

Jo Keirns
42 min read

Founded in 1998, Living Tree Company began with natural health, holistic living, and the wisdom of the Tree of Life. Today, it offers a welcoming space for wellness, emotional healing, relationship insight, romance scam awareness, safety, resilience, and understanding human behavior.
This space brings together natural wellness, holistic living, emotional awareness, relationship insight, personal safety, resilience, and a deeper exploration of the mind, heart, and human behavior.
Wellness is viewed here as more than physical health. It includes the roots beneath our choices, the stories people carry, the relationships that shape growth, and the wisdom gained through healing, self-protection, awareness, and change.
I write from a place of curiosity, lived experience, and care. Living Tree Company is not about quick fixes or surface answers. It is about noticing patterns, asking deeper questions, and helping readers feel more informed, more protected, and more connected to their own inner wisdom.
Join me for thoughtful articles on holistic wellness, mental health, emotional healing, relationship safety, romance scam awareness, and the psychology of human behavior.
Text: Join me for thoughtful articles on holistic wellness, mental health, emotional healing, relationship safety, romance scam awareness, and the psychology of human behavior.
Subscribe or Join the Newsletter

Romance fraud has entered a new phase. The old advice—look for broken English, demand a video call, run a reverse-image search on the profile photo, or assume a scammer will quickly ask for gift cards—is still useful, but no longer sufficient. Generative AI has changed the economics and mechanics of deception. Criminal groups can create convincing identities, sustain fluent emotional conversations, imitate faces and voices, and guide victims into fake investment platforms or credential-stealing traps without relying on many of the clumsy patterns that once exposed them. [1, 2, 3, 4]
The most important shift is that romance scams are becoming less like isolated catfishing attempts and more like industrialized confidence operations. Research from the Centre for Emerging Technology and Security describes how AI can automate initial outreach, generate persuasive scripts, create synthetic personas, and support large-scale scam workflows, while the Global Cyber Alliance warns that AI makes these scams smoother, more scalable, and harder to recognize. Security reporting also points to deepfake video, voice cloning, chatbot-driven intimacy, and crypto-investment grooming as central features of the modern threat landscape. [1, 2, 3]
For years, online communities were taught to spot romance scams through surface-level clues: strange grammar, reused profile photos, refusal to video chat, inconsistent personal details, and urgent pleas for money. Those clues still matter, but they are no longer reliable as a first line of defense. AI-generated writing can remove obvious language mistakes. Synthetic images may not appear in reverse-image searches because they were never posted anywhere before. Deepfake or synthetic video can weaken video-based verification, and voice cloning can add the warmth and continuity of a familiar speaker. Automated conversation systems can remember details, mirror tone, and deliver affectionate messages at scale. [1, 2, 3, 5]
This matters for fandom spaces because parasocial trust, shared enthusiasm, and community intimacy can be exploited. A scammer no longer has to appear as a random stranger. They can pose as a fellow fan, a creator-adjacent insider, a convention contact, a crew member, a journalist, a charity organizer, or a person who seems to understand the emotional language of the fandom perfectly. AI makes that mirroring easier. It can analyze public posts, generate references to beloved characters or story arcs, and produce messages that feel tailored rather than generic. [1, 2, 5]

The video-call test used to be treated as a decisive safeguard: if the person would not appear live, the relationship was suspicious; if they did appear live, many targets relaxed. That assumption is now less safe. Deepfake and face-swapping tools can create believable video evidence and, in some contexts, can support interactive impersonation. The strongest public evidence supports deepfake video and believable synthetic media as active fraud risks, while claims that real-time face swapping is routine in romance scams should be treated as plausible but still emerging rather than universal. [3, 6]
In romance scams, this changes the emotional weight of proof. A target may think, “I saw them. They smiled. They answered me.” That moment can become a psychological anchor. Once the victim believes the person is real, later inconsistencies are easier to rationalize. The scammer may blame poor connection quality, work restrictions, travel, privacy concerns, or camera glitches for any visual oddities. The goal is not cinematic perfection; it is enough believability to move the target past doubt.
Voice cloning further strengthens the illusion. A synthetic voice can be generated from short samples and used for voice notes, phone calls, or video conversations. When the voice matches the persona’s supposed age, accent, cadence, or celebrity-like presence, the target may experience the interaction as intimate and authentic. In fandom contexts, voice imitation is especially potent when scammers impersonate public figures, convention staff, podcast hosts, or people who claim to have access to cast and crew. [3, 6]
Live video should be treated as one data point, not proof of identity. Safer verification relies on independent channels, real-world continuity, and low-pressure consistency over time. If someone claims to represent an organization, verify through that organization’s official website, known email domain, or public contact information. If someone claims to be a creator or staff member, do not rely on a private message alone. If a relationship becomes emotionally intense but never moves into ordinary, verifiable reality, that gap matters even if the video calls look convincing.
