AI voice scams go global: multichannel fraud soars

The gist

AI-powered voice scams are exploding worldwide, blending calls, texts, and fake sites to steal billions with alarming speed and sophistication.

What to know

  • By September 2026, attackers were using AI to launch coordinated voice and SMS campaigns, luring victims to convincing Microsoft-style sign-in fakes.
  • AI lets scammers mass-produce personalized, multilingual phishing—KnowBe4 saw a 449% spike in AI-powered vishing, and the FBI warns to always verify requests through known channels.
  • Imposter scams hit record highs in 2025, with the FTC logging over 1 million reports and global losses soaring past $3.5 billion.

Coordinated Phishing Playbooks

Attackers now blend calls, texts, and fake websites in synchronized campaigns, industrializing multichannel phishing beyond isolated scams.

By late September 2026, the attack pattern had become visibly coordinated across channels rather than confined to a single phishing touchpoint. IT Brew reported that Microsoft in September 2026 revealed a “convincing combination of social engineering and realistic infrastructure” in which a threat actor “calls (or texts) a target’s personal phone number,” then directs the employee to “a website closely resembling a Microsoft sign-in page” to steal credentials and session tokens, showing the operational template of voice or SMS contact fused with a fake webpage to run personalized phishing at scale.

That late-September shift did not emerge from nowhere; it built on an already rising base of blended-channel phishing that was becoming easier to industrialize. IT Brew cited a SoSafe study conducted in September and October 2025 in which more than a quarter, 28%, of 100 security and IT leaders reported an increase in “multichannel attempts that combined email, calls, or SMS within the same campaign,” a timeline-adjacent signal that by late September 2026 attackers were broadly deploying integrated call, text, and web lures rather than isolated one-off scams.

Sources

AI Voices Blur Reality

Large language models and voice cloning let scammers impersonate colleagues across languages and channels, making real-time deception routine and scalable.

What makes these attacks harder to stop is not just better wording but automation of the persuasion layer. ToxSec argues that LLMs are industrializing the attack chain, able to produce thousands of personalized lures at once by using public information to reference colleagues, projects, and company context. As one July interview put it, even attackers without English-language skills can now generate convincing phishing or vishing, turning multilingual impersonation from a specialist craft into a fast, repeatable workflow that sounds polished enough to pass as routine business communication.

The credibility jump comes when AI moves across channels and into voice, where people are easier to pressure in real time. Security Intelligence noted that in 2024 scammers used voice cloning tools to pretend to be the company's CEO, and the fraud was only stopped when an executive challenged the caller with a personal question. At DEFCON’s John Henry contest, AI systems used different voices and tactics across calls, while N2K Networks reported Sophos tracking about 150 custom domains posing as help desks and near-perfect MFA pages. The FBI repeated in a 2025 warning that people should verify through a separate, known channel, and the FTC received over one million reports of imposter scams in 2025, with losses up nearly 20% to $3.5 billion.

Sources
ToxSec - AI and CybersecuritySiliconANGLE theCUBESecurity IntelligenceN2K NetworksEssential Risk Management: Cybersecurity for CreativesIntruvent Edge

Fraud at Industrial Scale

AI-driven scams are fueling record-breaking financial losses and complaint volumes, with single fraudsters automating thousands of attacks and targeting victims worldwide.

The escalation is no longer anecdotal; it is showing up in formal threat telemetry and abuse reporting. PR Newswire highlighted KnowBe4’s 2025 Phishing Threat Trends Report with a “67% Surge in Abuse of Legitimate Platforms” and a “449% Spike in AI-Powered Vishing Attacks,” while warning that “a single fraudster, armed with off-the-shelf AI tools, could soon run as many as 10,000 automated scams in a single day,” compressing what “once demanded call centres, scripts and manpower” into a far more scalable operation. Researchers tracking the “Ghost Stadium” campaign also found “over 3,500 malicious domains” aimed at fans, including fake FIFA login portals and fraudulent ticket sales, alongside “more than 2,500 FIFA account credentials” already circulating—evidence of a threat large enough to be counted across both infrastructure and victimization.

The same growth is visible in fraud losses and complaint volumes. The420.in cited a UK energy company that lost roughly ₹2.2 crore to an AI-cloned executive voice and a Hong Kong multinational that lost close to ₹215 crore in a deepfake video-conference scam; it also reported that India’s Ministry of Home Affairs told Parliament cyber fraud losses topped ₹22,495 crore in 2025, while “digital arrest” scams using AI-generated officials drew more than 90,000 complaints and losses near ₹3,000 crore, with 47 per cent of adults saying they had direct or secondhand exposure to such scams.

Sources

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.