Latest Scams 2026: Inside the AI Scam Compounds Draining $21 Billion a Year
New Black Hat 2026 research and the FBI's $20.9B internet crime report expose how AI voice cloning, deepfake video and scam-compound CRMs power today's pig butchering, toll-text and job-offer scams — plus how to check a number, wallet or name for free.

Fraud stopped being a cottage industry some time around 2024. In 2026 it looks like software.
At Black Hat USA 2026 in Las Vegas, Eric Huber, senior manager for adversary intelligence and disruption at TD Bank, walked an audience through the actual tooling running inside Southeast Asian scam compounds: real-time translation engines, LLM-powered reply generators, and a full victim CRM — pipelines, tags, follow-up reminders, conversion reporting. Not metaphorically like a call centre. Literally one, with a sales funnel whose product is your savings.
That research lands on top of the FBI's 2025 Internet Crime Report, released in April 2026: 1,008,597 complaints and $20.877 billion in reported losses — both all-time records — and, for the first time in IC3's 25-year history, a dedicated section on artificial intelligence as a crime tool.
This article is the practical read on what changed, which scams are actually trending right now, and the free checks that still beat all of them.
The 2026 numbers, in plain terms
- $20.877 billion reported lost to internet crime in the US in 2025, across 1,008,597 complaints.
- $893 million across 22,364 complaints carried an explicit AI descriptor — a floor, not a ceiling, because most victims never learn AI was involved.
- $7.7 billion lost by victims aged 60+, up 37% year on year.
- $7.2 billion attributed to pig-butchering-style investment fraud alone, widely believed to be under-reported.
- Phishing/spoofing, extortion and investment schemes remained the three most-reported complaint types.
The headline is not that losses grew. It is *why* they grew: the cost of running a convincing scam collapsed. A single operator who once managed three victims in broken English now manages thirty in fluent, idiomatic, culturally-tuned conversation.
What AI actually changed inside the compounds
Four capabilities, all commercially available, all now standard kit:
- Translation at native fluency. The classic grammar tells — the ones every "how to spot a scam" listicle taught for a decade — are gone. Do not use language quality as a signal any more.
- Reply generators with persona memory. The LLM remembers your dog's name, your shift pattern, the argument you had with your sister. Warmth at scale is the entire product.
- Real-time deepfake video overlay. The "prove you're real, get on video" test has been dead since roughly 2025. Compounds now run live face and voice overlays through ordinary video calls.
- KYC bypass. Synthetic identity documents and injected liveness video defeat the identity checks banks, exchanges and dating apps rely on — which is why fake "verified" investment platforms look so convincing.
Worth naming plainly: many of the people typing on the other end are themselves trafficking victims, held in compounds after answering a fake job advert. Prosecuting the keyboard is not the same as prosecuting the operation.
The five scams trending right now
### 1. Pig butchering (AI-assisted investment fraud)
Still the single most expensive script in circulation at roughly $7.2 billion in US losses. The opener is a "wrong number" text, a friendly DM, or a hotel-reservation mix-up. Weeks of genuine-feeling conversation follow. Then a trading platform appears — polished, responsive, with a balance that goes up. Withdrawal triggers a "tax", then a "compliance deposit", then silence.
Tell: any investment opportunity that arrives *after* a relationship, not before. Read our full pig-butchering breakdown for how the laundering side works.
### 2. AI voice-cloning emergency calls
Three seconds of audio from a public video is enough. A parent hears their child crying, then a "lawyer" or "officer" takes the phone and demands bail, a fine or a wire. Older victims are targeted deliberately — the $7.7 billion figure for over-60s is not an accident.
Tell: urgency plus a refusal to let you call back. Agree a family safe word today; it costs nothing and defeats the whole script.
### 3. Deepfake executive and vendor payment fraud
A finance employee joins a video call with people who look and sound like their CFO and two colleagues, and authorises a transfer. Every participant except the victim is synthetic.
Tell: any payment instruction that arrives through a channel that isn't your normal approval workflow. Confirm out-of-band, always.
### 4. Toll, delivery and "unpaid fee" text scams
The highest-volume, lowest-value script of 2026: a text claiming an unpaid road toll, a stuck parcel, or a small government fee, linking to a near-perfect clone of the real agency site. The prize is your card details plus a one-time passcode.
Tell: real toll and postal agencies do not chase small debts by SMS link. Check the domain character by character, or run it through our phishing link checker.
### 5. Fake remote jobs and task scams
"Like these videos and earn $200 a day." The first few payouts are real. Then you're asked to deposit to unlock a higher tier. This is also the recruitment funnel that fills the compounds themselves.
