Share
In the age of AI, financial institutions and fintechs must do more to protect their customers from social engineering fraud
Aug 11, 2026
A majority of Americans are worried that AI is making scams harder to detect.
You get a call from a loved one’s phone number. When you answer, you hear their voice for a moment. Then, someone joins the call to tell you that your loved one will be harmed if you don’t send money immediately.
The terrifying scenario creates a sense of urgency and an emotional reaction that overrides any logical reason to doubt the caller. So you send them money. Once they get it, they hang up on you. And when you call your loved one back, they answer completely unharmed.
You’ve just been scammed. A criminal used caller ID spoofing to make you think the call was coming from your loved one’s phone, coupled with sophisticated deepfake technology to generate their voice. And now, your bank account is lighter by hundreds or even thousands of dollars.
This is known as an emergency scam, and it’s becoming increasingly common as artificial intelligence (AI) becomes more accessible to bad actors. For financial institutions trying to keep their AI/ML checks up to date, AI offers new opportunities for fraud detection and prevention. But right along with them are new tactics fraudsters can use to steal people’s money. Increasingly, these cyberattacks are being powered by generative AI and scaled through AI-driven workflows that make social engineering faster, cheaper, and harder to detect.
The truth is, in the arms race of AI, financial organizations are still trying to catch up to fraudsters and cybercriminals. Alloy’s 2025 State of Scams Report found that 85% percent of Americans worry that advances in AI technology are making scams harder to detect, creating an opportunity for financial institutions and fintechs to step in as protectors. At the same time, over a quarter (27%) of Americans have experienced an AI-generated scam personally, or know someone who has, revealing the extent of the problem at hand.
From phishing and vishing to deepfakes and other social engineering attacks, AI is a powerful tool for fraudsters
Social engineering scams are schemes in which cybercriminals try to bait people into sharing sensitive information that can be used to commit fraud. These exploit human psychology, including the instinct to protect family members and respond quickly under stress. Recently, social engineering methods have only expanded with advances in AI.
One phish, two phish
In a phishing scam, the attacker impersonates a trusted person or organization to trick someone into sharing sensitive information such as login credentials, account details, or verification codes, or into taking an action that enables fraud. Phishing attacks can take many forms, including phishing emails, vishing (conducted over the phone), and smishing (delivered via text message).
AI has made spear phishing, an extremely targeted version of phishing, all the easier for a fraudster to employ. With LLMs, scammers can now spin up convincing phishing campaigns in minutes, tailoring tone and details to the exact person they’re impersonating. In many cases, the hook starts on social media, where scammers scrape public posts, job updates, or relationship details to make the outreach feel eerily personal. Bad actors may carry out impersonations directly via social media, phone calls, messaging apps, text messages, and more.
Per month, Americans received an average of 63 spam texts each — that’s 19.2 billion spam texts total in just one month. Instead of sending these messages manually, scammers can use bots and AI to automate outreach across thousands of targets at once, probing for human and system vulnerabilities in parallel. The sheer scale, along with the increasing believability, makes it difficult for both consumers and financial organizations to stop hackers before they gain access to sensitive financial information.
Looking for truth in a deepfake world
The word “deepfake” combines “deep,” from deep learning AI methods, and “fake,” to describe fabricated media. The term entered widespread use in late 2017 after users in Reddit communities began sharing AI-manipulated videos online.
In 2026, fraudsters are using AI to execute hyper-precise voice cloning or create deepfake videos that trick you into handing over confidential information — like your “boss” asking for your company credit card details. More abstractly, fraudsters have used AI to impersonate bankers reaching out to customers, often using a fake data breach, discovery of malware, or other cybersecurity issue as their cover. (Strangely enough, there have also been instances of customers reaching out to bankers.)
Deepfakes have become increasingly popular with scammers in recent years, with one report finding a 3,000% increase in deepfakes. As synthetic media becomes more convincing, distinguishing between authentic and manipulated content becomes significantly harder. This is especially true in moments of urgency, when there’s little time to verify what’s real.
How financial service providers can thwart AI-aided social engineering fraud
Consumers are increasingly looking to financial institutions and fintechs not just as service providers, but as partners in scam prevention and recovery. 67% of consumers believe their financial institution should reimburse them for money lost in a scam, even when they personally authorized the transaction. Customers want to see financial organizations act at key moments, not just respond after the damage is done.
It’s true that financial institutions and fintechs face an uphill battle when it comes to addressing social engineering scams, primarily because they can’t always adapt as quickly as cyber threats can. Unregulated and unconstrained by legacy systems, fraudsters are using AI to perfect social engineering tactics so they can extract as much money as possible. And it’s working. Approximately one-fourth of Gen Z and Millennial consumers have lost $5,000 or more to fraud, per Alloy’s State of Scams report.
