AI-driven deepfake scams push identity theft risks into new territory

Advancements in artificial intelligence are making identity fraud more convincing and scalable, prompting a wave of innovative privacy tools aimed at reducing personal data exposure and curbing AI-assisted scams.

Identity theft is becoming harder to detect and easier to scale, and artificial intelligence is a major reason why. The Federal Trade Commission said consumers reported losing more than $12.5 billion to fraud in 2024, a 25% increase from the year before, while the FBI’s latest Internet Crime Report put total reported losses above $16 billion. Both reports point to phishing, spoofing and impersonation schemes as persistent threats that are being sharpened by more convincing digital deception.

One of the clearest examples is deepfake fraud. Synthetic video and audio can now imitate executives, relatives or public figures closely enough to fool people in real time. Industry reporting has highlighted cases in which workers were tricked into authorising large payments after joining what appeared to be a routine video meeting, only to learn later that every participant had been fabricated. Experian’s identity and fraud research also shows that generative AI and deepfakes are now among the top concerns for both consumers and businesses.

That shift matters because the attack surface has widened. IBM’s threat intelligence research says cyber-criminals are increasingly using valid accounts and stolen access rather than brute-force attacks, which makes fraud harder to spot and easier to spread across organisations. TechRadar Pro has also reported a sharp rise in AI-assisted scam methods, including phishing lures designed to look more polished, more personal and more believable than the error-strewn emails of the past.

Against that backdrop, privacy tools are being marketed not only as convenience products but as fraud-reduction tools. Surfshark is positioning its service around that idea. Its package includes a standard VPN, which masks a user’s IP address and encrypts traffic, but also a wider set of privacy features intended to limit how much personal data is exposed in the first place. The company says that approach is meant to make it harder for fraudsters to assemble the information they need for impersonation or account takeover.

Among those features is Alternative ID, which creates a substitute identity for use on less-trusted websites or services. Surfshark also offers Incogni, a data-removal service that contacts data brokers and requests deletion of personal details, plus CleanWeb, which blocks trackers, ads and malware at the DNS level. The company has also introduced an anti-scam hub that groups masking tools, dark web monitoring and malicious-site blocking in one place, although the hub is still being tested on iOS.

Surfshark’s wider pitch reflects a broader reality in cyber-defence: no single tool can stop deepfakes, data brokers or AI-written phishing emails, but reducing exposed data can make successful fraud more difficult. That is especially relevant as phishing and spoofing remain among the most common cybercrimes and as businesses report more account abuse, more impersonation and more AI-driven attacks. In practical terms, the message is simple: the less a criminal can learn about a person, the less convincing the scam is likely to be.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.