FBI carves out AI-enabled fraud as voice cloning scams hit older victims

FBI carves out AI-enabled fraud as voice cloning scams hit older victims

N
News Editor
2026-07-16 02:53:46
The FBI has, for the first time in its 2025 Internet Crime Complaint Center report, listed AI-related fraud as a standalone category, reflecting how quickly synthetic voice scams have moved into the mainstream. The report logged more than 22,000 complaints and adjusted losses above $893 million, with $352 million tied to victims aged 60 and older. The broader backdrop is worsening: total U.S. cybercrime losses rose 26% over the year, while losses for people over 60 reached $7.7 billion, up nearly 60%. The article centers on a Florida case in which a retired woman was tricked after hearing what sounded like her daughter crying after a car crash. According to the report, only three seconds of audio can now be enough to clone a voice convincingly. It also points to weak safeguards across commercial voice-generation tools. Consumer Reports previously found that four of six tested services allowed users to create clones after little more than checking a box claiming they had permission. The piece argues that the burden should not fall on elderly victims to detect increasingly realistic synthetic audio. Instead, it points to institutional accountability, especially for banks and technology providers. The U.K.’s reimbursement regime for authorized push payment fraud is cited as one example where liability rules changed incentives and lifted compensation rates.
AI fraudvoice cloningFBIpolicy and regulationelder frauddeepfakesbank liability

AI voice cloning has pushed phone fraud into a new phase. According to the report, a convincing synthetic voice can now be built from as little as three seconds of audio, and the FBI has begun treating AI-related fraud as its own category in official crime reporting.

The article opens with a case from Dover, Florida. In the summer of 2025, retired resident Sharon Brightwell received a call and heard her daughter, April, crying and saying she had been in a car crash and was being held by police. A person claiming to be a lawyer then got on the line, asked for $15,000 in bail money, and told her not to tell the bank what the payment was for.

She paid. Only after reaching her daughter, who was at work and had not been in any crash, did she realize the crying, tone, and breathing pattern on the call had all been generated by a machine. The report says that was possible with just three seconds of recorded audio.

FBI separates AI-related fraud in IC3 report

In April, the FBI’s Internet Crime Complaint Center, or IC3, released its 2025 annual report. For the first time in the report’s 26-year history, AI-related fraud was listed as a standalone category. The figures cited in the article show more than 22,000 complaints and adjusted losses of over $893 million.

Of that total, $352 million involved victims aged 60 and older. The same report said overall cybercrime losses in the U.S. rose 26% in one year, while losses among people over 60 reached $7.7 billion, up nearly 60% year over year.

The FBI, as quoted in the article, acknowledged that these numbers are only a floor because many victims do not realize the person they heard was an algorithmic imitation rather than a real family member or trusted contact.

Global and U.S. data point in the same direction

The story also cited Interpol data showing that global financial fraud losses in 2025 reached $442 billion, roughly equal to Denmark’s annual GDP. Fraud aided by AI, it said, generated 4.5 times as much as traditional methods.

The U.S. Federal Trade Commission, in a report released last December, said fraud losses reported by people aged 60 and over nearly quadrupled between 2020 and 2024 to about $2.4 billion. It added that 68% of those losses came from individual incidents above $100,000. Including cases that were never reported, the FTC estimated actual annual losses could be as high as $81.5 billion.

Low barriers, thin safeguards

The article argues that the technical barrier to abuse is now close to zero. A voicemail greeting, a birthday video, or a TikTok clip can be enough to feed a voice-cloning model.

It cited a Consumer Reports review from last year covering six tools: Descript, ElevenLabs, Lovo, PlayHT, Resemble AI, and Speechify. Most, it said, lacked meaningful anti-abuse protections. Four of the six allowed users to generate a cloned voice after simply checking a box stating they had the right to clone it, with no verification step.

ElevenLabs was described as relatively stricter, with a classifier, traceable records, and controls to block specific people’s voices. Even so, the article said those layers mostly help after the fact. By the time they come into play, the voice may already have been copied and the scam call may already have been made.

Even specialists say detection is getting harder

The article also pointed to comments from Hany Farid, a University of California, Berkeley professor known for deepfake forensics. In a June interview with The New York Times, he said he could no longer pass his own tests and added, “I think I’m going blind.”

Its argument is that older adults are being targeted not because they are less capable, but because they are efficient targets: they may hold larger savings balances, are more likely to treat phone calls as extensions of real-world trust, and often have little familiarity with voice-cloning systems. The scam exploits emotional urgency tied to family relationships.

Amit Gupta of voice security company Pindrop put it this way in the article: “The goal is not perfect voice replication, but to create enough emotional uncertainty and urgency that the victim acts before verifying.”

Philadelphia attorney Gary Schildhorn, who was also deceived, said afterward, “I will swear until I die that it was your voice.” Liz Benz of Buffalo described hearing that her grandson had been kidnapped as “20 minutes of terror.”

The piece shifts the burden toward institutions

One common recommendation is for families to agree on a safe word and end the call if it cannot be confirmed. The article argues that this leaves the job of blocking an industrialized fraud pipeline to an older person who may already be in panic.

Adaptive Security CEO Bu was quoted saying, “One person in a room typing on a keyboard can create an infinite number of attackers.” In that setup, automated systems can produce scam calls at almost no cost, while the defender gets one frightened victim and one brief phone call to work with.

Bank liability is presented as a tested lever

The article says the one intervention with demonstrated results is at the banking layer. Since October 2024, the U.K. Payment Systems Regulator, or PSR, has required banks to fully reimburse victims of authorized push payment fraud, with sending and receiving banks each covering half, subject to an £85,000 cap.

After the rule took effect, the compensation rate for stolen funds rose from 65% to 89%, according to the article. Its reasoning is straightforward: once banks bear the cost of fraud, they have a reason to flag large withdrawals, add cooling-off periods for older customers, and place extra confirmation calls.

Regulation is beginning to catch up

The report said obligations under the European Union’s AI Act have been taking effect in stages from 2025 to 2026. It also cited Tennessee’s ELVIS Act in the U.S., which requires written consent for voice replication.

The article’s bottom line is not that regulation has caught up with the technology. It has not. Its point is narrower: the most durable response so far has been to make institutions responsible for the systems and transactions they handle.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.