The incidents
Every year we uncover more AI-fraud incidents, and more agentic-fraud traces
Each bar is a widely reported US case where AI or synthetic media was confirmed or credibly reported. These are only the cases that surface (most AI-enabled fraud is never reported), and our research indicates that across 2025-2026 a fast-growing share of them were automated or agentic, run with little human effort. Markers show when the major AI models shipped.
Hover a month to see its cases
Confirmed AI Reported / suspected
The multiplier
Fraud that scales by orders of magnitude
Agentic AI goes beyond making fraud more convincing. It removes the human-labor ceiling that historically limited how many attacks could run at once. Four shifts make the difference.
01
Automated
Attacks run at machine speed. What once required hours of manual work now happens in minutes or seconds, letting a single operator manage thousands of concurrent attempts.
02
Open to anyone
Far less experience or expertise is required to carry out a successful attack. Ready-made tools and agents lower the bar from skilled operator to almost anyone with a target list.
03
Industrialized
Agentic fraud includes tools as well as attacks, deepening the fraud-as-a-service economy. The infrastructure is becoming more sophisticated, modular, and rentable.
04
Personalized
Each attack can be tailored to the individual victim with a level of detail that previously would have been worth the effort only for a very lucrative target. That research once took weeks; now it takes minutes.
Together, these four shifts make attacks harder to identify and more persuasive.
The rise
The fraud categories rising fastest, several already fueled by agentic AI
Reported losses, each category indexed to its own 2019 level. The broad climb is unmistakable: employment, government impersonation, imposter and phishing are all surging alongside the headline giants. Romance scams are believed to be an example of a heavily underreported scam, explaining the low volume. Every category is on the chart.
Source: FBI IC3 Annual Reports 2019-2025 + FTC imposter total. Real annual values.
Most exposed
How much of each fraud type an AI agent can run by itself
The longer the bar, the more of that scam an autonomous agent can handle end-to-end, which is what makes it cheap to run at massive scale. The dollar figure is how big the category already is.
Automatability is a transparent 1-5 rubric (personalization + repeated conversation + target research + automation readiness).
The anatomy
Every scam is a sequence, and agentic AI is taking every step
A scam is a chain of actions, and each link used to need a person. Agentic fraud hands the whole chain to autonomous AI, so it gets cheaper and scales without limit.
Pick a scam type to see its chain, step by step
The scenario
What happens when the labor cost goes to zero?
Fraud has always been throttled by the cost of human effort. Agents remove that throttle. This is a projection built on the data.
Every category has a share of its work that agents can already run on their own (shown on each row). Pick how many times attackers multiply that automatable work, and see where reported US losses could land.
Reported 2025 Projected at 10×
Only the automatable share of each category multiplies: projected = reported × (1 + (multiplier−1) × automatability ÷ 5). An illustrative projection built on 2025 FTC/IC3 reported losses, not a forecast.
The case files
66 incidents, every one independently sourced
These are specific, real-world AI-fraud cases: independently sourced, cross-checked against primary reporting, and included only where we have strong confidence the scheme is agentic or at least partially automated. Each is graded Confirmed AI (method documented in filings, disclosures or technical analysis) or Reported / suspected AI (credible reporting points to AI, full confirmation not yet public).
Corroboration
Independent sources see the same pattern
Independent signals from official agencies and respected research, pointing the same way. Reported figures are a floor. The true totals are larger.
Methodology & sources
How we built this report
This report joins two evidence streams, kept deliberately separate so neither inflates the other.
Layer 1 · The dots The AI-fraud incident database
A hand-built catalog of 66 US fraud events where AI or synthetic media was confirmed or credibly reported. Each event was held to five gates:
- A discrete, dated, real-world fraud event
- The AI or synthetic-media method stated by a source, never inferred
- A clear US nexus
- A financial-gain or deception-for-gain motive
- At least one resolvable, non-competitor public source
Every row was then independently re-checked against its source in a separate verification pass. Disputes were adjudicated against the criteria, duplicate reporting of the same event was collapsed into a single record, and a random ~19% sample was re-audited from scratch. Candidates that didn't clear the bar are retained in a rejected log so the funnel stays transparent.
Confirmed AI · 44 incidents
The method is documented in a filing, disclosure, or technical analysis.
Reported / suspected AI · 19
Credible reporting, a victim, or an official attributes AI, but full forensic confirmation isn't public.
Early leads · 3
A small number of incidents are early leads still being corroborated.
Layer 2 · The lines and the ladder The fraud baseline & the automatability score
Official category-level reported losses from the FBI's Internet Crime Complaint Center (IC3) and the FTC, 2019–2025.
We call this the fraud surface exposed to agentic automation, explicitly not a measure of AI fraud. It exists to show scale and growth. Baseline lines and incident counts are never added together or placed on the same axis.
The automatability score
A transparent 1–5 rubric, not a measured quantity. Each category is rated on four factors: personalization required, repeated conversation required, target research required, and automation readiness, each scored low, medium, or high (1/2/3). The four are summed and rescaled to 1–5. A higher score means more of the work is the kind agents do well.
What to keep in mind
- Reported = a floor. Independent estimates (e.g. GASA) suggest only a small share of scam losses are ever reported, so true totals are far higher.
- Growth ≠ AI. A category being large or fast-growing is not, by itself, evidence of AI. Automatability and growth are kept as separate signals; the risk is where both are high.
- The scenario is an illustration, not a forecast. It scales each category's automatable share by a chosen multiplier to show relative exposure.
- Sourcing standard. Official agencies and reputable independent research only. We deliberately exclude identity-verification vendors' proprietary “deepfakes up X%” statistics, which rest on private platform data with no independent basis; every viral figure we checked traced back to a vendor's own numbers.
- Every incident link is checked. Primary sources were tested to confirm they resolve to the event described.
Sources
- FBI IC3 Category losses, AI-tagged figures
- FTC Consumer Sentinel + data spotlights
- FinCEN Deepfake / SAR alerts
- U.S. GAO Federal fraud loss range
- Nasdaq Verafin Global financial-crime totals
- GASA / Feedzai Global scam survey + underreporting
- APWG Phishing volumes
- Chainalysis Crypto scam + AI-vendor economics
- UNODC / UN OHCHR Scam-compound industrialization
- Verizon DBIR BEC / social-engineering trends
- Microsoft AI phishing efficacy, fraud blocked
- Deloitte GenAI fraud projection
- World Economic Forum Systemic-risk framing
- Javelin US identity-fraud sizing
- Federal Reserve Bank of Boston Synthetic-identity estimate
- Palo Alto Unit 42 · Anthropic · OpenAI Automation anatomy
© Incode 2026. Reported figures are a floor, the true totals are larger; baseline category losses are the fraud surface exposed to automation, not a measure of AI fraud. Built from official and independent sources only.