Device Type: 
Skip to Main Content Skip to Main Content

Scammers Are Winning the AI Arms Race

Fraudsters are developing new scams faster than the industry can keep up. Here's what the tech world must do about it.

Author
Product Expert, Network-Powered Solutions
August 05, 2026
Young Asian woman receiving an incoming suspected call from unknown caller on her smartphone and rejecting the call at home. Device screen showing warning sign as detected by network provider. Phone scam. Cyber security and fraud concept
LISTEN • 13 Minutes

Key Takeaways

  • AI has made sophisticated fraud accessible to anyone, collapsing the barrier to entry for even low-skilled criminals.

  • Detection tools lose up to 50% of their accuracy outside a lab, and humans can no longer reliably spot a cloned voice.

  • Embedding fraud protection at the infrastructure level is the only defense that doesn't degrade as AI improves.

The numbers are staggering — and getting worse. Americans reported nearly $21 billion in cybercrime losses in 2025, the highest total ever recorded, according to the FBI’s latest Internet Crime Report. 

For the first time, the FBI’s annual report includes AI-related fraud as its own category, a signal that artificial intelligence has moved from a background tool to the central engine of modern crime. And the trajectory is only accelerating: Fraud reporting platform Chainabuse says reports of generative AI-enabled scams between May 2024 and April 2025 rose by 456% from a year earlier.

We’re losing the arms race — not because defenders lack intelligence or resources, but because the asymmetry is structural. Criminals are early adopters by nature. They experiment, share methods, and iterate faster than regulators or defenders can respond. AI has handed them a force multiplier.

The attackers’ new toolkit

To understand the scale of the problem, you have to understand how dramatically AI has lowered the barrier to entry for fraud.

Voice cloning is perhaps the most visceral example. Researchers at McAfee Labs found that just three seconds of audio is enough to create a voice clone with 85% accuracy. Siwei Lyu, a computer science and engineering professor at the University at Buffalo, wrote recently that voice cloning has crossed the "indistinguishable threshold," where human listeners can no longer reliably recognize a cloned voice from a real one. “The perceptual tells that once gave away synthetic voices have largely disappeared,” Lyu wrote in The Conversation.

Deepfake video has evolved from obvious fakes to real-time interactive avatars. The most studied case of the decade: British engineering firm Arup lost $25 million in 2024 when a finance worker in Hong Kong approved 15 wire transfers during what appeared to be a routine video call with their CFO and several colleagues. Every person on that call — except the victim — was an AI-generated deepfake. The incident wasn't discovered for weeks.

AI-powered phishing has eliminated the telltale signs that once made scams detectable. Gone are the grammatical errors and clunky phrasing that legacy email filters and security training relied on. Over 82% of phishing emails are now created with the help of AI. Researchers at IBM said they tricked AI into creating convincing phishing emails in just five minutes. 

Synthetic identity fraud occurs when criminals create a hybrid identity from a mix of real and fake data. They might start with a stolen Social Security number, for example, generate a complete identity package, and then auto-fill new account applications en masse. By 2025, approximately 60% of estimated fraud losses were attributed to serial and synthetic fraud, a complete reversal from just four years prior, when traditional document fraud dominated.

And the cost of entry? A new phishing kit called Bluekit comes with an AI assistant, website templates, voice cloning, automated domain purchase, and more, reportedly priced at under $100 for a seven-day subscription. You can buy software that bypasses AI image and video detection for $800. A subscription to a “Dark LLM” such as WormGPT reportedly starts at $50 a month.

Fraudsters share methods. Defenders largely don't. This asymmetry is one of the most exploitable gaps in the current ecosystem.

Why defenders are falling behind

Criminals are opportunistic early adopters. When a new AI model drops, criminal forums are testing its fraud applications within days. Defenders, by contrast, operate within institutional constraints that slow adoption of countermeasures. AI has moved "closer into the heart of the offensive workflow," ReliaQuest's June 2026 threat intelligence report noted.

And the detection gap is widening. The market for tools that detect AI is growing between 28% and 42% every year. That sounds great until you consider that the threat itself is expanding at rates of 900% or more in key regions, according to DeepStrike. And when you take these defensive tools out of a controlled lab, their effectiveness plummets by as much as 50%.

Finally, the legal landscape hasn't kept pace. Many tools used in cybercrime, like language models, voice cloning, and image generation, also have legitimate business uses, which complicates enforcement. What is legally permissible varies by country, and some forms of AI-generated deception may not be criminalized everywhere, creating safe havens for misuse.

