
The FBI’s 2025 Internet Crime Report included a dedicated section on artificial intelligence being used in cybercrime, documenting 22,364 complaints and more than $893 million in adjusted losses.(IC REPORT)
The number attached to that first-time breakout was $893,346,472 in reported losses, across 22,364 complaints, and the bureau’s own framing was that this figure almost certainly understates the real total, since AI’s fingerprints show up inside romance scams, government impersonation calls, and investment fraud without always being tagged as “AI” by the person filing the complaint.
That’s the actual story behind “common identity theft scams” right now, and it’s a different story than the one most advice on this topic is still built around. The old checklist, bad grammar, a generic greeting, an obviously fake logo, was written for a threat model that’s aging out. This article covers what’s actually changed, why the old tells stopped being reliable, and what to do instead.
Table of Contents
Why the Old Advice Is Losing Its Grip
For years, the standard scam-spotting advice boiled down to: look for the tells. Misspellings. Awkward phrasing. A voice that doesn’t quite sound right. A photo that looks slightly off. Those tells worked because producing a convincing fake used to take real skill, time, or money, most scammers didn’t have all three.
That constraint is largely gone. Generative AI tools can now produce fluent, personalized, well-formatted text at essentially zero marginal cost, clone a voice from a few seconds of audio, and generate a realistic video of someone saying things they never said. None of that requires the scammer to be technically sophisticated anymore, it requires access to consumer-grade tools that are, in most cases, legally available and not built with fraud prevention in mind.
A Consumer Reports investigation into six popular AI voice cloning apps in 2025 found that four of them had no meaningful safeguards against this kind of misuse.(CFPB)
The practical result: the signal you used to rely on, “this feels a little off”, is disappearing as the baseline quality of fakes rises. That doesn’t mean you’re defenseless. It means the defense has to move from spotting the fake to verifying through a separate channel, which is a different habit than most people have practiced.
Old Tells vs. What Actually Works Now
| Old Advice | Why It’s Losing Reliability | What Actually Still Works |
| Look for spelling and grammar mistakes | AI-generated text is fluent by default | Verify the request through a channel you initiated, not one the message provided |
| Listen for a voice that doesn’t sound quite right | Voice cloning from a few seconds of audio is now widely accessible | Hang up and call back on a number you already have saved |
| Check if the photo/video looks fake | AI-generated video and images can be convincingly realistic | Ask something only the real person would know, unprompted by them |
| Trust caller ID | Caller ID can be spoofed independent of any AI involved | Caller ID was never reliable, this isn’t new, but it matters more now that the voice on the other end can be faked too |
This is IdentityBastion’s plain-language update to standard scam-spotting guidance, not a formal classification, but a reflection of what verification actually requires given the current tools available to scammers.
The distinction matters because clinging to outdated tells creates false confidence. Someone who’s trained themselves to “listen for the fake” may actually be more vulnerable now than someone who never learned that advice at all, because a good clone will pass the old test and the person won’t think to apply a different one.
The Scam Patterns Actually Driving Losses Right Now
Rather than a generic list of common identity theft scam types, here’s what the current data actually shows is doing the damage, grouped by mechanism, since several of these share the same underlying technique with different framing.
The Family Emergency Call, Now With a Real Voice
This is the classic “grandchild in trouble” identity theft scam, but the version running in 2025 uses a cloned voice built from audio the scammer pulled from social media, a voicemail greeting, or a video someone posted publicly.
The FBI’s IC3 data recorded over $5 million in documented losses tied specifically to this scam type in 2025, and that figure only reflects reported cases, likely a fraction of the total given how few victims of this particular scam report it out of embarrassment.
The mechanism is simple and that’s what makes it effective: panic short-circuits verification. A crying voice that sounds exactly like your grandchild, saying they need bail money right now, is designed to get you moving before you think to check.
The FTC’s own guidance on this is blunt: say “I’ll call you right back,” and hang up. If it’s real, they’ll answer when you call their actual number. If it’s a scam, either nobody answers or the real person tells you they never called.
Government and Bank Impersonation, Automated at Scale
Imposter scams, someone posing as your bank, a government agency, or a company you do business with, were the single most-reported fraud category in 2025, accounting for close to one in three of all fraud reports the FTC received that year, with losses topping $3.5 billion.
