By Alexander Stone
Alexander Stone
Eight people are defrauded every minute in the United Kingdom. In the time it takes to read this sentence, criminals will have siphoned roughly £30 from someone’s bank account, pension fund, or savings. By the end of today, that tally will reach nearly £3.5 million – not as a dramatic heist, but as the quiet, industrialised bleeding of a nation’s finances. The figure is staggering. But what makes it truly alarming is the engine driving it: artificial intelligence.
The Scale Nobody Prepared For
UK Finance’s Annual Fraud Report 2026, published in June, delivered numbers that even seasoned analysts found disquieting. Criminals stole £1.28 billion through payment fraud in 2025 – a four per cent increase on the prior year and the highest figure since the pandemic peak of 2021. The total number of cases reached a record 4.1 million, up eleven per cent, representing a 31 per cent surge in just two years.
These are not abstractions. They are the deposit accounts of retirees, the business revenues of small firms, the savings of young families. And the trajectory is not flattening. Authorised push payment (APP) fraud, where victims are manipulated into transferring money to criminals, jumped by 19 per cent to £576.4 million. Investment scam losses soared by 40 per cent to £221.5 million – another record.
“These figures are a measure not just of criminal ambition but of the technological advantage fraudsters currently enjoy,” said Ruth Ray, Managing Director of Economic Crime at UK Finance. “Criminals are exploiting advances like AI to industrialise operations, tailor cross-border scams, and target British victims through global platforms and social networks.”
What Ray describes is not a minor escalation. It is a structural transformation of how crime operates in the digital age.
When Deepfakes Became a Weapon of Scale
The numbers from UK Finance capture the financial cost. They do not fully convey the sophistication now being deployed against ordinary people. In 2025, an estimated eight million deepfakes were shared globally – up from 500,000 just two years earlier. In the UK alone, deepfake fraud attempts nearly doubled, rising 94 per cent, according to identity verification platform Sumsub.
This is no longer the domain of state-level actors or well-funded syndicates. Generative AI tools have democratised the production of synthetic media. A fraudster can clone a victim’s voice from three seconds of audio, generate a convincing video of a CEO approving a wire transfer, or fabricate an entire identity document in minutes. The National Assessment Centre’s 2025 Fraud Assessment confirmed that organised crime groups are using AI-generated text, audio, images, and video to facilitate investment, online shopping, romance, and payment diversion frauds.
In February 2024, a now-notorious case demonstrated the stakes: criminals used deepfake recreations of company employees in a virtual meeting to convince a finance worker to transfer £20 million into a criminally controlled account. The technique has since proliferated. The Surrey Police and Crime Commissioner, Lisa Townsend, became the subject of a deepfake video used in a public awareness campaign after warning that “only three seconds of audio is required to clone a person’s voice to be manipulated and say whatever a criminal wants.”
The implications extend beyond finance. The National Crime Agency has identified the growth of “scam compounds” – criminal hubs operating with the efficiency of call centres and the brutality of trafficking networks, where victims of human trafficking are forced to run investment scams, romance frauds, and phishing operations. Fraud is no longer merely a digital crime. It is an exploitation-driven industry linked to modern slavery.
The Other Side of the Coin
Here is the paradox that defines this moment: the same technology enabling criminals is also the most powerful weapon defenders possess. UK Finance reported that banks prevented £1.68 billion in unauthorised payment fraud in 2025 – equivalent to 70 pence in every pound of attempted attacks. The Cifas National Fraud Database helped organisations prevent an estimated £2.4 billion in losses. These are not minor interventions.
AI-powered systems now monitor transactions in real time, flagging anomalous behaviour through behavioural analytics that assess not merely what users do, but how they do it – the speed of their keystrokes, the pattern of their device usage, the cadence of their navigation. Machine learning models trained on consortium datasets can connect disparate signals across accounts, institutions, and geographies to surface risk that no single organisation could detect alone.
“The financial sector invests huge amounts in protecting customers, but we cannot be the only line of defence,” Ray told reporters. “We need an equally technology-led and joined-up approach to tackle the problem: smarter use of digital tools, greater commitment to data sharing, and shared accountability.”
The FCA’s 2024 survey of UK financial services found that 75 per cent of firms are already using AI, with 55 per cent of use cases involving some degree of automated decision-making. Among the greatest perceived benefits: anti-money laundering and fraud detection. Among the greatest perceived risks: cybersecurity itself – the very infrastructure on which these defences depend.
Pavel Goldman-Kalaydin, Head of AI/ML at Sumsub, framed the dynamic with precision: “AI reshapes both offense and defense. Attackers gain deepfakes, synthetic IDs, and autonomous fraud agents; defenders gain behaviour modelling, millisecond anomaly detection, and self-learning systems. The next frontier is verifying AI agents themselves – confirming not just who you are, but who acts on your behalf.”
That framing captures a truth that regulators are only beginning to absorb. The fraud ecosystem is no longer a contest between humans and humans. It is a contest between algorithms and algorithms, each learning from the other in real time.
