ChatGPT, voice assistants, and other AI tools aren’t just for boosting productivity anymore; they’re being turned toward scams. In 2025 alone, roughly one in ten reported scams in the US involved AI.
An AI scam is a deceptive scheme that uses AI capabilities, like voice cloning or deepfake videos, to impersonate a real person or organization and trick you into handing over money or personal details. You might know the delivery method as “AI phishing” (a suspicious message or email), but the scam itself is often a lot more complex.
In this blog, I’ll explain how these scams work, walk through the most common types you’re likely to run into, and share practical ways to spot them and protect yourself.
Understanding AI scams: how scammers use AI
Traditional scams used to be easy to spot because they had one of these signs:
- Bad grammar;
- Generic greetings;
- Fake logos.
But generative AI has changed that. Scammers now use AI tools to write flawless, hyper-personalized messages that reference real details about you, pulled from public social media posts and other online footprints.
Artificial intelligence scams vs. traditional fraud
The core difference comes down to speed and personalization. In one study, manually researching a target and writing a personalized phishing email took about 34 minutes, while the AI tool did the whole process in about a minute¹.
This is a massive jump in scale at equal or better quality. That means one scammer or one script can now run thousands of unique-sounding scams simultaneously, instead of one at a time.
AI-driven scams and automation
AI-driven scams thrive on automation, and the data show how fast that shift is happening:
- Fraud researchers have tracked AI-enabled fraud surging 1,210% in 2025²;
- Generative AI could drive fraud losses in the US from $12.3 billion in 2023 to $40 billion by 2027³;
- AI-driven email fraud alone could reach $11.5 billion a year by 2027³;
- Over one in ten scams reported in 2025 involved AI or a deepfake, out of an estimated $68 billion lost to scams in the US that year⁴.
Most common types of AI scams (with examples)
Here are the most common AI scams making the rounds right now.
AI voice cloning
AI can recreate a person’s voice from a short audio clip, sometimes pulled from a social media video or a voicemail greeting. According to McAfee research, just three seconds of audio is enough to clone a voice with about 85% accuracy⁵.
If you get an urgent call that sounds exactly like your grandchild or another family member, claiming they’ve been in an accident or arrested and need bail money right away, be aware. This could be a voice cloning attack, often called the “grandparent scam.”
The voice sounds real because it’s the actual cloned sound of your loved one, not a stranger doing an impression.
Deepfake scams and AI impersonation
A deepfake is a manipulated video or audio, generated or altered by AI to make it look and sound like something that never happened. AI impersonation takes this further, with scammers using deepfake technology to pose as celebrities, CEOs, or government officials in fake videos or live video calls.
Deepfake video scams surged 700% in 2025 alone⁶. This kind of fraud has already caused financial losses of around $900 million, and once you factor in AI’s broader role, total losses have surged past $1.56 billion. Much of it spreads through social media, where Facebook led all platforms in related losses that year.
In January 2024, a finance employee at an engineering firm joined a video call where every other participant, including the person who appeared to be the company’s CFO, was a deepfake, and ended up authorizing 15 wire transfers totaling $25.6 million⁷.
AI romance scams: the "perfect" virtual partner
AI romance scams start on dating platforms or social media with a profile picture that looks flawless because it’s AI-generated. These images are created specifically so that a reverse image search turns up nothing, since the person literally doesn’t exist.
Unlike traditional romance scams that rely on a fixed script, AI lets a scammer react naturally to a victim’s specific emotions, building trust much faster before ever mentioning money.
Some scammers use chatbots to maintain multiple relationships with different targets at the same time, adjusting tone and personality for each conversation⁸. Victims of confidence and romance scams have reported average losses as high as $39,300 per person.
If you get matched with a seemingly perfect partner on a dating app who always says the right thing, mirrors your interests, and builds an emotional connection over weeks, be extra careful.
That’s especially true if they eventually ask for money for an emergency or a plane ticket to finally meet in person. If this happens, try a video call (most scammers will make excuses to avoid it).
AI investment and crypto scams
These scams promote fake trading platforms, claiming a “proprietary AI algorithm” that guarantees huge, sometimes triple-digit returns on crypto or stocks. To make the pitch more convincing, scammers use AI-generated videos of well-known tech figures appearing to “confirm” the investment’s legitimacy.
Some platforms even show AI-generated dashboards displaying fake “live” profits, encouraging victims to deposit more money before the account and the scammer disappear.
US crypto scam losses nearly doubled in a single year, even before generative AI got involved.
If a deepfake video circulating on social media shows a well-known tech entrepreneur “endorsing” a crypto platform that promises to double your money in 24 hours, be aware. Nothing works like magic.
AI-generated fake websites
AI tools can now generate realistic-looking investment websites or login portals in seconds, often copying the layout, logo, and even the customer reviews of a real brand.
Such websites are built to be nearly identical to the real website, which makes it harder to catch at a glance.
If you come across a sponsored ad for a clothing brand and accidentally visit a phishing website that looks pixel-perfect but asks for your card details in exchange for a “surprise” discount, stop right there.
Chances are, the website was only spun up days earlier, and the real brand has never heard of it.
