A few seconds of someone's voice from a social media clip can be enough for AI tools to produce a convincing imitation. Criminals are using that capability to impersonate relatives in distress, executives approving urgent wire transfers, and customers trying to get past bank security. The good news: the best defenses are low-tech, and anyone can set them up today.
Last updated September 17, 2026.
Key takeaways
- Deepfakes are AI-generated or AI-altered audio, video, or images that realistically imitate a real person. Voice cloning is the audio version.
- Criminals use them in three main ways: impersonating loved ones or officials, impersonating executives to trigger business payments, and trying to defeat identity checks at banks [1].
- FinCEN, the U.S. Treasury's financial crimes unit, issued an alert on November 13, 2024, on fraud schemes using deepfake media to target financial institutions [1]. In July 2026, the FBI warned that criminals were using deepfake videos of senior FBI officials in fake "fraud recovery" schemes [12].
- Your strongest defense is verification through a separate channel you control — hang up and call back on a known number, or use a pre-agreed family "safe word."
- Organizations should not rely on voice or a video call alone to approve payments or account changes.
What deepfakes and voice clones actually are
Generative AI models learn patterns from large amounts of data and can produce new content. Applied to a person's voice, a model can generate new speech that sounds like them saying words they never said. Applied to video, it can swap or animate a face in real time.
What has changed in the past few years is accessibility: tools that once required expertise are now widely available, and some need only short audio samples. In a March 2023 consumer alert, the FTC warned that a scammer needs only a short audio clip of a family member's voice, which could come from content posted online, plus a voice-cloning program [2].
How criminals use deepfakes in financial fraud
1. "Family emergency" and impostor calls
The classic "grandparent scam" — a caller claims to be a relative who has been arrested or injured and needs money urgently — becomes more convincing when the voice sounds right. Callers typically insist on secrecy and fast payment by wire, P2P app, gift cards, cryptocurrency, or even a courier picking up cash.
The FBI has also warned about AI-generated voice messages impersonating senior U.S. government officials to build trust with targets (May 15, 2025) [3]. And in a July 2026 public service announcement (I-072026-PSA), it warned that criminals targeting past fraud victims used AI-generated videos of senior FBI officials to steer people to a counterfeit IC3 website that harvested personal information under the promise of recovering lost money [12].
2. Executive impersonation and business payments
Business email compromise (BEC) — tricking an employee into paying a fake invoice or wiring funds — has long been one of the costliest cybercrimes reported to the FBI [4]. Deepfakes add a voice or video layer to the con.
The most widely reported example: in early 2024, an employee at the UK engineering firm Arup was tricked into sending $25 million to criminals after a video call with what appeared to be senior managers, who were in fact AI-generated deepfakes. Arup's chief information officer has since discussed the incident publicly [5].
3. Defeating bank identity checks
Banks and fintechs verify customers during account opening and sign-in. Criminals have tried to:
- Fool voice authentication ("voiceprints") on phone banking lines with cloned audio.
- Beat "liveness" checks — selfie videos meant to prove a real person is present — with synthetic or manipulated video, sometimes injected directly into the app's camera feed.
- Submit AI-generated identity documents or photos to open accounts used for laundering money.
FinCEN's November 13, 2024 alert (FIN-2024-Alert004) described schemes in which criminals used generative AI to create fraudulent identity documents to circumvent identity verification and authentication, and asked banks, money services businesses, and other institutions to report suspected deepfake activity [1].
How big is the problem?
Reliable, comprehensive loss figures specifically for deepfake fraud are scarce, because victims and institutions often can't tell — or don't report — whether AI was involved.
- The FBI's Internet Crime Complaint Center publishes annual loss figures for categories like BEC, investment fraud, and government impersonation, but these don't isolate deepfakes [4].
- Industry forecasts exist; for example, Deloitte's Center for Financial Services projected in May 2024 that generative AI could enable U.S. fraud losses to reach $40 billion by 2027, up from $12.3 billion in 2023 [6]. Treat vendor and consulting forecasts as estimates, not measurements.
We've deliberately avoided citing viral "deepfake attacks up X%" statistics, which often come from vendors selling detection tools and use undisclosed methods.
Warning signs
Detection by ear or eye is getting harder, so focus on behavioral red flags rather than glitches:
| Red flag | Why it matters |
|---|---|
| Extreme urgency ("in the next hour") | Prevents you from verifying |
| Request for secrecy ("don't tell Mom," "don't tell finance") | Isolates you from people who would spot the scam |
| Unusual payment method (wire, crypto, gift cards, courier cash pickup) | Hard to reverse |
| A change to payment instructions or bank details | Classic BEC pattern |
| Caller won't let you call back, or asks you to stay on the line | Stops independent verification |
| Video call where the person avoids interaction or the call is cut short | Possible synthetic participant |
| Caller ID looks right | Numbers can be spoofed |
Defenses for individuals and families
- Agree on a family safe word or question that isn't on social media. If someone calls with an emergency, ask for it. In a December 2024 public service announcement, the FBI recommended creating a secret word or phrase with your family to verify their identity [7].
- Hang up and call back using a number you already have — not one the caller gives you.
- Slow down. Legitimate emergencies survive a five-minute verification call.
- Limit public voice and video samples where practical, and tighten social media privacy settings.
- Don't rely on voice ID alone for your bank accounts. If your bank offers stronger sign-in options such as passkeys, consider them. Related field note
- Know that your bank won't ask you to move money to a "safe account," read out one-time passcodes, or hand cash or cards to a courier.
