A single video call cost the multinational engineering firm Arup $25.6 million. The finance worker who authorised the transfer thought he was speaking with his Chief Financial Officer and several trusted colleagues—but every single face and voice on that screen was an AI-generated deepfake.
We have officially entered an era of digital deception where seeing is no longer believing.
The friction of fraud has collapsed. What used to take a team of skilled cybercriminals weeks to coordinate can now be executed by a single bad actor in minutes using off-the-shelf generative AI tools. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, a staggering 73% of respondents reported being directly or indirectly exposed to cyber-enabled fraud in the past year. The financial toll is catastrophic, with projected global losses expected to hit $40 billion by 2027.
As identity fraud undergoes what experts call a “Sophistication Shift,” moving from high-volume spam to highly targeted, multi-step attacks, knowing the enemy is your best defence. Here are the top 7 AI scams dominating 2026—and how to spot them.
1. Deepfake Video Impersonation

The Arup case was not an anomaly; it was a blueprint. Scammers use deepfake technology to overlay a trusted executive’s face and voice onto an attacker in real-time. These attacks often bypass traditional corporate security protocols because the victim believes they are receiving direct visual authorisation from leadership.
- The Tell: Look for unnatural eye movements, a lack of blinking, or subtle blurring where the face meets the neck and background.
2. AI Voice Cloning (Vishing)
Scammers no longer need you to read a script to steal your voice. Today’s AI models can generate a near-perfect clone from just three seconds of audio scraped from a TikTok video, a podcast, or a voicemail. This technology is driving a surge in the “grandparent scam,” where victims receive a panicked, late-night call from a cloned voice sounding exactly like a loved one begging for emergency bail or medical funds.
- The Tell: The caller will insist on extreme urgency and demand untraceable payment methods like wire transfers or cryptocurrency.
3. Hyper-Personalised AI Phishing
Forget the poorly worded emails from foreign princes. AI large language models (LLMs) can now ingest your LinkedIn profile, corporate filings, and social media history to craft a flawless, highly personalised spear-phishing email. IBM X-Force research found that AI can generate a highly convincing phishing email in just five minutes—a task that would take a human 16 hours to perfect.
- The Tell: Even if the grammar is perfect and the context is relevant, unexpected requests for credentials or unusual links are major red flags.
4. Synthetic Identity Fraud
This is a $20 billion annual nightmare for the financial sector. Instead of stealing a real person’s identity outright, AI is used to stitch together a “Frankenstein” identity—combining a real Social Security number with a fake name, AI-generated face, and fabricated credit history. Fraudsters use these synthetic identities to open credit lines, max them out, and vanish.
5. AI Romance and ‘Pig Butchering’ Scams
In romance scams, AI doesn’t just create fake profile pictures; it operates emotionally intelligent chatbots that can sustain romantic conversations with dozens of victims simultaneously. Once trust is established, the victim is manipulated into moving off-platform and convinced to invest heavily in fraudulent crypto platforms—a tactic known as “pig butchering”.
6. AI-Powered Business Email Compromise (BEC)
BEC attacks have evolved into multimodal threats. A sophisticated attack might begin with an AI-generated email from a supplier claiming a change in bank details, followed immediately by an AI-cloned voice mail from the “vendor” confirming the change. This layered deception is designed to bypass standard dual-verification security controls.
7. Deepfake Crypto and Investment Fraud
Scammers are aggressively utilizing deepfakes of prominent figures—like tech billionaires or well-known financial analysts—to promote fake cryptocurrency giveaways or trading platforms. According to Chainalysis, AI-enabled crypto scams proved 4.5 times more profitable than traditional fraud in 2025.
How to Protect Yourself and Your Business
Traditional antivirus software and legacy spam filters are no longer enough. The most effective defences against AI-powered fraud rely on human habits:
- Establish a “Safe Word”: This is the ultimate low-tech solution to high-tech fraud. Agree on a specific, private code word with your family members and key business colleagues. If you receive an urgent call for money or sensitive data, ask for the safe word. An AI voice clone cannot provide information it never ingested.
- Out-of-Band Verification: Never trust a single channel of communication. If you receive an urgent email from your boss requesting a wire transfer, do not reply to the email. Call them on a trusted, pre-saved phone number to verify.
- Starve the Urgency: AI scams rely on emotional manipulation and panic. Fraudsters want you to act before you think. If a request involves money or access, make urgency your immediate cue to slow down, hang up, and verify the story independently.
The Bottom Line: AI has forever changed the landscape of digital trust. We can no longer rely on our eyes and ears alone to verify identity. By combining healthy scepticism with strict verification habits, you can stop even the most sophisticated AI scams dead in their tracks. Share this guide with your family and colleagues—awareness is the first line of defence.








