Her phone rang and it was her grandson, frightened, talking fast. He'd wrecked the car, gotten arrested, and needed bail money before morning. No wallet, no phone of his own, just this one call. She grabbed her keys, pulled cash from the bank, and handed it over the way any grandmother would. The voice was a fake. A scammer had cloned her grandson from a handful of clips online and pointed her toward an emptied bank account.
That kind of con isn't an outlier anymore. Cloned audio, swapped faces, and machine-made documents now turn up in close to 11% of fraud attempts worldwide. Below, a tour of the schemes shaping this year and the controls that genuinely slow them down.
The State of Play: Losses, Numbers, and a Nasty Twist
People lost north of $12.5 billion to fraud in 2024, up a quarter on the prior year. The lazy phishing blast is mostly history. The crews working now scan each industry for its weak joint and drive a tailored tool into it. The UK is a clean example: deepfake attempts there climbed 94% in a year while total fraud barely budged. Volume isn't the story. Skill is.
The counterintuitive part: fraud rates slid a little in 2025 against 2024, even as sophisticated fraud shot up 180%. Translation — the attempts that land are meaner. They run on social engineering, AI-built personas, and stacked deception aimed at systems designed to stop simpler tricks.
Two things drive the jump. The tools got better, with generative models and self-running bots handing criminals talent they never had. The distribution got wider, as fraud-as-a-service sellers package those tools cheap, so a beginner with a card runs what used to need a gang. Card details stolen in one country surface in another with thinner protections. Defences can't aim at the average crook. They have to beat the best one.
Fabricated identities, mimicked faces, machine-built voices: AI quietly powers nearly every serious threat going. The classics — phishing and vishing — didn't fade. They sharpened, because AI hands a scammer personalisation and scale in one package.
Deepfakes Stopped Being a Novelty
Not long ago a deepfake was a party trick. The shift this year is structural. Instead of a clever fake surfacing now and then, there's a whole production line: models spitting out documents, voices, and video, then feeding straight into automation and resale shops.
The targets tend to be people with the least defence against the trick. A Florida mother lost $15,000 in July 2025 to a voice clone of her daughter, who supposedly got arrested after a crash. A 'lawyer' set the bail number, she paid cash, and only a second money demand made a relative suspicious. By then the first payment had vanished.
Businesses can push back, and two moves do the heavy lifting:
- Spend real money teaching customers what these scams sound like before the call ever comes.
- Deploy digital risk protection and deepfake detection to shut down fake ads and impostor profiles riding on your name.
Deepfakes are just the warmup. AI widened the reach, volume, and realism of fraud beyond what detection teams ever rehearsed for.
Self-Directed Bots Running Whole Campaigns
Agentic AI flips the equation. These systems act on their own, blending generated content, scripts, and copied human behaviour to slip past verification. Block one try and the thing studies the failure, then rewrites its play in real time to dodge whatever you just rolled out. For fraud-as-a-service, that's a force multiplier, putting top-shelf capability in amateur hands.
Defenders get the same toy, though. The likely result is a bot-versus-bot grind where whoever learns faster takes the round.
Malware That Adapts as It Attacks
AI is rewiring how malicious code acts. Ransomware and phishing payloads now read victim behaviour and shift in real time to slip past detection before striking. Cornell University researchers built AI-driven attack frameworks that sailed past most antivirus tools. Drop that into a fraud-as-a-service bundle and serious malware lands in the hands of anyone with cash to spend. Language models keep improving, biometrics keep getting harder to spoof, and neither side ever gets a breather.
Stitched-Together Identities That Pass the Check
Imagine a person built from spare parts: an AI face, a fictional address, a genuine stolen ID number. Combined, this 'Frankenstein' profile clears onboarding at a bank or fintech, looks spotless, lies dormant for months, then wakes up and drains out. Toronto Police, in a case dubbed Project Déjà Vu, traced one individual who'd spun up hundreds of accounts this way across Ontario, with confirmed losses near CA$4 million.
You catch this by reading behaviour, not documents, and machine learning does the work because humans can't keep pace with how fast criminals manufacture these personas.
Cloned Voices Turn Trust Into a Weapon
Copy a voice, dial a number, and your target swears they're speaking to family. Vishing rides that trust to extract secrets or cash, and it lands because hardly anyone expects it. In one test, listeners separated real voices from synthetic ones only 37.5% of the time.
The favoured script is the loved-one-in-trouble call — a panicked daughter or grandson needing money this instant — because panic shoves judgement aside. There's a design quirk too: research finds female voices read as warmer and tend to persuade harder, which is part of why so many digital assistants sound that way. Scammers lean on the same wiring.
