$690,000 Gone in One Video Call
Steve Beauchamp is 82 years old. He spent decades building his retirement savings. In 2024, he watched a video of Elon Musk explaining a cryptocurrency investment opportunity. The face was Musk's. The voice was Musk's. Everything checked out.
He drained his retirement fund. $690,000. Gone.
The video was AI-generated. Every pixel, every inflection—fake.
This isn't rare anymore. Deepfake fraud losses in the US tripled from $360 million in 2024 to $1.1 billion in 2025. And that's just what gets reported.
A Phone Call That Knows Too Much
Picture this: You get a call from your bank. The voice sounds professional, maybe even familiar. They mention a suspicious transaction on your account—the exact amount, the exact merchant, the exact time.
"For your security, I'll need you to verify a code that's about to appear on your screen."
You look at your computer. A verification code pops up.
Here's what you don't know: The caller already sees that code. They're watching your screen through a compromised security camera pointed at your monitor. Or through software on your computer. Or through the reflection in your office window.
When you read the code back to them, they're not verifying your identity. They're confirming you'll do what they tell you.
This isn't a movie plot. This is the new reality of AI-powered fraud.
The Three-Headed Scam
Traditional scams have always had a weakness: the scammer is flying blind. They call you, they lie, and they hope you believe them. If you hesitate, they can't see it. If you're suspicious, they can't adapt.
New AI scams work differently. They combine three technologies:
1. The Voice (AI That Sounds Human)
AI can now clone anyone's voice with just 30 seconds of audio—some systems need only 3 seconds (McAfee researchers achieved an 85% voice match from a 3-second sample). That voicemail from your boss? That podcast your doctor was on? That video your mom posted on Facebook? All of it can be used to create a convincing voice clone.
In January 2024, engineering firm Arup lost $25 million when an employee in their Hong Kong office received a video call from what appeared to be their UK-based CFO—along with other executives—instructing them to make an urgent transfer. Every face, every voice was AI-generated from publicly available conference recordings. The employee had initially been suspicious of a phishing email, but seeing familiar colleagues on video convinced them. (Confirmed by Hong Kong Police and Arup's CIO.)
Total reported fraud losses hit $12.5 billion in 2024 according to the FTC—a 25% increase from 2023. But 2025 is worse: between January and September alone, AI-driven deepfakes caused over $3 billion in losses in the United States. Voice phishing attacks specifically are up 442% year-over-year. More than 50% of all fraud now involves artificial intelligence.
2. The Eyes (AI That Watches)
Remember when the only cameras were the ones you could see? Now there are cameras everywhere:
- Security cameras in offices (often with default passwords anyone can guess)
- Smart home devices
- Baby monitors
- Laptop and phone cameras
- Even smart TVs
- Smart glasses — In October 2024, two Harvard students demonstrated they could hack Meta's Ray-Ban Smart Glasses to instantly identify anyone they looked at, pulling up names, addresses, and personal details in seconds
AI can now monitor these feeds automatically, waiting for the right moment. Waiting until you're at your computer. Waiting until you're logged into your bank. Waiting until you step away for coffee.
There's also a new threat: screenshot-stealing malware. A strain called SpyAgent uses optical character recognition to automatically scan every screenshot on your phone. If you ever took a photo of a password, a verification code, or a crypto wallet recovery phrase, it finds it and sends it to attackers.
3. The Puppet Master (AI That Acts)
If you've ever clicked a suspicious link or downloaded something you shouldn't have, there might be software on your computer that can:
- See everything on your screen
- Control your mouse and keyboard
- Wait for you to log into something important
- Act while you're distracted
Now imagine all three of these working together, coordinated by a single AI system that shares information between them in real-time.
The Attack That Nobody Sees
Here's how a sophisticated attack might work. I'll call the victim "Sarah."
Monday, 2:47 PM Sarah is a finance manager at a mid-sized company. She just got back to her desk after a meeting. Her computer is logged into the company's banking portal—she has to approve wire transfers.
What Sarah doesn't know: The office security camera behind her was hacked months ago. An AI has been watching, learning her routine, learning when she's at her desk, learning what systems she uses.
Monday, 2:48 PM Sarah's phone rings. It's the company's bank—or so it seems. The voice is calm, professional.
"Hi Sarah, this is Michael from First National's fraud prevention team. We've flagged some unusual activity on your business account. There's a $47,000 pending transfer to a vendor we don't have on file. Did you authorize this?"
Sarah didn't authorize anything like that. She's alarmed.
"Let me pull up your account verification," Michael says. "You should see a security code on your screen in just a moment."
What's really happening: The "Michael" voice is AI-generated. The $47,000 transfer is real—it was just initiated by the attackers using software on Sarah's computer. The AI watching the security camera can see Sarah's screen. It can see the verification code before Sarah even notices it.
Monday, 2:49 PM "I see the code appeared," Michael says (because the AI watching the camera just confirmed it). "Can you read that back to me so I can cancel this fraudulent transfer?"
Sarah reads the code. She thinks she's stopping a theft.
She just approved one.
Monday, 2:50 PM The call ends. Sarah feels relieved—crisis averted. She goes back to work.
The money is already gone.
Why This Is Different
You might be thinking: "Scams have always existed. What's new?"
Three things:
1. You Literally Can't Tell
Research shows humans correctly identify high-quality deepfake videos only 24.5% of the time—worse than flipping a coin. Even when people know they're being tested, detection barely reaches 55-60%. AI detection tools do better in labs, but their accuracy drops by up to 50% against real-world deepfakes.
Your eyes and ears evolved to trust what they see and hear. Scammers now exploit that biology.
2. The Scammer Adapts In Real-Time
Old scams were scripted. If you asked an unexpected question, scammers would stumble. AI doesn't stumble. It processes your responses, watches your body language through the camera, and adjusts its approach instantly.
Hesitating? The voice becomes more urgent. Getting suspicious? The voice provides more "verification details" it pulls from watching your screen. Reaching for your phone to verify? The voice says, "I'll wait while you check—in fact, I encourage it. This is exactly the kind of vigilance we need."
3. Multiple Channels Reinforce Each Other
The voice call seems legitimate because the scammer knows real details about your account. The details seem legitimate because they're watching your actual screen. The urgency seems legitimate because there really is a pending transaction (that they created).
Each lie supports the others. There's no single hole in the story because the AI is constructing the story from real data in real-time.
4. It Scales
A human scammer can make maybe 50 calls a day. An AI system can make thousands. It can target every employee at your company simultaneously. It can learn which people are most likely to comply and focus on them.
How to Protect Yourself
The good news: there are still defenses. The bad news: you have to actually use them.
1. Never Trust Caller ID
The number showing on your phone can be spoofed using VoIP technology. In fact, 74% of robocalls in 2025 used fake local area codes. "Bank of America" showing up doesn't mean Bank of America is calling.
What to do: If someone claims to be from your bank/company/government, hang up and call back using the number from the official website or your card. Never use a number the caller gives you.
2. Create a "Panic Word" With Family
If AI can clone voices, how do you know it's really your daughter calling for emergency money?
What to do: Establish a secret word or phrase with family members. If they can't say it, it's not them—no matter how much they sound like them.
3. Verify Through a Different Channel
If someone calls you about something urgent, verify it through a completely different method.
Example: Your "boss" calls asking you to buy gift cards for a client emergency. Before you do anything:
- Text or Slack them: "Hey, just got a call about gift cards—was that you?"
- Better yet: Walk to their office if you can
- Even better: Establish a policy that financial requests MUST be confirmed via video call where you can see their face (and even then, be careful)
4. Cover Cameras You're Not Using
If you have a security camera, smart display, or laptop webcam that you're not actively using, cover it or turn it away from your screen.
What to do: A $2 webcam cover could prevent a $25,000 loss. Worth it.
5. Assume Every Call Could Be AI
This sounds paranoid. It's also increasingly realistic. 92% of financial institutions now report fraudsters using generative AI.
What to do: For any call involving money, passwords, or sensitive information:
- Don't be rushed. Real institutions give you time.
- Verify independently. Always.
- When in doubt, hang up.
6. Never Screenshot Sensitive Information
That crypto recovery phrase you photographed "just in case"? That password you screenshotted to remember? Malware like SpyAgent specifically hunts for these images using AI-powered text recognition.
What to do: Write sensitive information on paper, stored somewhere physical and secure. Delete any screenshots containing passwords, codes, or financial information.
Why I'm Writing This
At my company, we build AI that makes phone calls on behalf of users—helping people deal with customer service, dispute charges, handle bureaucracy. We've seen firsthand how powerful voice AI has become.
That same power can be used to help people or hurt them.
I want you to know what's coming. Not to scare you, but to prepare you. The scam calls your parents are getting are about to get much more sophisticated. The "Nigerian prince" emails are evolving into phone calls that know your account balance.
The best defense is awareness. Now you're aware.
The Question I Keep Asking
We built phones to connect people. We built cameras to keep people safe. We built AI to help people be more productive.
All of these technologies can now be turned against us, coordinated by systems that never sleep, never get tired, and never feel guilty.
The answer isn't to abandon technology. It's to understand that the game has changed.
Your voice can be cloned from a YouTube video. Your screen can be watched through a hacked camera. Your trust can be exploited by a system that knows exactly which buttons to push.
But you can also hang up. You can verify. You can pause.
The AI is fast. You don't have to be.
Stay safe out there.
P.S. If you have elderly parents or grandparents, please share this with them. Steve Beauchamp was 82. He's not alone—seniors are often the primary targets.
Want to stay informed? We publish weekly insights on AI and what it means for humans. Join The Human+AI Project — it's free.