Artificial intelligence is increasingly being exploited by criminals to make existing forms of fraud, impersonation, extortion and cybercrime more convincing and scalable. From deepfake video calls to cloned voices and AI-generated phishing messages, criminals are using generative AI to automate deception and target victims at greater scale.
Here are 20 major forms of AI-related criminal misuse, along with documented or widely reported real-world examples.
1. Deepfake Executive and Video-Call Fraud
Criminals use AI-generated faces and cloned voices to impersonate company executives during video meetings and authorise fraudulent transactions. In a widely reported 2024 case in Hong Kong, an employee of engineering company Arup was reportedly deceived during a fake video conference involving an AI-generated version of a senior executive, resulting in a transfer of about $25 million.
2. AI Voice-Cloning Family Emergency Scams
Scammers clone a person’s voice and call relatives pretending to be a child, spouse or other family member in an emergency. Victims may be told that their relative has been kidnapped, arrested or involved in an accident and urgently needs money.
3. Celebrity Deepfake Crypto and Investment Scams
AI-generated videos can make celebrities or public figures appear to promote cryptocurrency giveaways, investment platforms or other financial schemes. Fake videos featuring figures such as Elon Musk have been widely circulated online, often promising victims that their cryptocurrency will be doubled.
4. AI-Generated Non-Consensual Intimate Imagery
Generative AI can be used to create fake sexual images or videos of real people without their consent. Victims have included students, celebrities and private individuals, with such material also being used for harassment, humiliation and extortion.
5. AI-Generated Child Sexual Abuse Material
Generative AI can create synthetic sexual images depicting minors. Law-enforcement agencies in several countries have investigated and prosecuted cases involving the creation, possession and distribution of AI-generated child sexual abuse material.
6. AI-Enhanced Business Email Compromise
Generative AI can help criminals produce highly convincing emails, messages and voice communications that impersonate executives, finance officers or business partners. AI removes many of the spelling, grammar and language errors that traditionally helped employees identify fraudulent communications.
7. AI Personas in Romance and Investment Scams
Criminal networks can use AI-generated profile photographs, chatbots, translated messages and deepfake video to create convincing online identities. These personas may spend weeks or months building relationships before victims are persuaded to transfer money or invest in fraudulent platforms.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
8. AI-Assisted Phishing and Spear-Phishing
Generative AI allows criminals to create personalised phishing messages quickly and in multiple languages. Instead of sending poorly written generic messages, attackers can generate communications tailored to a victim’s job, organisation or recent activities.
9. AI-Generated Fake IDs and Documents
AI-based image-generation and editing tools can be misused to create or manipulate identity documents, credentials and other records. These forged documents may subsequently be used in identity theft, account takeovers, loan fraud or other financial crimes.
10. Sextortion Using AI Deepfakes
Criminals can generate fake nude or sexual images of victims and then threaten to distribute them unless the victim pays money or complies with additional demands. The technique can affect both adults and minors.
11. AI-Generated Media for Market Manipulation
Synthetic photographs, videos or audio can be created to falsely depict disasters, corporate events, political statements or other developments capable of influencing financial markets. Criminals can use such material as part of schemes designed to manipulate investor behaviour or promote fraudulent investments.
12. AI-Powered Fake Social-Media Profiles
Generative AI makes it easier to create large numbers of realistic-looking social-media accounts. Criminals can use AI-generated profile photographs, biographies and conversations to establish fake identities for romance scams, investment fraud, impersonation and other confidence schemes.
13. Celebrity and Official Impersonation for Fake Donations
Deepfake videos and cloned voices can make public figures, celebrities or officials appear to ask the public for donations. Criminals may use fabricated disaster-relief campaigns, charity appeals or other causes to collect money from victims.
14. Voice-Cloned CEO Wire-Transfer Fraud
AI voice cloning has been used in executive impersonation fraud for several years. In a 2019 case in the UK, criminals reportedly used a cloned voice to impersonate the CEO of a German energy company and persuade an employee to transfer approximately €220,000.
15. AI-Enhanced Recovery Scams
After victims have already lost money to a scam, criminals may target them again. Fake officials, lawyers, investigators or recovery agents can use AI-generated profiles, voices and documents to promise that the original money can be recovered — for an additional fee.
16. AI-Assisted Malware and Malicious-Code Creation
Criminals can misuse generative AI to help write, modify or troubleshoot malicious code. Unrestricted or criminally marketed AI services, including models promoted under names such as WormGPT, have been associated with efforts to automate malware development, phishing and other cybercrime activities.
17. AI-Generated Defamatory Audio and Video
AI can be used to fabricate recordings that appear to show real people making racist, threatening, abusive or otherwise damaging statements. Such deepfakes can cause reputational harm and, in some cases, trigger school, workplace or community disruption.
18. Bypassing KYC and Identity Verification
Criminals can use synthetic faces, manipulated identity documents, voice cloning and deepfake video to attempt to defeat Know Your Customer (KYC) and other identity-verification systems. Such techniques can facilitate fraudulent account creation, financial fraud and abuse of promotional systems.
19. Large-Scale Automated Scam Operations
Organised criminal groups can combine AI chatbots, translation systems, synthetic identities and automated communication tools to operate scams across languages and jurisdictions. AI can reduce the amount of human effort required to maintain large numbers of conversations with potential victims.
20. AI-Assisted Planning and Research for Violent Crimes
Criminal investigations in several countries have examined cases in which suspects used AI systems to research subjects connected with violent crime, weapons or the disposal of evidence. The presence of an AI query alone does not establish criminal intent, but investigators may consider such digital activity alongside other evidence.
The Larger Pattern: Across these examples, AI is generally not creating entirely new categories of crime. Instead, it is increasing the speed, scale, personalisation and credibility of existing criminal methods.
Deepfakes strengthen impersonation. Voice cloning makes phone scams more convincing. Generative AI improves phishing and social engineering. Synthetic identities support fraud at scale, while automated translation and conversational systems allow criminal groups to target victims across languages and countries.
The result is an evolving criminal ecosystem in which relatively traditional crimes fraud, extortion, impersonation, identity theft and social engineering can be conducted more efficiently with AI.
For individuals, businesses and law-enforcement agencies, this means that visual or audio evidence can no longer automatically be treated as proof of authenticity. Verification through independent channels, transaction controls, identity checks and human review remain important safeguards as AI-generated deception becomes increasingly sophisticated.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics