Skip to content

Deepfake Scam

A deepfake scam is any fraud carried out using synthetic audio or video: a cloned voice, a fabricated call, a manufactured endorsement. What matters most about it is that synthetic media is a tool appearing across every kind of scheme rather than a scheme of its own.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • The FBI's complaint system treats artificial intelligence as a descriptor of how a crime was committed, applied only after a crime type has been chosen. There is no deepfake or voice-cloning crime type.
  • In 2025 the FBI recorded 22,364 complaints referencing AI, with $893,346,472 in adjusted losses, spread across more than twenty different crime types.
  • The practical consequence is that a familiar voice or a live face is no longer evidence of who you are speaking to, and no other rule about scams changes.
  • The defense is not detection. The Federal Trade Commission's advice is to reach the person through a channel the caller does not control.
  • The reported AI figures almost certainly understate the problem, and the FBI says so itself.

Definition

A deepfake scam is a fraud committed with the help of synthetic media: audio, video or images generated or altered by software so that a person appears to say or do something they did not. The commonest financial forms are a cloned voice on a telephone call, a fabricated video of a public figure endorsing an investment, and a manufactured face and voice in a live video meeting.

The most useful thing to understand about the category is that it is not really a category. The FBI's Internet Crime Complaint Center, which classifies every complaint it receives, does not have a deepfake crime type or a voice-cloning crime type. It handles artificial intelligence as a descriptor, a separate field from the crime type, and defines the concept in one sentence: "A Descriptor relates to the medium or tool used to facilitate crime and is used by IC3 for tracking purposes only. It is available as a descriptor only after a crime type has been selected." There are three descriptors in the system, and AI Related is one of them. The crime type has to be chosen first, and each complaint carries only one.

That architecture is the thesis of this page. Synthetic media is how a scheme is executed, not what the scheme is. A cloned voice used to demand a wire from a company is business email compromise. A cloned voice used to say a grandchild is in trouble is a family emergency scam, covered on our page about the grandparent scam. A fabricated video of a chief executive promoting a token is investment fraud. The technology raises the quality of the performance; it does not create a new offense or a new set of defenses.

A note on naming, and on a distinction this page declines to make. There is no single official name for the merged concept. "Deepfake scam" is the phrasing used in the title of a joint infographic from the American Bankers Association Foundation and the FBI, which the FBI lists in its own annual report, and it is the phrase most readers search. Whether a voice clone is best described as a species of deepfake or as a separate thing is genuinely unsettled in official usage: the FTC's own material about its Voice Cloning Challenge describes a submission that would "detect in real time voice cloning and deep fakes," naming them as two. This page treats both as synthetic media used as a medium and does not rule on the taxonomy.

Advanced Explanation

Where it actually shows up, in the FBI's own figures. In 2025 the Internet Crime Complaint Center recorded 22,364 complaints carrying an AI-related descriptor, with $893,346,472 in adjusted losses. The distribution is the point: those complaints were filed under more than twenty different crime types, twenty-six of them. The seven largest were Investment at 4,356, Extortion at 1,764, Personal Data Breach at 1,204, Phishing/Spoofing at 803, Harassment/Stalking at 763, Employment at 691 and Confidence/Romance at 626. Nineteen more categories sit behind those, tailing off through Government Impersonation at 260 to Charity at 19 and Botnet at 12. A tool that appears in every column is a tool, not a column.

The four uses the FBI describes, and what each one is really an attack on.

In business email compromise, the report notes that chat generators "can quickly create official-sounding emails mimicking a company's CEO or other officials," and that "voice cloning can also be used to request wire payment." Businesses reported losses over $30 million to BEC scams involving AI in 2025. The target here is a company's payment process rather than an individual, and the synthetic element is aimed at the one control most payment processes still rely on, which is a human recognizing a voice.

In confidence and romance fraud, AI is used to generate profiles and to make conversation more fluent, and voice cloning appears in the distress variant. Our pages on the romance scam and the grandparent scam cover those pretexts and carry the FBI's figures for them.

In employment fraud, the direction reverses, and this is the case most often misfiled. The FBI describes "the use of voice spoofing, or potentially voice deepfakes, during online interviews of the potential applicants," where "the actions and lip movement of the person interviewed on-camera do not completely coordinate with the audio of the person speaking. At times, actions such as coughing, sneezing, or other auditory actions are not aligned with what is presented visually." The FBI adds that dollar losses are not the objective: "the goal generally appears to be gaining access to private computer networks." This is fraud aimed at the employer by a fake applicant, which is a different thing from the fake job offer aimed at a jobseeker on our page about the fake job scam.

In investment fraud, the report describes investment clubs employing "AI-generated videos and voices of celebrities, CEOs, or trusted figures to create fraudulent, high-stakes opportunities," often with "fake, professional-looking endorsements on social media or in video calls." The underlying pitch is unchanged, and our page on the guaranteed return red flag covers what makes it recognizable regardless of who appears to be delivering it.

What synthetic media actually destroys, which is narrower than it sounds. It removes one specific form of evidence: sensory recognition. A voice that sounds like a relative, a face on a video call, an accent, a laugh, a verbal tic. Everything else that identifies a fraud survives untouched, because none of it depends on how the message sounded. The contact still arrives unbidden. There is still a reason the ordinary channel cannot be used. There is still urgency, and there is still a payment routed through something that cannot be pulled back. Our page on fraud sets out that architecture, and it is worth reading precisely because the technology leaves it intact.

