Technology

AI Scams: The Tells That Still Give Them Away

The FBI named AI a crime category for the first time after $893 million in losses. The old advice about spotting scams no longer works. Here is what does.

Quick Trend Insights

Quick Trend Insights

September 20, 20267 min read
Share
AI Scams: The Tells That Still Give Them Away
Table of contents

For twenty years the advice was the same. Watch for bad spelling. Look for the awkward phrasing. Check whether the greeting uses your actual name.

Advertisement

That advice is now worthless, and following it makes you more vulnerable rather than less, because you are checking for a flaw that no longer exists.

Research indicates 82.6% of phishing emails now contain AI-generated content. The grammar is clean. The tone matches the company. Your name is spelled correctly, along with the name of your actual bank branch.

The FBI took the step of introducing AI as a formal crime descriptor for the first time in its most recent annual report, logging 22,364 AI-related complaints and $893.3 million in attributed losses. Here is what actually identifies these now.

Key Takeaways

  • An estimated 82.6% of phishing emails contain AI-generated content, so spelling and grammar checks no longer filter anything.
  • The FBI logged 22,364 AI-related complaints and $893.3 million in losses, naming AI as a crime category for the first time.
  • AI-powered scams grew 1,210% in a year, against 195% for traditional fraud, roughly six times faster.
  • Adults aged 60 and over lost $4.885 billion, with an average loss of about $83,000 per affected person.
  • The reliable defenses are now structural: verify through a channel you chose, and treat urgency itself as the warning sign.

Why the Old Advice Stopped Working

Bad grammar was never a feature of scams. It was a side effect of scammers often not writing in their first language, and of sending millions of messages with no time to craft each one.

Language models removed both constraints at once. Fluent text is now free and instant, in any language, at any volume.

The figures show how thoroughly this landed. Around 82.6% of phishing emails contain AI-generated content, and roughly 40% of business email compromise messages are primarily AI-generated. Business email compromise, where an attacker impersonates a colleague or supplier to redirect a payment, drove $2.77 billion in losses across 21,442 incidents in a single year.

There is a second-order problem. People who were taught to look for typos now read a clean message and treat that cleanliness as evidence of legitimacy. The old heuristic did not just stop helping. It inverted.

What the Scale Actually Looks Like

The growth rate is the number that should change your behaviour.

AI-powered scams grew 1,210% in a year, while traditional fraud grew 195%. That is roughly six times faster, and it is why the FBI introduced AI as a formal descriptor in its reporting rather than folding these into existing categories.

The totals underneath:

  • $893.3 million in losses attributed specifically to AI-enabled crime across 22,364 complaints
  • $2.77 billion lost to business email compromise across 21,442 incidents
  • Roughly $470 million in consumer losses to text-message scams, per the FTC's Consumer Sentinel Network
  • Global phishing losses of around $25 billion annually, which works out to about $17,700 every minute

Deloitte's Center for Financial Services projects generative AI could push US fraud losses from $12.3 billion to $40 billion by 2027.

The demographic concentration is stark. Adults aged 60 and over filed 147,127 complaints, a 46% increase year over year, and lost $4.885 billion. The average loss per affected person in that group was about $83,000, which for most people is not a bad month. It is a retirement.

The Three Attacks Worth Knowing

Voice cloning

A few seconds of audio, which most people have posted publicly somewhere, is enough to clone a voice convincingly. The call comes from a family member in distress, asking for money urgently, and it sounds exactly like them.

The only defense that works is a shared verification phrase agreed in advance with people close to you, used for any request involving money. Set it up before you need it.

Business email compromise

An attacker impersonates a supplier, executive, or colleague and asks for a payment to be redirected to new bank details. AI writes it in the correct house style, referencing real projects scraped from public sources.

The structural fix is a rule rather than a judgment call: any change to payment details gets verified by phone, using a number you already had, never a number in the message.

Text message scams

The delivery notice, the toll charge, the bank alert. These cost consumers roughly $470 million in a year, and they work because they arrive at the exact moment when the message is plausible, such as when you are actually expecting a parcel.

These overlap heavily with mobile-specific attacks, and our guide on staying safe from targeted phone exploits covers the device side.

What Actually Works Now

Since you can no longer evaluate a message by how it reads, the defenses have to be structural.

Verify through a channel you chose. This is the single highest value habit. If a message asks for money, credentials, or a change to payment details, contact the organisation using a number or app you already had. Never use contact details supplied in the message. This defeats every attack above regardless of how convincing the content is.

Treat urgency as the signal. The content can now be flawless, but the structure cannot change: the attacker needs you to act before you verify. Any message combining a deadline with a payment or credential request deserves more suspicion, not less, the more polished it looks.

Use app-based two-factor authentication rather than text codes. Codes sent by SMS can be intercepted or phished in real time. An authenticator app or a hardware key removes that path.

Agree a family verification phrase. Specifically to defeat voice cloning. It costs one conversation and it is the only thing that reliably works against a cloned voice.

Slow down on anything involving money. Almost every large loss shares one feature: the victim acted quickly. A fifteen minute delay to verify costs nothing when the request is genuine.

The same capability driving these scams is the one making agents useful, which is why autonomous agents now cause security incidents at most organizations. The tooling does not distinguish between uses.

You can report incidents and check current fraud patterns through the FBI's Internet Crime Complaint Center.

Frequently Asked Questions

How can you tell if an email is an AI scam?

Not by how it is written. An estimated 82.6% of phishing emails now contain AI-generated content, so grammar, spelling, and tone are clean. The reliable test is structural: does the message create urgency around money, credentials, or changed payment details? If so, verify through a phone number or app you already had, never one supplied in the message.

How much money do AI scams cost victims?

The FBI attributed $893.3 million in losses to AI-enabled crime across 22,364 complaints in its most recent annual report. Separately, business email compromise drove $2.77 billion across 21,442 incidents, and text message scams cost consumers roughly $470 million according to FTC data.

What is voice cloning fraud and how do I stop it?

A scammer uses a short sample of someone's voice, often taken from public video, to generate a convincing fake call, usually claiming an emergency and asking for money. The only dependable defense is agreeing a verification phrase with family in advance and requiring it for any request involving money.

Why are older adults targeted more by AI scams?

They are targeted because losses per victim are higher. Adults aged 60 and over filed 147,127 complaints, up 46% year over year, and lost $4.885 billion in total. The average loss per affected person in that group was around $83,000, far above other age brackets.

Are AI scams growing faster than regular fraud?

Substantially. AI-powered scams grew 1,210% in a year against 195% for traditional fraud, roughly six times the rate. Deloitte projects generative AI could push US fraud losses from $12.3 billion to $40 billion by 2027.

The Bottom Line

The uncomfortable shift is that you can no longer trust your own judgment about whether a message looks legitimate. The thing you were trained to detect has been engineered out.

That sounds worse than it is, because the replacement defense is simpler than the old one. Stop evaluating messages and start verifying through channels you chose yourself.

A cloned voice, a perfect email, and a flawless text all fail against the same response: hang up, and call back on a number you already had.

Advertisement
Share
Quick Trend Insights editorial team

Written by

Quick Trend Insights Editorial Team

Our editors track the latest in technology, business, finance, and culture, turning fast-moving news into clear, reliable insight you can act on.

More articles

Related Articles

View all
Advertisement