AI-Fueled Cyber Scams Now Target 9 in 10 Americans, Report Finds

17% of U.S. consumers have lost money to digital security breaches, with vulnerable populations increasingly targeted by AI-enabled personalized fraud.
AI is making fraud faster, cheaper and more personal
Consumer Reports CEO on why individual defenses are no longer sufficient against AI-enabled scams.
Mark

So nine in ten Americans have been targeted. Does that mean nine in ten have lost money?

Mimi

No. The survey found that 90% encountered a scam or cyberattack, but only 17% actually lost money. Still, that's tens of millions of people.

Luke

Right, and we should be careful about the word "targeted." That could mean anything from a phishing email to a sophisticated deepfake. The report doesn't break down the severity.

Mark

What makes AI different from old-fashioned scams?

Mimi

Speed and personalization. Before, a scammer might send generic phishing emails. Now AI can take stolen data—your address, your financial history—and craft a message that feels like it's from your bank, offering you a specific mortgage rate.

Luke

But how many scams actually use AI right now? The report says one in five includes personalization, but that's not the same as saying one in five uses AI specifically.

Mimi

Fair point. It's growing, though. The experts quoted say this is just the beginning.

Mark

What can people actually do about it?

Mimi

Two-factor authentication, multifactor authentication, and the Take9 initiative—pausing for nine seconds before clicking anything suspicious.

Luke

Those help, but the experts also say personal precautions alone aren't enough. The real fix requires companies and governments to build better infrastructure.

Mark

So individuals can't solve this by themselves?

Mimi

No. That's the conclusion. It's too big, too fast, too personalized now.

Luke

And we don't yet know how effective those nine-second pauses actually are, or how quickly AI will evolve past current defenses.

  • AI has shattered the old economics of fraud — what once required skilled labor and time can now be done at massive scale in minutes, putting virtually every American in range.
  • One in five scams already carries personalized details drawn from data breaches, and deepfakes are making even cautious, tech-savvy people unable to trust what they see and hear.
  • The familiar defenses — spotting typos, checking sender addresses, avoiding suspicious links — are no longer enough when the attack is built from your own data and sounds exactly like someone you know.
  • Security experts are pushing multifactor authentication and layered protections as essential, not optional, while also acknowledging that individual precautions cannot fix insecure infrastructure upstream.
  • A nine-second pause before clicking — the Take9 initiative — has emerged as one of the few interventions that remains entirely in the hands of the person being targeted.
  • Researchers and executives are calling for corporate accountability and government regulation, warning that the scale of AI-enabled fraud has simply outgrown anything individuals or single institutions can solve alone.

In an age when fraud once demanded patience and craft, artificial intelligence has collapsed those barriers entirely — nine in ten Americans now find themselves in the crosshairs of digital scams that are faster, cheaper, and more intimate than anything criminals could have engineered before. A survey of nearly five thousand adults reveals not an epidemic at the margins but a condition of modern life, one where stolen data is alchemized by machines into messages that feel personal, trusted, and real. Seventeen percent have already lost money; experts warn the worst is still ahead. The question before institutions and individuals alike is whether accountability can move as swiftly as the threat.

Nine out of ten Americans have been targeted by a digital scam or cyberattack — not a niche vulnerability but a near-universal experience, according to a survey of nearly five thousand adults conducted by Consumer Reports, Aspen Digital, and the Global Cyber Alliance. Seventeen percent said they had actually lost money. The numbers are striking, but the mechanism behind them is what has changed: artificial intelligence has made fraud faster, cheaper, and far harder to recognize.

Before AI, personalizing a scam at scale was economically impractical. Crafting individual messages for thousands of targets required too much time and labor. Now, AI synthesizes stolen personal data — addresses, financial histories, behavioral patterns — and generates thousands of customized attacks in minutes. One in five scams already includes some form of personalization, and that proportion is expected to climb. A criminal armed with breach data could pose as your bank, referencing details only you would recognize. Even a deepfake video or a message that sounds like a trusted friend can fool people who consider themselves careful.

Stacey Higginbotham of Consumer Reports told CBS News that the old stereotypes about who gets scammed no longer apply. "It is truly everyone now," she said, "and AI is just going to accelerate that." The technology has democratized fraud, lowering barriers that once required real resources or technical sophistication. More data breaches mean more personal information circulating in criminal networks — and AI makes it trivial to weaponize all of it.

