Highlights
3 years in a row named a Leader First to achieve iBeta Level 3 on iOS and Android Introducing GovFaceMatch Privacy is the architecture
01/04
01/04

An Agentic Fraud Report by Incode

Every leap in AI has made fraud more convincing, and the latest, agentic AI, makes it limitless. Each new AI model lowers the cost of an attack, and the curve keeps climbing.

Nov 2022 ChatGPT Jan 2023 ElevenLabs Mar 2023 Midjourney Aug 2024 Face-swap Sep 2025 OpenAI Sora 2 Early 2026 AI Agents

A message can be machine-written

For the public

Fluent writing for everyone

Human-quality text on demand, free, for anyone.

For the fraudster

Native fluent scam text

Phishing scripts now read like a native speaker.

A voice can be cloned

For the public

Any voice, cloned in seconds

Studio-grade cloning from seconds of audio.

For the fraudster

Cloned-voice phone scams

Scam calls that arrive in a familiar voice.

A photo can be invented

For the public

Photoreal images from text

The viral fake Pope photo fools millions.

For the fraudster

Fake faces, fake proof

Invented faces and "evidence" for scam accounts.

A live call can be a mask

For the public

Wear any face, live

Free one-click tools swap faces in real time.

For the fraudster

Live video-call impersonation

A masked CFO on a live call: the $25M Arup heist.

A whole video can be synthetic

For the public

Generated video on tap

Hyperreal AI video becomes a consumer toy.

For the fraudster

Deepfake ads, fake clips

Fake endorsements and "news" at scroll speed.

You can't trust there's a human at all

For the public

Agents that act on their own

An AI agent you run from your phone goes viral.

For the fraudster

Fraud that runs itself

Agents run scams end-to-end, no human involved.

66 incidents, every one independently sourced Source: this report's case files
44 confirmed AI cases, method documented Source: this report's case files
$579.4B global fraud losses, 2025 Source: Nasdaq Verafin

The incidents

Every year we uncover more AI-fraud incidents, and more agentic-fraud traces

Each bar is a widely reported US case where AI or synthetic media was confirmed or credibly reported. These are only the cases that surface (most AI-enabled fraud is never reported), and our research indicates that across 2025-2026 a fast-growing share of them were automated or agentic, run with little human effort. Markers show when the major AI models shipped.

Hover a month to see its cases

Confirmed AI Reported / suspected

The multiplier

Fraud that scales by orders of magnitude

Agentic AI goes beyond making fraud more convincing. It removes the human-labor ceiling that historically limited how many attacks could run at once. Four shifts make the difference.

01

Automated

Attacks run at machine speed. What once required hours of manual work now happens in minutes or seconds, letting a single operator manage thousands of concurrent attempts.

02

Open to anyone

Far less experience or expertise is required to carry out a successful attack. Ready-made tools and agents lower the bar from skilled operator to almost anyone with a target list.

03

Industrialized

Agentic fraud includes tools as well as attacks, deepening the fraud-as-a-service economy. The infrastructure is becoming more sophisticated, modular, and rentable.

04

Personalized

Each attack can be tailored to the individual victim with a level of detail that previously would have been worth the effort only for a very lucrative target. That research once took weeks; now it takes minutes.

Together, these four shifts make attacks harder to identify and more persuasive.

The rise

The fraud categories rising fastest, several already fueled by agentic AI

Reported losses, each category indexed to its own 2019 level. The broad climb is unmistakable: employment, government impersonation, imposter and phishing are all surging alongside the headline giants. Romance scams are believed to be an example of a heavily underreported scam, explaining the low volume. Every category is on the chart.

Tap a chip to bring one category into color

2019202020212022202320242025 Indexed: 2019 = 100, each line vs its own 2019

Source: FBI IC3 Annual Reports 2019-2025 + FTC imposter total. Real annual values.

Most exposed

How much of each fraud type an AI agent can run by itself

The longer the bar, the more of that scam an autonomous agent can handle end-to-end, which is what makes it cheap to run at massive scale. The dollar figure is how big the category already is.