The modern romance scam often avoids an early direct ask. Instead of requesting emergency money, the scammer positions themselves as a supportive partner with financial knowledge. They talk about building a future together, traveling, buying a home, retiring early, paying off debt, or escaping instability. The emotional pitch is partnership: “I want us to win together.” This is the essence of financial grooming. The victim is not simply tricked into sending money; they are coached into believing that investing is an act of trust, maturity, and shared planning. [7, 8, 9]
This approach overlaps with “pig butchering,” a long-game fraud model in which the scammer patiently fattens the target emotionally before steering them toward a fake trading platform. The platform may show realistic dashboards, fabricated gains, customer-service chats, and withdrawal simulations. Victims may initially be allowed to withdraw small amounts, which builds confidence. Once larger deposits arrive—sometimes from retirement savings, loans, or home equity—the account is frozen, fees appear, taxes are demanded, or the platform disappears. [4, 7, 9, 10]
AI improves this con in several ways. It can generate persuasive explanations, coach across languages, and help criminals rapidly produce professional-looking text, websites, or app content; it can also personalize a pitch to the target’s stated financial goals or vulnerabilities. [1, 3] A victim worried about retirement may be shown a supposed passive-income strategy. A younger fan may be offered a way to afford travel to premieres or conventions. A grieving or isolated target may be told that investing together proves commitment and trust.
A romantic interest introduces investing, crypto, trading, or passive income before meeting in person.
They frame financial participation as teamwork, loyalty, or proof that you believe in the relationship.
They discourage discussing the opportunity with family, banks, or independent advisors.
They send links to unfamiliar apps, private platforms, QR codes, or invitation-only exchanges.
They celebrate early “profits” but become controlling or urgent when you hesitate to deposit more.
Large language models have made it possible to automate parts of romance fraud, especially early outreach and high-volume conversation. Older scams often betrayed themselves through repetition, broken scripts, or inconsistent memory. AI systems can produce fluent, emotionally adaptive messages that reference prior details and respond in the target’s style. However, research also finds that long, multi-turn deception remains difficult for LLMs without human oversight, so the most realistic threat is often a hybrid operation: automation for scale, with human scammers stepping in for persuasion, reassurance, and financial escalation. [1, 2, 5]
Public social media data makes this even more powerful. A scammer or bot can infer hobbies, favorite shows, ships, actors, anxieties, humor style, political sensitivities, grief points, and community ties. It can generate messages that sound like they belong inside the fandom. It can praise the exact fan art a person posted, quote the same episode, or ask thoughtful questions about a theory thread. The manipulation works because the connection feels specific rather than random. [1, 2, 5]
AI personas also change timing. Because automated systems can reduce the labor required to maintain many contacts, scammers can afford to wait longer before introducing money, identity verification, a private app, or a crisis. This patience makes the eventual request feel less suspicious. In a fandom setting, the scam may begin as ordinary community interaction: recommending episodes, discussing ships, sharing convention plans, or offering emotional support after online conflict. Only later does it pivot into money, secrecy, login links, or exclusive access. [1, 2]
Even when grammar is perfect and the persona is convincing, behavior remains revealing. Watch for rapid emotional escalation, isolation from trusted people, pressure to move off-platform, resistance to ordinary offline verification, repeated excuses for not meeting, and a gradual shift from affection to compliance testing. The problem is no longer whether the messages sound “real.” The problem is whether the relationship creates pressure, secrecy, dependency, or financial exposure.
Quishing—QR-code phishing—turns trust into a technical compromise. Instead of asking for money directly, the scammer may send a QR code under a romantic, playful, or exclusive pretext: a private playlist, a digital love letter, a photo album, a fan event invite, a ticket transfer, or a “secure” link for a surprise. The target scans the code because the relationship feels safe. The code may lead to a fake login page, a malicious app download, a payment capture form, or a site designed to collect credentials, personal data, or financial information. [11] Claims that QR codes automatically bypass all two-factor authentication should be avoided unless tied to a specific exploit or documented case. [12]
The danger is that QR codes conceal destinations. A visible web address gives users at least a chance to inspect the domain; a QR code turns that inspection into a quick camera action. On mobile devices, where many people are already logged into banking, email, cloud storage, and social apps, a malicious page can be especially effective. The scammer’s emotional groundwork lowers skepticism precisely when technical caution is needed most. [11]
For fandom communities, quishing can hide inside believable invitations: “scan this for the afterparty list,” “open the private gallery,” “claim your early merch code,” “verify your fan club account,” or “join the cast Q&A.” The scam does not need to look romantic at first. A scammer can blend social belonging, romantic attention, and exclusive access into a single lure.
The FTC specifically warns that virtual casting scams may begin with unexpected outreach, promises of acting or modeling work, requests for upfront payment, or demands for banking information. [14] In a fandom setting, related approaches may use claims of production access, publicity work, convention involvement, or private screeners, but those variations should be treated as illustrative warning signs rather than patterns documented in the FTC alert.
The persuasive advantage is borrowed authority. References to a network, studio, performer, production office, or event can make a request feel official even when the contact begins through a disposable account. AI can reinforce the impersonation with polished messages, images, forms, or other synthetic material. [1, 3] Fans should verify every opportunity through the production company, studio, network, agency, convention, or performer’s independently located official channel. They should not pay an upfront fee or provide banking information in response to an unsolicited casting approach. [14]
Major premieres, finales, convention weekends, cast appearances, and limited merchandise releases create urgency that scammers can exploit. Fraudulent sellers may offer nonexistent tickets, VIP upgrades, hotel rooms, meet-and-greet access, queue positions, or last-minute transfers. Scammers can also use polished screenshots, confirmation messages, invoices, or copycat websites to make the offer appear legitimate even when no valid ticket or reservation exists. [15]
Season-driven urgency is the pressure mechanism: the buyer is told that another fan is waiting, the transfer window is closing, or payment must be completed before a code expires. Fans should purchase through authorized sellers, confirm transfer procedures on the event’s official website, and avoid payment methods that remove chargeback or buyer-protection options. [15] Moderators should require sellers to follow transparent verification rules and should pause resale activity when multiple suspicious offers appear.
A scammer may promise an unaired episode, leaked script, private trailer, cast recording, deleted scene, spoiler archive, or invitation to a closed viewing group. The file or link may instead lead to credential theft, malicious downloads, fraudulent subscriptions, or demands for payment. AI can help produce convincing thumbnails, watermarks, captions, chat screenshots, and supposed insider explanations. [1, 3, 11]
The invitation may deliberately emphasize secrecy or urgency: the recipient is told not to alert moderators, not to share the link, or not to verify the sender because access will be withdrawn. Fans should treat unsolicited downloads, login requests, browser extensions, media players, and archive files as high risk. Legitimate promotional media should be traceable to an official platform or verified account, not to a private link that demands credentials or installation.
The FTC documents refund and recovery scams in which people who have already lost money are contacted again by someone claiming they can recover the loss, often while impersonating an agency, organization, or law firm and demanding an upfront fee or personal or financial information. [16] In fandom communities, moderators should also watch for related—but not specifically FTC-documented—requests for login codes, recovery phrases, remote access, cryptocurrency payments, or identity documents from people claiming to restore an account, remove leaked material, or provide technical help.
This secondary targeting exploits urgency and the desire to reverse the harm. Community notices should state that moderators will not request passwords, authentication codes, recovery phrases, remote access, or payment in private messages. Official platform support should always be reached through an independently located help page. The evidence-based rule is simple: an unsolicited promise of guaranteed recovery, especially when paired with an upfront fee or a request for sensitive information, should be treated as a new scam risk. [16]
Moderators should look beyond individual profiles when several accounts repeat the same story, use similar escalation patterns, promote the same platform or QR code, contact overlapping members, or appear immediately after one account is removed. AI-assisted operations can vary names, profile images, tone, and wording while preserving the same underlying payment destination, domain, app, wallet address, or social-engineering sequence. [1, 2, 3]
Reports should therefore record shared infrastructure and repeated behavior—not only usernames. Useful indicators include reused domains, identical QR destinations, recurring payment instructions, matching wallet addresses, repeated claims of insider status, and the same progression from public conversation to private contact, secrecy, technical action, or money. Grouping related reports can help moderators recognize a coordinated campaign before each account is evaluated in isolation.

The safest modern rule is not “trust but verify.” It is “verify through a separate channel before trust becomes costly.” Do not let romantic intensity, fandom familiarity, or apparent technical proof substitute for independent confirmation. A real person with good intentions will not punish you for taking reasonable precautions.
Never invest through a platform introduced by an online romantic interest.
Do not scan QR codes from private contacts unless you can independently verify the destination.
