The FBI's 2025 Internet Crime Report introduced IC3's first-ever dedicated AI-fraud tracking section in its nearly 25-year history, logging 22,364 complaints and $893,346,472 in losses from scams using voice clones, deepfake video, fake AI-generated social profiles, and forged identification documents.
Reviewed by the Social Engineering Examples team.
In its 2025 Internet Crime Report (covering calendar-year 2025 complaint data, released April 6, 2026), the FBI's Internet Crime Complaint Center (IC3) published, for the first time in the Center's nearly 25-year history, a dedicated section titled "Artificial Intelligence (AI) Used in Cybercrime." That section tallied 22,364 complaints in which AI played a role in the fraud, totaling $893,346,472 in reported/adjusted losses, a new, standalone tracking category distinct from IC3's traditional crime-type breakdowns (BEC, investment fraud, tech support fraud, etc.). The AI figure sits inside IC3's much larger 2025 totals: roughly 1,008,597 total complaints (up from 859,532 in 2024) and total reported losses of approximately $20.877 billion (the FBI's press release rounds this to "nearly $21 billion"), of which cryptocurrency-related complaints alone accounted for over $11 billion and cyber-enabled fraud complaints for over $17.7 billion. By comparison, IC3's prior report (calendar year 2024) recorded $16.6 billion in total losses with no dedicated AI section. The FBI explicitly framed the AI figure as likely an undercount, since many victims may not realize AI (e.g., a cloned voice or a synthetic video) was used against them.
The $893 million is not one incident but an aggregate tally the FBI built for the first time by tagging IC3 complaints in which the victim reported (or investigators identified) some form of AI involvement in the scam. Per the FBI's own description, the underlying techniques folded into that figure include: voice cloning used to impersonate a family member in distress, a company executive authorizing a wire, or a government official demanding payment; deepfake video (believable synthetic video of celebrities, CEOs, or a victim's loved one) used to add visual "proof" to investment pitches, romance scams, or emergency-money requests; fake AI-generated social media profiles used to build long-running romance/confidence relationships; AI-generated or forged identification documents used to pass identity checks in employment and financial scams; and AI-generated conversational scripts that let scammers run persuasive, personalized dialogue (in BEC-style emails, romance chats, and investment pitches) at a scale and polish that would previously have required more manual effort per victim. IC3's report frames the throughline as scammers "deploying fake social profiles, voice clones, identification documents, and believable videos" combined with classic pressure tactics (urgency, secrecy, emotional appeals) to get victims to move money or hand over credentials before they can verify what they're seeing or hearing is synthetic.
Because this record is an aggregate statistic rather than a single case, there is no single lure. The report's illustrative pattern spans several scam types, unified by AI making the impersonation more convincing than a text-only or voice-only con: a cloned voice claiming to be a grandchild, spouse, or executive urgently needing money; a deepfake video "proving" a celebrity or CEO is personally endorsing an investment; an AI-run chat persona sustaining a months-long romance before requesting funds; or an AI-forged ID clearing a background/identity check in an employment or loan scam. The unifying "tell" IC3 highlights across these is the pressure to act immediately without independent verification: its "Take a Beat" advisory exists specifically because AI-generated audio/video/text is now often good enough that visual or auditory instinct alone no longer reliably catches the fake.
The figure was published as part of the FBI's 2025 Internet Crime Report (covering calendar year 2025) and announced via FBI press release on April 6, 2026 under the headline "Cryptocurrency and AI Scams Bilk Americans of Billions." The FBI paired the release with renewed public-awareness messaging (the "Take a Beat" campaign) and pointed to related initiatives, Operation Level Up (proactive crypto-fraud victim notification, launched 2024) and Operation Winter SHIELD (2026, organizational security hardening), as its operational response. Separately and around the same period, DOJ's Fraud Division and Ohio federal/state prosecutors announced a partnership (June 4, 2026 press release) charging 9 defendants in over $42 million of fraud and establishing a data-sharing agreement and an FBI "Most Wanted Fraudsters" list; that Ohio announcement references AI-driven video platforms used in an unrelated romance-fraud scheme but does not itself report or corroborate the $893 million aggregate figure. The two are separate but contemporaneous data points about AI's role in the fraud landscape, not the same claim.
This is one of the first times a major U.S. law-enforcement body has stood up a dedicated, named tracking category for AI-facilitated fraud inside its flagship annual crime statistics, a signal that AI-enabled social engineering (voice cloning, deepfake video, synthetic profiles/documents, AI-generated persuasive text) has moved from a novel curiosity to a scale problem large enough to warrant its own line item, worth roughly 4.3% of all IC3-reported losses in its debut year. Because the figure is complaint-driven and self-identified by victims/investigators as "AI-involved," the FBI's own caveat that it is likely conservative matters for anyone citing the number: the true scale of AI-facilitated fraud is probably materially higher than $893 million, since much AI involvement (a well-executed voice clone, a convincingly deepfaked video) may go completely undetected by the victim who files the complaint. For an educational/awareness site, this record supports the broader claim that AI-driven impersonation (voice, video, and text) is now a nationally tracked, billion-dollar-adjacent driver of financial fraud in the US, while also illustrating the limits of complaint-based statistics as a way to size the problem precisely.
FBI's public messaging around the report centers on its "Take a Beat" campaign: resisting pressure to act quickly and verifying identity/context before sending money or personal/financial information, especially for calls or videos that "sound"/"look" like a known person. The Bureau also points to Operation Level Up (proactive victim notification for crypto-investment fraud, credited with over 8,000 victims notified and >$500M in losses averted since 2024) and the 2026 Operation Winter SHIELD (organizational digital-security hardening) as complementary mitigation efforts. For AI-specific risk, IC3's report implicitly recommends: independent callback verification (not the number/contact provided by the counterparty) before acting on a voice or video request; skepticism toward urgent financial asks from "known" contacts reached only through a single unverified channel; and reporting suspected AI-enabled fraud to ic3.gov promptly (the Bureau notes IC3 receives ~3,000 complaints/day) so patterns can be tracked. IC3 also flags that its own AI figure is likely an undercount, since many victims never realize AI (e.g., a cloned voice) was used against them, a real limitation of complaint-based statistics as an early-warning tool.
ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model (gpt-oss:20b via Ollama)…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…
A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family and…