The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
Social Engineering Examples·4 sources
In its 2025 Internet Crime Report (covering calendar-year 2025 complaint data, released April 6, 2026), the FBI's Internet Crime Complaint Center (IC3) published, for the first time in the Center's nearly 25-year history, a dedicated section titled "Artificial Intelligence (AI) Used in Cybercrime." That section tallied 22,364 complaints in which AI played a role in the fraud, totaling $893,346,472 in reported/adjusted losses, a new, standalone tracking category distinct from IC3's traditional crime-type breakdowns (BEC, investment fraud, tech support fraud, etc.).
The AI figure sits inside IC3's much larger 2025 totals: roughly 1,008,597 total complaints (up from 859,532 in 2024) and total reported losses of approximately $20.877 billion (the FBI's press release rounds this to "nearly $21 billion"), of which cryptocurrency-related complaints alone accounted for over $11 billion and cyber-enabled fraud complaints for over $17.7 billion.
By comparison, IC3's prior report (calendar year 2024) recorded $16.6 billion in total losses with no dedicated AI section. The FBI explicitly framed the AI figure as likely an undercount, since many victims may not realize AI (e.g., a cloned voice or a synthetic video) was used against them.
The $893 million is not one incident but an aggregate tally the FBI built for the first time by tagging IC3 complaints in which the victim reported (or investigators identified) some form of AI involvement in the scam. Per the FBI's own description, the underlying techniques folded into that figure include: voice cloning used to impersonate a family member in distress, a company executive authorizing a wire, or a government official demanding payment; deepfake video (believable synthetic video of celebrities, CEOs, or a victim's loved one) used to add visual "proof" to investment pitches, romance scams, or emergency-money requests; fake AI-generated social media profiles used to build long-running romance/confidence relationships; AI-generated or forged identification documents used to pass identity checks in employment and financial scams; and AI-generated conversational scripts that let scammers run persuasive, personalized dialogue (in BEC-style emails, romance chats, and investment pitches) at a scale and polish that would previously have required more manual effort per victim.
IC3's report frames the throughline as scammers "deploying fake social profiles, voice clones, identification documents, and believable videos" combined with classic pressure tactics (urgency, secrecy, emotional appeals) to get victims to move money or hand over credentials before they can verify what they're seeing or hearing is synthetic.
Because this record is an aggregate statistic rather than a single case, there is no single lure. The report's illustrative pattern spans several scam types, unified by AI making the impersonation more convincing than a text-only or voice-only con: a cloned voice claiming to be a grandchild, spouse, or executive urgently needing money; a deepfake video "proving" a celebrity or CEO is personally endorsing an investment; an AI-run chat persona sustaining a months-long romance before requesting funds; or an AI-forged ID clearing a background/identity check in an employment or loan scam.
The unifying "tell" IC3 highlights across these is the pressure to act immediately without independent verification: its "Take a Beat" advisory exists specifically because AI-generated audio/video/text is now often good enough that visual or auditory instinct alone no longer reliably catches the fake.
The figure was published as part of the FBI's 2025 Internet Crime Report (covering calendar year 2025) and announced via FBI press release on April 6, 2026 under the headline "Cryptocurrency and AI Scams Bilk Americans of Billions." The FBI paired the release with renewed public-awareness messaging (the "Take a Beat" campaign) and pointed to related initiatives, Operation Level Up (proactive crypto-fraud victim notification, launched 2024) and Operation Winter SHIELD (2026, organizational security hardening), as its operational response.
Separately and around the same period, DOJ's Fraud Division and Ohio federal/state prosecutors announced a partnership (June 4, 2026 press release) charging 9 defendants in over $42 million of fraud and establishing a data-sharing agreement and an FBI "Most Wanted Fraudsters" list; that Ohio announcement references AI-driven video platforms used in an unrelated romance-fraud scheme but does not itself report or corroborate the $893 million aggregate figure.
The two are separate but contemporaneous data points about AI's role in the fraud landscape, not the same claim.
This is one of the first times a major U.S. law-enforcement body has stood up a dedicated, named tracking category for AI-facilitated fraud inside its flagship annual crime statistics, a signal that AI-enabled social engineering (voice cloning, deepfake video, synthetic profiles/documents, AI-generated persuasive text) has moved from a novel curiosity to a scale problem large enough to warrant its own line item, worth roughly 4.3% of all IC3-reported losses in its debut year.
Because the figure is complaint-driven and self-identified by victims/investigators as "AI-involved," the FBI's own caveat that it is likely conservative matters for anyone citing the number: the true scale of AI-facilitated fraud is probably materially higher than $893 million, since much AI involvement (a well-executed voice clone, a convincingly deepfaked video) may go completely undetected by the victim who files the complaint.
For an educational/awareness site, this record supports the broader claim that AI-driven impersonation (voice, video, and text) is now a nationally tracked, billion-dollar-adjacent driver of financial fraud in the US, while also illustrating the limits of complaint-based statistics as a way to size the problem precisely.
