I spent way too long trying to find the exact line where AI voice cloning costs Americans $3.5 billion a year. It doesn’t exist. That number and the AI fraud number sit in two completely different government reports, and almost every scam alert article smashes them together like they’re the same statistic. But they aren’t.
But here’s the truth. The FTC says people reported losing $3.5 billion to imposter scams in 2025, the single biggest fraud category that year. Separately, the FBI’s Internet Crime Complaint Center tracked AI-related complaints, which were about $893 million across 22,364 complaints. AI voice cloning sits inside that second number as one tool among several, not as the explanation for the first one.
Key Takeaways
- The FTC’s $3.5 billion imposter scam total and the FBI’s $893 million AI fraud total are two separate datasets covering two different things. They are not the same number.
- AI voice cloning now needs under three seconds of audio to produce a usable clone, per UC Berkeley researcher Hany Farid.
- Investment fraud, not the panicked family-emergency call, carries the biggest AI-linked dollar losses inside the FBI’s data.
- Four out of six popular AI voice cloning apps had no real safeguards against misuse, according to a Consumer Reports investigation.
- A family code word and a callback to a number you already trust still beat every detection app on the market.
What the FTC’s $3.5 Billion Imposter Scam Number Actually Breaks Down To
The FTC’s June 2026 report on 2025 fraud data found that imposter scams were reported more than any other fraud category that year, accounting for nearly one in three fraud reports nationwide.

Two sub-categories carry most of that weight:
- Business impersonators (your bank, a tech company, a delivery service) cost people roughly $1 billion, with bank impersonators alone carrying the highest losses inside that group.
- Government impersonators (IRS, Social Security, “you have a warrant”) cost $920 million, up from $789 million in 2024.
That’s a real jump on the government side in just one year. And it sits inside a bigger trend: total fraud losses across every category hit $16 billion in 2025, a 25% increase YoY.
None of these numbers are directly AI-specific. The imposter scam category has existed for years, and most of these calls don’t involve a cloned voice. AI voice cloning makes a slice of these calls more convincing, but it didn’t create the imposter scam problem; it’s layering onto one that was already the country’s biggest fraud category before voice cloning was a mainstream concern.
Where AI Voice Cloning Sits Inside the FBI’s $893 Million Deepfake Scams Category
This is where the AI-specific numbers actually live. For the first time in its 25-year history, the FBI’s 2025 Internet Crime Report included a dedicated AI section; 22,364 complaints, $893 million in adjusted losses.
Here’s the breakdown by scam type, straight from the report’s own categories:
- Investment fraud: more than $632 million, by far the largest slice.
- Business email compromise: about $30 million, with AI voice cloning increasingly used for follow-up calls that reinforce a fake wire instruction.
- Romance and confidence scams: roughly $19 million.
- Employment scams: nearly $13 million.
- Distress scams, including fake kidnapping and emergency calls that often rely on cloned voices: more than $5 million.
Notice what’s at the top. Investment fraud. Voice cloning gets the headlines because the emotional version of the scam is more shareable, but most of the AI-linked money is somewhere quieter.
Why the FBI calls this a floor, not a ceiling
A cloned voice doesn’t leave any footprints as soon as the call ends. There’s no file to analyze, no screenshot to forward. A victim might suspect that AI was involved and still have no way to prove it when they file a report. That’s likely why the real total is more than $850 million.
How Three Seconds of Audio Becomes a Convincing AI Voice Cloning Threat
The technical bar here is very low. Hany Farid, a UC Berkeley professor and chief science officer at GetReal Security, told CNN that current AI voice cloning tools need only a few seconds of someone’s real voice to build a usable model. An old voicemail greeting, a TikTok clip, a few seconds from a podcast guest spot, any of it works as raw material.
What scammers do with that sample has also changed. The earlier version of this scam used one pre-recorded line played down the phone, something that often sounded a little off if you listened closely. The newer version, sometimes called voice skinning, runs in real time, like the scammer types, and the AI speaks it back in the cloned voice as the call starts. The voice can answer your questions and react to what you say instead of looping one panicked sentence.
Real-World Phone Scams: What a Cloned-Voice Call Actually Sounds Like
Gary Schildhorn’s story keeps getting cited because it shows exactly how fast this moves. He’s an attorney in Philadelphia, and he got a call that sounded exactly like his son saying he’d been in a car accident and needed bail money. He came close to wiring nearly $9,000 before a separate FaceTime call from his actual son interrupted the scam mid-progress.
The thing to notice here is that he didn’t catch the fake voice by himself; he caught it because his real son happened to call at the right moment.
What actually works is procedural, not auditory. Schildhorn’s case, where the victim described being totally taken by it, shares the same pattern. It triggers the sense of urgency, a familiar voice, and pressure to move fast or stay quiet. None of that requires the cloned voice to be technically perfect; it just needs to make you panic.
Which Imposter Scam Types Carry the Highest Voice-Cloning Risk
Putting the FTC and FBI numbers side by side makes the risk pattern clearer than either report does alone.
| Scam Type | How It Typically Works | 2025 Reported Losses | AI / Voice Cloning Flagged? |
| Bank impersonation | Caller poses as a fraud department, asks you to “protect” your money by moving it | ~$1B (FTC, business impersonators) | Increasingly used in BEC follow-up calls per FBI data |
| Government impersonation | Caller claims to be IRS, SSA, or police, threatens arrest or a warrant | $920M (FTC); complaints rose to roughly 32,500 in 2025, up from about 17,000 in 2024 | Referenced in a growing share of complaints |
| Distress/family emergency | Cloned voice of a relative claiming injury, arrest, or kidnapping | $5M+ AI-linked (FBI IC3) | Yes, explicitly flagged |
| Romance scams | Long-term fake relationship, sometimes paired with a cloned voice note for “proof” | $19M AI-linked (FBI IC3) | Yes, explicitly flagged |
| Investment fraud | Fake trading platform or advisor, sometimes using a cloned voice of a “mentor” or celebrity | $632M AI-linked (FBI IC3) | Yes, the largest AI-linked category by far |
If you notice the pattern, the scam type isn’t new; AI just makes the impersonation layer more convincing.
How to Verify a Caller’s Identity Before Sending Money
This is the part you can act on today,
- Set a family code word now, before you need it. The FTC and FBI both recommend this specifically. Pick something boring and unpostable.
- Hang up and call back on a number you already have saved, not one the caller gives you or texts you. This breaks the scam’s biggest advantage.
- Don’t treat caller ID as proof. Spoofing a phone number is trivial, so a call showing your bank’s real number isn’t the same thing as a call from your bank.
- Never move money, crypto, or gift cards because one call told you it was urgent. Real banks and agencies don’t ask for that, and they especially don’t ask you to keep it secret from family.

None of these steps require you to spot a fake voice by ear. AI voice cloning has gotten good enough that detection-by-ear isn’t reliable anymore, so the defense has to live outside the call itself.
How Banks and Telecoms Are Building Fraud Detection Into the Call Itself
Some of this responsibility is shifting toward institutions, slowly. Starling Bank in the UK and the Commonwealth Bank of Australia have both issued direct customer warnings about AI voice cloning. They tell their account holders not to trust a familiar voice alone when money is on the line.
On the network side, US carriers have been rolling out STIR/SHAKEN caller authentication, a protocol that verifies whether a call’s displayed number actually belongs to the person dialing. It catches some spoofed numbers before they reach your phone, though it does nothing about the voice itself once you’ve answered.
None of this is a complete fix yet. Bank warnings tell you the risk exists, but they can’t interrupt you while having a conversation. Caller authentication filters some spoofing, but a scammer using a legitimate burner SIM still gets through.
Why Deepfake Detector Apps Can’t Be the Main Line of AI Security
A market has shown up to sell you a fix, but you must be skeptical about it. Consumer Reports tested six popular AI voice cloning tools in 2025, the same kind of apps a scammer might actually use, and found that four of them (ElevenLabs, Speechify, PlayHT, and Lovo) had no real safeguards against cloning a voice without permission. Users just checked a box claiming they had the legal right to do it. Only two, Descript and Resemble AI, had something close to meaningful friction.
That’s just the supply side. Detection is the opposite problem. A tool trained to catch one generation of scam often misses another, and a scammer can do a lot of things to throw off a detector that worked fine in a clean lab test.
We Ran the Numbers on How Much of Total Fraud Is Actually AI-Driven
Here’s a calculation nobody publishes directly, because it means analyzing two separate government datasets and doing the division yourself. The FBI’s $893 million AI fraud figure works out to about 5.6% of the FTC’s $16 billion total fraud number for 2025. Inside the narrower imposter scam category specifically, treating the AI figure as a rough proxy, AI-referenced losses would represent somewhere around a quarter of the FTC’s $3.5 billion imposter scam total. That comparison is approximate, since the two agencies count complaints differently.
Who Isn’t a High-Risk Target Yet, and Why That’s Narrowing
If you don’t post videos of yourself, don’t do podcasts, and don’t have voicemail greetings or any call recordings floating around online, you’re a harder target for AI voice cloning specifically, at least today. Scammers still need a clean audio sample. A name and phone number alone isn’t enough for this version of the scam.

That window is closing fast, though. A short clip from a work Zoom call that someone records and uploads counts. A wedding video posted publicly counts. A voicemail greeting on a recycled number counts. Every video call, podcast guest spot, or public post you’ve ever made is a potential audio sample now.
But the point of concern for most of the people reading this is that they already have enough public audio out there that can be used as a sample.
What to Do in the First Hour After a Suspected Clone Call
If you’ve already hung up and you’re not sure what just happened, this is the order that matters.
- Call the person directly who claims to be on the phone, using a number you already had saved, not one from the suspicious call.
- If money has already moved, contact your bank immediately. Speed matters more than anything else here, since wires and crypto transfers are hard or impossible to reverse once they clear.
- Report it at ReportFraud.ftc.gov and IC3.gov. Even a near-miss report helps investigators connect patterns across victims.
- Freeze or flag any account that was discussed or accessed during the call, even if nothing seems to be missing yet.
Skip feeling embarrassed about almost falling for it. Schildhorn’s near-miss made international news specifically because he’s a practicing attorney, not someone anyone would call naive. This scam is built to work on careful people too.
Final Thoughts
Pull back from the specific numbers and the pattern is simple. The technology for faking a voice has gotten ahead of most people’s instinct for trusting one. Detection software is playing catch-up against generation tools that improve every few months, and right now detection is losing that race.
But all this has a simple fix, and it’s not technical. It’s just a two-minute conversation with your family about a code word, and a habit of calling back from a saved number. The FBI’s own data already shows investment fraud, not the dramatic kidnapping call, as where the real AI money is. Worth remembering next time a headline leads with the scarier story instead of the bigger one.
FAQs
Under three seconds of clear audio, according to UC Berkeley researcher Hany Farid. Voicemail greetings, social clips, and podcast snippets are all enough raw material.
No. The FTC’s $3.5 billion covers all imposter scams in 2025. The FBI’s separate $893 million figure covers AI-related fraud specifically, including but not limited to AI voice cloning.
Not reliably yet. Starling Bank and Commonwealth Bank of Australia warn customers, and STIR/SHAKEN filters some spoofed numbers, but neither stops a convincing live clone mid-call.
Hang up immediately, call the person back on a number you already saved, and report the call to ReportFraud.ftc.gov or IC3.gov if money was requested.
No. FBI data shows investment fraud, which targets all age groups, carries the largest AI-linked losses. Distress and family-emergency clones often target whoever answers fastest.

