Skip to content
NB EN
Nettsak

AI scams explode: three seconds of audio is enough to clone your voice

The FBI has made AI a distinct crime category for the first time: 893 million dollars lost, up 1,210 percent in a year. Voice cloning costs 20 dollars – but the defense is familiar.

Håkon Berntsen 3 min read
AI scams explode: three seconds of audio is enough to clone your voice
Illustrasjon: AI-generert

Americans lost more than 893 million dollars to AI-driven scams last year, and for the first time the FBI has listed artificial intelligence as a distinct crime category. The figure comes from 22,364 complaints in the FBI’s annual internet crime report. Even more striking is the growth: AI-driven scams rose 1,210 percent in 2025 – around six times faster than traditional fraud.

Three seconds is enough

The drivers behind the explosion are voice cloning, deepfake images and video, and AI-generated scripts. Voice cloning in particular has lowered the barrier dramatically: three seconds of audio is enough to clone a voice with 85 percent accuracy. The audio sample is scraped for free from a public social-media video, and the cloning tool can be bought for as little as 20 dollars on the dark web.

With that, scammers can call pretending to be a family member in distress, an executive asking for an urgent transfer, or a government agency. The methods are the classic ones – romance scams, extortion, CEO fraud – but AI makes them far more convincing and possible to aim at many more victims at once.

"AI has not invented new attacks"

Security experts agree on an important nuance: AI has not created new types of attacks, but made the old ones cheap and scalable. "AI is not the biggest cybersecurity problem – people are," as one researcher put it. The fraud targets people, not systems, and nearly always relies on one trick: creating time pressure so the victim does not get a chance to verify.

When the AI itself becomes the security hole

At the same time, another trend shows that the AI tools themselves often become weak links. One of the best-known examples is McDonald’s AI recruitment bot "Olivia," which exposed the data of 64 million job applicants – names, emails, phone numbers and interview transcripts. The cause was not sophisticated hacking, but a test account left open with the password "123456." Studies now estimate that around one in four data breaches over a year had an AI component – often because AI systems gather a lot of sensitive data behind interfaces built in haste.

The defense is familiar

The good news is that when the attacks are old, so is the defense. Experts recommend verifying all unexpected money or data requests through a different channel – for example a callback to a known number – and treating any request that is "urgent, irreversible and unverified" as a warning sign. Learning to "hear" a cloned voice is futile; the technology is too good. But simple, consistent routines stop the fraud no matter how real it sounds.

Related stories