AI scams: what the loss figures actually show

The FBI created a category for this for the first time in twenty-five years. The single largest recorded case was a video call in which every participant except the victim was fake.

Analysis by Inzonex · published 2026-09-25 · counted from published open data · how we work

Key figures

Americans reported $893m lost to AI-enabled fraud in 2025, across 22,364 complaints.

One company lost $25m in fifteen transfers after a video call with a deepfaked finance chief and deepfaked colleagues.

The technology did not invent new scams. It removed the cost of the convincing part.

The scale

Investment fraud with AI632.0Business email compromise with AI30.0Fake job interviews13.0
Reported United States losses by AI-enabled fraud type ($ millions reported lost, 2025).

The FBI's Internet Crime Complaint Center recorded $893m in reported losses to AI-enabled fraud in 2025 across 22,364 complaints. It was the first time in the centre's twenty-five year history that artificial intelligence was broken out as its own tracked category, which is itself the finding.

Investment fraud dominates at $632m. Business email compromise with a confirmed AI component accounts for more than $30m, and deepfaked candidates in online job interviews for around $13m.

These are reported losses. The real figure is higher, because most fraud is never reported and because the AI component is often not identified.

The case worth understanding

In early 2024 a finance employee at a multinational engineering firm received an email from the company's United Kingdom finance chief asking for a confidential transaction. The employee was suspicious, which is exactly what training teaches.

So the employee joined a video call. On it were the finance chief and several familiar colleagues, with their faces and voices. The call resolved the doubt. The employee then made fifteen transfers totalling about $25m to five Hong Kong bank accounts.

Every person on that call except the victim was synthetic, built from video and audio of the executives that was publicly available.

Read the sequence again. The suspicion worked. The verification step is what failed, because the verification step was “get on a call and see their face”, and that is precisely the check this technology removed.

Where the cost went

None of these are new crimes. Investment fraud, impersonation of a chief executive, the distressed relative phone call, the fake recruiter: all of them predate generative AI by decades.

The expensive part collapsed in price. Sounding like a specific person, looking like them on camera, writing fluently in a language you do not speak, producing a plausible company at volume — each of those was the bottleneck that limited how many victims one operation could reach. All of them now cost close to nothing.

So the right expectation is not exotic new attacks. It is old attacks at a conversion rate they never used to achieve.

The defence that still works

If seeing and hearing someone is no longer verification, the defences that survive are the ones that never depended on recognition.

A channel the attacker does not control. Not replying, not calling back on the number provided, not staying in the meeting. Contacting the person through a route you already had.

A procedure that does not bend for seniority. The Hong Kong case worked because urgency plus authority plus confidentiality overrode a process. Any payment process that a sufficiently senior voice can shorten is not a process.

A shared secret agreed in advance. Crude, unfashionable and effective, because it is the one thing a model trained on public video of someone cannot produce.

Sources and method

  • FBI Internet Crime Report 2025, Internet Crime Complaint Center. Source of the $893m total, the 22,364 complaints and the category breakdowns.
  • Hong Kong deepfaked CFO video call fraud, reported February 2024; the company was publicly identified as Arup in May 2024. Source of the fifteen transfers, the $25m total and the five Hong Kong accounts.
  • ChatGPT and large language models: what’s the risk?, UK National Cyber Security Centre. National guidance on the classes of attack that hosted language models make cheaper, and on why prompt injection is structural rather than patchable.
  • Loss figures are reported losses in the United States only and are a floor rather than an estimate of the true total.
  • Every source here was opened and checked on 25 September 2026. Where nothing has been measured, this page uses a table and says so rather than drawing a chart of an opinion.