← Back to the Ai blog
AISecurity

AI Scams and Deepfakes: Why Verified Identity Is Your Best Defense

Voice clones and deepfake video calls are stealing billions. Learn how AI identity scams work, why passwords aren't enough, and how blockchain-verified identity helps.

A finance employee joins a video call with the company’s CFO and several colleagues. Everyone looks and sounds right. The CFO asks for a series of urgent transfers. The employee complies — and $25 million disappears. Every other person on that call was a deepfake.

That isn’t a movie plot. It happened to the global engineering firm Arup in Hong Kong in early 2024 (CNN). And it’s a warning for all of us: when AI can copy a face and a voice, “I saw them” and “I heard them” are no longer proof of anything.

This article explains how AI identity scams work, why traditional security is falling behind, and how verified digital identity — including blockchain-based identity — can help protect individuals and communities.

The Scale of the Problem

The FBI’s 2025 Internet Crime Report, released in April 2026, shows cyber-enabled crime cost Americans nearly $21 billion in reported losses (FBI). Key findings:

  • Over 1 million complaints were filed, up from about 860,000 in 2024.
  • Cryptocurrency-related complaints caused the largest losses — more than $11 billion.
  • Americans over 60 reported about $7.7 billion in losses, up 37%.
  • For the first time, the report included a section on artificial intelligence: 22,364 AI-related complaints costing nearly $893 million.

The FBI specifically warns about scammers using “fake social profiles, voice clones, identification documents, and believable videos depicting public figures or loved ones.”

And those are only the reported cases. Many victims never come forward.

How AI Identity Scams Work

Voice cloning

A few seconds of audio from a social media video or voicemail is enough to clone a voice. Scammers then call a parent or grandparent: “Mom, I’ve been in an accident, I need money now.”

Deepfake video calls

As the Arup case shows, criminals can now fake live video meetings with multiple participants. Business email compromise has evolved into business video compromise.

Synthetic identities and fake documents

AI generates realistic ID photos, passports, and selfies that can fool weak verification systems, allowing scammers to open accounts in someone else’s name — or in the name of a person who doesn’t exist.

Impersonation at scale

AI chatbots can run thousands of romance scams, fake investment “advisors,” and customer-support impersonations simultaneously, 24 hours a day, in any language.

Why Traditional Security Is Falling Behind

Most of our security was designed for a world where faces and voices were hard to fake.

  • Passwords can be phished by convincing AI-written messages.
  • One-time codes can be tricked out of people through social engineering.
  • Security questions rely on information that is often public on social media.
  • “Seeing is believing” no longer works when video itself can be generated.

The core problem is simple: these methods verify something you know or something you look like — exactly what AI is now good at copying.

The Shift: From “Looks Like” to “Can Prove”

The answer isn’t to get better at spotting fakes. AI will keep improving. The answer is to rely on things AI can’t fake: cryptographic proof.

Here’s the idea. A verified digital identity is tied to a cryptographic key — a secret that only the real person controls. When someone contacts you, the question is no longer “Do they look like my boss?” but “Can they prove, cryptographically, that they are my boss?” An AI can clone a face. It can’t forge a digital signature without the private key.

Where Blockchain Fits In

Blockchain adds three important properties to verified identity.

1. No single point of failure

Traditional identity databases are centralized — one breach exposes millions. Blockchain-based identity systems distribute trust across many independent computers, so there is no single database to steal.

2. Tamper-proof credentials

Credentials — like “this person is a verified employee” or “this account belongs to this artist” — can be issued by trusted parties and anchored on a blockchain. Anyone can verify them, and no one can quietly alter them.

3. User control and privacy

With approaches known as self-sovereign identity and verifiable credentials, you hold your credentials in your own wallet and share only what’s needed. You can prove you’re over 18 without revealing your birthday, or prove you’re a real customer without handing over your ID.

Community verification

Identity is also social. When a community of people who know each other vouch for one another — and those attestations are recorded transparently — impersonation becomes much harder. A deepfake can fool one person. It’s far harder to fool a network of people who can each verify independently.

A Realistic View

Blockchain identity is promising, but not a finished solution. Adoption is still early, standards are evolving, and a stolen private key is as dangerous as a stolen password. Verified identity is one strong layer — not a replacement for common sense.

What You Can Do Today

  1. Create a family “safe word.” Agree on a secret phrase that must be used in any emergency request for money.
  2. Verify through a second channel. If your “boss” or “bank” calls with an urgent request, hang up and call back using a number you already know.
  3. Slow down. The FBI’s advice is to “Take a Beat.” Urgency is the scammer’s main weapon.
  4. Limit public voice and video samples where possible, especially for children and older relatives.
  5. Use passkeys and hardware security keys instead of passwords and SMS codes where available.
  6. Follow verified accounts only. For artists and projects, check the official website and verified wallet before buying or clicking.
  7. Report scams to local authorities or, in the U.S., at ic3.gov.

Why This Matters for the Art World

Digital artists are prime targets for impersonation. Fake profiles copy artists’ names and work, fake “drops” steal buyers’ funds, and cloned support accounts drain wallets. A verified on-chain identity — one public wallet, linked from official channels — protects both artists and collectors.

The Red Flags of an AI-Powered Scam

Whatever form the scam takes — a phone call, a video meeting, a message, or a social media profile — it usually carries at least one of these warning signs:

  • Urgency. “You must act right now” or “Don’t tell anyone yet.”
  • Secrecy. Requests to keep the conversation private from family, colleagues, or your bank.
  • Unusual payment methods. Gift cards, wire transfers to new accounts, or cryptocurrency sent to an unfamiliar wallet.
  • A change of channel. Moving you from an official platform to a private chat app.
  • Emotional pressure. Fear, love, or excitement that pushes you to skip normal checks.
  • Requests for codes or seed phrases. No bank, platform, or real artist will ever ask for these.

If you notice any of these, stop. Verify through a channel you already trust before you do anything else.

Frequently Asked Questions

How can I tell if a video call is a deepfake? Visual clues — odd blinking, mismatched lighting, lip-sync issues — are getting harder to spot as AI improves. Don’t rely on your eyes. Instead, verify through a separate channel: call the person back on a known number, ask a question only they would know, or use a pre-agreed safe word.

Is blockchain identity available today? Parts of it are. Verifiable credentials, crypto wallets used as login identities, and “proof of personhood” projects exist, but they’re not yet universal. For now, the most practical steps are passkeys, hardware security keys, and verifying through trusted channels.

Doesn’t putting identity on a blockchain hurt privacy? Well-designed systems don’t store personal data on-chain. They store cryptographic proofs, while your actual information stays in your own wallet. You share only what’s needed, when it’s needed.

Who is most at risk from AI scams? Everyone, but older adults suffer the largest losses. The FBI reports that Americans over 60 lost about $7.7 billion in 2025. Talk to older family members about voice-clone scams and set up a family safe word together.

The Bottom Line

AI has made faces and voices cheap to copy. The defense is to base trust on things that can’t be copied: cryptographic proof, verified credentials, and communities that verify one another. Until those systems are everywhere, the best protection is a mix of new tools and old wisdom — slow down, verify, and never let urgency make the decision for you.

At Gambocco, every work and every announcement comes from our verified identity. If it doesn’t come from our official channels, it isn’t us.

This article is for educational purposes only.