It Sounded Exactly Like Your Daughter. This Was the First Year the FBI Counted at All.
The FBI's first count of AI-related fraud: 22,364 complaints, $893 million lost — and a separate $5 million line for the call that sounds like your child. How to read all three.
My mother forwarded me an article about voice-cloning scams in the spring, with one line typed above the link: we should agree on a word. I did not agree on a word. I wrote back something breezy — she has been listening to me talk since before I could form sentences, and would know inside three syllables. She let it drop, and I felt quietly pleased with myself.
That was a warning, I ignored it, and I want to be precise about how — because I suspect most of us get it wrong in the same shape.
I did not underestimate the odds. I would have agreed on the spot that this happens constantly, and to people neither gullible nor elderly. What I misread was the request. I heard be more careful and answered I already am. She was asking for a procedure — something that works after carefulness has failed. She had worked out, faster than I did, that my ear for her voice had stopped counting as evidence.
What the bureau counted, and what it did not
The FBI's Internet Crime Complaint Center — IC3, the federal inbox for fraud reports — recorded 22,364 complaints in 2025 carrying an "AI Related" descriptor, with $893,346,472 in reported losses. The bureau's own prose is more cautious than the headlines it produced: more than 22,000 complaints, adjusted losses that "exceed $893 million."
Two things about that number matter more than its size.
First, it is brand new. In the report's three-year comparison, the AI Related line carries a figure for 2025 and an asterisk for 2024 and 2023, footnoted "Crime Type or Descriptor was not captured in these years." No trend, no baseline — anyone quoting you a spectacular growth rate is dividing by a year in which nobody counted.
Second, the tag is a self-report. A descriptor, the same report explains, is "used by IC3 for tracking purposes only," and AI Related means the information reported "contains a reference to artificial intelligence." Nobody at the bureau listened to a call. The accurate phrase is complaints that referenced AI — clumsier, but the short version is false.
Now the part that sent me to find my phone. Complainants aged sixty and over accounted for 3,143 of those complaints and $352,496,231 in losses — $352 million of the total borne by older adults. Forty percent of the money, from fourteen percent of the complaints.
It sits inside an older pattern. IC3 logged 1,008,597 complaints and $20.877 billion in losses across all crime types last year; people over sixty filed 201,266 of them and reported losing $7.748 billion, an average of $38,500 each — complaints up 37 percent over 2024, losses up 59 percent. Both are climbing; the money is climbing faster.
A caveat against my own case, though: this is a complaint database, not a census. These are, as one security firm noted, "only the reported losses, which may well be the proverbial tip of the iceberg" — and fraud that works by humiliating you is underreported worse than most.
Three seconds, or five, or thirty. Pick one; they are all small.
The technical requirement has collapsed. Microsoft's speech lab demonstrated a system producing personalized speech from "only a 3-second enrolled recording of an unseen speaker" — a voice the model had never heard. A laboratory result, not a fraud statistic; I won't let it masquerade as one.
The practitioners land nearby. Peter Warmka, a retired CIA officer and certified fraud examiner, told CBC's consumer program that "you need three to five seconds" of a voice sample, obtainable from a social media post or a phone call. The National Cybersecurity Alliance is more conservative, putting today's systems at around thirty seconds. Three seconds to half a minute, then — and if you have ever left a voicemail, you are over the line.
The other half of the collapse is on our side of the phone. Researchers at Berkeley's School of Information tested how well people detect synthetic speech, and Sarah Barrington summarized the result: we can tell something is fake "only 60% of the time" — barely better than a coin, since guessing gets you 50 percent. Side by side, people spot that two voices are different identities only about 20 percent of the time. Her co-author Hany Farid, now a professor of computer science at Dartmouth, has spent a career here; and the Federal Trade Commission, launching a Voice Cloning Challenge in 2023, already called these tools a way to replicate voices "in a way that is hard to detect by ear."
There is the sentence this article exists for. Every anti-fraud instruction we absorbed growing up — would a real bank ask that? does this sound like her? — routes through recognizing a person. That was never a rule. It was a sensor, and it now returns noise.
Now the part that should make you distrust my headline
The strongest objection to this piece is in the document I have been quoting.
The FBI's line for the exact scam in my title is not $893 million. The report puts losses at over $19 million to romance and confidence scams with a likely AI nexus, a group that "also includes grandparent scams, or 'distress' scams, in which voice cloning technology is used to mimic the sound of a loved one in distress" — and then, specifically: victims claimed losses over $5 million in 2025 to distress scams.