Security experts are now treating two-factor and multifactor authentication as essential rather than optional. But even layered defenses have limits. Brian Cute of the Global Cyber Alliance noted that personal precautions cannot address the insecure routing infrastructure and maliciously registered domains that enable abuse at the source — closing those gaps requires coordinated action across industry, government, and philanthropy.

One low-tech response has gained attention: the Take9 initiative asks people to pause nine seconds before clicking a link or responding to a suspicious message — a small friction that returns at least one tool to the person being targeted. Phil Radford of Consumer Reports put the larger challenge plainly: "AI is making fraud faster, cheaper and more personal, and no one can outsmart that alone. Companies need to be held accountable. Governments need real guardrails." What comes next depends on whether institutions can move as quickly as the criminals already are.

Nine out of every ten Americans have been targeted by a digital scam or cyberattack. That statistic, drawn from a survey of nearly five thousand U.S. adults conducted in March and April by Consumer Reports, Aspen Digital, and the Global Cyber Alliance, represents not a niche problem but a near-universal experience. Seventeen percent of those surveyed said they had actually lost money to a breach. The numbers are stark, but the mechanism behind them is what matters: artificial intelligence has fundamentally changed how criminals operate, making fraud faster, cheaper, and far more difficult to spot.

Before AI, running a personalized scam required time and labor that made it economically impractical at scale. A criminal might craft a convincing phishing email, but sending fifty of them with individual details tailored to each recipient was too much work. Now, AI synthesizes stolen personal data—your address, your financial history, your patterns—and generates thousands of customized messages in minutes. One in every five scams already includes some form of personalization, and experts expect that proportion to climb rapidly. A scammer armed with information from a data breach could pose as your bank and offer you a suspiciously good mortgage rate, using details only you would recognize. Even someone careful about clicking suspicious links, wary of spelling errors and odd sender addresses, could fall for a deepfake video or a message that sounds exactly like someone they trust.

Stacey Higginbotham, a cybersecurity fellow at Consumer Reports, told CBS News that the old stereotypes about who gets scammed no longer hold. "It is truly everyone now, and AI is just going to accelerate that," she said. "I don't think we've seen even the beginning with the number and quality of scams reaching people." The technology has democratized fraud. Where once you needed sophisticated technical skills or significant resources to run a convincing con, now the barrier to entry is lower than it has ever been. More data breaches mean more personal information circulating in criminal networks. AI makes it trivial to weaponize that information.

Colin Ferris, a cybersecurity expert at Silverfort, explained the shift plainly: before AI, the effort required to personalize something at scale was prohibitive. You couldn't do it. Now you can. The result is that consumers' defenses—the habits and instincts that once protected them—are no longer sufficient. Tech-savvy individuals who pride themselves on spotting scams are finding themselves vulnerable to attacks they never saw coming.

Security experts are now insisting on measures that once seemed optional or redundant. Two-factor authentication, multifactor authentication, and other layered defenses are no longer nice-to-have features but essential safeguards. Yet even these have limits. Brian Cute, president and CEO of the Global Cyber Alliance, noted that personal precautions alone cannot stop the abuse flowing from upstream—from insecure routing infrastructure and maliciously registered domain names. Closing those gaps requires coordination across industry, government, and philanthropy. No individual password or security patch can do it alone.

One low-tech intervention has gained traction: the Take9 initiative encourages people to pause for nine seconds before clicking a link, downloading a file, or responding to a suspicious message. It is a small friction, a moment to reset, to think. In a landscape where criminals can now generate thousands of personalized attacks in the time it takes to drink a cup of coffee, that nine-second pause may be one of the few tools that remains entirely in the hands of the person being targeted.

Phil Radford, president and CEO of Consumer Reports, framed the challenge as one of accountability and governance. "AI is making fraud faster, cheaper and more personal, and no one can outsmart that alone," he said. "Companies need to be held accountable. Governments need real guardrails." The implication is clear: the problem has outgrown individual solutions. What happens next depends on whether institutions move as quickly as the criminals do.

It is truly everyone now, and AI is just going to accelerate that. I don't think we've seen even the beginning with the number and quality of scams reaching people.
— Stacey Higginbotham, Consumer Reports cybersecurity fellow
AI is making fraud faster, cheaper and more personal, and no one can outsmart that alone. Companies need to be held accountable. Governments need real guardrails.
— Phil Radford, Consumer Reports president and CEO
Contact Us FAQ