Why detection is the wrong response and what the FTC recommends instead. Advice to look for unnatural blinking or listen for flat intonation ages badly, because the artifacts it relies on are exactly what the next release fixes. The FBI's lip-synchronization tell above is genuinely useful for the live-interview case and should be read as an observation about the tools of one period rather than as a durable test. The Federal Trade Commission's recommendation does not depend on the quality of the fake at all: if a call claims to be from someone you know, "call the person who supposedly contacted you using a phone number you know is theirs, and verify the story." That works against a perfect clone as well as against a poor one, because it changes the channel to one the caller did not choose.

The figures understate the problem, and the FBI says so in the same paragraph. Reporting an AI element requires the victim to have noticed one, which by construction is what a successful synthetic fake prevents. The report makes the point directly about its own largest category, and the arithmetic is in the next section.

How to Remember

Synthetic media changes what you can trust your ears and eyes about. It changes nothing about what you can trust a callback about.

Used in a Sentence

“The finance team approved the transfer after a video call with someone who looked and sounded like the chief executive, and only the bank's callback procedure caught the deepfake scam.”

How It Works

The sequence is the ordinary one with a single substitution:

  1. Source material is collected. A voice sample from a voicemail, a webinar, a social post or an earnings call; images or video from anywhere public.

  2. A synthetic performance is generated, in audio alone for a telephone call or with video for a meeting or an advertisement.

  3. It is inserted into an existing scheme as the credibility step, in place of a forged letterhead, a spoofed caller ID or a copied logo.

  4. The rest of the scheme runs unchanged, including the reason the normal channel cannot be used, the urgency, and the irreversible payment rail.

A computation the reader can check, using the FBI's published 2025 figures. The report states that "losses in Investment complaints with a reported AI-nexus, surpassed $632 million," while "overall losses to Investment scams exceeded $8 billion." Six hundred and thirty-two million out of eight billion is 632 divided by 8,000, or about 7.9 percent. So on the reported numbers, fewer than one dollar in twelve of investment-fraud losses carried an AI descriptor.

The FBI's own reading of that gap is not that AI was absent from the other ninety-two percent. It draws the opposite inference in the same sentence, saying the contrast demonstrates "that many victims do not realize the extent AI may be involved in scams." That is the honest limit of every figure on this page: they measure complaints in which someone noticed, which is a floor rather than an estimate.

Pros and Cons

Synthetic media in fraud has no upside for the target, so what follows is what survives the technology and what does not.

What still works

  • The callback on a number you already had. It defeats a perfect fake as easily as a crude one, because it changes the channel.
  • Every non-sensory signal: unbidden contact, a reason the normal route cannot be used, manufactured urgency, secrecy, and an irreversible payment rail.
  • Process controls that do not ask a human to recognize anyone. A payment approval that requires a second, independent confirmation is unaffected by how convincing the first request sounded.
  • Agreeing in advance, inside a family or a finance team, that no money moves on a single verbal instruction.

What no longer works

  • Recognizing a voice. This is the specific capability the technology removes, and it was the main one most people were relying on.
  • Being on a live video call, which was until recently taken as proof of presence.
  • Artifact-spotting advice. Unnatural blinking, flat intonation and lip-synchronization errors describe the tools of a moment, and the FBI's own interview tell should be read that way.
  • Assuming the loss figures describe the scale. Reporting an AI element requires having noticed one.

People Also Asked

Answers to the most frequently asked questions.

Is a voice clone the same thing as a deepfake?
Official usage does not settle this, and it is worth saying so rather than picking. "Deepfake" is generally used of synthetic video and imagery, and "voice cloning" of synthetic audio, and the two are frequently treated as one family of synthetic media. But the Federal Trade Commission's own material about its Voice Cloning Challenge describes a submission that would "detect in real time voice cloning and deep fakes," naming them as two things. What is settled, and what matters practically, is that both are media used to carry out other schemes rather than schemes in themselves.
Is there such a thing as a "deepfake scam" as a distinct type of scam?
Not in the FBI's classification, which is the most detailed public taxonomy of consumer fraud reporting. Its Internet Crime Complaint Center treats artificial intelligence as a descriptor of the medium or tool used, applied only after a crime type has been selected, and its crime-type list contains no deepfake or voice-cloning entry. In 2025 the AI descriptor was attached to complaints across more than twenty crime types, from investment fraud and extortion to employment and charity. The label is useful for describing how something was done; the scheme underneath it is always something else.
How can I tell whether a voice or a video call is real?
Increasingly you cannot, which is why the recommended response does not depend on telling. The Federal Trade Commission's advice is to "call the person who supposedly contacted you using a phone number you know is theirs, and verify the story," which works whatever the quality of the fake. The FBI does record one live tell for video interviews, that "the actions and lip movement of the person interviewed on-camera do not completely coordinate with the audio," including coughs and sneezes that do not align with the picture. Treat that as an observation about current tools rather than a test you can rely on next year.
Why do the reported AI fraud losses look small next to the totals?
Because reporting an AI element requires the victim to have noticed one, and a successful synthetic fake is one that was not noticed. The FBI makes this point about its own largest category: investment complaints with a reported AI connection exceeded $632 million in 2025, while overall investment scam losses exceeded $8 billion, which the report says demonstrates "that many victims do not realize the extent AI may be involved in scams." Read every figure in this area as a count of detected cases rather than as a measure of the whole.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Federal Bureau of Investigation, Internet Crime Complaint Center. "2025 Internet Crime Report."
  2. Federal Trade Commission. "Fighting back against harmful voice cloning."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor