The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning, and deepfake video to make fraud schemes, including loved-one crisis scams and bank-account impersonation, more scalable and believable.
Reviewed by the Social Engineering Examples team.
On December 3, 2024, the FBI's Internet Crime Complaint Center (IC3) published PSA241203, "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud." The advisory is not a report on a single incident but a synthesis of fraud patterns the FBI observed forming across many victim complaints submitted to IC3. It warns that generative AI lets criminals commit fraud "on a larger scale" with "increased believability," reducing the time/effort needed to deceive targets and correcting for the human errors (bad grammar, inconsistent details) that traditionally tipped victims off. The PSA organizes examples into four modalities: AI-generated text (phishing scripts, fake social profiles, translated scam messages, fraudulent investment site content, AI chatbots), AI-generated images (fake profile photos, forged IDs/credentials including law-enforcement and banking credentials, fake celebrity endorsements, fabricated disaster/conflict imagery for charity scams, sextortion images), AI-generated audio/vocal cloning (short cloned clips of a loved one's voice used in staged crisis calls demanding immediate payment or ransom, and cloned voice clips used to gain fraudulent access to victims' bank accounts by impersonating them to the institution), and AI-generated video/deepfakes (real-time deepfake video chats impersonating company executives, law enforcement, or other authority figures; video used in private chats to "prove" an online contact is real; and deepfake video used in investment-fraud promotional material).
The advisory describes vocal cloning fraud mechanically as follows: criminals source or fabricate a short audio sample of a target voice (a family member's voice scraped from social media/public content, or a bank customer's voice obtained via prior contact or leaked recordings), feed it into generative AI voice-cloning tools, and produce synthetic audio that convincingly reproduces the speaker's tone and cadence. In the "loved-one crisis" pattern, the cloned voice is used in an unsolicited phone call staged as an emergency (accident, arrest, kidnapping) demanding immediate financial assistance or ransom, exploiting the victim's fear and time pressure to bypass normal verification. In the "bank impersonation" pattern, the cloned voice of the actual account holder is used against a financial institution's phone-based identity checks (including, in some institutions, voice-biometric authentication) to gain unauthorized account access. The same underlying AI capability set (text, image, audio, video) is combined across schemes, for example a forged AI-generated bank ID plus a cloned voice plus AI-drafted messages, to build a layered, believable persona that defeats each individual verification step a victim or institution might otherwise rely on.
Lure: a phone call in which a cloned voice of a spouse, child, or parent claims to be in a crisis (car accident, arrest, kidnapping, medical emergency) and urgently needs money wired or transferred, or, in the banking variant, a caller whose cloned voice matches the real account holder attempts to authenticate to a bank and redirect or withdraw funds. Tells the FBI recommends: listen closely for subtle tonal or word-choice mismatches versus how the loved one actually speaks; the near-instant demand for money with no time to verify; requests specifically for wire transfers, gift cards, or cryptocurrency; and, for video, artifacts like distorted hands/feet, unrealistic teeth/eyes, indistinct faces, inaccurate shadows, watermarks, lag, or unnatural movement. The PSA's headline mitigation is establishing a pre-agreed secret family verification phrase and independently calling back a known, verified phone number rather than trusting the incoming call.
As a PSA, the advisory itself produced no arrests, prosecutions, or restitution; its stated outcome is public awareness and victim-reporting encouragement (directing readers to file complaints at ic3.gov with transaction/contact details). The FBI later operationalized this warning into a dedicated AI-fraud reporting category, which surfaced in the 2025 IC3 Annual Report (released and publicized April 6, 2026) showing 22,364 AI-related complaints and $893.3 million in adjusted losses for that year, with investment fraud the largest AI-related loss bucket ($632M) followed by BEC, romance/confidence fraud, and employment fraud.
PSA241203 is one of the FBI's earliest formal, primary-source acknowledgments that generative AI (text, image, vocal cloning, and deepfake video) had moved from theoretical risk to an active, aggregated pattern across real victim complaints, specifically naming the "loved-one in crisis" voice-clone scam and voice-based bank-account impersonation as concrete fraud vectors. It matters as a benchmark: it predates and anchors the much larger dollar figures the FBI would later attribute to AI-enabled fraud in its 2025 Annual Report, showing the trajectory from qualitative warning (2024) to measured nine-figure losses (2025) in roughly one year, and it gives defenders and educators a citable government source for why voice-clone verification protocols (secret phrases, callback verification) are now a recommended baseline control.
FBI-recommended mitigations from the PSA: establish a secret family verification word/phrase for crisis calls; independently verify by hanging up and calling back a known, previously-verified number rather than the number that called in; listen for tonal/word-choice inconsistencies versus the real person's normal speech; scrutinize images/video for AI artifacts (distorted extremities, unnatural eyes/teeth, inconsistent shadows, lag, unnatural movement); limit public exposure of one's own voice and image (private social media, restricted followers) to reduce the raw material available for cloning; never send money, gift cards, or cryptocurrency to unverified callers; and report suspected incidents to IC3 with full transactional and contact detail to feed aggregate law-enforcement pattern detection.
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…
KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…