Government impersonation saw complaint volume roughly double year-over-year, and the FTC has directly attributed a meaningful share of that increase to AI voice cloning, which makes follow-up calls sound convincingly official after an initial scam text or email.
The pattern usually starts with a message, a text about a supposed toll violation, a fake fraud alert from your bank, a warning about a warrant, followed by a phone call that sounds exactly like what you’d expect an actual representative to sound like, because it’s often built from publicly available audio of real customer service scripts or even real employees.
Neither your bank nor a government agency will demand immediate payment over the phone in gift cards, wire transfers, or cryptocurrency. That single fact hasn’t changed even though the delivery method has gotten far more convincing.
AI-Generated Investment Fraud and “Pig Butchering”
Cryptocurrency investment fraud, commonly called “pig butchering” because of the slow, deliberate trust-building involved before the scam, accounted for over $7.2 billion in reported losses across more than 61,000 complaints in 2025, a roughly 48% jump in complaint volume from the year before. What’s changed isn’t the core con, which has existed for years; it’s the production value.
Fraudsters are now using AI-generated video and audio to fabricate convincing endorsements from celebrities, executives, and financial commentators, distributed through social media and staged video calls that are professional enough to fool people who’d have caught an obvious fake.
Organized criminal enterprises frequently run these operations, and AI tools are primarily being used to accelerate the relationship-building phase and run more simultaneous targets at once, meaning the same operation can now credibly manage far more victims than it could a few years ago.
AI Romance Scams
Related to the above but distinct in framing, romance-specific fraud generated a smaller but real share of AI-linked losses in 2025, roughly $19 million tied specifically to AI-assisted confidence and romance schemes, according to FBI reporting.
A chatbot layer, sometimes combined with a cloned voice for the occasional call, allows one operator to sustain believable, personalized conversations with many targets simultaneously, something that used to require real human time and effort per victim.
AI-Personalized Phishing
Old phishing emails were often mass-blasted and generic, which is part of why grammar errors and awkward phrasing were reliable tells, the scammer wasn’t writing for you specifically.
AI-generated phishing content can now be personalized using data pulled from breaches or public sources, referencing your actual employer, a real recent purchase, or a specific service you use, which makes the message read as legitimate rather than templated. [What Is Identity Theft? Meaning, Types, and Warning Signs]
The habit that closes this off doesn’t depend on catching the fake: never click a link in an unexpected message, regardless of how personalized or convincing it reads, and navigate to the site directly instead.
How the Underlying Technology Actually Works
Understanding the mechanism behind these identity theft scams makes the verification habits above make more sense, rather than feeling like arbitrary caution.
- Voice cloning requires remarkably little source material, systems can create convincing imitations from relatively short samples of a person’s voice, making publicly available audio a potential source of material for impersonation scams.(CFPB) That threshold is why a single voicemail greeting, a video posted publicly, or even a few seconds of someone’s voice from a social media clip is enough raw material for a scammer to work with.
- Deepfake video generation works by training a model on existing footage and images of a real person, then generating new video and audio that maps their likeness onto content they never actually recorded. The production quality has risen enough that even attentive viewers can be fooled, particularly in short clips or staged video calls where the scammer controls lighting, framing, and script.
- AI-generated phishing content works by feeding a language model context about the target, pulled from breach data, social media, or public records, and generating a message tailored to reference real, specific details, which is what defeats the old “generic greeting” tell.
- Chatbot-driven long cons work by automating the conversational labor that used to limit how many victims one scammer could manage simultaneously, letting a single operation run dozens or hundreds of parallel “relationships” with enough personalization in each one to feel individually genuine.
None of these mechanisms require the victim to have made any technical mistake. That’s a meaningful shift from advice that implicitly blamed the target for not spotting a bad link or a suspicious attachment, the newer generation of identity scams are specifically designed to survive that kind of scrutiny.
