骗子是怎么把 AI 用在诈骗和欺诈上的?How Criminals Misuse AI for Scams and Fraud
用克隆的声音自导自演一场「绑架」,为你一个人量身定写钓鱼邮件:网络犯罪拿到了一次大幅升级。下面逐一拆解那些冲着你的钱和身份来的手法,以及真正能拦住它们的办法。
Cloned voices staging a "kidnapping," phishing written to fit you alone: cybercrime has been handed a significant upgrade. What follows is a walk through the exact tactics aimed at your money and your identity, plus the measures that genuinely shut them down.
你觉得自己一眼就能看穿骗局?放在 2026 年,这份自信未必靠得住。错字连篇的粗糙邮件、一听就是机器人的电话,基本已被淘汰。罪犯现在用的是 AI:复制他人的声音、写出挑不出毛病的钓鱼话术,还会花几周甚至几个月,与目标慢慢培养出一段感觉无比真实的关系。
跟踪这些工具被挪作犯罪用途的各种方式,正是 DSH Plugin Hub 在做的事,好让你不必亲身踩坑才学会。压缩成一句话:新的骗术类型并没有出现——只是老骗局变得更便宜、更难被发现,而且逼真得令人不安。
01AI 诈骗的演变:2026 年为何不一样
老式诈骗靠的是量:把成千上万条一模一样的话撒出去,指望有极小一部分人咬钩。AI 把这套逻辑颠倒过来。网不再撒得又大又糙,而是收紧、贴身、令人后颈发凉——用关于你的真实信息缝制而成,素材正是你自己曾经公开发布过的内容。
AI 诈骗只是更大图景中的一块拼图。隐私、偏见、数据安全——整个数字风险的地貌,在我们的 普通用户面对的 AI 风险 指南里有更深入的梳理。
这件事的规模如今已被官方记录在案。美国联邦调查局的网络犯罪投诉中心(IC3)发布 2025 年度报告时,首次把 AI 单列为一个独立的诈骗类别——而这个数字被普遍认为是低估的,因为在大多数案件里,受害者根本不知道其中用到了 AI。详细内容见 FBI 的完整公告。
来源:FBI 网络犯罪投诉中心(IC3)发布的《2025 年互联网犯罪报告》。另外,德勤金融服务中心(Deloitte's Center for Financial Services)预计,随着这类工具越来越便宜、越来越易用,美国的 AI 诈骗损失到 2027 年可能攀升至 每年约 400 亿美元。
02语音克隆与伪造的「绑架」电话
设想手机响了。听筒里在哭的,是你的孩子或伴侣,说自己出了事故,或者说被人带走了。那声音不会认错——音调、语速,连叫你名字的方式都对。可这一切都不存在。是机器在实时合成。
一通假绑架电话的完整流程
- 开场:一个陌生号码亮起屏幕,紧接着是你熟悉的声音,带着哭腔——「妈,求你了,他们抓了我!」
- 施压:第二个声音加入进来,自称「绑匪」,要求立刻电汇或购买礼品卡,说是保你家人平安的条件。
- 隔离:不许挂电话,也不许联系别人——剩下的交给恐慌,清醒的思考被挤到一边。
03只为一个人写的钓鱼邮件
满是错字的「尼日利亚王子」邮件,如今基本成了古董。这类借助 AI 的攻击通常叫「鱼叉式钓鱼」:它让语言模型翻遍你的 LinkedIn、早已被遗忘的帖子以及公开记录,然后一封只为你一个人起草的邮件就落进了你的收件箱。
冒充 CEO 诈骗(BEC)
冒充银行
快递与退税诈骗
密码重置陷阱
企业面临这一威胁不是理论问题,而是数字问题:FBI 的数据把 2025 年超过 6.32 亿美元的投资诈骗损失,以及约 3000 万美元的商业邮件诈骗损失,直接归因于使用了 AI 的手法——安全研究人员预计这两个数字还会继续攀升。想亲自举报,美国的官方渠道是 FTC 的 ReportFraud.ftc.gov。
04恋爱诈骗与数字「伪装身份」
恋爱诈骗从来都残忍,AI 添上的是「规模」。现在不必再有人花上几个小时,一个个去哄、去陪聊。一个被调教得听起来很懂感情的聊天机器人,可以同时维持几十段「恋情」:记得住生日,会问你今天过得如何,信任一点点垒高,人的防备就这样自己塌下来。
等到钱终于被提起——包装成一场医疗急症,或者一张「终于要见面」的机票——它已经不像诈骗了,而像是在帮一个你在乎的人。想先把安全习惯打牢,我们的 入门指南 把该有的基本功都列了出来。
05虚假投资与深度伪造加密货币骗局
金融犯罪同样在被改写。靠深度伪造视频,可以用一个复制出来的富豪或财经名人,办一场看起来「现场直播」的投资讲座——而且画面早已不是过去那种粗糙的拼贴。
- 🕵️
收集数据
→
🤖
AI 生成
→
🎣
抛下诱饵
→
💸
取走钱财
→
🛡️
你来核实
062026 年如何识别 AI 诈骗
骗局做到这般精致,凭直觉已经拦不住,找错别字也毫无用处。真正有效的习惯是:凡是你没有预料到的紧急请求,一律先当作可疑来对待。几个值得留意的信号:
- 声音上的异常:该有换气停顿的地方往往没有,背景里坐着一层奇怪的杂音,被人打断时反应也不自然。
