
The Lie Factory: AI’s Scam Complex
Posted August 19, 2026
Chris Campbell
The phone rings.
It's your grandson. Same voice that thanked you for the birthday check last spring.
He's in jail. Car wreck. No wallet, no phone—he's borrowing one. He needs bail money and he needs it in the next hour.
An American couple got this exact call.
Grandma rushed to the bank and pulled out every dollar the teller would hand her and sent it through Western Union.
The voice was AI. The grandson was fine.
The money? Gone. Poof.
I've spent all week on the dangers of using AI for crucial work. Today, the dangers of someone else using it. On you.
Two things today:
- The risk.
- 5 steps to stay safe.
The Math Just Changed
Before AI, your odds of getting scammed were a function of effort. Fraud took real work.
A human had to write the email, work the phone, study the mark. Sloppy work left fingerprints—typos, weird grammar, illogical stories about a Nigerian prince.
AI is deleting the cost of that effort.
The FBI logged $16.6 billion in cybercrime losses in 2024—up 33% in a single year. Complaints specifically flagging AI hit $893 million in 2025. McAfee says one in ten Americans has already lost money—or nearly lost it—to an AI deepfake scam.
And one in four victims filing reports is over 60.
Maybe you've spent years keeping yourself hard to hack. Good passwords. Healthy paranoia. Doesn't matter. The game has changed.
The $25 Million Zoom Call
In Hong Kong, a finance employee at engineering giant Arup joined a video call with the company's CFO and several colleagues. Familiar faces. Familiar voices. The CFO authorized 15 wire transfers.
$25.6 million walked out the door.
Every single person on that call was AI-generated. Every face. Every voice.
That attack once required a nation-state budget.
Today it costs under $50 in compute and runs in real time on a gaming PC. Spoofing a caller ID costs three-tenths of a penny. AI-written phishing emails get clicked four times more often than human-written ones.
Where This Goes Next
Last month, hackers pointed eight AI agents at Taiwan's government.
No humans at the keyboard. The agents mapped 21 systems, cracked 85 accounts, stole 2,500 personnel files, and pivoted into the nuclear safety agency—adapting on the fly whenever defenders blocked them.
Four days, start to finish.
One security researcher summed up the new world in a sentence: the cost of running a competent attack has collapsed, and the cost of defending against one has not.
But humans are infinitely creative. And there’s a little glint of light in this tunnel.
An Australian firm called Apate runs an army of AI personas whose entire job is answering scam calls all day and playing dumb.
Hundreds of thousands of calls per day. In six weeks, they burned through 500 days of scammer time for a single telco—roughly $13 million in fraud that never happened.
Somewhere in a call center, a con man is losing his mind at a grandmother who doesn't exist. Soon, of course, a bot will take his job. And the future of cybersecurity will be bots having fake phone calls with bots. Forever.
Until that time, you should know how to protect yourself.
Your First Line of Defense: A $50 Key
Here's the good news.
The best defense against a trillion-parameter AI getting inside your accounts is dumb, physical, and cheap.
Buy a YubiKey. It's a hardware security key. Plug it in, tap it, you're in. Without it, nobody gets into your accounts—even with your password, even with a perfect clone of your voice begging customer service. AI can fake your face. It cannot fake a piece of hardware sitting in an undisclosed location.
Buy two (one's a backup). About $50 each. Lock down your email first—your inbox is the skeleton key to every account you own—then your brokerages, then your bank.
Then add four habits that cost nothing:
Stop clicking links. In texts, in emails, anywhere. The "fraud alert" from your bank is the fraud. Type the address yourself or use the official app. Every link is a door—let the scammers knock forever.
Set a family safe word. One word your real family knows. The AI has your grandson's voice. It doesn't have the word.
Hang up and call backon the number you already have. Ninety percent of victims could have stopped the loss with that single step.
Distrust urgency plus secrecy. "Don't tell Mom" and "we have 15 minutes" in the same call? Real emergencies almost always demand urgency. But they rarely demand silence in the same sentence. Stop. Breathe. And think about what’s being asked of you.
The scammers are upgrading. Time you did too.
