Case Library / Deepfake & Synthetic Media / FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)

FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)

The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning, and deepfake video to make fraud schemes, including loved-one crisis scams and bank-account impersonation, more scalable and believable.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On December 3, 2024, the FBI's Internet Crime Complaint Center (IC3) published PSA241203, "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud." The advisory is not a report on a single incident but a synthesis of fraud patterns the FBI observed forming across many victim complaints submitted to IC3. It warns that generative AI lets criminals commit fraud "on a larger scale" with "increased believability," reducing the time/effort needed to deceive targets and correcting for the human errors (bad grammar, inconsistent details) that traditionally tipped victims off. The PSA organizes examples into four modalities: AI-generated text (phishing scripts, fake social profiles, translated scam messages, fraudulent investment site content, AI chatbots), AI-generated images (fake profile photos, forged IDs/credentials including law-enforcement and banking credentials, fake celebrity endorsements, fabricated disaster/conflict imagery for charity scams, sextortion images), AI-generated audio/vocal cloning (short cloned clips of a loved one's voice used in staged crisis calls demanding immediate payment or ransom, and cloned voice clips used to gain fraudulent access to victims' bank accounts by impersonating them to the institution), and AI-generated video/deepfakes (real-time deepfake video chats impersonating company executives, law enforcement, or other authority figures; video used in private chats to "prove" an online contact is real; and deepfake video used in investment-fraud promotional material).

How the Attack Worked

The advisory describes vocal cloning fraud mechanically as follows: criminals source or fabricate a short audio sample of a target voice (a family member's voice scraped from social media/public content, or a bank customer's voice obtained via prior contact or leaked recordings), feed it into generative AI voice-cloning tools, and produce synthetic audio that convincingly reproduces the speaker's tone and cadence. In the "loved-one crisis" pattern, the cloned voice is used in an unsolicited phone call staged as an emergency (accident, arrest, kidnapping) demanding immediate financial assistance or ransom, exploiting the victim's fear and time pressure to bypass normal verification. In the "bank impersonation" pattern, the cloned voice of the actual account holder is used against a financial institution's phone-based identity checks (including, in some institutions, voice-biometric authentication) to gain unauthorized account access. The same underlying AI capability set (text, image, audio, video) is combined across schemes, for example a forged AI-generated bank ID plus a cloned voice plus AI-drafted messages, to build a layered, believable persona that defeats each individual verification step a victim or institution might otherwise rely on.

The Lure & the Tell

Lure: a phone call in which a cloned voice of a spouse, child, or parent claims to be in a crisis (car accident, arrest, kidnapping, medical emergency) and urgently needs money wired or transferred, or, in the banking variant, a caller whose cloned voice matches the real account holder attempts to authenticate to a bank and redirect or withdraw funds. Tells the FBI recommends: listen closely for subtle tonal or word-choice mismatches versus how the loved one actually speaks; the near-instant demand for money with no time to verify; requests specifically for wire transfers, gift cards, or cryptocurrency; and, for video, artifacts like distorted hands/feet, unrealistic teeth/eyes, indistinct faces, inaccurate shadows, watermarks, lag, or unnatural movement. The PSA's headline mitigation is establishing a pre-agreed secret family verification phrase and independently calling back a known, verified phone number rather than trusting the incoming call.

Outcome

As a PSA, the advisory itself produced no arrests, prosecutions, or restitution; its stated outcome is public awareness and victim-reporting encouragement (directing readers to file complaints at ic3.gov with transaction/contact details). The FBI later operationalized this warning into a dedicated AI-fraud reporting category, which surfaced in the 2025 IC3 Annual Report (released and publicized April 6, 2026) showing 22,364 AI-related complaints and $893.3 million in adjusted losses for that year, with investment fraud the largest AI-related loss bucket ($632M) followed by BEC, romance/confidence fraud, and employment fraud.

Why It Matters

PSA241203 is one of the FBI's earliest formal, primary-source acknowledgments that generative AI (text, image, vocal cloning, and deepfake video) had moved from theoretical risk to an active, aggregated pattern across real victim complaints, specifically naming the "loved-one in crisis" voice-clone scam and voice-based bank-account impersonation as concrete fraud vectors. It matters as a benchmark: it predates and anchors the much larger dollar figures the FBI would later attribute to AI-enabled fraud in its 2025 Annual Report, showing the trajectory from qualitative warning (2024) to measured nine-figure losses (2025) in roughly one year, and it gives defenders and educators a citable government source for why voice-clone verification protocols (secret phrases, callback verification) are now a recommended baseline control.