- 画面上的异常:在深度伪造通话里,眨眼节奏不对,脸部轮廓发虚变糊,或者嘴唇比声音慢上一点。
- 紧迫加保密:要求你立刻行动、并且不要告诉任何人——仅凭这一条,就已经是最响亮的警号之一。
- 付款方式不合常理:正规企业或政府部门,没有任何理由要求你用加密货币、电汇或礼品卡付款。
07一套真正管用的防护流程
这些并不意味着你只能任人宰割。几个习惯,就足以让你变成明显更难下手的对象。
- 1
和家人约定一个安全词
随便挑一个词。如果有「家人」哭着打来电话,就让他报出这个词——克隆出来的声音根本答不上来。
2
先挂断,再回拨
来电显示不值得信任。如果自称是你银行或上司的人打来电话,先把通话结束,再用他们公开的号码自己拨过去。
3
收紧社交账号
把个人资料设为私密。要做出你的克隆,骗子需要你的声音录音和你的照片。
4
用动作检验视频通话
让对方猛地把头转向一侧,或者摸一下鼻子。合成视频往往正是在这一刻露馅。
如果你或身边的人已经被盯上,FTC 消费者警示页面 上有用日常语言写成的最新指引;也可以直接在 ReportFraud.ftc.gov 提交举报。
08大家常问的问题
AI 会在哪些方面被滥用于诈骗和欺诈?
有没有办法判断一通电话是 AI 克隆声音打来的?
AI 写的钓鱼邮件比普通钓鱼邮件更容易骗到人吗?
AI 恋爱诈骗是什么样子?
2026 年我要怎么做,才能让 AI 诈骗离自己远一点?
You reckon a con would never fool you? In 2026, that confidence may be misplaced. The sloppy emails full of typos and the stilted robocalls have largely been abandoned. What criminals reach for now is AI: voices duplicated, phishing copy written without a single flaw, and relationships patiently cultivated with a target over weeks or months until they feel entirely genuine.
Tracking the ways these tools get bent to criminal use is what DSH Plugin Hub does, so the lesson does not have to be learned the painful way. Condensed: no new species of fraud has appeared — the existing ones simply became cheaper to operate, tougher to detect and unnervingly believable.
01How AI Scams Changed: What Makes 2026 Its Own Thing
Volume was the old strategy — fire thousands of interchangeable messages into the void and count on a tiny fraction taking the bait. AI inverts that. The net is no longer wide and crude; it is tight, tailored and quietly alarming, stitched together from genuine facts about you that were harvested from whatever you had already posted publicly.
Fraud powered by AI is one piece of a larger picture. Privacy, bias, data security — the whole terrain of digital risk gets a fuller treatment in our guide to everyday AI risks.
Official statistics now capture the scale. When the FBI's Internet Crime Complaint Center (IC3) published its 2025 annual report, AI appeared as a standalone fraud category for the very first time — and the figure is broadly regarded as an undercount, because in most cases victims never learn that AI played a part. The full FBI announcement has the details.
