How Deepfakes Are Used to Commit Crimes (and How to Spot Them)

TRM Team

TRM User Conference

Which mission will you select?

REGISTER NOW
November 2-3, 2026
Washington, D.C.
How Deepfakes Are Used to Commit Crimes (and How to Spot Them)

In January 2024, an employee at the engineering firm Arup joined a video call with five colleagues, including the company's UK-based Chief Financial Officer. Every person on the call except the employee was a deepfake. Believing the instructions they received from these colleagues were genuine, the employee authorized 15 transfers totaling USD 25 million to accounts in Hong Kong.

Similar cases are becoming routine as generative AI becomes more realistic, convincing, and widely available. TRM's 2026 AI-in-Crime Adoption Index — which scores AI's growing role in crime on a scale of 0 to 100 — found the index had risen to 54 in 2026, up from 28 in 2024, with reported deepfake-scam losses in the first months of 2026 already exceeding the full-year 2025 total by 263%. 

Deloitte projects a similar trajectory in the United States: generative AI will push fraud losses from USD 12.3 billion in 2023 to USD 40 billion by 2027, a 32% compound annual growth rate driven largely by synthetic media. The Federal Bureau of Investigation (FBI) has issued repeated public warnings in 2025 and 2026 about criminals using AI-generated video and voice to impersonate government officials, company executives, and law enforcement itself.

Deepfakes are AI-generated video, audio, or images designed to convincingly imitate a real person.

The technology itself has existed for years. What changed is the cost and skill required to produce a convincing fake. Tools that once required specialized expertise are now consumer-grade and readily available. Criminal groups have capitalized on this shift, leveraging AI to stand up scam operations targeting individuals, companies, and government agencies at a scale and rate we’ve never seen before.

Key takeaways

  • Deepfake-enabled fraud is a measurable and growing category of crime. TRM’s 2026 AI-in-Crime Adoption Index found reported deepfake-scam losses in early 2026 already exceeded all of 2025 by 263%, and Deloitte projects USD 40 billion in generative AI-driven US fraud losses by 2027, up from USD 12.3 billion in 2023.
  • Criminals can now buy deepfake generation as a packaged service. TRM Labs has identified providers selling a single AI face-swap model for as little as USD 500 and a full year of deepfake tooling for about USD 3,000.
  • The Arup case is a clear example of deepfake fraud at scale. A fabricated video call convinced an employee to transfer USD 25 million to fraudulent accounts.
  • Executive and family-member impersonation, AI voice cloning, romance scams run through AI-generated personas, and impersonation of law enforcement or government officials are the most common ways criminals use deepfakes today.
  • The FBI's own guidance is a useful starting point for spotting a deepfake. Watch for distorted hands, unnatural facial movement, audio lag, and any request that pressures immediate action.

{{horizontal-line}}

What makes a deepfake an effective crime tool

A deepfake is synthetic media generated by AI models trained to reproduce a specific person's face, voice, or mannerisms. TRM Labs defines the broader category deepfakes exist within as AI-enabled crime: the use of machine learning, automation, and generative AI to facilitate, scale, or conceal illegal activity. Deepfakes are the highest-profile typology inside that category because they attack the thing people trust most by default — individuals they know, and what they can see and hear.

Deepfakes moved from novelty to criminal infrastructure within a few years thanks in large part to three key drivers: cost, ease of distribution, and model quality.

1. The cost to generate deepfakes has collapsed

Producing a convincing face swap or voice clone once required custom models and technical skill. Consumer tools now do both from just a few seconds of source audio or a handful of photos scraped from social media. Hany Farid, a digital forensics researcher at the University of California, Berkeley who studies deepfakes, demonstrated the point directly in a recent TRM Talks episode with host Ari Rebord: he used a single screenshot, fed it into a USD 10 piece of software, and quickly produced a real-time video impersonation running at 30 frames per second.

2. Criminals can now distribute deepfakes instantly

A cloned voice or fabricated video can be deployed in a single phone call or video conference, with no need to fool an automated detector — only a person under time pressure.

3. Deepfake generation continues to outpace detection

Model quality is improving faster than the public’s knowledge of how to spot convincing deepfakes. That gap is why the FBI's guidance below centers on basic, teachable signs rather than technical detection tools.

How deepfakes are used to commit crimes

Executive and family-member impersonation fraud

The Arup case is a prime example of corporate deepfake fraud. Similar schemes have targeted senior US officials since 2023, according to a separate FBI warning: threat actors frequently impersonate officials using AI-generated voice memos and messages, building false rapport with family members and associates before requesting sensitive information, authentication codes, or wire transfers. The success of these schemes depends heavily on playing on a person’s emotions and putting them under immense social and time pressure.

AI voice cloning and the modernized "grandparent scam"

Voice cloning has updated one of the oldest scams in the book. Instead of a stranger vaguely claiming to be a relative in trouble, scammers now clone the actual voice of a grandchild or family member from audio pulled from social media, then call an older relative claiming to need urgent bail or medical funds. The FBI's guidance recommends establishing a family "secret word" as a verification method, since confirming identity now requires more than recognizing a familiar voice.

Romance scams run through AI-generated personas

Romance scams caused USD 1.16 billion in reported losses to the Federal Trade Commission (FTC) in the first nine months of 2025 alone, with a median individual loss of USD 2,218 in the third quarter. These operations are still mostly run by human operators, often from organized scam compounds, but AI increasingly supplements the human element: generated photos and videos substitute for an in-person or video appearance, and chat assistance helps operators sustain simultaneous conversations with far more victims than a single scammer could manage manually.

Law enforcement and government impersonation

In July 2026, the FBI's Internet Crime Complaint Center (IC3) warned that scammers were using AI-generated video of senior FBI officials to direct victims to spoofed versions of the IC3 website itself — a scheme specifically aimed at people who had already lost money to a prior scam and were looking for help recovering it. The scheme is notable because it targets the exact moment a victim is most likely to trust an authority figure: right after realizing they have already been defrauded once.

Synthetic identity and KYC bypass

Beyond impersonating a specific person, criminals also use deepfake technology to fabricate people who don’t exist at all, or to defeat identity verification checks that rely on a photo or a selfie video. This overlaps with Know Your Customer (KYC) processes at banks, fintechs, and other regulated businesses, where a generated face or manipulated ID document can be used to open an account under a false or synthetic identity.

Deepfake-as-a-Service (DFaaS)

Deepfake generation has also become a packaged criminal service in its own right. TRM Labs' 2026 AI-in-Crime Adoption Index identified two named providers: NiMingZhe sells a single AI face-swap and voice-cloning model for about USD 500, and a full year of deepfake tooling for about USD 3,000. Novin Verify sells synthetic identity documents — fabricated passports, proof-of-address letters, and attestation letters — built to pass verification checks. FinCEN has separately warned that criminals are using generative AI and deepfake media to circumvent the identity verification, authentication, and due diligence controls financial institutions rely on.

Hany Farid has tested this vulnerability directly. He found that video-only identity checks at a major crypto exchange, with no human review, could be spoofed using synthetic video alone. His guidance is that any KYC process that relies on a single channel — voice only, or video only — should be treated as vulnerable.

How to spot a deepfake

Farid's research finds that people identify deepfakes only slightly better than chance, and that higher confidence in a judgment tends to correlate with lower accuracy. The FBI's own guidance, issued across multiple 2025 and 2026 alerts, still converges on a small set of practical signs for identifying deepfakes — useful as a first check, but not as a substitute for procedural defenses.

Visual signs

  • Distorted or oddly rendered hands
  • Unnatural blinking or facial movement
  • Irregular shadows or lighting
  • Accessories (glasses, jewelry) that shift or warp between frames
  • Unnatural mouth movement during speech
  • Inconsistent head poses
  • Expression glitches during fast movement

Audio signs

  • Slight lag between speech and lip movement
  • Unnatural pacing or intonation
  • A voice that sounds close to right but lacks the small imperfections of a live call

Behavioral signs

  • Urgency (e.g. a request for immediate action, secrecy, or a wire transfer — especially one that arrives through an unusual channel, like a sudden encrypted-app message from an otherwise unreachable executive)

Procedural defenses

The FBI recommends verifying identity through a previously established, independent channel rather than the one the request arrived on, and — for families specifically — agreeing on a private verification phrase in advance. For businesses, that means a callback to a known number or a secondary approver for any transfer request that originates from a video call or voice message alone, regardless of how convincing it appears.

What the law says about deepfake fraud

Most deepfake-enabled fraud is still prosecuted under existing law, with wire fraud, identity theft, and impersonation statutes applying regardless of how the underlying deception was produced. 