Which Industries Are Bleeding the Most
Where identity is the lock on the door, fraud crowds in. The five hardest-hit sectors across 2025 and 2026 are dating, online media, financial services, crypto, and professional services — with dating and online media on top at a 6.3% fraud rate each.
Finance is staring down more deepfakes and AI-forged paperwork that make a basic ID check feel obsolete. Payment fraud comes in two flavours. First-party fraud — lying about your own intentions — includes chargeback abuse at 16% of first-party payment fraud in 2025. Third-party fraud includes card testing, probing stolen numbers with small buys before scaling up, at 17% last year.
The takeaway holds: 2026 fraud isn't necessarily more common, just smarter, cheaper, and custom-fit at scale.
Money Crime Up Close: Wire Cons, Loan Fakes, Bogus Claims
Finance keeps reinventing itself, and the crime tracking it does the same. For the broader sweep of the global fraud index running through this year, the schemes below are where the losses pile up.
Business Email Compromise (BEC) is impersonation that ends in a payout. Someone poses as a trusted contact and steers an employee into wiring money, surrendering credentials, or swapping an invoice's bank details. AI-cleaned spoofing wiped out the typos that once exposed these emails. The data is stark: the 2025 AFP Payments Fraud survey found 79% of organisations hit by payment fraud attempts in 2024, with 63% calling BEC their top channel.
Staged crashes and padded claims are ancient, but AI made the evidence believable. Faked photos, edited video, forged repair bills — all generated well enough to pass a quick glance — stretch investigations and run up costs. The fix is detection that catches a manipulated image the second it arrives, not three weeks into a fight over the claim.
Your Phone Is Where Payment Fraud Lives Now
Buying coffee with a tap or clearing a bill from the sofa is wonderfully easy, and that's the catch. The convenience that serves you serves the scammer too. Mobile payment schemes sit among the busiest fraud categories in banking today.
With stolen credentials or a weak login, a criminal takes over a mobile banking account, then empties the balance, sends transfers, or attaches a fresh payment method to bleed it out. Account takeover came in as the second most common third-party fraud type in the 2025–2026 numbers at 19%, trailing identity theft at 28%.
QR codes sit at every payment point now, and criminals noticed. Cover a real code with a malicious one and you've sent people to a phishing page or a bogus payment prompt. In Tyne & Wear, fraudsters planted counterfeit codes in Metro park-and-ride lots and rerouted commuters' parking payments to themselves. Counterfeit apps pull the same stunt, looking identical to the genuine article while skimming data and funds. In November 2024, a fake app moved across India through WhatsApp, hunting users of the UPI instant-payment system.
Plenty of attacks need no code at all. A scammer plays a support rep or a familiar contact over text or a messaging app and talks the mark into okaying a fake transaction or reading out a one-time code. It's social engineering — pure pressure on trust rather than any technical break-in.
Real-time payment rails are a present to criminals. As more platforms push instant transfers, the gap to spot something off shrinks to seconds, and once funds hit a criminal account, clawing them back is usually a lost cause. With half of UK adults now using mobile payments regularly, the speed and finality of these systems call for monitoring that never stops and adjusts on its own.
Crypto Fraud Keeps Finding Fresh Angles
About one in four people holds crypto now, and the predators watch that curve. Cheap tooling and AI make crypto cons more manipulative every month, and the space attracts a signature lineup: pig butchering, pump-and-dump runs, and wallet drainers.
Pig Butchering Without the Riddles
The label traces to the Chinese phrase sha zhu pan, 'pig butchering.' The brutal idea: fatten the victim with trust over weeks, then take the whole account at once. First contact usually lands on a dating app or in a random message, and the scammer eventually nudges the target toward a fake investment platform. Chainalysis clocked revenue from these scams growing nearly 40% year over year, much of it tied to organised crime.
Drainer Kits That Clean Out Wallets on Autopilot
Crypto drainers are scripts built to siphon a victim's wallet into an attacker's. The hook is convincing someone to link their wallet to a fraudulent site posing as an NFT marketplace or DeFi app. The kits sell in fraud-as-a-service bundles on the dark web, which flattens the skill barrier to almost nothing. Chainalysis put drainers at the heart of the $2.2 billion stolen from victims in 2024.