Confidence/romance 5/5 $929M
Investment (incl. crypto) 4/5 $8.6B
Imposter scams (total) 4/5 $3.5B
Business email compromise 4/5 $3B
Employment 4/5 $363M
Extortion 3/5 $122M
Tech/customer support 2/5 $2.1B
Government impersonation 2/5 $798M
Non-payment/non-delivery 2/5 $503M
Phishing/spoofing 2/5 $216M
Identity theft 2/5 $186M

Automatability is a transparent 1-5 rubric (personalization + repeated conversation + target research + automation readiness).

The anatomy

Every scam is a sequence, and agentic AI is taking every step

A scam is a chain of actions, and each link used to need a person. Agentic fraud hands the whole chain to autonomous AI, so it gets cheaper and scales without limit.

Pick a scam type to see its chain, step by step

The scenario

What happens when the labor cost goes to zero?

Fraud has always been throttled by the cost of human effort. Agents remove that throttle. This is a projection built on the data.

Every category has a share of its work that agents can already run on their own (shown on each row). Pick how many times attackers multiply that automatable work, and see where reported US losses could land.

Reported US losses, 2025
Projected at 10×, illustrative
Agent multiplier

Reported 2025 Projected at 10×

Confidence/romance 100% automatable
Investment (incl. crypto) 80% automatable
Imposter scams (total) 80% automatable
Business email compromise 80% automatable
Employment 80% automatable
Extortion 60% automatable
Tech/customer support 40% automatable
Government impersonation 40% automatable
Non-payment/non-delivery 40% automatable
Phishing/spoofing 40% automatable
Identity theft 40% automatable

Only the automatable share of each category multiplies: projected = reported × (1 + (multiplier−1) × automatability ÷ 5). An illustrative projection built on 2025 FTC/IC3 reported losses, not a forecast.

The case files

66 incidents, every one independently sourced

These are specific, real-world AI-fraud cases: independently sourced, cross-checked against primary reporting, and included only where we have strong confidence the scheme is agentic or at least partially automated. Each is graded Confirmed AI (method documented in filings, disclosures or technical analysis) or Reported / suspected AI (credible reporting points to AI, full confirmation not yet public).

Corroboration

Independent sources see the same pattern

Independent signals from official agencies and respected research, pointing the same way. Reported figures are a floor. The true totals are larger.

Top-down scale $579.4B Global fraud-scam + bank-fraud losses, 2025 Nasdaq Verafin Top-down scale 19.3%/yr Scam losses growth rate (2-yr CAGR) Nasdaq Verafin AI acceleration 90% Fraud pros seeing more AI-driven attacks (2yr) Nasdaq Verafin Underreporting $1.03 trillion Global scam losses, 12 months GASA + Feedzai Underreporting $64B US total scam losses, 2025 GASA + Iris (Generali) Underreporting ~7% (93% unreported) Share of scam $ that reaches official stats GASA Forecast $40B (from $12.3B in 2023, 32% CAGR) Projected US GenAI-enabled fraud losses by 2027 Deloitte Center for Financial Services Official US $20.9B total; $893M AI-tagged IC3 total losses / AI-tagged, 2025 FBI IC3 Official US ~$16B (record, +25%) FTC total fraud losses, 2025 US FTC Official US $47B US identity fraud + scams, 2024 Javelin Strategy & Research Channel $470M US text-scam losses, 2024 (5x vs 2020) US FTC Channel ~3.76M (Q4 989,123) Phishing attacks observed, 2024 APWG Crypto $9.9B+ (likely >$12B) On-chain crypto scam revenue, 2024 Chainalysis Crypto/AI +1,900% Crypto paid to AI scam-service vendors (2021-24 CAGR) Chainalysis Industrialization 300,000+ (66+ countries) People working in SE Asia scam compounds UN OHCHR Industrialization $10B US victim losses to SE-Asia-based scam ops, 2024 UNODC Industrialization +600% Rise in deepfake mentions targeting SE Asia crime groups, H1 2024 UNODC Enterprise ~$50,000 BEC median transaction amount (2023-24) Verizon DBIR Enterprise Doubled Synthetic (AI) text in malicious emails (2-yr change) Verizon DBIR 2025 AI efficacy 4.5x (54% vs 12% click-through) AI-generated phishing effectiveness vs human Microsoft Systemic risk Rank #1 AI-amplified misinformation/disinformation = #1 short-term global risk World Economic Forum Elder harm $4.885B (+43%) US elder-fraud losses (60+), 2024 FBI IC3

Methodology & sources

How we built this report

This report joins two evidence streams, kept deliberately separate so neither inflates the other.