Five million dollars. So what is the $893 million? Mostly investment fraud — the AI-branded trading platform, the synthetic executive promising a guaranteed return — plus tens of millions in business email compromise and employment scams. The voice pretending to be your daughter is a small, separately counted item in a category dominated by something else. Letting the big number stand in for the grandparent scam is misleading.
Even the best-documented American case is not a finding of fact: in February 2025 a federal grand jury indicted 25 Canadian suspects over what prosecutors allege was a $21 million grandparent scam spanning 46 states. An indictment is an allegation the government still has to prove.
So — moral panic?
I don't think so, for two reasons. That $5 million is the reported figure from the first year anyone tallied it, for a crime engineered to leave victims too ashamed to file. And the loss column is the wrong thing to watch anyway: what changed is not how much money moved, but that the verification method a billion people rely on — I know that voice — became unreliable in about three years, with nothing distributed to replace it. Fraud totals lag a broken lock.
Britain ran the experiment. The verdict arrived in July.
American policy has spent this period arguing about whether to regulate the tools. One country changed who eats the loss instead — and now has data.
Britain calls the crime "authorised push payment" fraud, and its regulator defines it plainly: an APP scam happens when someone is tricked into sending money to a fraudster posing as a genuine payee, over Faster Payments or CHAPS between UK bank accounts, with sending and receiving firms splitting the reimbursement cost 50:50. Notice what it does not ask: not whether a fake invoice fooled you, or a romance, or a voice — only whether you were tricked into pushing the payment yourself.
Since October 7, 2024, UK payment firms have had to reimburse those victims within five business days, up to £85,000 per claim, across the whole market and for "individuals, microenterprises and charities" — with an optional £100 excess that cannot be applied to vulnerable consumers, and nothing at all if you were complicit or grossly negligent. Protection, not a blank check, and contested to the wire: the regulator cut the maximum from £415,000 to £85,000 weeks before launch.
Early data came fast: in the first three months, "86% of money lost to APP scams was returned to victims, totalling around £27m," with 84% of claims closed inside the deadline — though the regulator cautions against direct comparisons with earlier periods.
Then, on July 1, 2026, it published an independent evaluation. APP fraud losses sent over Faster Payments fell by around 21%, a reduction of £73m per year, with reimbursement rising from 54% before the policy to 65% after. The work, by Frontier Economics, also found firms reimbursing 97% of in-scope claims and put the short-term net economic benefit at £17 million to £29 million. Losses down, payouts up, net benefit positive — the three things critics said could not happen together.
They really did say it. The pre-launch warnings, as one account puts it, were that mandatory reimbursement would "create moral hazard, teaching consumers to stop caring," crush smaller firms and break instant payments. That same piece draws the comparison I keep returning to: British banks got a cap, a clock and an even split; American banks are getting discovery.
Now the other side, because a contrast reporting only good news is propaganda. The counter-fraud trade body Cifas argued the rules would "reduce consumer caution, incentivise people to commit fraudulent acts – so-called 'moral hazard'" and make Britain more of a target for organized fraud. Predictions, and the evaluation found they did not materialize — though it also notes outcomes for victims "remain inconsistent" depending on which firm they bank with.
And reimbursement is not prevention. Even with the rule in force, the most recent annual fraud report from Britain's banking trade body found APP fraud losses rose 19% to £576.4 million — fewer pounds lost per Faster Payment, more pounds lost overall. The ground is moving institutionally too: the government has announced its intention to abolish the Payment Systems Regulator and consolidate its primary functions into the Financial Conduct Authority, a transition still underway.
The lesson is narrower than "copy Britain." It is that Britain made a decision about liability rather than technology, and liability turned out to be the faster lever. Nobody had to detect a deepfake.
Now push it forward three years
Everything above is on the record. What follows is not.
Picture the call in 2029. It is live, conversational, and it answers your questions. You ask where she is and it tells you, correctly, because her commute sits in a data broker's file. You ask her roommate's name and it knows. The old weak link — a script cannot improvise — is gone.
Then the second-order effect, the corrosive one. Once you know a voice proves nothing, you start doubting the real calls. Your bank rings about an actual fraudulent charge and you hang up. Your kid calls from an emergency room and you demand the code word while they are crying. And the last to retreat from the phone — the ones who still answer unknown numbers — are the people already carrying forty percent of the losses.
