The caller sounds like your mother, panicked and urgent. She’s had an accident and needs money wired immediately for a hospital bill. And please, don’t tell anyone because she’s embarrassed. The voice sounds exactly like hers, down to the small catch in her throat when she’s stressed.

Except it wasn’t your mother. It was an artificial intelligence (AI)-generated voice clone, crafted by criminals who pulled 30 seconds of audio from a video she posted online last month. This scenario is no longer science fiction. Millions of Americans now report receiving suspected deepfake voice calls, and the average person fields close to ten scam or spam calls every week. The technology behind helpful tools such as ChatGPT is now being weaponized against us at scale.

Read on to learn how AI is changing the threat landscape, the warning signs of AI-related scams, and the measures you can take to steer clear of them.

Key Takeaways

  • AI-powered scams use generative tools to impersonate real people and trusted organizations, including voice cloning, deepfake video calls, and highly polished phishing messages that lack traditional red flags.
  • Criminals use the same generative AI models you access to create flawless emails, clone voices, and generate video calls that look and sound completely authentic.
  • AI amplifies traditional scams such as phishing, business email compromise, tech support fraud, and romance cons by making them faster, more personalized, and harder to spot.
  • Protecting yourself requires adopting new habits, such as verifying identities through separate channels, strengthening account security, and updating your red-flag spotting skills.

What Are AI-Powered Scams?

AI-powered scams are fraudulent schemes that use generative artificial intelligence (AI) to create convincing but fake text messages, images, audio, or video at scale. These tools allow criminals to impersonate people you trust, craft messages that feel personal and urgent, and bypass the telltale signs we’ve learned to watch for over the past two decades.

When we talk about ChatGPT-style tools, we’re referring to large language models that can generate human-quality writing, translate between languages instantly, and adapt the tone to match any audience. The same technology that helps you draft a work email or brainstorm vacation plans can also write a phishing message that perfectly mimics your bank’s customer service style, including the exact phrasing it uses in legitimate communication. These models analyze patterns so accurately that even careful readers struggle to spot the fake.

These online scams have existed for years, including phishing emails, fake customer support chatbots, cloned audio of family members or executives, and professional-looking fake websites. Creating and running them required more technical expertise and far more time in the past. Today, they take minutes and minimal skill to create and execute using AI.

Threat intelligence teams now document fraud-as-a-service platforms that bundle AI text generation, deepfake voice software, and spoofing services into subscription packages. These turnkey kits come with templates, pre-written scripts for romance scams or tech support cons, and even customer support channels where criminals help each other optimize their attacks.

Why AI-Powered Scams Are Growing So Fast

The FBI’s Internet Crime Complaint Center (IC3) reported $16.6 billion in cybercrime losses across 859,000+ complaints in 2024, a 33% jump from the previous year. Of these, cyber-enabled fraud accounted for about 38% of all complaints but 83% of all dollar losses.

Global voice phishing or vishing incidents leaped by over 1,600% in the first quarter of 2025 since the end of 2024, according to a Right-Hand Cybersecurity survey. The report also revealed that about 70% of surveyed organizations were targeted, with a median loss of $1,400 per victim, while a European energy conglomerate lost $25 million to such a scam. 

Another study documented vishing rising by 442% in 2025 and projected that deepfake-enabled fraud could reach $40 billion in global losses by 2027. These figures likely undercount the true magnitude of the problem because many victims never report fraud due to embarrassment or the belief that nothing can be done.

Real-World AI Scam Cases That Changed the Game

Seeing how AI scams actually play out makes the threat concrete.

In 2024, criminals carried out a costly deepfake attack against Arup, a multinational engineering firm. Staff received what appeared to be a routine invite from the company’s chief financial officer (CFO) to discuss a confidential transaction in a video call attended by multiple people. The CFO’s face and voice appeared completely normal. Following what seemed like legitimate instructions from leadership, a finance employee wired $25 million to accounts controlled by fraudsters. Every person on that call was an AI-generated deepfake. The real CFO never made the call.

The FBI has warned that scammers are also using similar tactics on individuals. These attacks involve AI-generated voice memos and video calls impersonating family members in crisis, trusted officials, or authority figures, all designed to create urgency and bypass your normal skepticism.

Vendors also report that AI-generated phishing emails now achieve click-through rates up to four times higher than those of human-written messages because they contain no grammatical errors, follow natural conversational patterns, and can be tailored to specific targets using information scraped from social media and company websites.

