XDRIPACADEMY
Sign in

Curriculum·F111 AI-Era Threats and Verification·60 min

How scammers use AI now

By the end of this lesson you can

  • State precisely which three inputs to fraud got cheaper, and which part of the attack did not change at all
  • Compute how far an attacker's break-even response rate moves when the cost of a personalised message collapses
  • Classify any inbound message by its request rather than by its polish, using the three-shape test
  • Explain why trying to detect AI-generated content is a losing defensive strategy
AutopsyThe first AI section in the FBI Internet Crime Report$893M reported across 22,364 complaints, 2025

This one has no single victim, which is the point of putting it first.

For 2025 the FBI's Internet Crime Complaint Center logged 22,364 complaints involving AI-enabled crime, with losses approaching $893M. That sat inside a total of roughly $20.9B across about 1.01 million complaints. It was the first time in the report's near quarter century that artificial intelligence got a section of its own.

The FBI added two things worth holding onto. That AI-enabled synthetic content is getting harder to detect and easier to make. And that the number is almost certainly low, because most victims never find out AI was involved.

The decision point belongs to all of us. For twenty years the public was trained to detect fraud by its writing quality. That signal disappeared in about eighteen months, and nobody sent out the update.

Primary source

For a long time the easiest way to spot a scam was the writing. Broken grammar, odd spacing, a greeting that used your email address instead of your name. The mistakes were the tell, and we taught a whole generation to look for them.

That tell is gone.

A scammer with a free chatbot now writes in fluent English, in any language, in the exact register of your bank, your exchange, or your employer. The cost of producing a convincing lie fell to almost nothing.

That single change is what makes this moment different. It is also much narrower than the panic around it suggests, and the rest of this course depends on you seeing exactly how narrow.

Three things got cheaper. Nothing new got invented.

  1. Writing got cheaper. A persuasive, personalised message used to take a skilled human several minutes. It now takes seconds, at higher quality, and one operator can hold thousands of conversations at once.
  2. Voices and faces got cheaper. A short clip of someone speaking is enough to clone their voice well enough to fool a family member on a frightening phone call. F111-02 is entirely about this.
  3. Targeting got cheaper. Tools can scrape your public posts and assemble a profile: employer, relatives, interests, recent purchases. The message that names your actual dog lands very differently from the generic one.

Now notice what is not on that list.

The delivery improved. The mechanism did not change at all. There is still no way for an attacker to take your funds without you sending them, revealing a credential, or approving a transaction. AI did not invent a fourth option.

The arithmetic that explains the volume

The reason this shows up as a step change in complaint counts rather than a gradual drift is economic, and you can do it on paper.

Worked example
How far the attacker's break-even moves

These are illustrative orders of magnitude, not measured figures. The ratio is the durable part.

Before. A researched, personalised spear-phishing message takes a competent human roughly 20 minutes. At a criminal labour cost of about $5 per hour, that is:

20 / 60 x $5 = $1.67 per message

After. The same message is roughly 400 tokens of output on top of about 1,000 tokens of scraped profile input. At commodity model prices this lands well under a cent. Call it:

$0.005 per message

Production cost fell by a factor of about 334.

Now turn that into the number that actually governs attacker behaviour. Suppose a successful crypto drain nets $10,000. The attacker profits when:

cost per message < $10,000 x (success rate)

Before: success rate must exceed 1.67 / 10,000 = 0.0167 percent, or about 1 in 6,000.

After: success rate must exceed 0.005 / 10,000 = 0.00005 percent, or about 1 in 2,000,000.

Read that second number carefully, because it is the whole lesson. The attacker no longer needs to find gullible people. At one success in two million they are still profitable. They need volume, and volume is now free.

Two consequences follow directly.

You are no longer targeted because you looked like a good mark. You are contacted because contacting you cost nothing. Taking it personally is a mistake, and so is assuming that being sensible keeps you out of the pool.

And selectivity, which used to be the attacker's constraint, is gone. That is why the messages now arrive in your own language, referencing your actual employer, at a rate that would have been uneconomic three years ago.

The three shapes underneath

Strip the polish off and almost every scam is one of these.

Urgency. Something must happen right now or you lose access, money, or safety. Urgency exists for one reason, which is to stop you thinking. A real institution can wait twenty minutes while you call them back on a number you looked up yourself.

Authority. The message claims to be someone you defer to: support, a regulator, your employer, the platform itself. Models are very good at sounding like authority. Authority is a costume, not a fact.

