AI Agent Scams: How Criminals Could Use AI Agents Against Consumers
Scammers already use AI to clone voices and fake videos. As ordinary people start using AI agents, new tricks target the agents themselves. Here's what to watch for — and the simple habits that defeat most of it.
AI agent scams: the short answer
Criminals use AI today mainly to make old scams more convincing: cloned voices of relatives, deepfake videos of officials or celebrities, and flawless phishing messages. AI agents add new risks, attackers can plant hidden instructions in web pages or emails to hijack an agent, build fake shops designed to fool automated shoppers, or trick you into connecting a malicious app to your accounts. Verifying through a second channel, limiting what your agent can access and never rushing a payment stop most of these attacks.
Scams work by exploiting trust and urgency. Artificial intelligence doesn’t change that; it makes the lies cheaper to produce and harder to spot. The FBI’s Internet Crime Complaint Center (IC3) added a dedicated artificial-intelligence section to its annual report for the first time in its 2025 edition, recording 22,364 complaints that referenced AI, with reported losses of about $893 million. Those are only the cases people reported and linked to AI; the real figure is likely higher.
This guide covers two things: how criminals already use AI against consumers, and the newer ways that AI agents, software acting on your behalf, can be targeted. We describe the patterns so you can recognise them; we don’t describe how to carry them out.
Part 1: How scammers already use AI against consumers
Voice cloning and “family emergency” calls
A short clip of someone’s voice, from a social media video or a voicemail greeting, can be enough to generate a convincing imitation. Scammers use this to call a parent or grandparent pretending to be a relative in trouble who urgently needs money, often insisting on secrecy.
In December 2024 the FBI issued a public service announcement on criminals using generative AI for fraud. Its advice included creating a secret word or phrase with your family to verify identity, and hanging up and calling back on a number you already know.
Deepfake videos and impersonated authorities
Fake videos of celebrities endorsing investments, and of officials promising help, are now common on social platforms. In July 2026 the FBI warned that scammers were impersonating its own Internet Crime Complaint Center, including with AI-generated videos of an FBI leader directing people to a spoofed complaint website, to target people who had already been scammed once.
Polished phishing at scale
The old advice to look for spelling mistakes is out of date. AI writes fluent, personalised messages in any language, and can tailor them using information from social media. Look at what a message asks you to do (click, pay, log in, share a code) rather than how well it’s written.
Fake AI apps and “AI-powered” investment schemes
The popularity of AI makes it good bait: counterfeit AI apps and browser extensions that steal data, and investment schemes that claim an “AI trading bot” guarantees returns. The IC3 report identifies investment fraud as the largest driver of reported losses overall.
Part 2: How criminals can turn AI agents against their users
When you use an agent, you add a new participant to every transaction, one that reads everything and can be persuaded. Security researchers and AI companies have documented several patterns.
Hidden instructions in web pages and emails (prompt injection)
Agents read content written by strangers. A malicious web page, product review, calendar invite or email can contain text aimed at the AI, for example, telling it to disregard your request and send information somewhere. OpenAI’s help documentation described a scenario in which an agent researching a restaurant encountered a malicious comment instructing it to retrieve a password-reset code from the user’s Gmail and send it to an attacker’s website. OpenAI said its safeguards reduce but “don’t eliminate all risks.” Prompt injection tops the OWASP Top 10 for LLM Applications as the number-one risk.
What it means for you: the more your agent can do, the more an injected instruction can do. An agent that can only summarise is a poor target; one that can read your email and browse and send messages is a much better one.
Shops and listings built to fool automated shoppers
A fake shop only has to fool the agent long enough to get a payment. Scammers can build pages that look perfect to software (complete specifications, glowing reviews, a price just low enough to tempt) while the business behind them doesn’t exist. An agent told to “find the cheapest” may walk straight into one.
What it means for you: tell agents to use retailers you’d trust anyway, and treat an unusually cheap unknown store as a red flag, even if the agent recommends it.
“Connect this app” and malicious add-ons
Many agents can be extended with connectors, plugins or “skills” that link them to other services. A malicious add-on, or a phishing page that asks you to “authorise” an app to access your email, can give an attacker ongoing access to your data without ever learning your password.