Most disturbingly, the FBI has warned that criminals are using AI to manipulate innocent photos into realistic, explicit images, then use those fabricated materials to harass or extort victims. Victims receive emails or direct messages with the fake images of themselves and threats to distribute them unless they pay in cryptocurrency or perform additional actions.

To combat cybercriminals, AI is being used as bait. The Federal Trade Commission’s (FTC) Operation AI Comply enforcement action in September 2024 targeted schemes that falsely promised income from fake AI-powered storefronts, Amazon fulfillment operations, and content creation tools. One scheme that sold expensive training programs and software swindled customers of more than $25 million, featuring AI-generated marketing copy, testimonial videos, and cutting-edge dashboards.

How AI Amplifies Traditional Scams

AI has taken traditional scams and made them exponentially more dangerous. Let’s break down how it works across the most common attack types.

Phishing and Business Email Compromise

Traditional phishing relied on mass emails with obviously misspelled company names, generic greetings, and awkward phrasing, typically indicating a non-English native scammer working from a template. AI eliminates every one of these tells. ChatGPT-style tools can generate highly localized, company-specific phishing in seconds: HR notices referencing actual policies, invoice reminders identical to your vendor’s real communications, or security alerts that mirror your IT department’s writing style.

AI systems can also analyze publicly available information from LinkedIn, company websites, and social media to personalize messages down to organizational structure and current projects. An email might read: “Hi Sarah, following up on the discussion from yesterday’s accounts payable meeting about the Q1 vendor reconciliation. Can you verify this updated W-9 form?”

If you’re Sarah and you did attend an AP meeting yesterday, the message feels perfectly legitimate even though the sender’s email address is slightly off and the attachment contains malware. This personalization capability has become a multibillion-dollar threat category even as organizations invest heavily in email security. 

Tech Support and Impersonation Scams Sound More Human

AI has taken scripts from rigid and obviously fake technical support, tax authorities, or bank representatives to make them dynamic and convincingly natural. Criminals use large language models to generate call scripts that adjust tone, empathy, and urgency based on the victim’s response. 

Some operations even use live AI assistants or AI-powered chatbots to staff fake support portals and respond in real time, walking victims through verification procedures that steal login credentials or convincing them to install remote access software that gives criminals full control of their devices. These bots can handle dozens of conversations simultaneously, respond instantly, and never make tired mistakes at 3 A.M. when call volume is high.

This has led authentic-sounding tech support scams to rake in hundreds of millions of dollars because they feel more like genuine interactions with legitimate companies.

Crypto and AI Opportunity Scams Exploit Two Hype Cycles at Once

Cybercriminals have combined cryptocurrency enthusiasm with generative AI to create professional-looking whitepapers, landing pages, and pitch decks promoting AI-powered trading bots, non-fungible token (NFT) minting platforms, and ChatGPT-driven arbitrage systems that promise guaranteed high returns.

These operations deploy chatbots in Telegram and Discord groups, auto-responding to skeptical potential investors using AI-generated answers that sound technically sophisticated, handling objections, generating fake testimonials, and even adapting their pitch. Because these conversations happen in real time and feel personalized, victims often believe they’re talking to actual traders or developers.

Romance Scams Scale Faster with AI

Scammers could traditionally maintain only a few convincing romantic relationships at once because each required months of personalized messages and careful attention to each victim. AI removes that bottleneck.

Using large language models, criminals can now maintain hundreds of relationships simultaneously. The AI generates personalized love letters, apologies, explanations, and reassurances in the victim’s native language and cultural style. It can mimic texting patterns, adjust between formal and informal tone, and remember details from earlier conversations that make the relationship feel authentic.

Governments and Regulators Respond

Federal agencies and regulatory bodies recognize that AI has changed the fraud landscape, and they’re updating their guidance and enforcement posture. In December 2024, the Federal Bureau of Investigation (FBI) issued a public service announcement explicitly warning that criminals use generative AI to scale fraud, including phishing, vishing, and deepfake content, and urged organizations and the public to update their security training. The FBI also emphasized that identity verification through trusted, separate channels is essential, as voices and video can now be convincingly faked.