Fraudsters have discovered the same productivity gains from AI that the legitimate business world has. Jailbroken LLMs — often marketed under names like “FraudGPT” — help bad actors generate convincing scripts, scrape publicly available data, and scale AI-enhanced social engineering techniques. No longer crafting each message manually, fraudsters are applying AI to help them refine language, mimic writing styles, and expand their attack surface across geographies. By the time your customer realizes what has happened, the red flags are long past.
Leveraging AI is a powerful way that financial institutions and fintechs can protect their customers. McKinsey is clear on the benefit of agentic AI-powered KYC/AML processes. In the UK, banks like Lloyds Banking Group and Halifax have implemented Mastercard’s consumer fraud risk model, which is trained on years of transaction data to help predict if someone is trying to transfer money to an account associated with previous scams.
Where does Alloy fit in?
At Alloy, we’re building AI tools designed to detect and disrupt fraud enabled by social engineering. Here’s what to know.
Orchestrate diverse data solutions
Social engineering fraud rarely succeeds because a single signal is missing. Instead, it succeeds when identity and behavioral data live in silos, preventing financial organizations from seeing how risk signals interact across the customer journey.
In these cases, a fraudulent transaction initiated by a legitimate customer may pass traditional identity checks because the customer is real and authenticated. The risk often becomes visible only when multiple data points are analyzed together rather than in isolation.
That’s where Alloy’s data orchestration layer comes into play. It joins more than 250 third-party data solutions covering user identity, device, and behavior into a unified decisioning engine. So instead of toggling between point solutions, teams can assess risk holistically at onboarding and throughout the customer lifecycle. This enables financial institutions and fintechs to introduce the right level of friction at the right moment without impacting the broader customer experience.
Connect identity signals with Fraud Signal
Orchestrating data is only the first step. It’s also important to look at how that data is interpreted.
Fraud Signal is Alloy’s predictive machine learning model that connects onboarding, transaction, and ongoing account activity to deliver full-lifecycle fraud detection. It condenses numerous risk checks into a single, dynamic fraud score, helping teams cut through noise and prioritize what requires action.
Rather than relying on static thresholds, Fraud Signal identifies patterns that indicate elevated scam risk, including subtle shifts in behavior and scam typologies that evolve over time. Because the model continuously learns from aggregated activity across Alloy’s network, it automatically adapts as fraud tactics change, strengthening detection without requiring constant manual rule updates.
In social engineering cases, where a customer is authenticated and appears legitimate, Fraud Signal contextualizes actions against their typical behavioral patterns to flag anomalous behavior. Signals like an atypical login time, a sudden change to contact information or security settings, or unusual activity leading up to a transaction can trigger a spike in risk score before funds have moved. By the same token, Fraud Signal reduces false positives, combatting alert fatigue and allowing agents and teams to redirect their attention to where intervention is most likely to prevent loss.
Reduce investigation bottlenecks with AI Assistant
As AI-powered social engineering scams scale, investigation often becomes the bottleneck. Determining whether a transaction reflects genuine intent or external manipulation often requires analyzing multiple factors to get a clearer picture of the underlying context.
Alloy’s AI Assistant is an agentic solution designed to accelerate that process by surfacing key insights in a unified snapshot view, making reviews faster and more intuitive. It contextualizes risk drivers, highlights relevant behavioral shifts, and recommends clear next steps for investigators to take. Instead of gathering context manually, teams can focus on making time-sensitive decisions. By accelerating case review and reducing operational friction, AI Assistant helps teams act before losses escalate.
A world where AI is everywhere
Bad actors rely on manufactured urgency to push customers into making decisions before they have time to question them. Defensive systems need to do the opposite: introduce clarity and, when appropriate, friction. When deployed at the right moment, even small friction points like multi-factor authentication (MFA) or step-up verification can interrupt that urgency and give a customer space to reconsider what’s happening.
AI will remain both a threat and a tool to be used against fraudsters in the coming years. The financial organizations that take on AI-powered protection from social engineering scams will be better positioned to get ahead of fraudsters and build trust with their customers.
Alloy’s capabilities reflect how we think about defending against AI-enabled social engineering. The attack may start with a convincing message, a spoofed number, or a deepfake. But the fraud that follows leaves patterns. The more scalable social engineering threats like phishing scams become, the more important it is for threat intelligence and identity risk systems to keep pace.
Read about why your fraud model might be broken from Alloy’s CEO Tommy Nicholas.
Stay two steps ahead of scammers
Social engineering scam prevention starts with a well-rounded understanding of customer behavior and identity. Alloy can help.