AI Romance Scams: Why Spotting Them Is the Wrong Defence
AI romance scams defeat every visual check. See the FBI 2025 loss data, why 77% of victims never saw it, and the structural defences that still work.
AI romance scams defeat every visual check. See the FBI 2025 loss data, why 77% of victims never saw it, and the structural defences that still work.
AI romance scams use synthetic images, cloned voices, and real-time face swapping to sustain relationships that were once exposed by a video call. Detection advice no longer works: FBI data shows 77% of people actively being defrauded did not know it when investigators reached them. The defence that holds is structural, not perceptual.
Table of Contents
ToggleRelationship fraud used to be limited by the attacker’s ability to appear consistent. Stolen photographs ran out, accents did not match claimed nationalities, and a live video call collapsed the whole construction. Every one of those constraints has been removed.
Generated imagery now produces a person in any location holding any object, which retires the custom-photo test that once served as verification. Real-time face swapping and voice synthesis mean a video call confirms very little, and conversational models can sustain an emotionally consistent relationship over months without a human present for most of it. The economics changed with the technology: one operator can now run relationships at a volume that previously required a team.
The shift matters most for what it does to advice. Guidance built on noticing flaws assumes flaws exist, and the flaws that awareness training taught people to look for are exactly the ones automation removed first. Wider mechanics of manipulation are covered in how social engineering exploits human psychology.
The FBI’s 2025 Internet Crime Report recorded 1,008,597 complaints, the first time the Internet Crime Complaint Center has passed a million in its twenty-five year history, with reported losses of $20,877,000,000, up 26% on the previous year.
Relationship-based fraud sits inside the largest loss category rather than beside it. Investment fraud accounted for $8,648,617,756, close to 49% of all reported losses, across nearly 73,000 complaints, a rise of 52% by volume. Cryptocurrency-related complaints numbered 181,565 and carried more than $11,000,000,000 in losses. Most of that damage follows the pattern in which a relationship is built over weeks or months on a dating app or social platform, then converted into an urgent investment opportunity.
Older adults are disproportionately affected, reporting approximately $7,700,000,000 in losses, up 37% on 2024, of which $584,000,000 was categorized as confidence and romance fraud. And 2025 was the first year the IC3 tracked AI as a complaint descriptor, logging 22,364 complaints carrying nearly $893,000,000 in losses.
| IC3 2025 measure | Figure |
|---|---|
| Total complaints | 1,008,597 |
| Total reported losses | $20,877,000,000 |
| Investment fraud losses | $8,648,617,756 |
| Cryptocurrency-related losses | More than $11,000,000,000 |
| Losses reported by people over 60 | Approximately $7,700,000,000 |
| Confidence and romance fraud, over 60 | $584,000,000 |
| AI-related complaints, first year tracked | 22,364, nearly $893,000,000 |
The most useful figure in the FBI’s work on this does not appear in loss tables. Through Operation Level Up, which identifies people while a fraud is still running and contacts them, the FBI reported notifying 8,103 victims of cryptocurrency investment fraud, and 77% of them did not know they were being defrauded at the point of contact.
That number reframes every piece of advice built on recognition. These were not people who missed a warning list; they were people inside a relationship they believed was real, receiving information from someone they trusted. A checklist of red flags is only useful to someone who has stepped outside the frame long enough to run it, and the entire design of the scam is to prevent that step.
Two things follow. Any control that depends on the targeted person evaluating the relationship is weak by construction. And controls that work do so by involving someone outside the relationship, which is why the FBI’s own public guidance emphasizes pausing before acting rather than assessing the other party. The same principle runs through countermeasures against social engineering.
Structural defences do not ask a person to judge whether a relationship is genuine. They put a step between the emotion and the money, and they work whether or not the person believes anything is wrong.
A named second person for any first-time transfer to someone met online, agreed in advance with family or a colleague rather than chosen in the moment
A fixed waiting period before any transfer above a threshold the person sets while nothing is happening
A rule about payment rails: cryptocurrency, gift cards, and prepaid instruments are dealbreakers regardless of explanation, because they exist in this context to evade recovery
Independent platform verification, checking whether an investment platform is registered with the relevant regulator, done by a second person rather than the target
A standing invitation to talk about it, since isolation is a scam’s most reliable precondition and embarrassment is what sustains it
The last one is the hardest and the most valuable. People who are being defrauded often stop discussing the relationship because they anticipate judgment, which removes the only reliable detection mechanism available. Organizations and families that treat disclosure as unremarkable get told earlier.
Coverage of romance fraud treats it as a consumer matter, which leaves the enterprise exposure unexamined. Three routes connect it directly to organizational risk.
The same operators now impersonate employers. The FBI has identified work-from-home schemes in which fraudsters pose as employees of legitimate companies and recruit people for online-only positions, then require them to deposit their own funds to complete tasks. That makes any recognizable brand a potential lure, and it makes candidate-facing fraud a brand protection issue. Related patterns are set out in AI-coordinated hiring scams and employment identity theft.
