---
title: "AI made impersonation cheap. Here is what that means for brand protection"
description: "Generative AI did not invent brand impersonation. It removed the cost, the skill and the telltale mistakes that used to keep it small. What the FBI, FTC and APWG data show, what changed, what did not, and what to do about it."
date: "2026-10-08"
author: "Fraudox Team"
tags: ["Brand Protection", "Impersonation", "AI"]
canonical: "https://fraudox.com/blogs/how-ai-raised-the-need-for-brand-protection"
publisher: "Fraudox"
publisher_url: "https://fraudox.com"
license: "Free to quote with attribution to the canonical URL."
---

# AI made impersonation cheap. Here is what that means for brand protection

> Generative AI did not invent brand impersonation. It removed the cost, the skill and the telltale mistakes that used to keep it small. What the FBI, FTC and APWG data show, what changed, what did not, and what to do about it.

*Published October 8, 2026 by Fraudox Team. Canonical version: https://fraudox.com/blogs/how-ai-raised-the-need-for-brand-protection*

For most of the internet's history, impersonating a brand was limited by effort and skill. A convincing fake store took days to build. A fake support account needed someone who wrote the language well. A scam aimed at a bank's customers usually gave itself away with a misspelled word, a stretched logo or a sentence no native speaker would write.

Those flaws were doing quiet, unpaid protection work. Customers spotted them. Platforms' filters caught them. Most impersonators were too lazy or too unskilled to get past them.

Generative AI removed most of those flaws at the same time. It did not invent impersonation, and it did not create a new kind of crime. What it changed is the cost, the skill and the telltale mistakes that used to keep impersonation small. That change is why brand protection has moved from something large companies buy to something almost any brand with customers online now needs.

This piece covers what the numbers actually show, what changed for the people impersonating you, what did not change, and what a sensible response looks like. It is written to be useful whether or not you ever hire anyone to help.

## What the numbers show, and what they cannot

The cleanest long-running dataset is the FBI's Internet Crime Complaint Center (IC3), which has published reported losses every year since 2001.

![Bar chart of losses reported to the FBI's IC3: $4.2B in 2020, $6.9B in 2021, $10.3B in 2022, $12.5B in 2023, $16.6B in 2024 and $20.9B in 2025.](https://fraudox.com/images/blog/ai-brand-protection/ic3-losses-2020-2025.svg)

In 2025, IC3 received 1,008,597 complaints with $20.877 billion in reported losses, a 26 percent increase on 2024 and the highest figure in its 25 years. Roughly five times the 2020 figure, in five years.

The 2025 report is also the first with a dedicated section on artificial intelligence. IC3 counted 22,364 complaints that referenced AI, with adjusted losses above $893 million. The FBI's own description of the problem is worth paraphrasing: AI makes it possible to produce convincing synthetic content such as social media profiles and personalised conversations in mass quantities, and that content is becoming harder to detect and easier to make.

Here is where the AI-linked losses landed, by the categories the FBI used:

| Where AI showed up in 2025 IC3 complaints | Reported losses |
| --- | --- |
| Investment scams with a reported AI link | over $632 million |
| Business email compromise involving AI | over $30 million |
| Confidence and romance scams with a likely AI link | over $19 million |
| Employment scams involving AI | almost $13 million |
| Of the romance figure: "distress" scams using voice cloning | over $5 million |

The $893 million figure is a floor, not an estimate. The AI flag only appears when a victim knows, and says, that AI was involved. The FBI makes the point itself, using its largest category.

![Bar showing that of more than $8 billion in investment-fraud losses reported to the FBI in 2025, $632 million, under 8 percent, was flagged as AI-involved.](https://fraudox.com/images/blog/ai-brand-protection/ic3-investment-fraud-ai-share.svg)

Investment-fraud losses with a reported AI link passed $632 million. Total investment-fraud losses passed $8 billion. The FBI's reading is that many victims do not realise how much AI was involved in what happened to them. Someone who watched a deepfaked CEO recommend a trading platform rarely reports "AI". They report a trading platform.

The Federal Trade Commission's data points the same way from a different angle. Consumers reported losing about $16 billion to fraud in 2025, the highest on record and around 25 percent more than 2024. Imposter scams were the most-reported category for the fifth year running, about one fraud report in three, with $3.5 billion lost. Within that, losses to people impersonating a business reached nearly $1 billion, up from $866 million in 2024, and the largest share went to people posing as banks. Government impersonation reached about $920 million, up from $789 million.

### Three honest caveats

**Reported losses are not total losses.** Both datasets only count what people report, and both agencies say most fraud goes unreported.

