AI has many great things to offer, like making things faster, helping us make better decisions, and even improving online security. It can automate tasks, analyze huge amounts of data, and even create content.
However, as more people use AI, new worries about safety arise. Cybercriminals use AI to create trickier, more sophisticated and realistic attacks, ranging from shopping scams to voice and video impersonations.
How is AI used for fraud?
- Phishing emails: Attackers use AI to create realistic emails. It can review information you've posted online (such as on social media) and craft emails that are perfectly personalized just for you. AI can mimic the tone of a real company and eliminate simple mistakes like typos, making the email appear legitimate.
- Voice scams and deepfakes: Impersonating your banker, known brands, organizational leaders, or even loved ones asking for help, fake video or audio content can look and sound like a real person. This makes it harder for people to spot the scams.
- Creating fake identities: AI can generate a fake yet realistic personal identity—with a fake name, address, and more—by mixing real and fake information. These synthetic identities can be used to open new fraudulent accounts or apply for loans.
What is the impact?
- Large consumer losses.
- $16 billion in 2024, per the Internet Crime Complaint Center (IC3)
- $5 billion lost by ages 60+ due to internet crime per the FBI
- $50.5 billion reported losses since 2020, with a growing portion stemming from deepfake scams.
- Fraud supercharged by technology
- Deepfakes are becoming increasingly sophisticated and harder to detect, according to the American Bankers Association (ABA) Foundation
- 83% of 2024 fraud losses reported to IC3 are attributed to cyber-enabled fraud, where criminals use the internet or other technology
- 82.6% of all phishing emails analyzed exhibited some use of AI.
How can you protect yourself?
- Stop and Verify: If you receive a call, email, or video request asking for money or sensitive information, never act immediately. Call the person or company back using an official, known phone number—not the number that called or emailed you
- Be careful what you share: AI tools collect data. Never provide private or sensitive information to chatbots or AI assistants. Additionally, when using social media, be mindful of what information you post and check your privacy settings.
- Question the intent: If a message or call makes you feel a certain way in order to get you to act, stop and verify.
Additionally, always follow the National Cybersecurity Alliance's Core 4 security practices when going online for both personal, school, and business-related use:
- Use a strong password: Make sure your passwords are unique and difficult to guess. Don't write them down where others can find them.
- Enable multi-factor authentication (MFA): This requires an additional step to sign in, such as receiving a code on your phone. Use it for all your services, especially for financial services, remote access, virtual private networks (VPNs), and accounts that access sensitive information.
- Keep your software updated: Install new updates for your apps and operating systems right away. This important step ensures security is up to date for web browsers and apps. Ensure your antivirus software updates automatically and runs regular scans.
- Watch out for phishing attacks: Stay vigilant when learning about phishing attack risks. Use caution when interacting with unexpected links and attachments or unknown websites.
If you suspect your information has been compromised, send a notification to ReportFraud@arvest.com, report it to the FTC at ReportFraud.ftc.gov, and to the FBI at IC3.gov.
