The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.
Social Engineering Examples·4 sources
On December 3, 2024, the FBI's Internet Crime Complaint Center (IC3) published PSA241203, "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud." The advisory is not a report on a single incident but a synthesis of fraud patterns the FBI observed forming across many victim complaints submitted to IC3. It warns that generative AI lets criminals commit fraud "on a larger scale" with "increased believability," reducing the time/effort needed to deceive targets and correcting for the human errors (bad grammar, inconsistent details) that traditionally tipped victims off.
The PSA organizes examples into four modalities: AI-generated text (phishing scripts, fake social profiles, translated scam messages, fraudulent investment site content, AI chatbots), AI-generated images (fake profile photos, forged IDs/credentials including law-enforcement and banking credentials, fake celebrity endorsements, fabricated disaster/conflict imagery for charity scams, sextortion images), AI-generated audio/vocal cloning (short cloned clips of a loved one's voice used in staged crisis calls demanding immediate payment or ransom, and cloned voice clips used to gain fraudulent access to victims' bank accounts by impersonating them to the institution), and AI-generated video/deepfakes (real-time deepfake video chats impersonating company executives, law enforcement, or other authority figures; video used in private chats to "prove" an online contact is real; and deepfake video used in investment-fraud promotional material).
The advisory describes vocal cloning fraud mechanically as follows: criminals source or fabricate a short audio sample of a target voice (a family member's voice scraped from social media/public content, or a bank customer's voice obtained via prior contact or leaked recordings), feed it into generative AI voice-cloning tools, and produce synthetic audio that convincingly reproduces the speaker's tone and cadence.
In the "loved-one crisis" pattern, the cloned voice is used in an unsolicited phone call staged as an emergency (accident, arrest, kidnapping) demanding immediate financial assistance or ransom, exploiting the victim's fear and time pressure to bypass normal verification. In the "bank impersonation" pattern, the cloned voice of the actual account holder is used against a financial institution's phone-based identity checks (including, in some institutions, voice-biometric authentication) to gain unauthorized account access.
The same underlying AI capability set (text, image, audio, video) is combined across schemes, for example a forged AI-generated bank ID plus a cloned voice plus AI-drafted messages, to build a layered, believable persona that defeats each individual verification step a victim or institution might otherwise rely on.
Lure: a phone call in which a cloned voice of a spouse, child, or parent claims to be in a crisis (car accident, arrest, kidnapping, medical emergency) and urgently needs money wired or transferred, or, in the banking variant, a caller whose cloned voice matches the real account holder attempts to authenticate to a bank and redirect or withdraw funds.
Tells the FBI recommends: listen closely for subtle tonal or word-choice mismatches versus how the loved one actually speaks; the near-instant demand for money with no time to verify; requests specifically for wire transfers, gift cards, or cryptocurrency; and, for video, artifacts like distorted hands/feet, unrealistic teeth/eyes, indistinct faces, inaccurate shadows, watermarks, lag, or unnatural movement.
The PSA's headline mitigation is establishing a pre-agreed secret family verification phrase and independently calling back a known, verified phone number rather than trusting the incoming call.
As a PSA, the advisory itself produced no arrests, prosecutions, or restitution; its stated outcome is public awareness and victim-reporting encouragement (directing readers to file complaints at ic3.gov with transaction/contact details). The FBI later operationalized this warning into a dedicated AI-fraud reporting category, which surfaced in the 2025 IC3 Annual Report (released and publicized April 6, 2026) showing 22,364 AI-related complaints and $893.3 million in adjusted losses for that year, with investment fraud the largest AI-related loss bucket ($632M) followed by BEC, romance/confidence fraud, and employment fraud.
PSA241203 is one of the FBI's earliest formal, primary-source acknowledgments that generative AI (text, image, vocal cloning, and deepfake video) had moved from theoretical risk to an active, aggregated pattern across real victim complaints, specifically naming the "loved-one in crisis" voice-clone scam and voice-based bank-account impersonation as concrete fraud vectors.
It matters as a benchmark: it predates and anchors the much larger dollar figures the FBI would later attribute to AI-enabled fraud in its 2025 Annual Report, showing the trajectory from qualitative warning (2024) to measured nine-figure losses (2025) in roughly one year, and it gives defenders and educators a citable government source for why voice-clone verification protocols (secret phrases, callback verification) are now a recommended baseline control.
