Established by a former federal prosecutor · 20+ years prosecutorial experience · $12.5B lost to fraud in 2024 (FTC)
The Fraud CodexScam Intelligence
Live Threats
NewPig-butchering scams estimated to have stolen $75B globallyAlertIRS impersonation scams surge this 2026 filing seasonNewFake Coinbase support calls reported nationwide
Threat Intelligence·March 31, 2026·Updated June 17, 2026

Phishing Complaints Jumped 85% Last Year. The Vector Is AI.

The National Consumers League's Top Ten Scams of 2025 report: phishing and spoofing complaints nearly doubled year-over-year, with median losses jumping from $1,000 to $2,060. The mechanism is AI.

Phishing Complaints Jumped 85% Last Year. The Vector Is AI.
● Interactive SimulationEmail
⚠️ Unusual Sign-In Detected — Verify Your Account Within 24 Hours
Chase Online Security Team
<secure-alert@chase-account-verify.net>

Dear Valued Customer, our systems detected a sign-in attempt to your Chase account from an unrecognized device in Portland, OR at 2:47 AM. For your protection, we have temporarily limited your account.

To restore full access, you must verify your identity by clicking the secure link below. Failure to verify within 24 hours will result in permanent account suspension.

✅ Verify My Identity Now → https://chase-secure-login.account-verify.net/auth

Once verified, you will be asked to confirm your full name, date of birth, Social Security Number, and card details so we can authenticate the account holder.

This message was generated by Chase Automated Fraud Prevention. Reference ID: CHX-2025-884712. Do not reply to this email.

Thank you for banking with Chase. We apologize for any inconvenience and appreciate your prompt attention to this security matter.

The National Consumers League's Fraud.org Top Ten Scams of 2025 report documents something that's been visible in case loads for a while: phishing and spoofing complaints nearly doubled year-over-year, with median losses jumping from $1,000 to $2,060.

That 85.6% increase isn't noise. It reflects a structural shift in how phishing is produced. NCL's Vice President of Fraud Policy, John Breyault, names the mechanism directly: AI enables criminals to generate highly realistic phishing emails and clone voices at volume, making the outreach more convincing and allowing them to reach more targets than before. The marginal cost of a phishing campaign has collapsed.

The Numbers Behind the Headline

The report analyzed 1,376 consumer complaints. Investment scams led in median loss at $30,000 per victim, a figure that reflects the long-con structure of pig-butchering and related schemes, where operators invest weeks building trust before the extraction. Phishing complaints may generate lower individual losses, but the volume multiplier matters: 85% more complaints means 85% more entry points for account compromise, credential theft, and secondary fraud.

What AI-Generated Phishing Actually Looks Like Now

The tells that used to mark phishing... awkward phrasing, odd formatting, generic greetings, are largely gone. Current AI-generated phishing emails are contextually appropriate, grammatically clean, and often reflect specific details about the target pulled from public data. The email appearing to come from your bank now sounds exactly like your bank's actual communication style.

Voice cloning adds a second layer. When the phishing email is followed by a call from what sounds exactly like your bank's fraud department, the combined attack is substantially more effective than either alone.

The Protocol Hasn't Changed

The correct response to any unexpected contact from a bank, government agency, or financial institution is identical regardless of how convincing the message seems: hang up or close the email. Navigate to the institution's verified website or call the number on the back of your card. Never click a link to "verify" anything. Never call back a number provided in a text or voicemail.

The AI is better. The protocol to defeat it hasn't changed.

phishingspoofingAI fraudinvestment scamsNCL report