**These are US figures.** The US publishes the most detailed public data, which is why it dominates every article on this subject. Nothing about the mechanics below is American, but the dollar figures are.

**Not all of the growth is AI.** Crypto investment fraud, scam compounds and better reporting all contribute. Anyone who tells you AI caused a specific percentage of the increase is guessing. The defensible claim is narrower and stronger: the tools that make impersonation cheap arrived during the same years the losses accelerated, and the agencies collecting the data now track AI as a factor because they keep seeing it.

## Five things AI changed for the people impersonating you

### 1. A convincing fake now costs almost nothing to make

Building a credible fake used to take real work: product photography, a store layout, an "about us" story, reviews, a support page. Microsoft's Cyber Signals report from April 2025 describes scammers using AI to generate entire storefronts, with fabricated business histories, customer testimonials and AI-written product reviews, and notes that work which used to take days or weeks can now be done in minutes. Microsoft said it blocked about $4 billion in fraud attempts over the twelve months the report covered.

When the cost of a fake approaches zero, the economics of impersonation change. A scammer no longer needs a big, valuable brand to justify the effort. A mid-sized e-commerce brand, a regional bank, a course creator with a loyal audience and a founder with a recognisable face are all worth copying now, because copying them costs almost nothing.

### 2. The mistakes that warned your customers are gone

For years, consumer advice relied on spotting errors: bad grammar, odd phrasing, a slightly wrong logo, a page that looked cheap. That advice is now close to useless. Language models write fluent copy in dozens of languages. Image models produce clean product shots and plausible logos. Translation is instant.

This matters most in markets that used to be partly protected by language. A scam operation that could not write convincing Arabic, Malay, Portuguese or Japanese once skipped those audiences. That barrier is gone. Your customers' instinct is no longer a reliable control, and a brand can no longer count on its customers to catch the fake before they pay it.

### 3. Volume and personalisation at the same time

Mass scams used to be generic, and personalised scams used to be slow. AI removes that trade-off. The FBI describes investment scammers using AI to "quickly generate thousands of conversations that appear different to each prospective victim". OpenAI's October 2025 threat report describes banning accounts tied to scam networks, likely based in Cambodia, Myanmar and Nigeria, that used its models to write outreach scripts, translate, and keep fake personas going in conversation, including groups dressed up to resemble a legitimate investment firm.

For a brand, the result is that the fake account claiming to be your support team can now answer questions, in your customer's language, at any hour, with a consistent tone. It no longer has to be clumsy to be cheap.

### 4. Your people became part of the attack surface

The clearest change is that a known person's face and voice can now be borrowed. In early 2024, an employee at the Hong Kong office of the engineering firm Arup made 15 transfers totalling HK$200 million, about US$25 million, after a video call in which, according to Hong Kong police, every other participant was a deepfake of a real colleague, including the CFO. The same year, fraudsters tried to impersonate the CEO of WPP using a cloned voice and a fake WhatsApp account. That attempt failed.

The FBI's 2025 report describes "investment clubs" using AI-generated video and voices of celebrities, CEOs and trusted figures as fake endorsements. That is the version most brands meet: their founder or chief executive, apparently recommending a product they have never heard of, in an ad they did not pay for. We covered the mechanics in [deepfake ads using your founder's face](https://fraudox.com/blogs/deepfake-ads-using-your-founders-face).

The practical shift is that the faces of a company are now brand assets in the same sense as its logo. Anyone who appears on camera for your brand, posts publicly or speaks at events has supplied the raw material for an [executive impersonation](https://fraudox.com/glossary/executive-impersonation).

### 5. Reach is bought, not earned

A fake page with no audience does limited damage. Paid ads fix that problem for the impersonator. In November 2025, Reuters reported on internal Meta documents projecting that about 10 percent of the company's 2024 revenue, roughly $16 billion, would come from ads for scams and banned goods. One December 2024 document estimated that users were shown about 15 billion "higher risk" scam ads a day, and the documents said advertisers were only banned when automated systems were at least 95 percent sure they were committing fraud. Meta disputed the framing and said it removes scam ads, including deceptive ads using public figures, when it detects them.

Whatever the exact figures, the mechanism matters for brands. A cheap AI-generated fake can now be pushed in front of exactly the people who already trust your name, through the same ad systems you use to reach them.