Source: the 2025 Internet Crime Report, published by the FBI's Internet Crime Complaint Center (IC3). Separately, Deloitte's Center for Financial Services expects these tools to grow cheaper and simpler to operate — and US losses from AI-enabled fraud to rise toward $40 billion annually by 2027.
02Cloned Voices and the Fake "Kidnapping" Call
Imagine the phone buzzing. On the line, sobbing, is your child or your partner, telling you there has been an accident or that they have been seized. The voice is unmistakable — the pitch, the rhythm, the particular way they pronounce your name. Only none of it is happening. A machine is producing it live.
Inside a Fake-Kidnapping Call, Step by Step
- The opening: an unfamiliar number lights up the screen, and then a voice you know, in tears — "Mom, please, they've got me!"
- The squeeze: a second voice joins in, the supposed "kidnapper," insisting on an immediate wire transfer or gift cards as the price of your family member's safety.
- The isolation: hanging up is forbidden, calling anyone else is forbidden — and panic does the rest, crowding out clear thought.
03Phishing Written for One Person Only
The typo-riddled "Nigerian Prince" message is a relic. Spear phishing, as the AI-assisted variety is known, puts language models to work combing your LinkedIn profile, half-forgotten posts and public records — after which a message drafted for you and nobody else lands in your inbox.
CEO Fraud (BEC)
Impersonating the Bank
Delivery and Tax Cons
The Password Reset Trap
Businesses face this too, not in theory but in the numbers: FBI data ties more than $632 million of 2025 investment-fraud losses, along with roughly $30 million lost to business email compromise, straight to tactics that used AI — and researchers in security expect both totals to keep rising. To report an attempt yourself, the official US route is the FTC's ReportFraud.ftc.gov.
04Romance Fraud and Digital Catfishing
Cruelty was always part of romance fraud; what AI added is scale. Nobody has to spend hours charming one victim after another by hand any more. A chatbot tuned to sound emotionally present keeps dozens of "relationships" running in parallel — birthdays recalled, small questions about your day asked, trust assembled so gradually that defences come down on their own.
When the subject of money finally surfaces — dressed up as a medical crisis, or a plane ticket for the long-awaited first meeting — it no longer reads as fraud. It reads as coming to the aid of somebody you love. Our starter guides lay out the safety habits worth having first.
05Bogus Investments and Deepfake Crypto Schemes
Financial crime is being reshaped as well. With deepfake video, a convincing "live" investment seminar can be staged around a duplicated billionaire or finance celebrity — and the quality is no longer the crude cut-and-paste it once was.
- 🕵️
Harvesting Data
→
🤖
Generating with AI
→
🎣
Setting the Bait
→
💸
Taking the Money
→
🛡️
You Check
06Recognising an AI Scam in 2026
With scams this well finished, instinct is no longer a shield, and hunting for spelling mistakes gets you nowhere. The habit that does work: assume any urgent request you did not expect is suspect until proven otherwise. Some signals worth knowing:
- Oddities in the audio: breaths tend to be missing where they ought to fall, a strange hiss sits in the background, and interruptions provoke odd responses.
- Oddities in the video: on a deepfake call, blink patterns look wrong, the outline of the face softens into blur, or the lips slide a fraction behind the sound.
- Pressure plus secrecy: an instruction to move at once and inform nobody is, by itself, one of the loudest warning signs there is.
- Payment methods that do not fit: a genuine company or government body has no reason to demand cryptocurrency, a wire transfer or gift cards.
07A Protection Routine That Works
None of that leaves you defenceless. A handful of habits is enough to make you considerably harder to hook.
- 1
Agree a family safe word
Pick something arbitrary. Should a "loved one" ring you in distress, ask for that word — a clone will have no way to supply it.
2
Hang up, then dial back
Caller ID deserves no trust. When your bank or your manager supposedly calls, end the conversation and ring their published number yourself.
3
Tighten your social accounts
Switch profiles to private. To build a clone, a criminal needs recordings of your voice and your photographs.
4
Test a video call for deepfakes
Ask the person to snap their head to one side, or to touch their nose. Synthetic video tends to glitch at exactly that moment.
If you or somebody close to you has already been approached, the FTC Consumer Alerts page carries up-to-date guidance written in ordinary language, and a report can be filed straight away at ReportFraud.ftc.gov.