Relationship-building is also an established route to credentials. State-aligned groups have run long-form approaches through professional networks and messaging apps for years, as the activity described in Charming Kitten’s use of WhatsApp and LinkedIn shows. The pretext differs, the mechanics are identical: sustained rapport, then a request that would look absurd from a stranger.
And employees under acute financial pressure become a different kind of exposure. A person who has lost substantial personal savings is more susceptible to approaches offering money for access, which is a documented insider risk pathway rather than a hypothetical one. The category is examined in insider threats that are misguided rather than malicious.
Treating romance fraud as the work of individual opportunists understates it. The US Department of Justice, FBI, and Secret Service established a Scam Center Strike Force targeting compounds in Southeast Asia, focusing on organized crime affiliates operating in Cambodia, Laos, and Burma.
That is the relevant fact for anyone still imagining a lone scammer. These are managed operations with scripts, quotas, shift patterns, and specialist roles, in which the person sending messages is frequently not the person who profits and is sometimes not there voluntarily. Meta reported removing 2,000,000 accounts linked to these schemes in 2024, concentrated in the same region.
The operational consequence is that volume is not a constraint on the attacker. An approach that fails costs nothing, so a target who declines once will be approached again through a different profile, and a workforce is a list of targets rather than a set of individual incidents. Regional patterns are collected in online fraud in the UAE and WhatsApp scams.
Dating apps are the channel most associated with romance fraud and no longer the main one. Contact is now initiated across several surfaces, and the opening move is usually designed to look like an accident rather than an approach.
The misdirected message is the most common opener: a text or WhatsApp message apparently intended for someone else, warm and apologetic when corrected, which converts an unsolicited contact into a conversation the target feels they chose to continue. Professional networks supply a second route, where a plausible industry connection carries built-in context and a reason to respond. Interest-based communities, particularly around investing and cryptocurrency, supply a third, where financial conversation is native and an investment suggestion arrives without a change of subject.
Two features are shared across all of them. The first exchange asks for nothing, which defeats any control keyed to suspicious requests, and the move to an encrypted messaging app happens early, which removes the platform’s ability to detect the pattern and removes any record an employer or family member might notice. Channel-specific patterns are collected in WhatsApp identity theft.
Training that lists warning signs teaches a skill that automation has already defeated. Training that builds procedure survives improvements in the technology, because the procedure does not depend on the quality of the deception.
Three objectives carry most of the value. People should know that a video call is no longer identity verification, which contradicts what many were taught and needs saying explicitly. They should have a rehearsed response to any request involving cryptocurrency or gift cards, so the answer is automatic rather than reasoned under emotional pressure. And they should know that disclosing an approach carries no penalty, because the organizational value of this training is mostly in what gets reported.
Threatcop’s TLMS delivers this as role-appropriate content with scenario-based assessments rather than a single annual module, so finance staff and candidate-facing recruiters get the versions that match what they will actually encounter. Programme design for this kind of content is covered in examples of social engineering.
Ask the awkward question about your own awareness programme: does it teach people to identify a scammer, or does it give them a procedure that works when they cannot? The first is a skill with a short shelf life. The second holds regardless of how good the deception gets.
The organizational version of the same question is whether anyone would hear about it. Most of what an employer could usefully act on, an approach through a professional network, a candidate reporting a fake recruiter, an employee in sudden financial difficulty, only surfaces if disclosure feels safe.
Build the procedure into how your workforce is trained so the response to an unexpected financial request is a step someone takes, not a judgment they have to make alone.
An operator builds a relationship over weeks or months through a dating app or social platform, using generated images and, increasingly, real-time face swapping and voice synthesis to pass video verification. Once trust is established, the conversation moves to an urgent financial request, most commonly a cryptocurrency investment platform that displays fictitious returns and blocks withdrawal.
No longer. Real-time face-swapping and voice cloning can sustain a live video call, and generated images can place a person in any location holding any requested object, which defeats the custom-photo test. Identity should be confirmed through independent means, such as verifying the person against a channel neither party controls, rather than through visual confirmation.
The FBI’s 2025 Internet Crime Report recorded $20,877,000,000 in total reported losses across 1,008,597 complaints. Investment fraud, which is where most relationship-initiated fraud ends, accounted for $8,648,617,756, nearly 49% of all losses. People over 60 reported approximately $7,700,000,000 in losses, including $584,000,000 categorized as confidence and romance fraud.
Because the scam is engineered to prevent evaluation rather than to survive it. FBI figures from Operation Level Up show 77% of identified victims did not know they were being defrauded when contacted. Targets are typically selected during periods of transition or isolation, and the relationship is built slowly enough that each individual request seems reasonable in context.
Yes, through three routes. Fraudsters impersonate legitimate employers in work-from-home schemes, making any known brand a lure. Relationship-building is an established method for obtaining credentials from employees, particularly through professional networks. And employees facing severe personal financial loss represent a recognized insider risk pathway.
Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures supporting AI...
Shadow AI governance is the practice of finding, assessing, and managing the AI tools employees use without approval. Most...
Verifying an AI-generated image means checking provenance rather than appearance. Detection classifiers degrade as generators improve, so the reliable...
Table of Contents
×