骗子是怎么把 AI 用在诈骗和欺诈上的?How Criminals Misuse AI for Scams and Fraud

🚨 网络犯罪警示⏱11 分钟阅读📅更新于 2026 年 7 月

用克隆的声音自导自演一场「绑架」,为你一个人量身定写钓鱼邮件:网络犯罪拿到了一次大幅升级。下面逐一拆解那些冲着你的钱和身份来的手法,以及真正能拦住它们的办法。

◆知微•🚨 网络犯罪警示 · ⏱11 分钟阅读 · 2026 年 6 月 23 日
🚨 Cybercrime Alert⏱ 11 min read📅 Updated July 2026

Cloned voices staging a "kidnapping," phishing written to fit you alone: cybercrime has been handed a significant upgrade. What follows is a walk through the exact tactics aimed at your money and your identity, plus the measures that genuinely shut them down.

◆知微•🚨 Cybercrime Alert · ⏱ 11 min read · June 23, 2026

你觉得自己一眼就能看穿骗局?放在 2026 年,这份自信未必靠得住。错字连篇的粗糙邮件、一听就是机器人的电话,基本已被淘汰。罪犯现在用的是 AI:复制他人的声音、写出挑不出毛病的钓鱼话术,还会花几周甚至几个月,与目标慢慢培养出一段感觉无比真实的关系。

跟踪这些工具被挪作犯罪用途的各种方式,正是 DSH Plugin Hub 在做的事,好让你不必亲身踩坑才学会。压缩成一句话:新的骗术类型并没有出现——只是老骗局变得更便宜、更难被发现,而且逼真得令人不安。

01AI 诈骗的演变:2026 年为何不一样

老式诈骗靠的是量:把成千上万条一模一样的话撒出去,指望有极小一部分人咬钩。AI 把这套逻辑颠倒过来。网不再撒得又大又糙,而是收紧、贴身、令人后颈发凉——用关于你的真实信息缝制而成,素材正是你自己曾经公开发布过的内容。

AI 诈骗只是更大图景中的一块拼图。隐私、偏见、数据安全——整个数字风险的地貌,在我们的 普通用户面对的 AI 风险 指南里有更深入的梳理。

这件事的规模如今已被官方记录在案。美国联邦调查局的网络犯罪投诉中心(IC3)发布 2025 年度报告时,首次把 AI 单列为一个独立的诈骗类别——而这个数字被普遍认为是低估的,因为在大多数案件里,受害者根本不知道其中用到了 AI。详细内容见 FBI 的完整公告。

22K+
带 AI 标记的诈骗投诉量(FBI,2025 年)
$893M
上报的 AI 诈骗损失金额(几乎肯定被低估)
3 sec
克隆一段声音所需的音频时长

来源:FBI 网络犯罪投诉中心(IC3)发布的《2025 年互联网犯罪报告》。另外,德勤金融服务中心(Deloitte's Center for Financial Services)预计,随着这类工具越来越便宜、越来越易用,美国的 AI 诈骗损失到 2027 年可能攀升至 每年约 400 亿美元。

02语音克隆与伪造的「绑架」电话

设想手机响了。听筒里在哭的,是你的孩子或伴侣,说自己出了事故,或者说被人带走了。那声音不会认错——音调、语速,连叫你名字的方式都对。可这一切都不存在。是机器在实时合成。

一通假绑架电话的完整流程

  1. 开场:一个陌生号码亮起屏幕,紧接着是你熟悉的声音,带着哭腔——「妈,求你了,他们抓了我!」
  2. 施压:第二个声音加入进来,自称「绑匪」,要求立刻电汇或购买礼品卡,说是保你家人平安的条件。
  3. 隔离:不许挂电话,也不许联系别人——剩下的交给恐慌,清醒的思考被挤到一边。

03只为一个人写的钓鱼邮件

满是错字的「尼日利亚王子」邮件,如今基本成了古董。这类借助 AI 的攻击通常叫「鱼叉式钓鱼」:它让语言模型翻遍你的 LinkedIn、早已被遗忘的帖子以及公开记录,然后一封只为你一个人起草的邮件就落进了你的收件箱。

👔极高风险

冒充 CEO 诈骗(BEC)

