The call comes late. The voice is your son's, or your mother's, and it is frightened. There has been an accident, or an arrest, and money is needed now. Family emergency scams are old. What is new is the voice. As the Federal Trade Commission put it in 2023, "All he needs is a short audio clip of your family member's voice," the kind many people have already posted online.

What the FBI is seeing

In December 2024 the FBI warned that criminals use generative AI to "generate short audio clips containing a loved one's voice to impersonate a close relative in a crisis situation," asking for immediate help or a ransom. The same alert warned that criminals "obtain access to bank accounts using AI-generated audio clips of individuals and impersonating them."

The targets have moved up the ladder. Since April 2025, the FBI says, criminals have sent text messages and AI-generated voice messages claiming to come from senior U.S. officials. In December 2025 it reported the campaign was still running and warned that "AI-generated content has advanced to the point that it is often difficult to identify." In July 2026 it warned of scammers impersonating the IC3 itself, using spoofed caller ID and AI-generated video, including "real time video chats with alleged company executives, law enforcement, or other authority figures."

The money

In 2025, people reported losing $3.5 billion to imposter scams to the FTC: nearly $1 billion to business impersonators and about $920 million to government impersonators, up from $866 million and $789 million in 2024. Total reported fraud losses reached about $16 billion, the highest on record. The FTC does not say how much of this involved AI. These are reported losses, and most fraud is never reported.

Businesses are targets too. A 2023 information sheet from the NSA, FBI, and CISA told organizations to train staff on deepfakes used to target executives and in business email compromise fraud, and cited a 2019 case in which deepfake audio was used to steal $243,000 from a UK company. Their conclusion: "Identity verification for real-time communications will now require testing for liveness."

The defense that still works

A cloned voice can copy how someone sounds. It cannot know something only your family knows, and it cannot answer a call you place yourself. Every official warning comes back to those two ideas.

Don't trust the voice. Call the person who supposedly contacted you and verify the story.

Federal Trade Commission
  • Set a family code word today. The FBI's first tip is to "create a secret word or phrase with your family to verify their identity." Pick something that is not online anywhere.
  • Hang up and call back. Use a number you already know is theirs, or one you look up yourself, never the number that called you.
  • Treat the payment method as the tell. The FTC says requests to "wire money, send cryptocurrency, or buy gift cards" could be signs of a scam.
  • Slow down. Urgency is the scammer's tool. A real emergency survives a two minute call back.
  • At work, verify every payment change. The FBI advises businesses to "verify payment and purchase requests in person if possible or by calling the person to make sure it is legitimate."

What the law now says

Robocalls. In February 2024 the Federal Communications Commission ruled unanimously that "calls made with AI-generated voices are 'artificial' under the Telephone Consumer Protection Act," which brings them under that law's consent rules and gives state attorneys general another tool against scam calls.

Impersonating agencies and businesses. The FTC's Impersonation Rule took effect on April 1, 2024, letting the agency go to federal court to get money back for victims and seek civil penalties. An extension to cover impersonating individuals was proposed in February 2024 and has not been finalized. On September 24, 2026, the FTC asked for public comment on whether to update the rule to address how platforms' ad tools help impersonation scams.

Intimate deepfakes. The TAKE IT DOWN Act, signed May 19, 2025, made it a federal crime to knowingly publish intimate images of an identifiable person without consent, including AI-made forgeries. Covered platforms must remove a reported image within 48 hours of a valid request, and had until May 19, 2026 to set up the process. The FTC enforces it.