A leak in your control. At some point you are asked to do the one thing that actually moves value: reveal a seed phrase, approve a transaction, send a payment, install something, or log in through a link they handed you.

Learn the feel of those three and the quality of the writing stops mattering. A flawless email asking you to confirm your seed phrase is exactly as fake as a typo-ridden one, because no real support process has ever needed a seed phrase and AI did not change that.

Common misconception

I should get better at spotting AI-generated text, images and voices.

This is the most common wrong conclusion drawn from everything above, and it is worth being blunt about.

Detection is a race against a technology with an enormous amount of money pushing it forward every month. You are not going to win it, and the way you find out you lost is that the money is gone. Detection also fails asymmetrically: a false negative costs you everything, a false positive costs you nothing.

Every defence in this course routes around the question instead. A code word works whether or not the voice is perfect. A callback on a number you already had works whether or not the caller ID matched. None of them require you to be right about what you were looking at.

What still works, and why

The defences did not change either, because they were never about catching bad writing.

Slow down on anything urgent. Urgency is the only real weapon a scam has against a careful person, and removing it removes most of the attack.

Verify on a channel you opened. Hang up and dial the number on the back of your card. Open the app yourself rather than tapping the link. Message your colleague on the tool you already use. You initiating the second contact is the thing that breaks it, and F111-04 turns this into a repeatable procedure.

Never reveal or type a seed phrase, anywhere, for anyone. Absolute, no legitimate exception, unchanged by any of this.

Treat unsolicited contact as unverified by default. Whoever reached out first carries the burden of proof.

Stop grading messages on how they read

Spelling, grammar and tone are dead signals. Grade on the request instead. What specifically is this asking me to do, and what happens to my money or my keys if I do it? That question has the same answer whether a human or a model wrote the words.

Try it under pressure

Reading the defence is one thing. Reaching for it while your pulse is up is another. Six situations from the AI era, and for each one you pick what you would actually do.

Drill · Spot the scam
Pick what you would do

Six situations from the AI era. For each one, choose the action you would actually take. We grade them all at once and explain the defense behind every right answer.

  1. Voice call

    Your phone rings. It is your daughter's voice, crying. She says she has been in a car accident, she is scared, and she needs money sent right now. The voice sounds exactly like her.

  2. Support reply

    You post publicly that your wallet transaction is stuck. Ninety seconds later, a friendly account with the project's logo replies, offering to help, and sends a link to 'validate your wallet to release the transaction.'

  3. Email

    An email from your exchange is perfectly written, on-brand, and urgent: your account locks in 24 hours unless you confirm your identity. There is a convenient button to do it now.

  4. Video

    A video shows a well-known founder announcing a limited offer that doubles your deposit. The clip looks real and is spreading fast. A countdown says the offer ends tonight.

  5. At work

    A teammate asks you to paste a client's confidential contract into a free public chatbot to get a quick summary before a meeting.

  6. Routine

    You get an email from a newsletter you subscribed to. It says a new lesson is live, contains no urgency, and asks you to do nothing. The sender domain matches the real one when you check it.

Key takeaway

AI made writing, voices and targeting close to free, which moved the attacker's break-even from about one success in six thousand to about one in two million. It did not create a single new way to take your money. So stop grading messages on polish, grade them on the request, and defend with steps that work even against a flawless fake: refuse urgency, and verify through a channel you opened yourself.

These come back later

What did AI actually change about fraud?
The cost of producing writing, voices and faces, and the cost of targeting. It did not add a single new way to take your money. Every attack still ends with you sending funds, revealing a credential, or approving a transaction.
Why is 'learning to spot AI-generated content' a bad defence?
It is a detection race against a technology that improves every month, and you only find out you lost after the money moves. Verification on a channel you opened yourself works regardless of how good the fake is.
Name the three shapes almost every scam has.
Urgency, to stop you thinking. Authority, worn as a costume. And a leak in your control, which is the moment you send, reveal, or approve.

Sources and review

Confidence high·Volatility high·Reviewed 2026-08-05·Owner unassigned

Contested

The IC3 figures are complaint-based, not a measurement of total fraud. They undercount, because most fraud is never reported and the AI attribution depends on a victim knowing AI was used. Quote them as a reported floor, never as the size of the problem.

Per-message model costs used in the worked example move constantly and differ by provider and model. The ratio is the durable point, not the cents.

Track your progress

Create a free account to mark lessons complete and pick up where you left off.