Log in Sign up My Account
Deepfake Fraud Statistics 2026: The Real Numbers, Sourced

Deepfake Fraud Statistics 2026: The Real Numbers, Sourced

Every few weeks another headline claims deepfake fraud grew by some four-digit percentage. Most of these numbers are real — they just come from different datasets, different time windows, and different definitions of "attack." Here's what happens when you put them side by side.

Definition

Deepfake fraud is AI-generated audio, video, or image content used to impersonate a real person in order to authorize a payment, bypass identity verification, or manipulate a victim.

In 2026 it's the fastest-growing category of AI-enabled fraud. The FBI, Gartner, and multiple identity-verification vendors now track it as a distinct threat rather than folding it into ordinary phishing or social engineering.

This report pulls together the figures we could trace to a named, dated source, so security, fraud, and trust-and-safety teams can size the actual risk rather than repeat a stat that's already stale. It was last checked against source reports on August 27, 2026, and will be updated as new data lands.

Metric Figure Source
US AI-fraud losses reported to FBI (2025) ~$893 million, 22,000+ complaints FBI Internet Crime Report 2025
Biometric fraud attempts involving deepfakes 1 in 5, globally Entrust 2026 Identity Fraud Report
Organizations hit by a deepfake attack in past year 62% Gartner CISO Survey, Sept. 2025
Projected US generative-AI fraud losses by 2027 $40 billion (up from $12.3B in 2023) Deloitte Center for Financial Services
Growth in contact-center deepfake attempts (YoY) 1,300%+ Pindrop 2025 Voice Intelligence Report
Single largest disclosed case (Arup, 2024) $25.6 million lost via video-call impersonation CFO Dive
Check before you trust it

Want to check a suspicious file right now?

UncovAI scans text, image, video, and audio for signs of AI generation in seconds.

Try It Free →

How big is the problem, really?

The clearest headline number comes from the FBI: its 2025 Internet Crime Report logged the bureau's first standalone AI-fraud category, with over 22,000 complaints and roughly $893 million in reported losses in the US alone. That's a floor, not a ceiling — it only counts what victims reported and attributed to AI.

Identity-verification data adds a second, independent confirmation. Entrust's 2026 Identity Fraud Report, built from more than a billion identity checks across 195 countries, found that deepfakes now sit behind one in five biometric fraud attempts globally — deepfaked selfie attempts up 58% year over year, and injection attacks (feeding synthetic video straight into a verification pipeline rather than holding a fake up to a camera) up 40%.

On the corporate side, Gartner's late-2025 CISO survey found that 62% of organizations had already experienced a deepfake attack in the previous year, and a separate 2026 Gartner survey put the share of organizations hit by a deepfake-plus-social-engineering phone attack at 41%. Different survey, different question, same direction.

Where the money is going

Loss estimates vary more than attack-volume estimates, mostly because most incidents never disclose a dollar figure. Still, a few numbers are well-anchored:

  • Deloitte's Center for Financial Services projects generative-AI-enabled fraud losses in the US alone will reach $40 billion by 2027, up from $12.3 billion in 2023 — a trajectory built from losses banks are already booking, not a hypothetical.
  • Sumsub's Identity Fraud Report tracked "sophisticated" fraud — deepfakes, synthetic identities, and telemetry tampering — growing from 10% to 28% of all identity fraud between 2024 and 2025, even as the overall identity fraud rate ticked down slightly. The attacks are getting rarer but sharper.
  • Contact centers are a particular soft spot: Pindrop's analysis of 1.2 billion calls found deepfake fraud attempts in that channel rose more than 1,300% in a single year, moving from roughly one attempt a month to seven a day.

The single case that still best illustrates the mechanism is the 2024 Arup incident, where a finance employee in Hong Kong joined a video call with people who looked and sounded exactly like his CFO and colleagues — and transferred $25.6 million across 15 payments before anyone realized every person on that call was synthetic. No technical system failed. The employee followed procedure and checked with "colleagues" who appeared to be in the room. The room itself was fake.