    5 steps the tech world must take

    This is not a problem that any single company, government, or technology can solve alone. It requires a coordinated, multi-layered response across the industry. Here's where to start:

    1. Build AI defenses into the infrastructure layer

    The most durable defenses won't live at the endpoint. They'll be embedded in the communications infrastructure itself. Telecom providers, cloud platforms, and API providers are uniquely positioned to detect and block AI-enabled fraud at the network level, before it ever reaches a human target.

    Technologies like network-based authentication, branded calling, and real-time fraud signal APIs can verify the legitimacy of communications before they reach consumers. When fraud detection is built into the pipes rather than bolted on at the application layer, it becomes far harder to circumvent. The industry needs to accelerate the deployment of these capabilities and make them accessible to businesses of all sizes. 

    2. Shift from detection to procedural resilience

    Any security strategy that relies solely on detecting deepfakes is destined to fail. Detection accuracy drops dramatically in real-world conditions, and the technology will only get better at evading detection. The strategic focus must shift from "can we spot the fake?" to "have we built processes that are robust even if we can't?"

    This means establishing out-of-band verification protocols for high-stakes requests: a second channel confirmation before any wire transfer, a shared code word for urgent executive communications, a mandatory callback to a known number before acting on any voice instruction. These procedural controls are low-tech, high-impact, and don't degrade as AI improves.

    3. Treat AI safety as a product responsibility 

    The companies building the AI models that fraudsters are weaponizing have a responsibility to make misuse harder. This means investing in guardrails that are genuinely difficult to circumvent, not just terms of service that bad actors ignore. It means building detection capabilities into the models themselves, e.g., watermarking AI-generated content, flagging high-risk use patterns, and sharing threat intelligence with law enforcement.

    The open-source AI ecosystem presents a particular challenge here. The industry needs honest conversations about the tradeoffs between openness and safety — and regulators need to be part of that conversation.

    What are the best Zero Trust strategies?

    Instead of one-size-fits-all access rules, respond to threats as they happen using live data from the network itself.

    4. Create shared fraud intelligence networks

    Fraudsters share methods. Defenders largely don't. This asymmetry is one of the most exploitable gaps in the current ecosystem. A synthetic identity that fails at one bank simply moves to the next. A phishing kit blocked by one email provider gets deployed through another.

    The solution is trusted fraud prevention networks, where organizations can securely share threat signals without exposing competitive or customer data. Encouragingly, 51% of consumers say they would opt in to securely share their own data with such networks if used exclusively for fraud prevention — a signal that the public understands the stakes and is willing to participate in collective defense.

    5. Invest in human resilience, not just technical defenses 

    Technology alone will not win this fight. The most sophisticated deepfake in the world still requires a human to act on it. That means security awareness training must evolve from "spot the phishing email" to "understand the psychological manipulation tactics AI enables."

    AI-powered scams are 4.5x more profitable than traditional fraud, according to blockchain data platform Chainalysis. They exploit cognitive biases like authority, urgency, fear, and trust, at scale and with personalization that was previously impossible. Defenders need to train people not just to recognize technical red flags, but to pause, verify, and resist the emotional pressure that AI-powered social engineering is specifically designed to create.

    How Vonage is fighting back

    At Vonage, we believe the most effective fraud defenses are built into the communications layer itself, not bolted on after the fact. Our Vonage Protection Suite is designed around exactly this principle: network-powered fraud protection that stops attacks before they reach your customers.

    Branded Calling directly counters one of AI fraud's most dangerous vectors: impersonation. By displaying your brand name, logo, and call intent on every outbound call, Branded Calling makes it virtually impossible for scammers to convincingly impersonate your business. Fraudsters love anonymity; Branded Calling takes it away. Customers who see a verified brand identity on their screen are far less likely to fall for a spoofed call — and far more likely to answer a legitimate one.

    Vonage Verify API with Silent Authentication eliminates the OTP vulnerabilities that AI-powered social engineering exploits. Rather than sending a one-time passcode that can be intercepted, phished, or manipulated, Silent Authentication validates users invisibly through their mobile network connection — no codes, no extra steps, no attack surface for fraudsters to exploit. The result: up to 26% higher sign-up conversion, 4x faster authentication, and 100% elimination of OTP-based social engineering attacks. Lydia, one of Europe's fastest-growing neobanks, deployed Silent Authentication to protect its 8 million users and saw a 50% reduction in authentication time alongside a dramatic drop in fake advisor scams.

