Fraud automation: does AI change conversion, attacker cost, or successful cash-out?

#topic #research-brief #fraud

Fraud automation: does AI change conversion, attacker cost, or successful cash-out?

Question and standard (5 October 2026): When a model drafts personalized emails or voices a scam, which link changes—reconnaissance, persuasive contact, reply, payment authorization, withdrawal, or irrecoverable proceeds? A good answer compares equal-personalization humans and models, measures actions rather than stated intent, and counts all-in delivery, account bans, bank checks and recovery costs. Gates/Amodei map | separate bio chain.

Three subquestions and primary source shortlist

  1. Comparable recipient experiments? Heiding et al. 2026 email field click experiment finds 54% for both AI and expert human among 101 mostly university recruits, but human messages are group-tailored while machine messages are individually researched, and the only measured consequential action is clicking a safe link. A widely repeated 54%-versus-12% claim compares AI to untargeted generic mail, not humans. The 2026 voice survey compares AI and human scripts/voices among 4,100 matched US adults, but its 16.5% “yes or unsure” is stated willingness to comply with a recording stripped of safeguards, not live transfers.
  2. Observed operator-to-victim handoff? OpenAI’s July Cambodia incident traces ChatGPT accounts writing and translating persona-based chats, fabricated visuals and requests for transfer proof. It does not verify alleged losses or incremental efficacy, and disruption of those accounts does not measure actor cessation. The FTC’s 2025 reported impersonation losses are not classified by AI involvement.
  3. What stops cash-out? FBI IC3 2025 tracks complaint reports and bank freezes; $679m frozen of $1.164bn in attempted theft across 3,900 selected financial fraud recovery actions demonstrates intervention but is not a population-wide prevention probability. An “AI related” descriptor just means a complaint references AI. The email researchers' large profitability improvement and voice paper's small positive hourly profits for some hosted models are modeled conditional on assumed click→payment conversion and attacker wage, not measured returns.

Synthesis and named disagreement

The authors’ strongest case, expressed accessibly in Heiding/Schneier/Vishwanath’s 2024 essay, is that existing consumer models can collapse labor-intensive reconnaissance and wording into low-cost service calls while retaining persuasive human-level messages; the 2026 trial is a partial later check and OpenAI documents actual criminal use. Against the stronger claim that models have already caused a specified increase in stolen funds, the experiments stop at click or stated intent, the live report cannot verify loss, and the official aggregate tallies have neither AI causal labels nor comparison groups. A criminal actor needs access to a hosted model and victim-delivery channel, not its own frontier GPUs, but must still pass filtering, verification and banking rails; detection, account termination, payment freezes and law-enforcement action are genuine, nonuniversal brakes. Next discriminating observation: consenting, real-world matched human/AI campaigns with equal profiles and held-out recipients, tracked delivered→interacted→security-gated→authorized→recovered endpoints; a separate privacy-protecting sample of actual incidents linking AI-use logs, total attacker inputs and net unrecovered funds to credible controls.

Search discipline and feed

Queried studies of human-versus-AI phishing/voice, official fraud counts, observed criminal operations and transaction interdiction; checked email study methods and modeled economics, voice-survey safeguards, OpenAI incident limitations and the IC3 data descriptor against their primary texts. Further open query only if Dru asks for bank-control effectiveness on a particular payment rail. Monday: share the short authors’ essay (originally 2024, now interpreted with 2026 results) instead of sending a 21-page methods paper; hold original email and voice papers for a weekend if the thread lands. No causal AI-loss series located.