Blog

2026 AI scams: What you need to watch for (and how to fight back)

Cloned voices, deepfake video calls, and AI phishing explained.

Man views mobile phone with a perturbed look on his face.
AI didn't invent scams. It made the ones we already knew unrecognizable.

AI hasn't invented new scams — it's removed the tells that used to give them away. Cloned voices, deepfake video, and flawless phishing emails now beat the old “look for typos” advice. The fix is verifying through a second channel every time, plus security software that can flag scam contact, verify identity, and cover you if money is stolen.

In January 2024, a finance employee at an engineering firm's Hong Kong office joined a video call with who appeared to be the company's CFO and several colleagues, and wired $25.6 million on their instructions. Every face and voice on that call was AI-generated. The technology involved cost thousands of dollars to run at the time.

By 2026, a comparable attack costs under $50 in computing power and can run in real time on a regular laptop. That's the real story of AI scams this year: not a new type of fraud, but the same old ones — the fake grandchild, the fake bank rep, the fake romantic interest — with every giveaway sanded off.

Why 2026 is different: By the numbers

The FBI's Internet Crime Complaint Center logged $20.9 billion in reported consumer fraud losses in its 2025 Annual Report — a 26% jump from the year before. The first time IC3 has tracked AI-related complaints as their own category: over 22,000 complaints and nearly $900 million in losses tied directly to AI-enabled fraud.

  • 1 in 4 Americans has now received an AI deepfake voice call, according to Hiya's State of the Call 2026 report.
  • Adults 60 and older filed the most complaints of any age group and absorbed $7.7 billion in losses — roughly 39% of the total.
  • Voice clones need as little as 3 seconds of audio to reach 85% accuracy, and only about 1 in 4 people can reliably spot a high-quality deepfake voice.
  • 82.6% of phishing emails now contain AI-generated content, erasing the broken-English and awkward-phrasing tells people were taught to look for.

Sources: FBI IC3 2025 Annual Report (April 2026); Hiya State of the Call 2026; McAfee, Sumsub, and StationX deepfake research (2026).

The 5 AI scams you should watch out for in 2026

Every AI-enabled scam making headlines this year falls into one of five patterns. None of them are new — what's new is how convincing they've become.

Scam TypeHow AI Is UsedWhat to Watch For
Cloned-voice calls3 seconds of audio from a video or voicemail clones a voice with 85% accuracy.Urgent request for money from a family member or official. Hang up and call them back directly.
Deepfake video callsReal-time face-swap on a video call, used to impersonate a boss, bank representative, or relative.Ask them to turn their head or touch their face on camera. Live deepfakes still glitch under motion.
AI-written phishingEmails and texts with no typos, correct tone, and personal details pulled from social media.Don't judge by accuracy anymore. Verify the sender through a separate, known channel.
Romance & "pig butchering"AI chatbots sustain months-long relationships before steering the victim into a fake investment.Any online relationship that moves toward investment advice or a special app is a red flag.
Fake AI apps & toolsLookalike ChatGPT or Sora downloads that install malware instead of an AI tool.Only download AI tools from the official app store listing or the company's own site.

Why the old advice doesn't work anymore

For years, the standard scam advice was: look for typos, listen for a robotic voice, watch for a blurry logo. That advice assumed the scammer was working with limited tools and limited time. Neither is true anymore. A cloned voice carries the real person's tone and inflection. A phishing email is grammatically perfect and references details pulled from a public social media profile. The sloppiness that used to be the tell is gone — which means the defense has to change, from spotting mistakes to verifying identity.

How to protect yourself and your family

Set a family safe phrase

Agree on a word or phrase in advance that only your family knows, to be used if anyone calls in distress asking for money. If the person on the phone can't produce it, hang up. An AI clone cannot guess it.

Verify on a separate channel, every time

If a call, text, or video claims to be your bank, a relative, or an official, hang up and call the number you already have on file — never the one given to you during the same contact. This single step stops the vast majority of impersonation scams before money moves.

Never trust caller ID alone

Spoofing a phone number costs fractions of a cent and works against every major carrier. Caller ID showing a familiar name or number is no longer proof of who's calling.

Watch for urgency and secrecy

Scammers, human or AI-scripted, rely on pressure: act now, don't tell anyone, stay on the line. Legitimate banks, agencies, and family members generally don't demand instant, silent action.

Where Webroot Total Protection fits in

None of the habits above require special software. They work on their own with a little bit of practice. But they ask a lot of a person in the moment a scam is actually happening, which is exactly when it's hardest to think clearly. Webroot Total Protection provides tools designed to help navigate scams, including:

  • Real-time scam detection that flags suspicious calls, texts, and links before you engage with them rather than relying on you to catch every red flag yourself.
  • Identity verification tools that help confirm whether a message, caller, or contact is genuinely who they claim to be.
  • Financial and identity monitoring that alerts you to unusual account activity early, when there's still time to act.
  • Scam-loss coverage that reimburses stolen funds if a scam gets through despite your precautions — protection for the moment prevention isn't enough.

That last point matters because prevention alone is no longer a complete strategy. Even careful, informed people are being fooled by cloned voices and deepfake video — the technology has gotten good enough that vigilance can't be the only line of defense. Coverage that reimburses a scam loss is what turns a worst-case moment back into a manageable one.

Frequently asked questions

How can I tell if a voice on the phone is AI-generated?

It's getting harder — human detection accuracy on high-quality voice clones is below 30%. The reliable method isn't listening harder, it's hanging up and calling the person back on a number you already trust.

Are AI scams covered by bank fraud protection?

It depends on how the money left your account. Wire transfers and person-to-person payments you authorize yourself, even under a scammer's influence, often fall outside standard bank fraud protection — which is why dedicated scam-loss coverage in a security suite can matter.

Who is most at risk from AI scams right now?

Adults 60 and older filed the most fraud complaints and absorbed the largest share of losses in the FBI's 2025 report, but AI-related complaints were logged across every age group — no one is too tech-savvy to be targeted.

What's the single most effective defense against AI voice scams?

A pre-agreed family safe phrase combined with a strict callback rule: hang up and dial a number you already have on file, never one given to you during the suspicious contact.