Defenses

FBI-recommended mitigations from the PSA: establish a secret family verification word/phrase for crisis calls; independently verify by hanging up and calling back a known, previously-verified number rather than the number that called in; listen for tonal/word-choice inconsistencies versus the real person's normal speech; scrutinize images/video for AI artifacts (distorted extremities, unnatural eyes/teeth, inconsistent shadows, lag, unnatural movement); limit public exposure of one's own voice and image (private social media, restricted followers) to reduce the raw material available for cloning; never send money, gift cards, or cryptocurrency to unverified callers; and report suspected incidents to IC3 with full transactional and contact detail to feed aggregate law-enforcement pattern detection.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target and Sample Selection: Criminals identify a target, typically a family member for the loved-one crisis scam or a specific bank customer or executive for account-impersonation schemes, and source a short authentic audio, image, or video sample of the real person, per the PSA typically scraped from social media, public video or voicemail content, prior phone contact, or previously leaked recordings and data.
Countering Stage 1: Public voice and image exposure (social media videos, voicemail greetings, conference or earnings-call recordings) is very hard to eliminate at the scale the PSA describes; the FBI's own realistic recommendation is to limit how much voice and image content of yourself or your family is posted publicly and to restrict social accounts and followers, shrinking the raw material available to clone rather than assuming it can be hidden entirely.
2
Synthetic Media Generation: The harvested sample is fed into a commercially available generative AI vocal-cloning or deepfake image/video tool to produce synthetic content that convincingly reproduces the target's voice, likeness, or supporting documents (forged IDs or credentials), correcting for the grammar and consistency errors that traditionally tipped off fraud.
Countering Stage 2: Generation of the synthetic audio or video happens outside the victim's or institution's view, so there is no direct control at this stage; the realistic defense is the human verification built into Stage 4, training people and call-handling staff to treat any single piece of audio or video as unverified by default.
3
Persona and Pretext Assembly: The cloned voice or likeness is layered with other AI-generated material, per the PSA this can include forged law-enforcement or banking credentials, AI-drafted or translated scripts, and fictitious social media profiles, to build a single, internally consistent persona that defeats several verification checks at once.
Countering Stage 3: Financial institutions and individuals can reduce the payoff of any single forged credential or cloned voice by requiring multi-factor, out-of-band identity checks rather than relying on voice biometrics or one document as sufficient proof, so no single AI-forged artifact alone can authenticate a high-risk action.
4
Urgent Contact: Criminals place an unsolicited phone call, video chat, or message to the victim, or to a financial institution's phone channel, staged as a crisis (accident, arrest, kidnapping), an authority figure, or the account holder, pairing the synthetic audio or video with deliberate time pressure that discourages the target from pausing to verify.
Countering Stage 4: The PSA's headline mitigation, a pre-agreed family verification phrase and hanging up to independently call back a previously known number rather than trusting the incoming call, directly defeats a fabricated urgent-crisis call because a cloned voice cannot supply the offline shared secret or reach the real callback number.
5
Payment or Account-Access Extraction: The victim is directed to wire money or send gift cards or cryptocurrency, or the cloned voice is used directly against a bank's phone-based (including, per the PSA, voice-biometric) identity checks to gain unauthorized account access and redirect funds.
Countering Stage 5: Never sending wire transfers, gift cards, or cryptocurrency to an unverified caller, and bank policies that require additional verification before approving high-risk actions from voice-only authentication, block the point where the scheme actually converts into a loss.
6
Cash-Out and Reporting Gap: Funds move through channels, wire transfer, gift cards, or cryptocurrency, that are difficult to reverse once sent, and because each victim typically experiences the scheme as an isolated incident, the underlying criminal infrastructure usually only becomes visible after the FBI aggregates many individual IC3 complaints.
Countering Stage 6: Once funds move through wire transfers, gift cards, or cryptocurrency they are difficult to claw back; the closest realistic control is speed, reporting the incident immediately to IC3, which can route qualifying wire-transfer cases through its Recovery Asset Team Financial Fraud Kill Chain process, so financial institutions have a chance to freeze funds before criminals move them further, consistent with the fund-freezing outcomes the FBI describes for that process in its 2025 Annual Report.
Quick Facts
Victim
General public and financial institutions in the United States (advisory synthesizes aggregated IC3 victim-complaint patterns rather than naming specific victims)
Location
United States (nationwide advisory; IC3 complaints are filed by U.S. victims, though perpetrators may be foreign-based)
Date
2024-12-03
Impact
The PSA itself cites no dollar figures or complaint counts: it is a qualitative awareness bulletin. The FBI's later 2025 IC3 Annual Report (published April 6, 2026) quantified the same threat category for the first time: 22,364 AI-related complaints with $893,346,472 in adjusted losses in 2025. The report's dedicated AI section itemizes several sub-category figures, including Investment fraud (4,356 complaints, $632,041,188), Business Email Compromise (135 complaints, $30,256,592), Confidence/Romance (626 complaints, $19,041,653), and Employment fraud (691 complaints, $12,550,185); the remainder of the $893 million total is attributed to other AI-tagged categories the report also lists, such as Tech/Customer Support, Personal Data Breach, Phishing/Spoofing, and Government Impersonation. The FBI states these AI-related figures are likely an undercount since they rely on complainant keyword self-reporting. Total 2025 IC3 complaints across all categories: 1,008,597, with $20.877 billion in total reported losses.
Status
Confirmed
Case Type
Research / Advisory
Sector
Consumer / General Public, Cross-Sector / Multiple Industries, Financial Services & Insurance
Related

Related Cases

LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)

An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…

Incident 2024Read →

KnowBe4 Unknowingly Hires a North Korean Fake IT Worker Using an AI-Enhanced Photo and Stolen Identity

KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…

Incident 2024Read →

Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)

A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…

Incident 2024Read →