![Stacked bar: impersonation 43.8 percent of social media threats, scams 27.1 percent, all other threat types 29.1 percent.](https://fraudox.com/images/blog/ai-brand-protection/social-media-threat-mix.svg)

The Anti-Phishing Working Group's Q1 2026 report, citing ZeroFox data, puts impersonation at 43.8 percent of social media threats and scams at 27.1 percent, and says threat volume rose on every social platform. Impersonation is no longer an edge case on social media. It is the main category.

## What did not change

It is easy to read the above and conclude that everything is now different. The parts that did not change are just as important, because they decide what a sensible response looks like.

**The platform still decides.** A [takedown](https://fraudox.com/glossary/takedown) is still a request to the party that runs the service: a social network, a registrar, a host, an app store, a marketplace. They apply their own policies, on their own schedule, and they can reinstate on appeal. AI made fakes faster to produce. It did not make anyone else's review queue faster. We wrote about this in [nobody can guarantee a takedown](https://fraudox.com/blogs/nobody-can-guarantee-a-takedown).

**You still need a legal basis.** A platform will remove an impersonating account or an infringing listing because it breaches a policy or a right: trademark, copyright, impersonation rules. "This looks AI-generated" is not a reason to remove anything. Some rights channels will not act on a pending trademark application, only a registered one. If your rights are not documented, the fastest fake in the world can stay up.

**Evidence still has to hold up.** The reviewer needs to see the infringing content, your rights, and the connection between them, captured before the impersonator changes or deletes it. AI-generated fakes get edited and re-uploaded constantly, which makes timestamped captures more important, not less. The details are in [the evidence pack platforms need](https://fraudox.com/blogs/the-evidence-pack-what-platforms-need).

**Removal kills a copy, not the capability.** This was true before AI and it is more true now. If a fake costs minutes to make, it costs minutes to remake. A removed account or domain should stay on a watch list afterwards, which is the subject of [monitoring for recurrence after a takedown](https://fraudox.com/blogs/monitoring-for-recurrence-after-a-takedown).

![Diagram. Got cheap for the impersonator: fluent copy in any language, product photos and whole storefronts, profiles and a posting history, a known person's face and voice, thousands of personalised chats, a fresh copy after every removal. Still slow for the brand: proving the brand is yours, evidence that holds up in review, finding the right party to report to, the platform's review and decision, appeals and reinstatements, noticing when it comes back.](https://fraudox.com/images/blog/ai-brand-protection/cost-asymmetry.svg)

That is the core of the problem. Every step on the attacker's side got cheaper. Almost every step on the defender's side still runs at human speed, through processes the brand does not control.

## Why this raises the need for brand protection, specifically

It is fair to ask why this is a brand's problem rather than a consumer-safety problem. The losses in the FBI and FTC data belong to the people who were scammed, not to the brand that was impersonated.

In practice, the brand pays in other ways.

**Support load.** Customers who were scammed by "you" contact you. They ask where their order is, why their refund has not arrived, why your support agent asked for their card details.

**Trust and reviews.** A victim rarely writes "I was scammed by someone impersonating this company". They write "this company scammed me". Search results, app store reviews and social comments carry that forward to customers who were never targeted.

**Chargebacks, disputes and regulator attention.** For banks, payment providers and anyone handling money, impersonation produces disputes, complaints and questions about whether the business is doing enough to warn customers. The FTC's note that bank impersonators drove the largest share of business-impersonation losses is a description of a reputational problem as much as a financial one.

**Revenue diverted directly.** For course creators, digital products and consumer brands, the fake is often selling your product, or a cheap copy of it, to your audience. Every sale there is one you lost and one that may end in a complaint about quality.

**Late detection.** Because the obvious flaws are gone, customers notice later and brands hear later. By the time a complaint reaches you, the fake may have been running ads for weeks.

None of these costs show up in a crime report. All of them grow as impersonation gets cheaper, which is why the need for brand protection has grown faster than the headline loss numbers suggest.

## What to change in practice

None of this calls for panic, and most of it does not call for buying anything. It calls for treating impersonation as a standing operational risk rather than an occasional incident.

### Get your rights in order before you need them

Register trademarks in the markets where you sell, not only where you are incorporated. Keep dated originals of your content: course material, product photography, brand assets. When a fake appears, the question a platform asks first is whether you can prove the thing is yours, and that answer is much faster to give if the paperwork already exists.

### Publish your official channels, and say how you will never contact people

Keep one page that lists every official account, domain and app, and link it from your site footer and profiles. Tell customers plainly what you will never do: ask for a password, ask for a card number in chat, move a conversation to WhatsApp, offer guaranteed returns. In a world where fakes look real, a clear "this is the only way we contact you" is one of the few signals a customer can still check.