Then the fix everyone reaches for: attested identity, a badge certifying this really is your daughter's phone. Notice the trade before it is offered to you — a system that can prove who is calling can also log who called whom, forever.
What the people who study this are actually asking for
Nobody serious thinks detection alone will save us, and the proposals split along familiar lines.
Start with the tools. Consumer Reports evaluated six commercial voice-cloning services and found that four fail to take basic steps to stop unauthorized voice cloning — often the only barrier is a box you tick affirming you have permission. Covering the same investigation, NBC News framed it as most leading programs having no meaningful barriers to stop people from nonconsensually impersonating others, counting five of six with easily bypassable safeguards. (Two counts of two different things; I am not merging them into one scarier number.)
Congress has started asking. In April 2026, Senator Maggie Hassan, ranking member of the Joint Economic Committee, pressed four companies with leading AI voice cloning services to prevent exploitation by scammers — ElevenLabs, LOVO, Speechify and VEED — citing the FBI's figure alongside a specific New Hampshire case. ElevenLabs responded that it maintains an extensive array of safeguards, including blocking clones of public figures. A real answer. Letters, though, are not law.
There is more law here than people realize, and less than they need. In February 2024 the Federal Communications Commission confirmed that the TCPA's restrictions on an "artificial or prerecorded voice" encompass current AI technologies that generate human voices, so such calls need prior express consent, and said the ruling would hand state attorneys general new tools to go after voice cloning scams. Read the fine print, though: that lives in robocall law. It aims at automated campaigns, not at one person in a call center dialing your mother.
The think tanks disagree about what comes next. From the right of center, the R Street Institute argues much of the regulatory landscape is "antiquated and geared toward outdated systems" and wants a whole-of-society approach using AI defensively rather than another statute. From the civil-liberties side, the Electronic Frontier Foundation warns the leading federal likeness-and-voice bill could silence satire, commentary, and news through its notice-and-takedown machinery — the worry being that ordinary people could sign the rights to their own face and voice into someone else's hands by clicking through a platform's terms. A risk, framed as such, not a proven outcome.
Neither camp says do nothing. They are arguing about the instrument.
Four minutes, tonight, at the kitchen table
The most useful thing in this article costs nothing. AARP's family guidance runs to two sentences: establish a secret code word with family members to confirm identities during emergency calls, and hang up and call back using a known number when someone claims to be a relative in crisis. That is the whole defense.
Agree on a code word tonight, before anyone is shouting — with your parents and in-laws too, not just your kids. The National Cybersecurity Alliance describes it as a pre-agreed code word or phrase only you and your trusted group know: not a birthday, not a pet, nothing that appears online. As one elder-law practice puts it, the point is that it is decided on before anyone is under pressure.
Make hanging up the reflex, not the insult. You are not accusing your child of being a fraud; you are ending one call and starting another, to a number already in your contacts. A real emergency survives a ninety-second callback. A scam does not.
Treat urgency as the tell, since the voice no longer is. Every version of this crime needs you to act before you think, on rails that do not reverse — wire, gift card, crypto, cash courier.
Know where you stand if it happens. In the United States, whether you see that money again depends largely on your bank's goodwill and your state attorney general, not on a five-day clock and a statutory cap. That is a policy choice, with people you can vote for attached.
What my mother understood first
I keep coming back to those four words, because she was right in a way I have still not caught up to. She was not asking me to be more suspicious. She was asking me to stop relying on a sense.
For all of human history, recognizing someone was authentication — the face at the door, the voice on the line, the hand on the envelope. Never perfect, but cheap, instant and good enough. Machine synthesis has not so much defeated that instinct as retired it, quietly, without a notification, while we went on trusting it.
The replacement is not exotic: a word you agree on with the people you love, and a habit of hanging up. Humans proved identity with shared secrets for as long as we have had enemies; we simply stopped needing to. The catch is that it only works in advance, in calm — which is exactly why the losses land where they do.
And the policy lesson is Britain's. When you cannot fix the sensor, fix the incentives. Somebody in that chain — the sending bank, the receiving bank, the service selling the clone — is better placed than a seventy-four-year-old with a ringing phone to stop this. The question is not who got fooled but who could most cheaply have prevented it. Britain answered it, and its losses fell. We are still arguing about whose problem it is.
So go pick the word. I finally did, three days into writing this — and my mother, to her credit, said nothing about it.
Agree on the word tonight, while nobody is shouting. The rest of what we are working on lives at haia.foundation.