    Identity Insights plugs real-time telecom intelligence directly into risk models. SIM Swap detection identifies when a phone number has recently been transferred to a new SIM — often a telltale sign of account takeover fraud — and enables businesses to block suspicious transactions before they complete. Subscriber Match validates user identity against mobile network data, stopping synthetic identities at the point of onboarding. Number Format cleans phone numbers by fixing formatting errors before they’re saved to your database. And Carrier ID reduces fraud risk by verifying the current and original carrier, plus network type. These are signals that only a network-native provider can access, and they represent a fundamentally different class of fraud defense than anything an over-the-top provider can offer. 

    Vonage Fraud Defender provides real-time monitoring, alerting, and blocking for SMS, Voice, and Verify traffic, protecting businesses from Artificially Inflated Traffic (AIT), SMS pumping, and other high-volume communications fraud. Since launching Fraud Defender Advanced, Vonage customers have collectively saved millions in fraud losses, with most customers achieving ROI within 60 days of implementation.

    The common thread across all of these solutions is that they operate at the network level, leveraging mobile carrier intelligence that fraudsters cannot fake, spoof, or circumvent with even the most sophisticated AI tools. As part of Ericsson, Vonage is uniquely positioned to bring this telecom-grade security to developers and enterprises worldwide through simple, programmable APIs.

    The stakes are higher than money

    It's tempting to frame this as a financial problem, and the numbers certainly justify alarm. But the implications run deeper.

    When consumers can no longer trust that the voice on the phone is real or that the email from their bank is legitimate, the foundations of digital commerce begin to erode. Trust is the invisible infrastructure that makes the modern economy function. AI-powered fraud is an attack on that infrastructure.

    The tech industry built the tools that fraudsters are now weaponizing. That comes with a responsibility, not just to build better defenses, but to think more carefully about what we build and how it can be misused before it reaches the market. The arms race is real, and right now, the wrong side is winning.

    The question isn't whether we can build AI systems capable of detecting AI-generated fraud. We can, and we are. The question is whether we can deploy them fast enough, at sufficient scale, and with enough coordination across industry, government, and civil society to close the gap before the damage becomes irreversible. 

    The window to act is open. But it won't stay open forever.

    Shield your business against rising fraud attacks

    Vonage Protection Suite is a comprehensive set of tools that simplify end-to-end protection. Mix and match the tools you need to guard your business securely.

    Frequently asked questions about AI-enabled fraud

    Select to expand or collapse this FAQ answer.

    Americans reported nearly $21 billion in cybercrime losses in 2025 — the highest total ever recorded. Reports of AI-enabled fraud tracked by Chainabuse rose 456% between May 2024 and April 2025 compared to the prior year. AI has shifted from a background tool to the central engine of modern crime, and there is no sign of it slowing down.

    Select to expand or collapse this FAQ answer.

    The attacker toolkit spans voice cloning, real-time deepfake video avatars, and AI-generated phishing emails that have eliminated the grammatical tells that once made scams detectable. Perhaps most alarming is the cost of entry: the Bluekit phishing-as-a-service kit runs under $100 for a week, and a Dark LLM subscription costs just $50/month. Fraud is no longer limited to sophisticated criminal organizations; these tools have democratized it.

    Select to expand or collapse this FAQ answer.

    When a new AI model launches, criminal forums are testing fraud applications within days, while defenders face institutional and legal constraints that slow their response. The detection tool market is growing 28–42% annually, but the threat is expanding at 900% or more in key regions — and real-world detection effectiveness drops by as much as 50% outside controlled lab settings.

    Select to expand or collapse this FAQ answer.

    Embed fraud detection at the infrastructure layer rather than the endpoint. Shift from deepfake detection to procedural resilience. Hold AI model makers accountable for genuine safety guardrails, not just terms of service. Organizations should also join shared fraud intelligence networks. Finally, human resilience training must address the psychological manipulation tactics that AI-powered social engineering exploits.

    Select to expand or collapse this FAQ answer.

    Vonage's Protection Suite builds fraud defenses into the communications layer itself, leveraging mobile carrier intelligence that fraudsters cannot fake or spoof. Key tools include Branded Calling, Silent Authentication, and Identity Insights. 

    Recent Posts