AI 把你上司的文风复制得分毫不差:一条消息催你立刻把款打给一家「新供应商」,或者为一场「客户会议」去采购礼品卡。
🏦高风险

冒充银行

你确实做过的近期交易、你本人真实的账号、用得毫无破绽的银行业术语——这些细节全被搬出来,只为骗你点下那个恶意链接。
📦中风险

快递与退税诈骗

编造出来的物流单号,以及写着「派送失败」「退税」的消息,里面如实印着你家的地址——全部由 AI 生成。
🔑偏高风险

密码重置陷阱

一次真实的密码重置在 AI 帮助下被触发;随后一封格式毫无瑕疵的邮件请你「确认」这次变更——你的账号密码就这样走出门外。

企业面临这一威胁不是理论问题,而是数字问题:FBI 的数据把 2025 年超过 6.32 亿美元的投资诈骗损失,以及约 3000 万美元的商业邮件诈骗损失,直接归因于使用了 AI 的手法——安全研究人员预计这两个数字还会继续攀升。想亲自举报,美国的官方渠道是 FTC 的 ReportFraud.ftc.gov。

04恋爱诈骗与数字「伪装身份」

恋爱诈骗从来都残忍,AI 添上的是「规模」。现在不必再有人花上几个小时,一个个去哄、去陪聊。一个被调教得听起来很懂感情的聊天机器人,可以同时维持几十段「恋情」:记得住生日,会问你今天过得如何,信任一点点垒高,人的防备就这样自己塌下来。

等到钱终于被提起——包装成一场医疗急症,或者一张「终于要见面」的机票——它已经不像诈骗了,而像是在帮一个你在乎的人。想先把安全习惯打牢,我们的 入门指南 把该有的基本功都列了出来。

05虚假投资与深度伪造加密货币骗局

金融犯罪同样在被改写。靠深度伪造视频,可以用一个复制出来的富豪或财经名人,办一场看起来「现场直播」的投资讲座——而且画面早已不是过去那种粗糙的拼贴。

AI 诈骗的完整链条——陷阱是怎么合上的
  1. 🕵️
    收集数据

    →

    🤖
    AI 生成

    →

    🎣
    抛下诱饵

    →

    💸
    取走钱财

    →

    🛡️
    你来核实

062026 年如何识别 AI 诈骗

骗局做到这般精致,凭直觉已经拦不住,找错别字也毫无用处。真正有效的习惯是:凡是你没有预料到的紧急请求,一律先当作可疑来对待。几个值得留意的信号:

  • 声音上的异常:该有换气停顿的地方往往没有,背景里坐着一层奇怪的杂音,被人打断时反应也不自然。
  • 画面上的异常:在深度伪造通话里,眨眼节奏不对,脸部轮廓发虚变糊,或者嘴唇比声音慢上一点。
  • 紧迫加保密:要求你立刻行动、并且不要告诉任何人——仅凭这一条,就已经是最响亮的警号之一。
  • 付款方式不合常理:正规企业或政府部门,没有任何理由要求你用加密货币、电汇或礼品卡付款。

07一套真正管用的防护流程

这些并不意味着你只能任人宰割。几个习惯,就足以让你变成明显更难下手的对象。

抵御 AI 诈骗的四步守则
  1. 1

    和家人约定一个安全词
    随便挑一个词。如果有「家人」哭着打来电话,就让他报出这个词——克隆出来的声音根本答不上来。



    2

    先挂断,再回拨
    来电显示不值得信任。如果自称是你银行或上司的人打来电话,先把通话结束,再用他们公开的号码自己拨过去。



    3

    收紧社交账号
    把个人资料设为私密。要做出你的克隆,骗子需要你的声音录音和你的照片。



    4

    用动作检验视频通话
    让对方猛地把头转向一侧,或者摸一下鼻子。合成视频往往正是在这一刻露馅。

如果你或身边的人已经被盯上,FTC 消费者警示页面 上有用日常语言写成的最新指引;也可以直接在 ReportFraud.ftc.gov 提交举报。

08大家常问的问题

AI 会在哪些方面被滥用于诈骗和欺诈?
涉及的路径有好几条:用克隆的声音冒充亲属索要现金、为某个人单独撰写的钓鱼邮件、深度伪造视频通话、由 AI 搭起的恋爱骗局,以及自动运转的假客服。它们合在一起,让诈骗成本更低、上线更快、也更难被戳穿。
有没有办法判断一通电话是 AI 克隆声音打来的?
要听「缺了什么」。自然的换气停顿、情绪激动时依然有温度的语气、以及应对嘈杂背景音的能力——这些都是克隆容易失手的地方。一旦对方急着要钱,就结束通话,用你确认属于本人的号码打回去。
AI 写的钓鱼邮件比普通钓鱼邮件更容易骗到人吗?
确实更容易。它的语法毫无瑕疵,你上司或银行的语气能被精确复现,再加上从社交平台取来的真实个人信息,整封邮件读起来就是 100% 正规。这类请求,都应该换一个渠道再核实一遍。
AI 恋爱诈骗是什么样子?
聊天机器人被用来在几周、有时几个月里培植真实的情感依恋。信任是前提;一旦信任成立,编造的紧急事件就成了开口要钱的由头。因为说话的是 AI,几百名受害者可以同时应付。
2026 年我要怎么做,才能让 AI 诈骗离自己远一点?
给家人之间约定一个应急「安全词」;开启多因素认证;任何主动打来或发来的消息,都不构成转账的理由;视频通话时让对方转头或摸脸来验证;并把社交资料保持为非公开状态。
◆

知微

我们做的事,是研究 AI 风险,再把它变成普通用户能用的安全建议。内容的准确性已于 2026 年 7 月复核。如果你成了 AI 诈骗的目标,请 联系我们的团队,并立即向当地网络犯罪主管部门报案。

You reckon a con would never fool you? In 2026, that confidence may be misplaced. The sloppy emails full of typos and the stilted robocalls have largely been abandoned. What criminals reach for now is AI: voices duplicated, phishing copy written without a single flaw, and relationships patiently cultivated with a target over weeks or months until they feel entirely genuine.

Tracking the ways these tools get bent to criminal use is what DSH Plugin Hub does, so the lesson does not have to be learned the painful way. Condensed: no new species of fraud has appeared — the existing ones simply became cheaper to operate, tougher to detect and unnervingly believable.

01How AI Scams Changed: What Makes 2026 Its Own Thing

Volume was the old strategy — fire thousands of interchangeable messages into the void and count on a tiny fraction taking the bait. AI inverts that. The net is no longer wide and crude; it is tight, tailored and quietly alarming, stitched together from genuine facts about you that were harvested from whatever you had already posted publicly.

Fraud powered by AI is one piece of a larger picture. Privacy, bias, data security — the whole terrain of digital risk gets a fuller treatment in our guide to everyday AI risks.

Official statistics now capture the scale. When the FBI's Internet Crime Complaint Center (IC3) published its 2025 annual report, AI appeared as a standalone fraud category for the very first time — and the figure is broadly regarded as an undercount, because in most cases victims never learn that AI played a part. The full FBI announcement has the details.

22K+
Fraud complaints carrying an AI flag, per the FBI in 2025
$893M
Losses reported from AI-enabled fraud (almost certainly understated)
3 sec
audio required to clone a voice

Source: the 2025 Internet Crime Report, published by the FBI's Internet Crime Complaint Center (IC3). Separately, Deloitte's Center for Financial Services expects these tools to grow cheaper and simpler to operate — and US losses from AI-enabled fraud to rise toward $40 billion annually by 2027.

02Cloned Voices and the Fake "Kidnapping" Call

Imagine the phone buzzing. On the line, sobbing, is your child or your partner, telling you there has been an accident or that they have been seized. The voice is unmistakable — the pitch, the rhythm, the particular way they pronounce your name. Only none of it is happening. A machine is producing it live.

Inside a Fake-Kidnapping Call, Step by Step

  1. The opening: an unfamiliar number lights up the screen, and then a voice you know, in tears — "Mom, please, they've got me!"
  2. The squeeze: a second voice joins in, the supposed "kidnapper," insisting on an immediate wire transfer or gift cards as the price of your family member's safety.
  3. The isolation: hanging up is forbidden, calling anyone else is forbidden — and panic does the rest, crowding out clear thought.

03Phishing Written for One Person Only

The typo-riddled "Nigerian Prince" message is a relic. Spear phishing, as the AI-assisted variety is known, puts language models to work combing your LinkedIn profile, half-forgotten posts and public records — after which a message drafted for you and nobody else lands in your inbox.

👔Critical exposure

CEO Fraud (BEC)

Your manager's writing style, reproduced exactly by AI: a message arrives pressing you to wire funds to a "new vendor" without delay, or to pick up gift cards for a "client meeting."
🏦Severe risk

Impersonating the Bank

Recent transactions you really made, your genuine account number, banking jargon used faultlessly — every one of those details deployed to get your click onto a malicious link.
📦Moderate risk

Delivery and Tax Cons

Made-up tracking numbers, and messages about a "failed delivery" or a "tax refund" that carry your precise home address — all of it generated by AI.
🔑Elevated risk

The Password Reset Trap

A genuine password reset is triggered with AI's help; a flawlessly formatted follow-up then asks you to "confirm" it — and your credentials walk out the door.

Businesses face this too, not in theory but in the numbers: FBI data ties more than $632 million of 2025 investment-fraud losses, along with roughly $30 million lost to business email compromise, straight to tactics that used AI — and researchers in security expect both totals to keep rising. To report an attempt yourself, the official US route is the FTC's ReportFraud.ftc.gov.

04Romance Fraud and Digital Catfishing

Cruelty was always part of romance fraud; what AI added is scale. Nobody has to spend hours charming one victim after another by hand any more. A chatbot tuned to sound emotionally present keeps dozens of "relationships" running in parallel — birthdays recalled, small questions about your day asked, trust assembled so gradually that defences come down on their own.

When the subject of money finally surfaces — dressed up as a medical crisis, or a plane ticket for the long-awaited first meeting — it no longer reads as fraud. It reads as coming to the aid of somebody you love. Our starter guides lay out the safety habits worth having first.

05Bogus Investments and Deepfake Crypto Schemes

Financial crime is being reshaped as well. With deepfake video, a convincing "live" investment seminar can be staged around a duplicated billionaire or finance celebrity — and the quality is no longer the crude cut-and-paste it once was.

The Lifecycle of an AI Scam — How the Trap Closes
  1. 🕵️
    Harvesting Data

    →

    🤖
    Generating with AI

    →

    🎣
    Setting the Bait

    →

    💸
    Taking the Money

    →

    🛡️
    You Check

06Recognising an AI Scam in 2026

With scams this well finished, instinct is no longer a shield, and hunting for spelling mistakes gets you nowhere. The habit that does work: assume any urgent request you did not expect is suspect until proven otherwise. Some signals worth knowing:

  • Oddities in the audio: breaths tend to be missing where they ought to fall, a strange hiss sits in the background, and interruptions provoke odd responses.
  • Oddities in the video: on a deepfake call, blink patterns look wrong, the outline of the face softens into blur, or the lips slide a fraction behind the sound.
  • Pressure plus secrecy: an instruction to move at once and inform nobody is, by itself, one of the loudest warning signs there is.
  • Payment methods that do not fit: a genuine company or government body has no reason to demand cryptocurrency, a wire transfer or gift cards.

07A Protection Routine That Works

None of that leaves you defenceless. A handful of habits is enough to make you considerably harder to hook.

A Four-Step Defence Against AI Scams
  1. 1

    Agree a family safe word
    Pick something arbitrary. Should a "loved one" ring you in distress, ask for that word — a clone will have no way to supply it.



    2

    Hang up, then dial back
    Caller ID deserves no trust. When your bank or your manager supposedly calls, end the conversation and ring their published number yourself.



    3

    Tighten your social accounts
    Switch profiles to private. To build a clone, a criminal needs recordings of your voice and your photographs.



    4

    Test a video call for deepfakes
    Ask the person to snap their head to one side, or to touch their nose. Synthetic video tends to glitch at exactly that moment.

If you or somebody close to you has already been approached, the FTC Consumer Alerts page carries up-to-date guidance written in ordinary language, and a report can be filed straight away at ReportFraud.ftc.gov.

08Questions We Get Asked

In what ways does AI get misused for scams and fraud?
Several routes are involved: a cloned voice pretending to be a relative and demanding cash, phishing written for one individual, deepfake video calls, romance fraud built by AI, and fake customer-service operations that run automatically. Together they make fraud less costly, quicker to launch and far tougher to expose.
Is there a way to know a call is coming from an AI voice clone?
Listen for what is missing. Natural pauses for breath, a voice that keeps its warmth when emotions run high, and the ability to cope with messy background sound are all places where a clone stumbles. If money is being demanded urgently, end the call and ring the person back on a number you know is theirs.
Do AI-written phishing emails fool people more easily than ordinary ones?
They do. Grammar comes out flawless, the tone of your manager or your bank can be reproduced exactly, and authentic personal details lifted from social platforms make the message read as 100% legitimate. Any request of that kind should be confirmed through a second channel.
What does an AI romance scam look like?
Chatbots are deployed to cultivate real emotional attachment over weeks, sometimes months. Trust is the precondition; once it exists, an invented emergency becomes the pretext for asking for money. Because AI does the talking, hundreds of victims can be handled at the same time.
What can I do in 2026 to keep AI fraud away from me?
Set up a family 'safe word' for crises; turn on multi-factor authentication; treat any unsolicited call or text as no reason at all to send money; confirm a video call by getting the other party to tilt their head or tap their nose; and leave social profiles closed to the public.
◆

知微

Our work is investigating AI risks and turning them into practical safety advice for ordinary users. Accuracy was reviewed in July 2026. Been targeted by an AI scam? Get in touch with our team, and report the incident to your local cybercrime authorities without delay.