U.K. rule returns 88 percent of eligible scam money to victims
More than 22,000 fraud cases connected to artificial intelligence were filed with the FBI in 2025, with victims reporting roughly $893 million in losses — the first time the agency’s Internet Crime Complaint Center tracked AI’s role in fraud filings. Pawan Jain, an associate professor of finance at the University of Michigan Flint, wrote the analysis, which was republished Monday by United Press International.
Investment fraud accounted for $632 million of the reported AI-related losses, and Americans over 60 reported $352 million of the total, according to Jain. The figures cover only victims who reported to the FBI and only cases where AI’s role could be identified.
The reported losses are a fraction of expected totals. Deloitte projects that AI-enabled fraud will help push overall U.S. fraud losses to $40 billion by 2027, up from $12.3 billion in 2023, according to Jain.
The scams themselves are familiar — panicked relatives, urgent bosses, short-windowed investment pitches — but the technology has lowered the cost and improved the quality, Jain wrote. Voice cloning now requires only a few seconds of audio and inexpensive consumer tools, and listeners in one study correctly identified an AI-generated voice only about 60% of the time. In 2024, a finance employee at the architecture and design firm Arup was tricked into wiring approximately $25 million after fraudsters staged a video meeting populated by deepfake images of the company’s chief financial officer and several colleagues, Jain wrote.
Phishing messages have grown more convincing. Language models now produce fluent, personalized messages at scale using information scraped from social media, and deepfake videos of well-known business figures are used to promote fraudulent trading platforms, Jain wrote. The cyber insurer Resilience reported that more than 85% of the losses in its claims portfolio in the first half of 2026 stemmed from attacks aimed at people rather than systems, according to Jain.
Behavioral finance research points to fear and urgency as the mechanism, Jain wrote. Stress narrows attention and pushes people toward fast, intuitive judgments at the moment they need deliberate ones. Fluency also plays a role: error-free messages in convincing voices pass defenses that clumsy imitations would have tripped, according to Jain’s own research on AI-generated communication.
AI-enabled theft does not always require direct contact with the victim, Jain wrote. Stolen personal data sells for a few dollars on dark-web markets, and criminals feed it to automated AI agents that probe bank and financial-technology accounts around the clock, testing credentials and hunting for weak points at speeds no human crew could match. Last fall, Anthropic disrupted an espionage campaign in which an AI agent performed 80% to 90% of the intrusion work against roughly 30 targets, including financial institutions, Jain wrote.
Once an attacker reaches a customer account, the takeover can be completed in minutes, Jain wrote. Instant-payment platforms like Zelle, built for speed and convenience, become the getaway car; the money typically moves within minutes and is almost impossible to recover.
Federal law is supposed to protect consumers from unauthorized electronic transfers, and regulators have said that a transfer set in motion by a fraudster counts as unauthorized even when the victim was tricked into handing over account credentials, Jain wrote. In practice, victims of instant-payment fraud often recover little because banks frequently classify losses as “authorized” when a customer was deceived into approving the payment, Jain wrote. The Consumer Financial Protection Bureau sued Zelle’s operator and three of the nation’s largest banks over their handling of alleged fraud in late 2024, then dropped the case in March 2025. New York’s attorney general filed a separate lawsuit, which a judge allowed to proceed in July. Zelle’s operator denies the allegations and has said it will appeal.
The United Kingdom has taken a different approach. Since late 2024, U.K. banks have been required to reimburse most scam victims up to £85,000 (roughly $115,000), with the cost split between the sending and receiving institutions, Jain wrote. The U.K. financial regulator’s dashboard shows that 88% of money lost to eligible scams has been returned to victims since the rules took effect, and an independent evaluation found that scam losses fell by roughly a fifth in the rule’s first year.
Jain wrote that the U.K. experience suggests that when banks bear the financial cost of fraud, they find ways to prevent it. He recommended that American regulators and Congress study the U.K. model, arguing that when payments are instant and irreversible, the risk cannot rest almost entirely on the customer, who is the least-equipped party in the chain. He also outlined household-level protections drawn from how banks secure their own operations: callback verification using a known phone number, family code words for emergency money requests, two-person authorization for large transfers, a self-imposed 24-hour wait before any big payment, two-factor login on financial accounts, transaction alerts, and credit freezes to block new-account fraud using dark-web information. If money has already moved, Jain advised calling the bank immediately to attempt a recovery and reporting the scam to the Federal Trade Commission.