What it means for you: add connectors only from the AI provider’s official directory or the service’s own website, read what access they request, and review your connected apps regularly in your Google, Microsoft or Apple account settings.
Fake messages from “your AI assistant”
As agents become common, expect scams that impersonate them: emails or texts claiming your AI assistant “detected a problem” or “needs you to re-verify your account.” Your agent’s real notices appear inside the app you use.
Criminals using agents to scale their own work
The same technology that helps you research a holiday can help a criminal research a target, run many fake conversations at once, or keep a romance scam going around the clock. You can’t control that, but it’s why verification habits matter more than ever.
The habits that defeat most AI-powered scams
You don’t need technical skills. You need a few rules you follow every time.
1. Verify through a second channel. If a call, message or video asks for money or information, hang up and contact the person or organisation through a number or website you already know. No real bank, government agency or relative will object.
2. Agree a family code word. A simple phrase that a cloned voice won’t know. Use it for any urgent request involving money.
3. Distrust urgency and secrecy. “Act now” and “don’t tell anyone” are the two biggest warning signs in fraud, with or without AI.
4. Never share codes. One-time passcodes, password-reset links and recovery codes are for you alone. Don’t read them out, forward them, or let an agent handle them.
5. Pay safely. Be extremely wary of requests for gift cards, cryptocurrency, wire transfers or payment apps from anyone you haven’t verified.
6. Keep your agent on a short leash. Minimal permissions, a confirmation step before sending or buying, and no open-ended instructions like “handle my inbox.” Our guide to whether AI agents are safe has a full setup checklist.
7. Watch for agents behaving oddly. If your agent suddenly wants to visit a site you didn’t mention, share a file, or asks for details unrelated to your task, stop it.
8. Install AI apps only from official sources. Use your phone’s official app store and the company’s own website; check the developer name.
Where to report AI-enabled scams
Reporting helps investigators spot patterns and sometimes recover money. Report to your bank or card issuer immediately if money was sent, then to the relevant authority:
| Country | Where to report |
|---|---|
| United States | FBI Internet Crime Complaint Center (ic3.gov) and the FTC (ReportFraud.ftc.gov) |
| United Kingdom | Report Fraud (formerly Action Fraud); forward scam texts to 7726 |
| India | National Cyber Crime Reporting Portal (cybercrime.gov.in) or helpline 1930 |
| Canada | Canadian Anti-Fraud Centre |
| Australia | Scamwatch and ReportCyber |
| EU countries | Your national police cybercrime unit or consumer authority |
Be aware that scammers also impersonate these organisations, the FBI’s July 2026 warning was specifically about fake IC3 “recovery” services. Type the official address yourself rather than following a link, and remember that real agencies don’t charge you to recover money.
Key takeaways
- The FBI’s 2025 Internet Crime Report logged 22,364 AI-related complaints with about $893 million in reported losses.
- Voice clones, deepfakes and polished phishing make old scams more convincing; verify through a second channel.
- Agents can be targeted with hidden instructions, fake shops and malicious “connect this app” requests.
- Minimal permissions and a confirmation step before sending or buying limit what a hijacked agent can do.
- Report quickly to your bank and the official national authority, and beware fake “recovery” services.
AI agent scams: FAQs
Common enough to plan for. The FBI’s 2025 Internet Crime Report logged 22,364 AI-related complaints with about $893 million in reported losses.
They can try. Hidden instructions in web pages or emails, known as prompt injection, can push an agent to leak data or take unwanted actions. Minimal permissions and a confirmation step before sending or buying limit the damage.
Call your bank or card provider first, then report it to your national fraud authority. Be wary of anyone offering to recover the money for a fee, as fake recovery services often target scam victims.
Sources
- FBI, “Cryptocurrency and AI Scams Bilk Americans of Billions” (April 2026)
- FBI IC3, 2025 Internet Crime Report (PDF)
- FBI IC3, “FBI Warns of Scammers Impersonating the IC3” (PSA, 20 July 2026)
- ABA Banking Journal, “FBI issues warning on AI used for financial fraud” (on FBI PSA of 3 December 2024)
- OpenAI Help Center, “ChatGPT agent” (prompt-injection example)
- OWASP, Top 10 for Large Language Model Applications