Why detection alone won't fix this

It's worth being honest about the limits here, since we build detection tools ourselves. Gartner's own guidance is blunt: detection scores are probabilistic, vendor benchmarks aren't standardized against each other, and adversaries iterate faster than any single model can be retrained. A detector that scores 98% on last quarter's generators tells you little about a generator released last week.

Human judgment doesn't close that gap either. Surveys have repeatedly found that most people perform close to a coin flip at telling a cloned voice from a real one. That's the actual argument for layered defense: detection tools that flag likely synthetic content, paired with process controls — callback verification, out-of-band confirmation for anything involving money or credentials — rather than detection as a single point of trust.

What this means if you're the one being targeted

Three patterns show up across almost every dataset in this report:

  1. Executive and finance-team impersonation is the highest-value target. Real-time voice or video cloning aimed at authorizing a payment or a credential reset is where the biggest single losses happen.
  2. Contact centers and account-recovery flows are the highest-volume target. This is a numbers game for attackers, and it scales with how cheap voice cloning has become.
  3. Reported losses undercount the real number by a wide margin, both because many incidents go unreported and because non-financial harms — harassment, non-consensual imagery, reputational damage — don't show up in a dollar figure at all.

Put this into practice

If any of the patterns above sound like your team's exposure — wire approvals over video, phone-based account recovery, vendor onboarding — the fastest next step isn't a new policy document. It's checking your actual risk surface.

  • Run a real call recording, a vendor-submitted ID photo, or a video approval request through a detector before you act on it.
  • Check text, image, video, and audio in one pass rather than juggling separate tools per format.
  • Build the habit into the workflow that already carries the risk: anything involving money, credentials, or an identity check gets an out-of-band confirmation, no exceptions for "the CFO seemed rushed."

Frequently asked questions

How much has deepfake fraud grown in 2026?

Growth depends on what's measured. Sumsub found "sophisticated" identity fraud — deepfakes, synthetic identities, telemetry tampering — grew from 10% to 28% of all identity fraud between 2024 and 2025. Pindrop found deepfake attempts in contact centers rose more than 1,300% year over year. Both are accurate; they're measuring different channels.

How much money has deepfake fraud cost?

The FBI's 2025 Internet Crime Report attributes roughly $893 million in US losses to its new AI-fraud category, though that's a floor based only on reported, attributed incidents. Deloitte projects total US generative-AI-enabled fraud losses will reach $40 billion by 2027.

Can humans reliably detect a deepfake voice or video on their own?

No. Surveys cited in Gartner's guidance and echoed across the industry find most people perform close to chance at distinguishing a cloned voice from a real one in real time, which is why the recommended defense pairs detection tools with process controls like out-of-band callback verification.

Is AI detection software 100% accurate?

No, and any vendor claiming otherwise should be treated skeptically. Detection scores are probabilistic, benchmarks aren't standardized across vendors, and generators released after a detector was trained can evade it. Detection is one layer in a defense strategy, not a single point of trust.

Who is most often targeted by deepfake fraud?

Two distinct patterns: executive and finance-team impersonation (highest dollar value per incident, e.g. the $25.6M Arup case) and contact-center or account-recovery flows (highest volume, driven by how cheap voice cloning has become).

Sources

FBI Internet Crime Report 2025 · Entrust 2026 Identity Fraud Report · Gartner CISO Survey (Sept. 2025, n=302) and 2026 role-based survey (n=297) · Deloitte Center for Financial Services, Deepfake Banking Fraud Risk on the Rise · Sumsub Identity Fraud Report 2025–2026 · Pindrop 2025 Voice Intelligence & Security Report · CFO Dive reporting on the Arup incident (2024).

Check before you trust it

UncovAI's detection engine checks text, image, video, and audio for signs of AI generation in seconds — including the real-time voice-cloning scenario described above. If your team handles wire transfers, vendor changes, or executive approvals over video or phone, see what it catches.

Get Started Free →