INTERPOL and the United Nations Office on Drugs and Crime said on March 17, 2026, that generative AI tools, including deepfake video, images and audio, were making it easier for criminals to impersonate trusted people. A familiar face or voice can support a story, but it cannot authenticate a request for money, credentials or sensitive data.
The US National Institute of Standards and Technology (NIST) defines synthetic content as images, video, audio or text that algorithms, including AI, have substantially altered or generated. Deepfakes use that capability to make an identity appear to say or do something that did not happen. The fraud risk comes from what the media is used to establish: a recognizable identity, a plausible story and a demand designed to prevent independent checks.
Complaints filed with the US Federal Bureau of Investigation's (FBI) Internet Crime Complaint Center (IC3) in 2025 referenced AI in 22,364 cases and reported US$893,346,472 in adjusted losses. The report also recorded more than US$5 million in distress-scam losses, a category in which it said voice cloning can imitate loved ones, and more than US$632 million in investment complaints with a reported AI nexus. IC3 defines AI-related only as a complaint containing a reference to AI, so the figures do not measure deepfake losses alone or provide a global estimate.
The media supplies credibility; social engineering moves the money
A December 3, 2024, US FBI alert described voice clones impersonating relatives in a crisis, synthetic audio used to seek access to bank accounts, and video calls presenting supposed executives or public officials. The underlying requests remain familiar: send money now, disclose account information or accept an investment pitch before checking it elsewhere.
Voice and face generation can be only one part of the approach. Details collected from social profiles, breached accounts or previous conversations can make the story fit the target, while caller-ID spoofing and copied websites add separate signs of legitimacy.
On July 20, 2026, IC3 described scammers who used AI-generated videos of a senior US FBI official to direct previous fraud victims toward a spoofed IC3 website. The video did not carry out the fraud by itself: the recovery claim targeted people who had already lost money, and the copied site collected contact and financial information.
Visible glitches are clues, not an identity check
Lagging speech, mismatched lip movement, unnatural facial details and unusual word choice can justify closer scrutiny. The US FBI lists those irregularities as warning signs, but its July 2026 notice also says cloned voices can sound nearly identical to a known contact. A clip with no obvious defect is therefore not verified; it is only a clip with no defect the recipient noticed.
NIST's 2024 review says provenance records, watermarks, labels and content-based detection can provide evidence, but none offers a comprehensive solution by itself. The report says transparency may contribute to trustworthiness without guaranteeing it, and notes that watermarks can be removed, altered or placed on untrustworthy content. Authentic media can also mislead when removed from its original context.
European Union labels add information, not proof
The European Commission said the European Union's AI Act transparency requirements, which began to apply on August 2, 2026, require clear labels for deepfakes and for AI-generated or AI-manipulated text published on matters of public interest in covered cases. The Commission also published a voluntary code to help AI providers and deployers implement those legal duties.
The rule applies within the European Union framework rather than worldwide, and national obligations elsewhere vary. A visible disclosure can help a viewer identify synthetic media, but an absent label cannot make an unsolicited payment request authentic. A criminal impersonator has no reason to follow a disclosure rule.
Verification should leave the caller's channel
The US Federal Trade Commission says a short audio clip, including material posted online, can supply a voice-cloning program and that emergency scammers often combine the imitation with urgency and demands for secrecy. Its guidance tells recipients to end the exchange, call a number already known to belong to the person and consult another trusted contact if the person cannot be reached.
The US FBI recommends a private family word or phrase, while the US FTC suggests asking a personal question whose answer is not publicly available. Both measures add a check inside the conversation; a callback through a previously confirmed route moves the check outside the channel controlled by the caller.
Organizations can apply the same separation to payment and account requests. An employee can locate the requester in an existing corporate directory and follow the established approval process; a number, link or video room supplied in the suspicious message is not an independent route.
The available evidence does not yield a global loss figure
APPI News could not find published official data that separates worldwide losses from voice- and face-cloning scams from broader impersonation fraud. The IC3 figures are complaint data collected by a US agency, and its AI-related label records a reference in the complaint rather than a verified technical finding. INTERPOL's March 2026 statement establishes that international law-enforcement bodies are seeing the method, but it does not give a deepfake case count.
The evidence supports a narrower operational rule. Voice and video can trigger a verification process, but a payment, credential disclosure or account change should wait until the identity and the request have been confirmed through a separate channel.
Sources and further reading
- INTERPOL-UNODC global summit ends with call to action against fraud surge(INTERPOL)March 2026 statement on generative AI and deepfake media making trusted-person impersonation easier.
- 2025 IC3 Annual Report(US Federal Bureau of Investigation)Complaint counts, adjusted losses and the scope of the AI-related descriptor.
- Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud(US Federal Bureau of Investigation Internet Crime Complaint Center)Documented uses of synthetic text, images, audio and video in impersonation and financial fraud.
- FBI Warns of Scammers Impersonating the IC3(US Federal Bureau of Investigation Internet Crime Complaint Center)July 2026 account of AI-generated videos directing previous fraud victims to a spoofed government website.
- Scammers Use Fake Emergencies To Steal Your Money(US Federal Trade Commission)Voice-cloning inputs, urgency and secrecy tactics, and independent callback guidance.
- Reducing Risks Posed by Synthetic Content(US National Institute of Standards and Technology)Definitions and limits of provenance, watermarking, labeling and synthetic-content detection.
- Commission publishes Code of Practice on marking and labelling AI-generated content(European Commission)Application date and scope summary for the European Union AI Act's synthetic-content transparency rules.