Layer 1 · The dots The AI-fraud incident database

A hand-built catalog of 66 US fraud events where AI or synthetic media was confirmed or credibly reported. Each event was held to five gates:

  1. A discrete, dated, real-world fraud event
  2. The AI or synthetic-media method stated by a source, never inferred
  3. A clear US nexus
  4. A financial-gain or deception-for-gain motive
  5. At least one resolvable, non-competitor public source

Every row was then independently re-checked against its source in a separate verification pass. Disputes were adjudicated against the criteria, duplicate reporting of the same event was collapsed into a single record, and a random ~19% sample was re-audited from scratch. Candidates that didn't clear the bar are retained in a rejected log so the funnel stays transparent.

Confirmed AI · 44 incidents

The method is documented in a filing, disclosure, or technical analysis.

Reported / suspected AI · 19

Credible reporting, a victim, or an official attributes AI, but full forensic confirmation isn't public.

Early leads · 3

A small number of incidents are early leads still being corroborated.

Layer 2 · The lines and the ladder The fraud baseline & the automatability score

Official category-level reported losses from the FBI's Internet Crime Complaint Center (IC3) and the FTC, 2019–2025.

We call this the fraud surface exposed to agentic automation, explicitly not a measure of AI fraud. It exists to show scale and growth. Baseline lines and incident counts are never added together or placed on the same axis.

The automatability score

A transparent 1–5 rubric, not a measured quantity. Each category is rated on four factors: personalization required, repeated conversation required, target research required, and automation readiness, each scored low, medium, or high (1/2/3). The four are summed and rescaled to 1–5. A higher score means more of the work is the kind agents do well.

What to keep in mind
  • Reported = a floor. Independent estimates (e.g. GASA) suggest only a small share of scam losses are ever reported, so true totals are far higher.
  • Growth ≠ AI. A category being large or fast-growing is not, by itself, evidence of AI. Automatability and growth are kept as separate signals; the risk is where both are high.
  • The scenario is an illustration, not a forecast. It scales each category's automatable share by a chosen multiplier to show relative exposure.
  • Sourcing standard. Official agencies and reputable independent research only. We deliberately exclude identity-verification vendors' proprietary “deepfakes up X%” statistics, which rest on private platform data with no independent basis; every viral figure we checked traced back to a vendor's own numbers.
  • Every incident link is checked. Primary sources were tested to confirm they resolve to the event described.
Sources
  • FBI IC3 Category losses, AI-tagged figures
  • FTC Consumer Sentinel + data spotlights
  • FinCEN Deepfake / SAR alerts
  • U.S. GAO Federal fraud loss range
  • Nasdaq Verafin Global financial-crime totals
  • GASA / Feedzai Global scam survey + underreporting
  • APWG Phishing volumes
  • Chainalysis Crypto scam + AI-vendor economics
  • UNODC / UN OHCHR Scam-compound industrialization
  • Verizon DBIR BEC / social-engineering trends
  • Microsoft AI phishing efficacy, fraud blocked
  • Deloitte GenAI fraud projection
  • World Economic Forum Systemic-risk framing
  • Javelin US identity-fraud sizing
  • Federal Reserve Bank of Boston Synthetic-identity estimate
  • Palo Alto Unit 42 · Anthropic · OpenAI Automation anatomy

© Incode 2026. Reported figures are a floor, the true totals are larger; baseline category losses are the fraud surface exposed to automation, not a measure of AI fraud. Built from official and independent sources only.

What's next

Fraud went agentic. So did our defense.