A Billion Dollars, Give or Take a Rounding Error
The Federal Bureau of Investigation has, for the first time, given its annual fraud report a dedicated section on artificial intelligence. The number that earned it one: 22,364 complaints and $893,346,472 in reported losses in a single year, drawn from voice cloning, fake kidnapping calls, romance scams, and government impersonation, all running through the same generative pipeline. Even now, the bureau notes this is almost certainly an undercount — congressional researchers estimate fewer than 5 percent of victims report their losses at all, which means the real total is not $893 million so much as it is $893 million plus whatever number of embarrassed people declined to call.
The FBI got a new chart. The victims got a receipt.
The Machines Are Learning to Pass as Human, Specifically at Banks
Entrust's seventh annual Identity Fraud Report, drawn from more than one billion identity verifications across 195 countries, found that deepfakes are now linked to one in five biometric fraud attempts worldwide. Injection attacks — the practice of feeding a fabricated face or voice directly into a verification system rather than bothering to show up as a person — rose 40 percent year over year, and deepfaked selfies alone climbed 58 percent in 2025. Sources within the Identity Verification Community note that a security layer built specifically to confirm "this is a real human" is now failing that exact test with rising regularity.
The gate was built to keep people out. It did not anticipate people who no longer needed to exist.
Two-Thirds of Everyone, Give or Take
Gartner surveyed 302 cybersecurity leaders across North America, EMEA, and Asia-Pacific and found that 62 percent had experienced a deepfake-driven attack — social engineering, impersonated video calls, spoofed biometric checks — in the past year. That is not a niche threat model anymore; that is most of the room raising a hand. In a development that will surprise no one who has been paying attention, "62 percent of organizations" is the kind of statistic that used to describe things like "uses cloud storage," not "has been personally deceived by a synthetic executive."
The Algorithm did not need to hack the network. It just needed to sound like the CFO.
The Projection Nobody Wants to Be Right About
Deloitte's Center for Financial Services has modeled where this goes next, running FBI complaint categories through a generative-risk score and landing on a range: $22 billion in a conservative scenario, $40 billion in an aggressive one, by 2027 — up from roughly $12 billion in 2023. That is a compound annual growth rate of 32 percent, which is the kind of number that gets circled in a strategy deck right before someone asks who is supposed to stop it.
Nobody has yet volunteered.
The Tally So Far
Four institutions — a federal law enforcement agency, an identity verification firm, an analyst house, and an accounting giant — independently arrived at the same conclusion using four different methodologies: this is not a hypothetical. It is a line item. The fraud has already been committed, tallied, and filed. The only open question is which quarter the number gets worse in.
The receipts, dear reader, keep arriving. Nobody has managed to keep them from being generated in the first place.
Sources: Malwarebytes (FBI IC3 data) · Entrust · Gartner · Deloitte



