How AI agents are fueling a record surge in fraud losses

A headshot photo of Veljko Davidovic.
Veljko Davidovic

August 13, 2026

How AI agents are fueling a record surge in fraud losses

Every leap in AI has made fraud a little more convincing. Chatbots gave scammers fluent, native-sounding scripts. Voice cloning gave them a familiar voice on the phone. Generated video gave them a face to wear on a live call.

Each leap lowered the cost of an attack. Agentic AI is the leap that makes it limitless.

Picture an operation that never sleeps, never gets tired, and never has to explain itself to anyone. It researches its next target while messaging its last one, running thousands of conversations at once, in perfect English, for the price of an API call. This is already happening, at scale, and it is why fraud losses just had their worst year on record.

A timeline view of AI-related incidents. Incidents spike around 2024, alongside the release of GPT-4 and Sora.
AI-related fraud incidents have skyrocketed since 2024. These are only extremely well-documented cases; the true number of incidents is likely much higher.

Fraud no longer has limits

For as long as fraud has existed, it has been capped by the number of people a criminal operation could hire, train, and manage.

Yet fraud losses keep setting records anyway. The FBI's Internet Crime Complaint Center logged 20.9 billion dollars in reported US cyber-enabled losses in 2025. The FTC recorded an all-time high the same year. Global scam losses are growing at nearly 20% annually, according to Nasdaq Verafin. The workforce is essentially fixed, but the output from that workforce has kept climbing every year.

Our newly published Agentic Fraud Report lays out why: autonomous AI agents have removed the human labor ceiling that used to throttle how many attacks could run at once. An agent researches a target, opens a conversation, adapts to replies, and adjusts after every rejection, across thousands of victims simultaneously. It never needs to sleep, and it learns in minutes.

Insights from Incode’s Agentic Fraud Report

The report's incident database tracks 66 independently sourced, cross-checked AI-fraud cases in the US, with 44 confirmed through documented methods. Documented AI-enabled fraud grew more than fivefold between 2023 and 2025, after sitting near zero for years, and those are only the cases that became public.

Reported losses across those catalogued cases approach 900 million dollars, and that figure represents only a fraction of the true total. An estimated 93% of scam losses never reach official statistics, according to the Global Anti-Scam Alliance. Voice cloning now appears in over half of catalogued cases, and AI chatbots and agents running scams end to end are the fastest-growing method.

Nine in ten catalogued incidents fall into fraud categories that an autonomous agent can already run fully on its own, and FBI and FTC data show those same categories growing fastest. Employment scams are up 8.5x since 2019, government impersonation is up 6.4x, and investment fraud has climbed nearly 39x.

A graph displaying the rise in agentic fraud, 2019-2025. Tech and customer support fraud is off-the-charts, as is investment fraud. Employment fraud and government impersonation fraud are the next highest categories.
Tech/customer support and Investment fraud are the categories hit hardest by agentic fraud.

The true threat of agentic fraud

The report grades each fraud category on a simple 1-to-5 scale for how much of it an agent can already run end to end, no human required. Confidence and romance scams score a perfect 5 out of 5. Investment fraud, imposter scams, and business email compromise all score 4 out of 5, and together those three categories already account for more than 15 billion dollars in reported losses.

A graphic displaying the relative maturity of various types of agentic fraud. Romance fraud is the highest, scoring a 5/5, closely followed by investment fraud, imposter scams, business email compromise, and employment fraud.
Many categories of fraud are already running on their own, or nearly there.

One case from the report's files makes this concrete. In 2024, engineering firm Arup lost 25 million dollars after an employee joined a video call where every other participant, including someone who appeared to be the company's CFO, was a real-time deepfake. No one on that call needed criminal skill. A convincing mask was enough.

The criminal supply chain confirms the shift is already industrialized. Payments to AI scam-service vendors have surged roughly 1,900 percent since 2021. AI-generated phishing converts 4.5x better than human-written attempts. Ninety percent of fraud professionals report facing more AI-driven attacks than they did two years ago.

Where this trend goes if nothing changes

The report's most sobering section is a projection built directly from the data. Reported US fraud losses hit 20.4 billion dollars in 2025. If attackers multiply their already-automatable work by 10x, a plausible near-term scenario given how fast agent capability is improving, that figure could reach 155.3 billion dollars. At the higher end of the report's model, losses could multiply by up to 25x.

A graphic displaying the forecasted losses if agentic fraud were to improve 25x. Losses are estimated at $380.1 billion annually under these conditions.
If agent activity increased by 25x, projected fraud losses could reach $380.1 billion in the US alone.

This projection is built on real 2025 data. It shows what happens to a system when the cost of running an attack drops toward zero. As our founder and CEO Ricardo Amper put it, "For all of history, fraud was capped by how many skilled people a criminal operation could hire. That cap is gone."

The same architecture that can staff a company with tireless digital workers is already staffing scam operations with tireless digital criminals, fluent in every language, awake at every hour, and nearly free to copy.

Agentic fraud is here

Fraud was once limited by how many bad actors existed. That assumption no longer holds. Fraud now scales like software, and defenses built for a labor-constrained threat will not hold against one that isn't.

That mismatch is exactly why identity verification becomes essential in an agentic world. If an agent can run a scam end to end, the only reliable checkpoint left is confirming there is a real, verified person on the other side of the interaction. It's also why we built our own Risk AI Agent and Agentic Identity capabilities to meet that threat on its own terms.

Trying to understand the implications of agentic fraud on your business today? Read the full Agentic Fraud Report for the complete case files, methodology, and projection model.

Curious how Incode can help you stay ahead in the era of agentic fraud? Request a demo today.

A headshot photo of Veljko Davidovic.
Veljko Davidovic
Veljko Davidovic is Senior Manager, GTM Strategy & Growth at Incode, where he leads growth marketing for North America. With 15 years in technology marketing across B2C and B2B SaaS, he has built lean, high-performance teams and driven measurable growth for brands including NVIDIA, Sonos, Xiaomi, Cisco, Nutanix, and Symantec, with experience spanning North America, EMEA, and APAC.
Linkedin
Chapters