### Treat the people on camera as brand assets

List the people whose face or voice is publicly associated with the brand: founders, executives, presenters, ambassadors. Include them in monitoring the same way you include the logo and the name. For high-profile individuals, consider protecting their own accounts and handles as part of the brand programme, not as a personal matter.

### Verify payment and access requests out of band

The Arup case was not a failure of detection software. It was a payment made on the strength of a video call. Any request to move money, change bank details or grant access should be confirmed through a separate channel the requester did not supply, however real the voice or face appears. This is an internal control, and it costs nothing.

### Watch where your customers actually are

Impersonation shows up in social profiles, paid ads, marketplace listings, [lookalike domains](https://fraudox.com/glossary/lookalike-domain), app stores and messaging groups. Waiting for complaints means finding out late. A regular, scheduled check of the places your customers spend time, against your brand names, product names and key people, is the minimum. We go through the common surfaces in [where brand impersonation actually surfaces](https://fraudox.com/blogs/brand-impersonation-detection-surfaces).

### Treat removal as a recurring operation, not a closed case

Track what comes back. Group related fakes into one case so the platform sees a pattern rather than a single account. Measure the things you control: how quickly you detect, how quickly you file, how complete your evidence is, how often a removed fake reappears. Be sceptical of anyone, internal or external, who promises how quickly a platform will act.

### Keep evidence standards high

Capture the URL, the content, the date and the account details before you report, because AI-assisted fakes get edited and reposted quickly. Write reports that point to the specific policy breached and the specific right infringed. A thin report costs a whole review cycle, which you can no longer afford when the fake can be remade in minutes.

## A note on AI on the defending side

AI is useful for defence too. It is good at sifting large volumes of accounts, images and domains for things that look like your brand, and at grouping near-duplicates into clusters. That is real progress, because volume is exactly what changed. It cuts the other way for consumers too: OpenAI estimates that people use ChatGPT to check whether something is a scam up to three times more often than scammers use it to run one.

It is worth being clear about where that help ends. Detection is not removal. The decision still sits with a platform, a registrar or a host, made by people applying a policy to the evidence in front of them. Tools that promise fully automated takedowns are usually promising faster filing, not faster decisions. The bottleneck has moved from finding the fake to proving it and getting it in front of the right reviewer, and that part is still mostly human work.

## The bottom line

Generative AI did not create brand impersonation. It removed the friction that used to contain it: cost, skill and visible mistakes. The FBI now tracks AI as its own category and still calls its numbers an undercount. The FTC reports record imposter losses for the fifth straight year. Impersonation is the largest single category of social media threats in APWG's latest data.

What did not change is the process for getting a fake removed: rights, evidence, the right channel and a decision by someone else. That gap, cheap to create and slow to remove, is the whole reason brand protection is no longer optional for brands that live online. The work is not dramatic. It is documented rights, published official channels, protected people, steady monitoring and careful reporting, done before the next fake appears rather than after the complaints arrive.

### Sources

- FBI Internet Crime Complaint Center, [2025 Internet Crime Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf), including the section "Artificial Intelligence (AI) Used in Cybercrime".
- Federal Trade Commission, [FTC data show people reported losing $3.5 billion to imposter scams in 2025](https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025) (June 2026).
- Anti-Phishing Working Group, [Phishing Activity Trends Report, Q1 2026](https://docs.apwg.org/reports/apwg_trends_report_q1_2026.pdf).
- Microsoft, [Cyber Signals Issue 9: AI-powered deception](https://www.microsoft.com/en-us/security/blog/2025/04/16/cyber-signals-issue-9-ai-powered-deception-emerging-fraud-threats-and-countermeasures/) (April 2025).
- OpenAI, [Scam operations: online fraud networks](https://openai.com/index/disrupting-malicious-uses-of-ai-scam-operations/) (October 2025).
- Reuters, [Meta is earning a fortune on a deluge of fraudulent ads, documents show](https://www.reuters.com/investigations/meta-is-earning-fortune-deluge-fraudulent-ads-documents-show-2025-11-06/) (November 2025).
- South China Morning Post, [Arup confirmed as victim of HK$200 million deepfake scam](https://scmp.com/news/hong-kong/law-and-crime/article/3263151/uk-multinational-arup-confirmed-victim-hk200-million-deepfake-scam-used-digital-version-cfo-dupe) (May 2024).

---

Published by Fraudox (https://fraudox.com), a brand protection takedown service that
removes phishing sites, impersonating pages, fake social accounts, counterfeit apps,
scam domains and stolen content, and bills only for confirmed removals.