Britain’s Regulatory Reckoning
The UK government has begun to respond, though critics argue the measures remain insufficient relative to the scale of the problem. In February 2026, the Home Office launched a world-first deepfake detection evaluation framework, bringing together Microsoft, academics, and experts from the Five Eyes intelligence-sharing alliance to test detection tools against real-world threats including impersonation, fraud, and non-consensual sexual images.
The National Crime Agency and City of London Police ran Operation Henhouse throughout February 2026 – the most successful iteration yet of the UK-wide anti-fraud campaign, resulting in 557 arrests, the freezing of accounts holding £9 million, and seizures of cash and assets worth £18.1 million. Since its inception five years ago, 1,904 people have been arrested and more than £67 million has been seized or disrupted.
The government has also committed £250 million over three years to a new online crime squad, drawing specialists from law enforcement, intelligence agencies, banks, mobile networks, and major tech firms. Fraud now constitutes 45 per cent of all crime in England and Wales, according to the NCA – a statistic that elevates it from a consumer nuisance to a matter of national security.
Yet the enforcement machinery remains reactive. The UK Finance report called for “stronger, enforceable responsibilities” on tech platforms, including mandatory seller verification and secure payment protections on online marketplaces. Ofcom’s Online Safety Act consultation, which could impose proactive fraud prevention duties on social media companies, has moved slowly. Sixty-six per cent of APP fraud cases originate online, where criminals exploit the advertising infrastructure of platforms such as Facebook Marketplace, Instagram, and TikTok.
“The alarming truth is that the tech platforms are financially benefiting from fraudulent advertising,” Ray said. “It’s wholly wrong that other sectors are knowingly profiting from fraud and scams due to loose controls around advertising.”
The tension between platform liability and innovation is not new. But the scale of loss – £1.28 billion in a single year, with 12 per cent of APP fraud losses still not reimbursed – has shifted the political calculus. Fraud minister Lord Hanson stated plainly: “Fraudsters are exploiting new technology, industrialising their operations and targeting the British public at scale.”
The Human Cost Behind the Numbers
What statistics obscure is the psychological toll. Fraud does not merely empty bank accounts. It erodes trust – in institutions, in technology, in one’s own judgement. Victims of romance fraud, which saw losses rise 23 per cent to £39.2 million in 2025, describe a betrayal that cuts deeper than any financial calculation. Victims of investment scams, many of whom are first-time investors lured by deepfake celebrity endorsements, report lasting damage to their confidence and relationships.
The Cifas Fraudscape 2026 report noted that 72 per cent of all cases recorded in 2025 were linked to identity fraud and facility takeover – meaning that for the majority of victims, the violation is not merely transactional. It is personal. Criminals are not merely stealing money. They are stealing identities, then using those identities to commit further crimes, creating a cascade of harm that propagates through the financial system.
Mike Haley, CEO of Cifas, put it starkly: “Our data and intelligence show how fraud is being industrialised, with AI accelerating crime that is increasingly digital, organised and international. Fraud must be treated as a national enforcement priority.”
Nick Sharp, Deputy Director of Fraud at the National Crime Agency, added that “convictions by UK law enforcement are up 27 per cent since 2022” – a meaningful uptick, but one that pales against the volume of cases entering the system. The enforcement gap remains vast.
What Comes Next
The trajectory is clear. AI will continue to lower the barrier to entry for criminals while simultaneously enhancing the sophistication of their attacks. The NCA’s 2026 National Strategic Assessment warned that “agentic AI” – autonomous systems capable of executing multi-step fraud operations without human intervention – is “highly likely” to be the next force multiplier for organised crime.
Defending against this requires more than better algorithms. It demands a structural reimagining of how fraud prevention is coordinated across sectors. The Financial Conduct Authority has launched its AI Lab, testing solutions in real-world conditions with regulatory oversight. Over 200 firms have participated. The FCA’s Supercharged Sandbox, launched in May 2025, offers a controlled environment for firms to experiment with AI-driven fraud detection under supervision.
But technology is only as effective as the governance surrounding it. The dual-use nature of AI means that every defensive advance is quickly studied and circumvented by adversaries with access to the same open-source models. Black-box algorithms, whose decision-making processes remain opaque, create accountability gaps that undermine public trust. Explainable AI – systems whose reasoning can be understood and audited by human operators – is no longer a theoretical ideal. It is an operational necessity.
The road ahead demands collaboration at a scale that has not yet been achieved. Banks, technology platforms, telecoms providers, and law enforcement agencies must share data in real time, align incentives, and accept shared responsibility for outcomes. The £1.28 billion stolen in 2025 is not merely a financial loss. It is a measure of the gap between what is possible and what is being done.
As Ray warned: “The UK cannot afford delay. The longer these gaps remain, the longer criminals will exploit them.”
The clock ticks. Eight people per minute are paying the price.
This article draws on data from UK Finance’s Annual Fraud Report 2026, Cifas Fraudscape 2026, the FCA/Bank of England AI in UK Financial Services Survey, the NCA’s 2026 National Strategic Assessment, the Government’s Cyber Security Breaches Survey 2025/2026, and Sumsub’s Annual Fraud Report.
Related reading:





