When I think about AI-enabled fraud, I see three main categories:
1️⃣ Synthetic media fraud
→ Using AI to generate fake images, videos, documents, and audio that pass identity verification
Fraudsters can already access massive datasets of stolen PII from breaches and social media. AI takes that real data and produces fake documents that look legitimate.
Photos taken from social media become inputs for video generation. The model turns left, turns right, blinks on command. The output passes liveness detection. Voice recognition gets bypassed the same way.
2️⃣ Social engineering fraud
→ Using AI to make scams more convincing, more personalized, and easier to scale
Phishing used to be obvious with bad grammar and generic messages. Now, GenAI enables hyper-personalization at scale. Messages that match the tone of your actual bank. Fake websites built in hours.
Voice scams are scaling the same way. AI voice generation and real-time cloning let fraudsters impersonate bank representatives autonomously. No call center needed. Spoof the number, sound legitimate, and push payment scams follow.
3️⃣ Automation and scale
→ Using AI to accelerate fraud operations, from writing attack scripts to running end-to-end autonomous fraud campaigns
Coding agents let fraudsters vibe code fraud-as-a-service tools on demand.
A device farm kit costs about $100. Ten phones, app cloners on each, a hundred instances running in parallel. Thousands of fake accounts per day.
When devices get blocked, automated resets generate fresh device IDs. Attack again with what looks like a new device.
And then there’s agentic fraud.
As consumers delegate tasks to AI agents, those agents become a new attack surface. Stolen credentials instructing agents. Compromised payment data placing orders. The agent does what it's designed to do. Just not for the right person.
—
Any verification built on digital signals alone is living on borrowed time.
AI can fake pixels, but it can't fake physics.
Every user interaction still happens from a physical device. That device is always somewhere in the physical world.
A fraudster can clone your voice. Deepfake your face. Steal your credentials. But they can't be in two places at once. They can't fake months of consistent behavioral patterns at scale.
The physical world will be the only ground left to stand on.