The clearest AI-specific federal law to date is the TAKE IT DOWN Act, signed into law in May 2025, which requires platforms to remove non-consensual intimate imagery — including AI-generated deepfakes — within 48 hours of a valid request, with criminal penalties for publication. 

States have moved faster and more broadly than the federal government, with a growing patchwork of laws addressing election-related deepfakes, deepfake pornography, and, in some states, deepfakes used specifically in fraud. That patchwork means the legal consequences for the same deepfake scheme can vary significantly depending on where a victim is located and which specific harm the content caused.

Why deepfake fraud is an investigative challenge

While deepfake deception itself happens over a phone call or video conference, the money and infrastructure behind it — the accounts receiving transfers, tools used to generate the content, and networks distributing it — leave a trail. For investigators, this means the response involves detecting the fake itself, followed by tracing where the funds and infrastructure lead.

This is the direction TRM Labs is building toward. TRM recently raised its Series C at a USD 2 billion valuation, specifically to continue building crime-fighting AI — giving investigators, compliance teams, and government agencies the tools to follow and disrupt AI-enabled crime wherever it leads.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. How are deepfakes used to commit crimes?

Deepfakes are primarily used to impersonate a trusted person — an executive, family member, law enforcement official, or romantic interest — in order to convince a victim to send money, share sensitive information, or approve a transaction. The most common schemes are corporate executive impersonation, AI voice cloning of family members, romance scams supplemented by generated images or video, and impersonation of government or law enforcement officials.

2. What is an AI voice cloning scam?

An AI voice cloning scam uses a small sample of a real person's voice — often pulled from social media or a previous phone call — to generate a convincing synthetic version of that voice. Scammers use the cloned voice, usually in a phone call claiming to be an emergency, to pressure a victim into sending money or sharing information quickly, before they have time to verify the caller's identity through another channel.

3. How can I tell if a phone call is an AI deepfake?

Listen for a slight lag between what should be natural speech patterns, unusual pacing or flat intonation, and any audio that sounds close to right but slightly artificial. Behavioral signals are also invaluable: a legitimate emergency rarely requires instant payment with no time to verify. Hang up and call the person back on a number you already have, or use a pre-agreed verification phrase, rather than continuing the original call.

4. How do I spot an AI deepfake scam?

Look for visual artifacts (distorted hands, unnatural blinking, unnatural mouth movement, warped accessories or shadows), audio artifacts (lag, flat tone), and behavioral red flags (urgency, secrecy, requests to move to an encrypted messaging app, pressure to avoid telling anyone else). A request combining several red flags — especially urgency plus a request for money or credentials — should be treated as a likely scam until verified independently through a separate channel.

5. Can deepfakes be used to fake a kidnapping or emergency call?

Yes. Virtual kidnapping and family-emergency scams increasingly use a cloned voice of the supposed victim to make the threat sound credible, then pressure a family member into paying a ransom or "bail" before they can verify what actually happened. Because the scheme depends entirely on preventing the target from checking in with the person directly, the single most effective defense is a pre-agreed family verification phrase that a scammer would have no way to know.

6. How has the grandparent scam gone high-tech with AI?

The traditional grandparent scam relied on a stranger vaguely claiming to be a grandchild in trouble, hoping the victim wouldn't notice the voice didn't quite match. AI voice cloning removes that weakness. Scammers can now clone the actual voice of a specific grandchild from social media audio and use it in the call, making the scam far more convincing to older relatives who trust what they recognize as a familiar voice.

7. How are romance scammers using AI chatbots?

Romance scams are still largely run by human operators, but AI increasingly extends what a single scammer can do: generating photos or short videos to support a fabricated identity, and using chat assistance to sustain believable, personalized conversations with many victims simultaneously.

8. Are there laws against deepfake fraud?

Most deepfake fraud is prosecuted under existing wire fraud, identity theft, and impersonation laws rather than AI-specific statutes, since the underlying crime — theft by deception — doesn't change based on how the deception was created. The federal TAKE IT DOWN Act, signed in May 2025, is the clearest AI-specific law to date, though it addresses non-consensual intimate imagery rather than fraud broadly. A growing number of US states have passed their own deepfake laws covering election content, intimate imagery, and in some cases fraud specifically, creating a patchwork that varies by state.

This is some text inside of a div block.
Subscribe and stay up to date with our insights
No items found.