MEBRO
DISINFO DESK
Technology & AI
AI Deepfake Voice Scam Epidemic: 1 in 4 Americans Targeted
How $5 voice-cloning tools and a 1,300% fraud surge are overwhelming detection systems and the regulatory response.
FILED MAR 2, 2026 · UPDATED JUL 8, 2026 · 30 SOURCES
The verdict
TRUE — active threat. One in four Americans report receiving AI deepfake voice calls. Contact-center fraud attempts surged 1,300%. Voice cloning now costs about $5/month and needs just three seconds of audio. The best detection tools still miss 30% of fakes, and federal enforcement has produced only a handful of FTC cases despite billions in losses. [1][2]
Voice-based fraud has crossed a technological threshold that changes the threat landscape for ordinary consumers. Hiya’s State of the Call 2026 report — based on a survey of over 12,000 consumers across six countries — found that one in four Americans reported receiving a deepfake voice call in the past twelve months, with a further 24% unable to tell whether the calls they receive are AI-generated. [1] Pindrop’s 2025 Voice Intelligence and Security Report independently documented a 1,300% surge in deepfake fraud attempts between 2023 and 2024, now occurring roughly every 46 seconds in U.S. contact centers. [2] Deloitte projects generative-AI-enabled fraud will reach $40 billion annually in the U.S. by 2027, up from $12.3 billion in 2023. [3]
The scale of the crisis
One in four Americans — 25% — report receiving an AI-generated deepfake voice call in the past twelve months. Drawn from Hiya’s survey of more than 12,000 consumers, it is the first large-scale primary measurement of synthetic-voice fraud targeting ordinary Americans. [1] An additional 24% said they could not determine whether calls were AI-generated — meaning a combined 49% are either confirmed targets or functionally defenseless when they answer the phone. [14]
That figure is self-reported: respondents flagged calls as deepfakes on suspicion, not technical verification, and may conflate robotic voices or awkward pauses with AI. But the direction is independently validated by Pindrop’s technically measured contact-center data. [2] When Hiya asked whether carriers or scammers are winning, scammers won nearly two-to-one; 72% of Americans now support stronger government regulation of AI voice fraud — the clearest signal that voluntary, market-driven solutions have not answered the threat. [1][14]
The technology stack — how $5 buys a convincing clone
Voice cloning crossed two thresholds at once in 2024–2025: quality and cost. On quality, University at Buffalo forensics director Siwei Lyu told Fortune that cloning has reached the “indistinguishable threshold,” generating audio with natural intonation, rhythm, emphasis, emotion, pauses, and breathing noise — describing software available today, not a future capability. [4]
On cost: in February 2025, Zyphra unveiled models that clone a voice from as little as five seconds of audio, and commercial tools now routinely clone from 3–15 seconds — audio harvestable from any public video, voicemail, or recorded call. [11] Some offer a free tier; paid plans start around $5/month, with no technical expertise required and phone-grade audio sufficient. The workflow is industrialized: find a target online, extract a sample, clone in seconds, and call their family or colleagues — major retailers report more than 1,000 AI-generated scam calls per day. [5] As Experian’s Kathleen Peters framed it, the old human-versus-bot binary has collapsed; the new problem is telling a malicious bot from a benign one in real time. [12] Deepfake volume online grew from an estimated 500,000 items in 2023 to roughly 8 million by the end of 2025 — near 900% annual growth. [4]
The fraud surge — 1,300% and counting
Pindrop analyzed over 1.2 billion calls through its deployed contact-center security platform — instrumented measurement, not survey data. [2] The headline: deepfake fraud attempts surged 1,300% between 2023 and 2024, from roughly one attempt per month to seven per day in monitored centers — one every 46 seconds. CEO Vijay Balasubramaniyan: “Voice fraud is no longer a future threat — it’s here, and it’s scaling at a rate no one could have predicted.” [2]
By sector, insurance led with a +475% increase in synthetic-voice attacks, banking +149%, and retail +107%, with 1 in every 127 calls now a fraud attempt. [15] The Pindrop figure is a known lower bound — it covers only Pindrop-monitored environments. Separate analysis by Infosecurity Magazine found AI-enabled voice and virtual-meeting fraud surged over 1,000% (1,210%) in 2025, versus a 195% rise in traditional fraud — the clearest sign that AI has become the dominant driver of fraud escalation. [15]
Pindrop; Infosecurity Magazine [15]
Who gets hurt — the human cost
Voice deepfake fraud falls hardest on older Americans. The grandparent scam — cloning a relative’s voice to call an elderly family member in a fake emergency — has been transformed by AI from crude impersonation into an attack that defeats human detection. [6] Hiya found seniors (55+) lose an average of $1,298 per deepfake voice incident, roughly triple younger adults’ losses. [14] The FBI’s 2024 Internet Crime Report is starker: Americans 60 and older filed 147,127 complaints reporting nearly $4.9 billion in losses — up 43% from 2023 — with 7,500 victims each losing more than $100,000. [22] FTC data show losses among older adults quadrupled from $600 million in 2020 to $2.4 billion in 2024. [7]
The harm extends to enterprises. A Singapore finance director authorized a $499,000 wire transfer after joining a Zoom call in which every face and voice was AI-generated. [5] The benchmark case remains the 2024 Arup incident, in which the firm lost $25 million; average enterprise loss per deepfake incident runs near $500,000. [10] Vishing surged 442% in 2025 as tools hit commodity pricing, and adults 60+ account for 58% of tech-support scam losses — a category where voice social engineering is the primary vector. [23]
The detection gap
The most structurally significant finding is not the scale of the attack — it is the inadequacy of the defense. Human listeners achieve only about 24.5% accuracy identifying high-quality deepfake audio; only 0.1% of study participants correctly identified every fake and real sample. For high-quality synthetic voice, human detection performs worse than chance. [10]
The best free public tool — the DeepFake-o-Meter from Siwei Lyu’s University at Buffalo lab — reached 69.7% likelihood accuracy in Poynter’s independent test on the January 2024 New Hampshire Biden robocall, the highest of four free tools tested. [24] It returns results in under 60 seconds and has processed 6,300+ submissions since its November 2024 launch — but it requires a file upload and cannot intercept a live call. [24] So the best available public tool misses roughly 30 of every 100 deepfakes even in controlled conditions, and for a real-time phone call, no comparable consumer tool exists at all. Enterprise platforms like Pindrop’s apply real-time detection, but only inside institutions that deployed them; individuals on personal phones have essentially none. That asymmetry between attack accessibility and defense accessibility is the core structural problem. [4]
Human-listener study; Poynter / UB DeepFake-o-Meter test [10][24]
The regulatory response — active but insufficient
On February 8, 2024, the FCC ruled unanimously that AI-generated voices are “artificial” under the Telephone Consumer Protection Act, making AI voice robocalls illegal without prior consent — triggered partly by the New Hampshire cloned-Biden robocall telling voters to stay home. [19] A July 2024 proposal to require in-call AI disclosure remained in comment review as of March 2026. The FTC finalized its impersonation rule in April 2024 (penalties up to $53,088 per violation) and brought five enforcement cases in its first year, plus Operation AI Comply. [16] It also ran a competition seeding four technical countermeasures — none yet mandated at the carrier level — while a proposal to extend the rule to individuals stays pending. [17][18]
At the state level, Tennessee’s ELVIS Act (March 2024) was the first U.S. law to protect individual voices from AI cloning, passing 93–0 and 30–0. [25] By 2025 the Transparency Coalition counted 73 new AI laws across 27 states. [27] Congress has three tracks, none addressing real-time voice authentication at the carrier level: the TAKE IT DOWN Act (signed May 2025) covers intimate imagery, not voice fraud; the NO FAKES Act carries roughly a 5% enactment probability; and the Preventing Deep Fake Scams Act creates a study group, not a prohibition. [9][26]
The undefended frontier
The epidemic is real, measurable, actively accelerating, and structurally unaddressed. The statistics are not contested: a technically verified 1,300% surge in attempts, $12.5 billion in government-certified U.S. fraud losses in 2024, and a detection gap where the best public tool misses 30% while humans do worse than chance. The technology moved faster than the institutions built to contain it — what once required specialist hardware is now a consumer subscription. [7][17][19]
Researchers frame the fix clearly: shift defense from human judgment to infrastructure-level AI detection and cryptographic media provenance. Carriers already authenticate call origin at scale via STIR/SHAKEN — but that verifies origin, not content, and cannot detect AI audio inside an authenticated call. [8] The FBI’s advice to “listen closely” is, at 24.5% human accuracy, a ritual of false confidence, not a defense. [20] Deloitte projects $40 billion in annual AI-enabled fraud losses by 2027 — a 32% compound growth rate. Without infrastructure-level intervention, the question is not whether the epidemic worsens, but by how much before defenses catch up. [3][13]
Addendum
UPDATED JUL 8, 2026
Since this dossier was filed, the government’s own accounting caught up to the threat. The FBI’s 2025 Internet Crime Report, released in April 2026, put total reported internet-crime losses at $20.9 billion — up 26% in a single year — and for the first time in the report’s history broke out AI-facilitated fraud as its own category: more than 22,000 complaints and roughly $893 million in losses tied to tools like voice cloning and deepfakes. [28] The FTC’s 2025 data told the same story from the consumer side — imposter scams, the category the cloned ‘family-in-distress’ call falls under, were the single most-reported fraud of the year and drove $3.5 billion in losses. [29]
Washington also moved past the study-group posture described above. On March 4, 2026, a bipartisan pair of senators introduced the AI Fraud Accountability Act (S.3982), which would amend the Communications Act of 1934 to make an AI-generated ‘digital impersonation’ used to defraud a federal crime as well as an FTC-enforceable violation. [30] Unlike the three tracks catalogued above — intimate imagery, a right of publicity, and a study group — it targets impersonation fraud itself. It remained a bill, not a law, as of this update, and still stops short of the carrier-level, real-time voice authentication researchers say the epidemic actually requires — but it is the first federal measure aimed squarely at the enforcement gap this investigation identified.
