dated April 23, 2025; reports 859,532 complaints and losses exceeding $16 billion).
  • Fraud Division Announces Federal-State Partnership in Ohio to Prosecute Fraud. United States Department of Justice Primary. June 4, 2026 DOJ press release on the separate Ohio fraud task force/rollout; provides contemporaneous context (references AI-driven video platforms in an unrelated romance-fraud case) but is not the source of the $893 million aggregate figure. Verified by direct fetch.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and persona/target research: This is an aggregate statistic rather than a single incident, so IC3's report does not detail one recon method, but the scam types folded into the AI figure (romance scams, BEC, executive/official impersonation, investment fraud) typically require identifying both a plausible person to impersonate and a person to target, drawing on OSINT sources such as social media, company websites and org charts, dating-app profiles, and public records to learn names, relationships, and enough personal detail to make an AI-generated persona or cloned voice convincing.
Countering Stage 1: Employee, family, and public OSINT exposure (LinkedIn roles, org charts, social media, dating-app profiles) is very hard to eliminate at the individual or enterprise level; the realistic control assumes an attacker can already learn this and instead limits what a stranger can achieve through a single channel, rather than trying to hide the underlying information.
2
AI tooling acquisition and synthetic-asset creation: Per IC3's description of the techniques inside the $893 million figure, scammers typically source commercially available voice-cloning services, deepfake video generation tools, AI-generated or forged identification-document templates, and AI chat/LLM tools to produce the synthetic voice sample, video clip, fake social profile, or forged ID used in the scheme.
Countering Stage 2: There is no practical way to block private acquisition of commercial voice-cloning or deepfake tools before contact occurs; the nearest realistic control sits downstream, treating any voice or video 'proof' received unexpectedly as unverified by default rather than trying to prevent the tooling's existence.
3
Initial contact and pretext delivery: The scammer reaches the victim through a channel matching the scam type, a phone or video call for a cloned voice claiming to be a family member, executive, or government official, a dating app or social media message for a fake AI-generated profile, or a job/loan application flow for a forged ID, opening with a scenario (distress, opportunity, or an official demand) built to feel urgent from first contact.
Countering Stage 3: Unsolicited contact making an urgent claim, a distress call, an investment tip, a romantic overture, or an official demand should trigger independent verification through a channel the recipient controls, not one the caller or messenger provides, before any further engagement.
4
Trust-building and synthetic-credibility reinforcement: For longer-running schemes (romance, investment), IC3 notes AI-generated conversational scripts let scammers sustain a believable, personalized relationship over weeks or months at a scale that would previously have required more manual effort per victim; for shorter schemes, a deepfake video or cloned voice is used as one-time 'proof' (a celebrity or CEO endorsing an investment, a loved one's panicked voice) standing in for the identity verification a victim would otherwise seek.
Countering Stage 4: Skepticism toward 'proof' delivered only through the same channel as the ask is the core defense here; verifying a loved one's, executive's, or official's claim through a separately initiated call to a known number, or an established in-person channel, neutralizes synthetic credibility regardless of how convincing it sounds or looks.
5
Pressure and urgency to bypass verification: IC3's report frames this as the throughline across the AI-enabled scam types it tracked, pairing the synthetic 'proof' built up in earlier stages with classic pressure tactics, urgency, secrecy, and emotional appeals, specifically to get the victim to act before they can independently verify what they are seeing or hearing.
Countering Stage 5: This is exactly what IC3's 'Take a Beat' campaign targets: deliberately pausing under pressure and confirming identity and context before acting is the FBI's stated primary countermeasure for AI-enabled impersonation fraud.
6
Payment or credential extraction: The victim wires money, buys and sends cryptocurrency, purchases gift cards, or hands over identity/financial credentials (in employment or loan-fraud variants using forged IDs), completing the transaction the earlier stages built toward.
Countering Stage 6: Financial-institution controls, transaction holds, out-of-band confirmation for large wires or crypto purchases, and IC3's Recovery Asset Team Financial Fraud Kill Chain process, can intercept funds if the transfer is reported within the narrow window before funds clear.
7
Objective completion, fund movement, and complaint capture: Losses are realized once funds leave the victim's control, and IC3's own Recovery Asset Team data shows scammers typically routing stolen funds through further transfers before law enforcement can intervene; the case only enters the $893 million aggregate once a victim later files an IC3 complaint that gets tagged AI-related, which is also why the FBI describes the figure as a likely undercount.
Countering Stage 7: Prompt reporting to ic3.gov (the Bureau notes it receives roughly 3,000 complaints per day) is the main lever once funds have moved, both for the Recovery Asset Team's chance at freezing funds and for improving the completeness of the AI-fraud statistic itself, which the FBI already flags as an undercount driven by victims not recognizing AI was involved.
Quick Facts
Victim
US consumers nationally who filed complaints with the FBI's Internet Crime Complaint Center (IC3) in which AI was identified as involved in the fraud, 22,364 complaints in aggregate, drawn from IC3's broader 2025 intake of over 1 million total complaints.
Location
United States (nationwide, aggregate of IC3 complaints from consumers across all states)
Date
Calendar year 2025 (figure published in FBI's 2025 Internet Crime Report, released April 6, 2026)
Impact
$893,346,472 in adjusted/reported losses across 22,364 AI-related complaints for calendar year 2025, a subset (roughly 4.3%) of IC3's total 2025 reported losses of approximately $20.877 billion (per the FBI's April 6, 2026 press release, "nearly $21 billion" across ~1,008,597 total complaints). For comparison, IC3's prior (2024) annual report, which had no dedicated AI category, recorded $16.6 billion in total losses.
Status
Confirmed
Case Type
Research / Advisory
Sector
Cross-Sector / Multiple Industries, Cryptocurrency & Digital Assets, Financial Services & Insurance
Related

Related Cases

PromptLock: AI-Generated Ransomware Proof-of-Concept Discovered on VirusTotal

ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model (gpt-oss:20b via Ollama)…

Incident 2025Read →

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…

Incident 2025Read →

OpenAI's "ScopeCreep": Russian-Speaking Actor Used Disposable ChatGPT Accounts to Build C2-Enabled Windows Malware Distributed via a Trojanized "Crosshair-X" Gaming Tool

A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family and…

Incident 2025Read →