What Actually Helps Against These, and What It Doesn’t
| Protection | What It Solves | What It Doesn’t Solve |
| Callback verification (hang up, call a saved number) | Defeats voice cloning and caller ID spoofing regardless of how convincing the clone is | Requires you to actually pause and do it in the moment, which panic works against |
| A family code word | Gives you a fast, low-friction way to verify a family emergency call | Only works if it’s set up in advance and everyone in the family actually knows it |
| Never clicking links in unexpected messages | Defeats AI-personalized phishing regardless of how convincing the content is | Doesn’t help if you’re tricked into a phone call instead, which bypasses this entirely |
| Slowing down before acting on urgency | Counters the core psychological mechanism nearly all of these scams rely on | Doesn’t work if you’re not aware urgency itself is the manipulation, not just a side effect |
| Credit freeze and fraud monitoring | Limits the financial damage if a scam does result in exposed information | Doesn’t prevent the scam itself or stop someone from being deceived in the moment |
None of these fully closes the gap on its own, the callback habit and the code word both depend on being set up and remembered before an actual emergency, not improvised during one.
Common Mistakes People Make With These Newer Scams
- Assuming a familiar voice confirms identity. This used to be a reasonably safe assumption. It no longer is, and the mistake isn’t a lapse in judgment, it’s outdated pattern-matching that hasn’t caught up to what’s actually possible now.
- Relying on “checking for red flags” instead of verifying independently. Looking for tells assumes the fake will have flaws. Increasingly, it won’t. Verification through a separate channel doesn’t depend on the fake having any flaws at all.
- Treating caller ID as meaningful evidence. Caller ID has been spoofable for years independent of any AI involved, this isn’t a new vulnerability, but it compounds badly with a cloned voice, since neither signal can be trusted and people often haven’t updated their instincts on either.
- Engaging with a suspicious message to “test” it. Replying, asking questions, or trying to catch the scammer in an inconsistency gives an AI-generated conversation partner more context to work with and more time to build a convincing response. Disengaging entirely is safer than probing.
- Assuming this only targets older or less tech-savvy people. FBI data on AI-linked losses shows investment fraud, which spans all age groups, carries the largest dollar losses of any AI-linked category, not the family-emergency scam most people picture when they think about who’s vulnerable.
FAQs: Common Identity Theft Scams
What Are the Most Common Identity Theft Scams Right Now?
AI voice-cloned family emergency calls, government and bank impersonation calls that follow up an initial text or email, AI-generated investment fraud (including “pig butchering” crypto schemes), and AI-personalized phishing messages are driving the largest documented losses as of the FBI’s 2025 reporting.
How Can I Tell if a Call Is an AI Voice Clone?
You often can’t, reliably, by listening alone, that’s the core problem these scams exploit. The safer approach is hanging up and calling the person back on a number you already have saved, rather than trying to judge the voice itself.
Are AI Scams Only Targeting Elderly People?
No. While family-emergency and government-impersonation scams do disproportionately target older adults, FBI data shows AI-linked investment fraud, which spans all age groups, accounts for the largest dollar losses among AI-related scam categories.
Does a Credit Freeze Protect Me From These Scams?
Not directly. A credit freeze limits what a scammer can do with your information if a scam results in it being exposed, but it doesn’t prevent you from being deceived into handing over money or information in the first place, those are two different problems requiring different defenses.
What Should I Do if I Think I’ve Already Fallen for One of These Scams?
Treat it the same as confirmed fraud: contact any financial institution involved immediately, and follow the full type-specific recovery process for whatever was compromised.
Bottom Line: Common Identity Theft Scams
The biggest change in identity theft scams in 2026 isn’t that scammers suddenly have completely new tricks. It’s that AI has made the old tricks faster, cheaper, more personalized, and much harder to recognize by appearance alone. The FBI recorded more than 22,000 AI-related complaints and over $893 million in adjusted losses in 2025, while the FTC recorded $3.5 billion in reported losses from imposter scams.
That means the old advice, look for bad grammar, strange voices, fake-looking images, or obvious inconsistencies, is no longer enough. A scam can sound like your family member, look like a legitimate company, and contain details that are genuinely specific to you.
The defense that holds up is independent verification. Hang up and call the person back using a number you already trust. Navigate to your bank’s website yourself instead of using a link in a message. Confirm unusual requests through a separate channel. And when someone creates urgency, slow down rather than speeding up.
You don’t need to become an expert at detecting AI-generated content. You need to stop treating a convincing message, voice, or video as proof of identity. In 2026, trust the request only after you’ve verified the person behind it.
What to Do Next
If a scam like the ones above resulted in your information being exposed, even if you’re not sure whether it was fully misused yet, the next step is figuring out exactly what to check and how urgently. Our diagnostic guide walks through exactly where to look.