The Federal Trade Commission (FTC) has also taken aggressive enforcement action. In September 2024, the agency launched Operation AI Comply, a coordinated effort to eradicate deceptive AI-driven schemes that defraud consumers. The FTC simultaneously proposed and advanced rules on AI-powered impersonation scams that mimic individuals, government entities, or businesses. The Commission underscored that “using AI tools to trick, mislead, or defraud people is illegal” and that existing consumer protection laws apply fully to AI-generated fraud.

The FTC is actively seeking public input on how to assess liability for companies that provide tools used to create AI-powered scams. Industry forums and standards bodies are pushing for technical solutions such as watermarking AI-generated content, content provenance systems that track the history of an image or audio file, and mandatory labeling for synthetic media.

How to Protect Yourself from AI Scams

Meanwhile, as legal frameworks take years to develop and enforce, your best defense right now is awareness and healthy skepticism, updated security tools, and helping the people around you understand these risks.

Update Your Mental Model

For the past 20 years, cybersecurity experts have told you to watch for poor grammar, misspelled words, and awkward phrasing as signs of a scam. That advice is now obsolete. AI can now produce flawless prose, realistic conversational tone, and brand-accurate formatting. 

Train yourself to be skeptical of any unexpected message or call that requests money, login credentials, personal information, or urgent action, regardless of how authentic it looks or sounds.

Focus instead on the request itself and question if this is something your bank would really ask you to do via email. Does your company authorize wire transfers based on a single call? Would your family member really need you to wire money without calling from a known number first?

Verify Every Voice and Video in a Deepfake World

This is perhaps the most important new habit to build: when someone contacts you with an urgent request, especially involving money or sensitive information, verify their identity through a separate, trusted channel before you act. Even if it’s your mother, boss, or bank’s fraud department, hang up and call them back at a number you’ve saved independently. Don’t use any number provided in the suspicious message or call. 

If you work in an office that handles financial transactions, suggest a layered approach that includes call-back policies and dual approvals for high-value transfers, recognizing that both email and voice can now be spoofed. If a department head sends an unusual payment request by email, require voice confirmation through a known phone line. If you receive an urgent voice request, require email confirmation to a verified address. 

Fortify Your Email, Accounts, and Devices

Most AI-powered scams still depend on traditional responses from you, such as clicking a malicious link, downloading malware, or giving away login credentials. For this reason, strengthening your baseline security greatly helps thwart these attacks.

Enable app-based multifactor authentication for key accounts, including email, banking, investments, and social media platforms. If possible, use hardware token authentication instead of SMS-based codes, which can be intercepted. 

Use strong, unique passwords for every account and store them in a reputable password manager. Remember, each distinct password serves much like a different key to every door. Keep your operating system, web browser, and mobile applications updated to close security gaps that AI-powered scams try to exploit through malicious links or attachments. Also, turn on advanced spam and phishing filters in your email client to help detect and block fraudulent messages.

Build Family Awareness

Fraud prevention works best when your household shares a common understanding of AI threats. Within your family, establish verification protocols proactively. Agree on a code word or phrase to confirm someone’s identity in an emergency voice or video call. This might sound overly cautious, but it takes only five minutes to walk through scenarios together and set up a code that could prevent a devastating loss. 

Discuss AI voice risks with older relatives and teenagers, who are frequently targeted by scammers in grandchild-emergency scams and fake celebrity opportunities.

Consider Security Tools

Add a technical layer of defense to complement your human judgment and best practices. A comprehensive security suite such as McAfee+ can help flag fake support sites and spoofed links, login pages, and malware-laden downloads pretending to be software updates. 

Identity monitoring can alert you if your personal information appears in a data breach that criminals might use to personalize AI-driven attacks, or if explicit deepfake content surfaces on the dark web as part of a sextortion campaign.

McAfee also provides ongoing education and guidance about emerging AI scam patterns through its blog and learning resources.

Final Thoughts

We’re living through a time when artificial intelligence is being used to separate you from your money and security in large-scale, high-speed operations. But the fundamental patterns remain the same. Fraud still depends on urgency, secrecy, emotional manipulation, and requests that bypass normal verification procedures. 

By updating your mental models of what looks real, adding simple verification steps before you act on voice or video requests, hardening your accounts and devices with security solutions, and sharing this knowledge with family and coworkers, you can dramatically reduce the likelihood that AI will be used against you. The technology might be new, but the defense strategy is timeless: healthy skepticism, verification before action, and a refusal to be rushed into decisions by artificial urgency.

These steps feel small, but together they create layers of protection that make you a much harder target.