FBI-recommended mitigations from the PSA: establish a secret family verification word/phrase for crisis calls; independently verify by hanging up and calling back a known, previously-verified number rather than the number that called in; listen for tonal/word-choice inconsistencies versus the real person's normal speech; scrutinize images/video for AI artifacts (distorted extremities, unnatural eyes/teeth, inconsistent shadows, lag, unnatural movement); limit public exposure of one's own voice and image (private social media, restricted followers) to reduce the raw material available for cloning; never send money, gift cards, or cryptocurrency to unverified callers; and report suspected incidents to IC3 with full transactional and contact detail to feed aggregate law-enforcement pattern detection.
Social Engineering Examples. “FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)”. Accessed 19 September 2026. https://socialengineeringexamples.com/fbi-ic3-psa241203-generative-ai-financial-fraud-2024
Criminals identify a target, typically a family member for the loved-one crisis scam or a specific bank customer or executive for account-impersonation schemes, and source a short authentic audio, image, or video sample of the real person, per the PSA typically scraped from social media, public video or voicemail content, prior phone contact, or previously leaked recordings and data.
Public voice and image exposure (social media videos, voicemail greetings, conference or earnings-call recordings) is very hard to eliminate at the scale the PSA describes; the FBI's own realistic recommendation is to limit how much voice and image content of yourself or your family is posted publicly and to restrict social accounts and followers, shrinking the raw material available to clone rather than assuming it can be hidden entirely.
The harvested sample is fed into a commercially available generative AI vocal-cloning or deepfake image/video tool to produce synthetic content that convincingly reproduces the target's voice, likeness, or supporting documents (forged IDs or credentials), correcting for the grammar and consistency errors that traditionally tipped off fraud.
Generation of the synthetic audio or video happens outside the victim's or institution's view, so there is no direct control at this stage; the realistic defense is the human verification built into Stage 4, training people and call-handling staff to treat any single piece of audio or video as unverified by default.
The cloned voice or likeness is layered with other AI-generated material, per the PSA this can include forged law-enforcement or banking credentials, AI-drafted or translated scripts, and fictitious social media profiles, to build a single, internally consistent persona that defeats several verification checks at once.
Financial institutions and individuals can reduce the payoff of any single forged credential or cloned voice by requiring multi-factor, out-of-band identity checks rather than relying on voice biometrics or one document as sufficient proof, so no single AI-forged artifact alone can authenticate a high-risk action.
Criminals place an unsolicited phone call, video chat, or message to the victim, or to a financial institution's phone channel, staged as a crisis (accident, arrest, kidnapping), an authority figure, or the account holder, pairing the synthetic audio or video with deliberate time pressure that discourages the target from pausing to verify.
The PSA's headline mitigation, a pre-agreed family verification phrase and hanging up to independently call back a previously known number rather than trusting the incoming call, directly defeats a fabricated urgent-crisis call because a cloned voice cannot supply the offline shared secret or reach the real callback number.
The victim is directed to wire money or send gift cards or cryptocurrency, or the cloned voice is used directly against a bank's phone-based (including, per the PSA, voice-biometric) identity checks to gain unauthorized account access and redirect funds.
Never sending wire transfers, gift cards, or cryptocurrency to an unverified caller, and bank policies that require additional verification before approving high-risk actions from voice-only authentication, block the point where the scheme actually converts into a loss.
Funds move through channels, wire transfer, gift cards, or cryptocurrency, that are difficult to reverse once sent, and because each victim typically experiences the scheme as an isolated incident, the underlying criminal infrastructure usually only becomes visible after the FBI aggregates many individual IC3 complaints.
Once funds move through wire transfers, gift cards, or cryptocurrency they are difficult to claw back; the closest realistic control is speed, reporting the incident immediately to IC3, which can route qualifying wire-transfer cases through its Recovery Asset Team Financial Fraud Kill Chain process, so financial institutions have a chance to freeze funds before criminals move them further, consistent with the fund-freezing outcomes the FBI describes for that process in its 2025 Annual Report.
Browse by what this case has in common with others in the library.
KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
The FBI, FTC, and USPIS each issued 2025 public warnings about "brushing 2.0" -- unsolicited packages containing QR codes that,…
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…