Pump-and-Dump, Bot-Powered Edition
The play is ancient, the gear is new. Snap up a cheap token, hype it until the crowd buys in, ride the climb, then dump at the top and leave stragglers with junk. AI juices the hype stage with bots, fake accounts, and deepfaked influencers pushing low-cap tokens. Chainalysis found 3.59% of tokens launched in 2024 — over 74,000 — carrying pump-and-dump fingerprints. It reaches past crypto too: in December 2025, four people in Australia received prison terms of up to two years for rigging listed-stock prices before cashing out.
Romance Cons Turn Feelings Into Leverage
Romance fraud stays vicious and stays everywhere, and AI gave it an edge. Dating platforms carry the steepest fraud rate of any sector at 6.3% — over double what finance sees. These cons usually get filed under social engineering, but they bleed into identity fraud, since the personal details a victim shares often reappear later in account takeovers or synthetic profiles.
The arc rarely changes. A convincing profile, sometimes propped up by deepfake photos or video, earns trust. Then the emergency arrives: a hospital bill, a stranded trip, an investment that can't wait. The victim wires money, frequently into a fake crypto project. In October 2024, Hong Kong police arrested 27 people running a deepfake romance ring that used face-swapping and voice-changing, ran live deepfake video calls, and funnelled victims into fake crypto investments worth millions.
The defence is dull but reliable: run names, photos, and bios through a wider web search, and slow everything down the moment money or sensitive data comes up.
Familiar Scams That Refuse to Die
Fresh threats hog attention, but the old reliables keep cashing checks, and writing them off is a mistake:
- Fraud-as-a-service. Dark-web kits let nearly anyone fire off advanced attacks.
- AI impersonation. Fakes convincing enough to fool people and companies both.
- Synthetic data attacks. Invented transaction histories that breeze through verification.
- Formjacking. Buried code on payment forms skimming card data mid-checkout, no warning sign.
- Click fraud. Bots faking clicks to burn ad budgets.
- Fake exchanges and flash loan attacks. Sham platforms that swallow deposits, and DeFi exploits that drain protocols.
- Ransomware and data poisoning. Crypto extortion after encryption hits, plus junk data fed in to blind AI detection.
Threats Worth Tracking Through the Year
AI tore up the rulebook, letting fraud hit systemic gaps at a scale that simply didn't exist before. A few trends earn extra watching:
- The sophistication shift. Advanced fraud jumped 180% in 2025 on social engineering and AI identities.
- AI-assisted forgery. Fake documents built with mainstream AI tools went from 0% to 2% in a single year.
- Regional surges. Fraud fell in Europe and North America but rose 9.3% in Africa, 16.4% in APAC, 19.8% in the Middle East.
- Autonomous fraud agents. First sightings came in 2025 — self-running systems that learn and pivot mid-campaign.
- Telemetry tampering. Criminals now hit the data pipelines feeding identity checks, not just the documents.
Defences That Hold Up Under Pressure
The 2026 landscape is messy and a little scary. Criminals wield serious tools to crack the trust signals everyone leans on. Outrunning them takes deliberate caution from both sides.
If you're an individual, the answer is mostly friction: double-check any ask for payment or personal data, ignore links from strangers, turn on multi-factor authentication where it counts, and keep your devices current. A pause before approving a transaction — or a quick confirmation through another channel — kills off a shocking number of scams.
If you're a business, a single barrier won't survive contact. What holds is a blend of real-time monitoring, risk-adaptive identity verification, device intelligence, and biometric checks, all working in concert to surface trouble before it spreads. Easy to say, brutal to execute: fight AI with AI.
The encouraging news is that detection is sprinting to keep up. Companies should run layered systems catching fraud at several points in the journey instead of staking everything on one gate.
No lone control stops a committed attacker. The setups working in 2026 draw from a deep bench: advanced identity verification, biometrics, transaction monitoring, behavioural pattern analysis, device fingerprinting, background checks, deepfake detection, customer education, and tight cooperation among banks, law enforcement, and tech firms. Stacked, they turn a quick hit into a slog.
Where to Put Your Money
To stay current, organisations should build around a core kit: user verification, biometric checks, business verification, transaction monitoring, email and phone risk scoring, liveness detection, device intelligence, risk scoring, fraud network detection, and behavioural monitoring. No single piece wins on its own. Layered together, they make fraud slow and expensive — which is generally enough to push a criminal toward a softer target.
Verifying that an ID number checks out proves almost nothing anymore. As synthetic identities and AI fakes grow sharper, verification has to confirm a living person is actually there — hunting for liveness: skin texture, true 3D depth, natural motion, the small tells an AI image still can't fake cleanly.