SOURCES · 30
- [1]Hiya — “State of the Call 2026” (March 1, 2026)
82/100 · businesswire.com
- [2]Pindrop — “2025 Voice Intelligence & Security Report”
80/100 · prnewswire.com
- [3]Deloitte — “Deepfake Banking Fraud Risk” (2024)
88/100 · deloitte.com
- [4]Fortune — “2026 will be the year you get fooled by a deepfake” (Dec 27, 2025)
85/100 · fortune.com
- [5]ScamWatchHQ — “$200 Million Deepfake Disaster” (2025)
72/100 · scamwatchhq.com
- [6]CBC News — “AI voice cloning upgrades the grandparent scam”
90/100 · cbc.ca
- [7]FTC — “Reported losses to fraud reach $12.5 billion in 2024” (March 2025)
97/100 · ftc.gov
- [8]TNS — “Top Five Voice Security Takeaways in 2025”
74/100 · tnsi.com
- [9]Congress.gov — “Preventing Deep Fake Scams Act” (H.R.1734)
98/100 · congress.gov
- [10]DeepStrike — “Deepfake Statistics 2025”
70/100 · deepstrike.io
- [11]The Register — “Zyphra clones your voice with 5s of audio” (Feb 2025)
82/100 · theregister.com
- [12]Fortune — “Experian warns AI-powered scams set to explode in 2026” (Jan 13, 2026)
85/100 · fortune.com
- [13]Biometric Update — “Deloitte predicts up to $40B from generative-AI fraud”
74/100 · biometricupdate.com
- [14]National Law Review — “State of the Call 2026” full release (March 1, 2026)
78/100 · natlawreview.com
- [15]Infosecurity Magazine — “AI voice & virtual-meeting fraud surges 1000%+” (2025)
80/100 · infosecurity-magazine.com
- [16]FTC — “Actions to protect consumers from impersonation scams” (April 2025)
97/100 · ftc.gov
- [17]FTC — “Exploratory Challenge to prevent AI voice-cloning harms” (Nov 2023)
97/100 · ftc.gov
- [18]FTC — “Proposes new protections against AI impersonation” (Feb 2024)
97/100 · ftc.gov
- [19]FCC — “AI-generated voices in robocalls are illegal” (Feb 8, 2024)
97/100 · fcc.gov
- [20]FBI / IC3 — PSA-250515: senior officials impersonated (May 2025)
98/100 · ic3.gov
- [21]FBI / IC3 — PSA-251219: impersonation campaign continues (Dec 2025)
98/100 · ic3.gov
- [22]FBI — “2024 Internet Crime Report” (IC3 Annual Report)
98/100 · ic3.gov
- [23]DeepStrike — “Vishing Statistics 2025”
70/100 · deepstrike.io
- [24]University at Buffalo — “DeepFake-o-Meter democratizes detection” (Sep 2024)
90/100 · buffalo.edu
- [25]Tennessee Governor’s Office — “Gov. Lee signs ELVIS Act into law” (Mar 21, 2024)
95/100 · tn.gov
- [26]Congress.gov — “NO FAKES Act of 2025” (S.1367)
98/100 · congress.gov
- [27]Transparency Coalition — “2025 State AI Legislation Report”
72/100 · transparencycoalition.ai
- [28]FBI / IC3 — “2025 Internet Crime Report” (April 2026)
98/100 · ic3.gov
- [29]FTC — “People Reported Losing $3.5 Billion to Imposter Scams in 2025” (June 2026)
97/100 · ftc.gov
- [30]Congress.gov — “AI Fraud Accountability Act of 2026” (S.3982)
98/100 · congress.gov
MEBRO · DISINFO DESK · mebro.app
Investigative report — not a user-submitted fact-check.
AI-built, source-verified. Every claim here was checked against the sources cited above before publishing — but don't just trust us: follow any citation to its source and confirm it yourself. That's the whole point.