Scammers using AI for "smart" phishing
Scammers use generative AI to write personalized phishing emails and text messages that are grammatically perfect and tailored to the target, which helps them bypass spam filters.
A 2024 study found that AI-generated phishing emails hit a 54% click-through rate, compared to just 12% for traditional phishing.¹ In fact, 82.6% of phishing emails now contain some form of AI-generated content⁹.
If you get an email that references your employer, your job title, and a recent project by name, asks you to “verify” your login through a link, and still doesn’t read like the broken-English phishing emails of a few years ago, be aware.
That level of detail doesn’t mean the email is legitimate. It could mean AI pulled it from your LinkedIn profile, a company press release, or another public source in seconds.
Red flags: how to spot an AI scammer
Because AI removes the classic signs like typos, awkward phrasing, and fake logos, you need a different set of red flags to stay ahead of common AI scams:
- Unnatural language: watch for paragraphs that sound slightly “off,” oddly formal, or repetitive, sometimes overusing certain words or phrases;
- Visual inconsistencies: look for video glitches like unnatural blinking, mismatched lip-syncing, or strange lighting;
- Urgency and high pressure: treat any unusual request that demands immediate payment via gift cards, wire transfer, or crypto as a serious warning sign;
- The “uncanny” feeling: trust your gut if a voice or video from a family member, coworker, or reputable company doesn’t feel quite right, even if you can’t say exactly why;
- Suspicious sender details: check the caller ID, phone number, and sender email address closely because even a small misspelling in an otherwise legitimate-looking address can reveal a scam.
How to protect yourself from AI-related scams
You can’t out-detect every AI scam by eye alone, so build a few habits that make you a harder target in the first place:
- Verify the source through an official channel: if you get a suspicious “emergency” call, hang up and call the person back on their known number rather than trusting the caller ID;
- Set up a family code word: agree on a simple, non-technical word or phrase with close family members to verify identity during an unexpected or urgent call;
- Tighten your privacy settings: voice cloning and deepfakes rely on audio and video pulled from public posts, so limit what you share publicly;
- Turn on 2FA (Two-factor Authentication): add 2FA to your important accounts to give scammers one more barrier to cross, even if they get your login credentials;
- Use a password manager and change passwords regularly: this keeps your accounts fresh and makes it easier to spot if something was compromised;
- Set up fraud alerts: real-time alerts from your bank can flag unusual payment demands or unauthorized transactions before they cause more damage;
- Review your financial statements: check them for unauthorized transactions, especially after receiving any unusual request tied to money;
- Talk to your family about AI scams: educate family members, especially older relatives, about how AI voice cloning and deepfake scams work, as it can prevent them from taking a risky step.
Final thoughts: staying one step ahead of AI scams
AI is a tool, and like most tools, it can both help and harm. The same AI capabilities that write your emails or plan your trip can just as easily generate a fake voice, a fake video, or a fake website to steal your money or damage your reputation.
To stay protected from such scams, build a habit of skepticism toward unexpected, high-pressure requests, no matter how real they sound or look. Pause and verify through a channel you trust before acting, especially if money or personal details are involved.
You can also add an extra layer of defense with Surfshark’s scam protection tools, which flag suspicious messages and links before they reach you.
If this guide helped, share it with a family member or friend who might not know how far AI scams have come today.
FAQ
How can you tell if someone is using AI?
There can be several signs, and once you know what to look for, they’re not too hard to spot:
- Video glitches: unnatural blinking, odd lighting, or lip movements that don’t quite match the words;
- Voice that feels a little off: flat tone, missing background noise, or a word pronounced the way the real person never would;
- A chatbot pretending to be human: replies that come too fast, sound too consistent, or dodge specific personal questions.
If something feels off, trust that instinct and verify through a separate, trusted channel.
Is AI phishing the same as an AI scam?
Not exactly. AI phishing refers to the delivery method, such as an AI-generated email or text message, designed to trick you into clicking a link or sharing information. An AI scam is the broader scheme itself, which may use phishing, voice cloning, deepfakes, or fake websites, alone or combined, to carry out the fraud.
Sources
- Heiding et al., “Evaluating Large Language Models’ Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects“, arXiv, 2024.
- Muncaster, P., “AI-Enabled Voice and Virtual Meeting Fraud Surges 1000%+“, Infosecurity Magazine, February 5, 2026.
- Lalchand, S., Srinivas, V., Maggiore, B., & Henderson, J., “Generative AI is expected to magnify the risk of deepfakes and other fraud in banking“, Deloitte Insights, May 29, 2024.
- Stop Scams Alliance & Gallup, “United States of Scams: The Financial and Emotional Fallout“, 2026.
- McAfee, “Artificial Imposters — Cybercriminals Turn to AI Voice Cloning for a New Breed of Scam“.
- Sumsub, “Synthetic Identity Document Fraud Surges 300% in the U.S. — Sumsub Warns E-Commerce, Healthtech and Fintech at Risk“, Sumsub Newsroom, June 12, 2025.
- CNN Business, “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee“, May 2024.
- UNSW, “Are you at risk of an AI romance scam this Valentine’s Day?“, BusinessThink, 2026.
- KnowBe4, Phishing Threat Trends Report, Vol. 5 (PDF), March 2025.