Tell: any job that asks you to pay in, or interviews entirely over Telegram. See our employment-scam guide.
The signals that still work in 2026
Grammar, stock photos and clunky websites are obsolete signals. These are not:
- Payment rail. Crypto, gift cards, wire to a personal account, or "friends and family" transfers. No legitimate institution insists on an irreversible rail.
- Channel migration. Any push from the platform you met on to WhatsApp, Telegram or Signal within the first few exchanges.
- Refused callback. The single most reliable test against voice clones and deepfakes.
- Domain age. A registration date measured in days. Free to check with WHOIS.
- The "one final fee". Tax, gas, customs, compliance, release fee. There is always one more, and it is always the last one.
- A search that returns nothing — or everything. A brand-new "10-year-old investment firm" with no footprint is as suspicious as a name with twelve public scam reports.
Check before you send — free, in under a minute
Every identifier a scammer hands you is a search key. Run all of them:
- [Scam phone number lookup](/) — the number that texted or called you.
- Email, username and name search — the persona they built.
- Crypto wallet search — the address funds are going to.
- [Scam website and domain lookup](/scam-domains) — the platform holding your "balance".
- [Browse the international scammer database](/scammers) — by country or scam category.
A match means another victim already filed a moderated report on that exact identifier. No account, no paywall.
If it already happened: the first-hour checklist
- Bank and card issuer first. Wires can sometimes be recalled within 24-72 hours; card chargebacks run up to 120 days. Speed beats identification.
- Notify the receiving crypto exchange. Major exchanges freeze incoming funds on credible, fast reports.
- Preserve evidence. Screenshot the full conversation, profile URLs, wallet addresses, transaction hashes and domain names before accounts vanish.
- File officially. IC3 and reportfraud.ftc.gov (US), Action Fraud (UK), Canadian Anti-Fraud Centre, Scamwatch (AU), Europol (EU).
- [File a free public report](/report). Moderated, reporter identity never exposed — and it makes those identifiers searchable for whoever gets targeted next.
- Expect the second wave. Recovery scams find victims fast. Nobody legitimate charges an upfront fee to get your money back — see why crypto recovery services are almost always a second scam.
The honest conclusion
Detection advice built on spotting bad English and blurry logos is now worthless. The defence that survived the AI transition is procedural, not perceptual: slow down, verify on a second channel, and search every identifier before money moves. Six minutes, zero cost, and it beats a compound with a CRM.
*Sources: FBI IC3 2025 Internet Crime Report (April 2026); Black Hat USA 2026 research by Eric Huber, TD Bank; CNN Business and Dark Reading reporting, August 2026.*
Frequently asked questions
What are the latest scams in 2026?
The fastest-growing scams reported in 2026 are AI-assisted pig butchering (fake crypto investment after weeks of chat), AI voice-cloning emergency calls, deepfake video 'executive' payment requests, unpaid toll and delivery text scams, and fake remote job / task-based work offers. All five now use generative AI to scale.
How much money is lost to scams each year?
The FBI's IC3 recorded 1,008,597 complaints and $20.877 billion in reported losses for 2025 — the first time both figures crossed those thresholds. Roughly 22,364 complaints carried an AI descriptor, totalling $893 million, and the FBI treats that as a floor rather than a ceiling. Victims over 60 reported about $7.7 billion, up 37% year on year.
What is a scam compound and why does AI matter?
Scam compounds are industrial fraud centres, largely in Southeast Asia and West Africa, where trafficked workers run scripted long cons. Research presented at Black Hat USA 2026 by TD Bank's adversary-intelligence team showed these compounds now buy off-the-shelf translation engines, LLM reply generators and victim CRM platforms — the same software stack a call centre would use, aimed at fraud.
How do I check if a phone number, wallet or name belongs to a scammer?
Search the identifier on scamers.org. Our free scam phone number lookup, email, username, crypto wallet, website and name search returns moderated community reports in seconds, with no signup. A match means another victim already filed a report on that exact identifier.
How can I tell if a voice on the phone is AI-cloned?
Ask a question only the real person could answer, hang up and call back on a number you already have saved, and agree a family safe word in advance. Cloned voices handle scripted emotion well but fail on specific shared memories, and any caller who refuses a callback is a red flag.
What should I do in the first hour after being scammed?
Contact your bank or card issuer immediately (wires can sometimes be recalled within 24-72 hours, card chargebacks run up to 120 days), notify the crypto exchange that received the funds, file with IC3 or your national fraud body, and post a free public report on scamers.org so the identifiers become searchable for the next target.