Defenses for businesses and finance teams
- Out-of-band verification. Confirm any payment request or change to vendor bank details via a known phone number or in person — never via contact details in the request.
- Dual approval for wires and new payees above a threshold.
- No exceptions for executives. Make it policy that urgency from a senior leader never overrides verification.
- Train staff with realistic scenarios, including voice and video.
- Review authentication on customer-facing channels. FinCEN's alert lists red flags for deepfake attempts to get around identity verification and authentication [1].
What regulators and lawmakers have done
| Action | What it does | Status (as of last verified date) |
|---|---|---|
| FinCEN Alert on deepfake media (FIN-2024-Alert004) [1] | Red flags and suspicious activity reporting guidance for financial institutions | Issued Nov. 13, 2024 |
| FCC declaratory ruling (FCC 24-17) [8] | Treats AI-generated voices in robocalls as "artificial" under the Telephone Consumer Protection Act, so such calls require prior express consent | Released Feb. 8, 2024 |
| FTC Impersonation Rule [9] | Lets the FTC seek civil penalties and redress from scammers impersonating government agencies and businesses | In effect since April 1, 2024 [9]; the FTC proposed extending it to impersonation of individuals, including via AI, in February 2024 [13], and we found no final amendment on the FTC's rule page as of September 17, 2026 [9] |
| State laws | Some states have their own deepfake laws, which vary widely in scope | Varies by state; check your state |
Ordinary fraud, wire fraud, and identity theft laws already apply regardless of whether AI was used.
The bottom line
Deepfakes don't create a new kind of scam so much as make old scams more persuasive. That means the defenses that stop impostor fraud still work — as long as you use a verification step the scammer can't control.
FAQ
Can scammers really clone a voice from a short clip? Consumer protection agencies including the FTC have warned that they can, using widely available tools [2]. Quality varies, but it may be good enough over a phone line during a stressful call.
Is voice authentication at my bank still safe? Voice ID adds convenience but can be targeted with cloned audio. Where available, stronger methods like passkeys or app-based verification are harder to spoof. Ask your bank what options it offers.
How do I set up a family safe word? Choose a word or phrase that isn't guessable from social media, share it in person or through a secure channel, and agree that anyone requesting urgent money must say it.
What should I do if I sent money after a deepfake call? Contact your bank or payment provider immediately, report to ReportFraud.ftc.gov and IC3.gov, and keep call logs and messages [10][11]. Type those addresses yourself — the FBI has warned about fake IC3 sites and bogus "recovery" offers [12].
Can I tell a deepfake video call by looking for glitches? Sometimes, but don't count on it. Verify through a separate channel instead.
Sources
- Financial Crimes Enforcement Network, "FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions" (FIN-2024-Alert004), November 13, 2024, https://fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial, accessed 2026-09-17.
- Federal Trade Commission, "Scammers use AI to enhance their family emergency schemes," March 20, 2023, https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes, accessed 2026-09-17.
- FBI Internet Crime Complaint Center, public service announcement on malicious text and voice messaging impersonating senior U.S. officials, May 15, 2025, https://www.ic3.gov/PSA/2025/PSA250515, accessed 2026-09-17.
- FBI Internet Crime Complaint Center, Annual Internet Crime Report (latest), https://www.ic3.gov/AnnualReport/Reports, accessed 2026-09-17.
- World Economic Forum, "'This happens more frequently than people realize': Arup chief on the lessons learned from a $25m deepfake crime," February 4, 2025, https://www.weforum.org/stories/2025/02/deepfake-ai-cybercrime-arup/, accessed 2026-09-17.
- Deloitte Center for Financial Services, "Generative AI is expected to magnify the risk of deepfakes and other fraud in banking," May 29, 2024, https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html, accessed 2026-09-17.
- FBI Internet Crime Complaint Center, "Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud," December 3, 2024, https://www.ic3.gov/PSA/2024/PSA241203, accessed 2026-09-17.
- Federal Communications Commission, Declaratory Ruling, "Implications of Artificial Intelligence Technologies on Protecting Consumers from Unwanted Robocalls and Robotexts," FCC 24-17, CG Docket No. 23-362, released February 8, 2024, https://docs.fcc.gov/public/attachments/FCC-24-17A1.pdf, accessed 2026-09-17.
- Federal Trade Commission, "Impersonation of Government and Businesses Rule," https://www.ftc.gov/legal-library/browse/rules/impersonation-government-businesses-rule, accessed 2026-09-17.
- Federal Trade Commission, ReportFraud.ftc.gov, https://reportfraud.ftc.gov/, accessed 2026-09-17.
- FBI Internet Crime Complaint Center, https://www.ic3.gov/, accessed 2026-09-17.
- McDonald Hopkins, "FBI renews warning on AI-generated deepfakes impersonating law enforcement in fraud recovery schemes," July 2026 (summarizing FBI PSA I-072026-PSA, July 20, 2026), https://www.mcdonaldhopkins.com/insights/news/fbi-renews-warning-on-ai-generated-deepfakes, accessed 2026-09-17. Primary: https://www.ic3.gov/PSA.
- Federal Trade Commission, "FTC Proposes New Protections to Combat AI Impersonation of Individuals," February 2024, https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-proposes-new-protections-combat-ai-impersonation-individuals, accessed 2026-09-17.
This article is for educational purposes only and is not financial, legal, or security advice. Threats and regulations evolve quickly; verify current guidance with your bank, employer's security team, and official sources.