FBI's public messaging around the report centers on its "Take a Beat" campaign: resisting pressure to act quickly and verifying identity/context before sending money or personal/financial information, especially for calls or videos that "sound"/"look" like a known person. The Bureau also points to Operation Level Up (proactive victim notification for crypto-investment fraud, credited with over 8,000 victims notified and >$500M in losses averted since 2024) and the 2026 Operation Winter SHIELD (organizational digital-security hardening) as complementary mitigation efforts.
For AI-specific risk, IC3's report implicitly recommends: independent callback verification (not the number/contact provided by the counterparty) before acting on a voice or video request; skepticism toward urgent financial asks from "known" contacts reached only through a single unverified channel; and reporting suspected AI-enabled fraud to ic3.gov promptly (the Bureau notes IC3 receives ~3,000 complaints/day) so patterns can be tracked.
IC3 also flags that its own AI figure is likely an undercount, since many victims never realize AI (e.g., a cloned voice) was used against them, a real limitation of complaint-based statistics as an early-warning tool.
Social Engineering Examples. “FBI IC3's First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)”. Accessed 19 September 2026. https://socialengineeringexamples.com/fbi-ic3-ai-fraud-893m-2025
This is an aggregate statistic rather than a single incident, so IC3's report does not detail one recon method, but the scam types folded into the AI figure (romance scams, BEC, executive/official impersonation, investment fraud) typically require identifying both a plausible person to impersonate and a person to target, drawing on OSINT sources such as social media, company websites and org charts, dating-app profiles, and public records to learn names, relationships, and enough personal detail to make an AI-generated persona or cloned voice convincing.
Employee, family, and public OSINT exposure (LinkedIn roles, org charts, social media, dating-app profiles) is very hard to eliminate at the individual or enterprise level; the realistic control assumes an attacker can already learn this and instead limits what a stranger can achieve through a single channel, rather than trying to hide the underlying information.
Per IC3's description of the techniques inside the $893 million figure, scammers typically source commercially available voice-cloning services, deepfake video generation tools, AI-generated or forged identification-document templates, and AI chat/LLM tools to produce the synthetic voice sample, video clip, fake social profile, or forged ID used in the scheme.
There is no practical way to block private acquisition of commercial voice-cloning or deepfake tools before contact occurs; the nearest realistic control sits downstream, treating any voice or video 'proof' received unexpectedly as unverified by default rather than trying to prevent the tooling's existence.
The scammer reaches the victim through a channel matching the scam type, a phone or video call for a cloned voice claiming to be a family member, executive, or government official, a dating app or social media message for a fake AI-generated profile, or a job/loan application flow for a forged ID, opening with a scenario (distress, opportunity, or an official demand) built to feel urgent from first contact.
Unsolicited contact making an urgent claim, a distress call, an investment tip, a romantic overture, or an official demand should trigger independent verification through a channel the recipient controls, not one the caller or messenger provides, before any further engagement.
For longer-running schemes (romance, investment), IC3 notes AI-generated conversational scripts let scammers sustain a believable, personalized relationship over weeks or months at a scale that would previously have required more manual effort per victim; for shorter schemes, a deepfake video or cloned voice is used as one-time 'proof' (a celebrity or CEO endorsing an investment, a loved one's panicked voice) standing in for the identity verification a victim would otherwise seek.
Skepticism toward 'proof' delivered only through the same channel as the ask is the core defense here; verifying a loved one's, executive's, or official's claim through a separately initiated call to a known number, or an established in-person channel, neutralizes synthetic credibility regardless of how convincing it sounds or looks.
IC3's report frames this as the throughline across the AI-enabled scam types it tracked, pairing the synthetic 'proof' built up in earlier stages with classic pressure tactics, urgency, secrecy, and emotional appeals, specifically to get the victim to act before they can independently verify what they are seeing or hearing.
This is exactly what IC3's 'Take a Beat' campaign targets: deliberately pausing under pressure and confirming identity and context before acting is the FBI's stated primary countermeasure for AI-enabled impersonation fraud.
The victim wires money, buys and sends cryptocurrency, purchases gift cards, or hands over identity/financial credentials (in employment or loan-fraud variants using forged IDs), completing the transaction the earlier stages built toward.
Financial-institution controls, transaction holds, out-of-band confirmation for large wires or crypto purchases, and IC3's Recovery Asset Team Financial Fraud Kill Chain process, can intercept funds if the transfer is reported within the narrow window before funds clear.
Losses are realized once funds leave the victim's control, and IC3's own Recovery Asset Team data shows scammers typically routing stolen funds through further transfers before law enforcement can intervene; the case only enters the $893 million aggregate once a victim later files an IC3 complaint that gets tagged AI-related, which is also why the FBI describes the figure as a likely undercount.
Prompt reporting to ic3.gov (the Bureau notes it receives roughly 3,000 complaints per day) is the main lever once funds have moved, both for the Recovery Asset Team's chance at freezing funds and for improving the completeness of the AI-fraud statistic itself, which the FBI already flags as an undercount driven by victims not recognizing AI was involved.
Browse by what this case has in common with others in the library.
ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to…
In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.