Keep conversations on the original platform until the person has been meaningfully verified.
Use official websites and known contact channels to confirm events, fundraisers, ticket offers, or creator-related claims.
Talk to a trusted person before sending money, sharing identification, downloading apps, or moving assets.
Assume that video, voice, and polished writing can be synthetic or manipulated.
Report suspicious profiles, preserve screenshots, and warn moderators when fandom spaces are being targeted.
These examples are fictional composites designed to show patterns, not real cases. They should be used for training moderators, fans, and community managers to recognize escalation points. The goal is not to make people distrust every new friendship, but to help them notice when affection, access, urgency, and technical requests begin to converge.
A fan receives private messages from someone claiming to work near a television production team. The person is careful, knowledgeable, and never asks for money at first. When the fan asks for proof, the person agrees to a short video call. The call appears live: the person waves, says the fan’s name, and references an earlier conversation. Afterward, the fan stops questioning the identity because the video call feels decisive.
The risk is not that every video call is fake. The risk is that a convincing call can become a shortcut around safer verification. Moderators should teach members that live video is not enough when the person is claiming access, status, employment, or inside information. Verification should move through official channels, public-facing accounts, known emails, event websites, or trusted organizational contacts.
A community member begins talking daily with someone who shares their favorite show, praises their fan posts, and offers emotional support. After several weeks, the conversation shifts toward future plans: travel, financial security, and attending events together. The person never says, “send me money.” Instead, they say, “I want to teach you what worked for me.” They introduce a trading app, show screenshots of gains, and suggest starting with a small deposit.
The key warning sign is the emotional framing of the financial decision. The scammer presents investment as partnership, loyalty, or shared destiny. Moderators should encourage members to report posts or private messages that promote investment platforms, crypto opportunities, or “exclusive” financial coaching, especially when the offer begins in a romantic or emotionally intense exchange.
A new account enters a fandom space and quickly becomes beloved. It remembers everyone’s favorite characters, compliments specific posts, and sends thoughtful private messages after conflicts or stressful episodes. The account seems unusually available and emotionally precise. Over time, it asks members to move to a private chat, join a closed group, or test a “fan-made” app.
The warning sign is not kindness; it is rapid intimacy paired with private-channel migration and technical requests. A bot-assisted persona can use publicly available information to seem unusually attentive. Moderators should watch for accounts that privately contact many members with similar emotional language, request secrecy, or repeatedly direct users away from the moderated platform.
A user receives a message promising early access to a private gallery, cast Q&A, charity event, or digital love letter. The sender uses a QR code rather than a visible link. The destination asks the user to sign in, install something, enter payment details, or verify identity. The interaction feels low-risk because it is framed as fandom participation or personal affection, not as a financial transaction.
Moderators should discourage QR codes in private messages and require official links for events, fundraisers, ticket transfers, fan projects, or merchandise offers. If QR codes are allowed at all, they should be posted only by verified organizers, accompanied by the full destination URL, and reviewed before being approved.
Moderators cannot prevent every scam attempt, especially when much of the grooming happens in private messages. They can, however, reduce the attack surface by setting clear rules, creating reporting pathways, slowing down financial and technical escalation, and educating members without shaming victims. The best moderation posture is protective, specific, and repeatable.
No investment, crypto, trading, loan, or “passive income” offers in posts or private outreach connected to the community.
No private fundraising, ticket resale, merchandise sales, or event access claims without moderator approval and official verification.
No QR codes for events, galleries, fan projects, payments, or private groups unless the destination is visible and reviewed.
No impersonation of cast, crew, production staff, journalists, convention workers, charity organizers, or platform representatives.
No pressure to move conversations off-platform when the purpose involves money, identity verification, downloads, or exclusive access.
Ask for screenshots of the profile, messages, links, QR codes, payment requests, and app names.
Record whether the account requested secrecy, urgency, off-platform migration, financial action, identity documents, or downloads.
Preserve visible usernames, timestamps, platform names, and destination domains without asking the victim to continue engaging.
Check whether other members received similar messages from the same or related accounts.
Escalate threats involving financial loss, stolen credentials, malware, impersonation, or self-harm language to platform safety channels and appropriate reporting resources.
Short, repeated reminders work better than long warnings posted once. Good safety messages are direct and nonjudgmental: “A real friend or partner will not rush you into investing, scanning a code, downloading an app, or keeping secrets from people you trust.” Another useful reminder is: “Video calls, voice notes, polished writing, and shared fandom knowledge are not proof of identity.” These messages should appear before high-risk events such as premieres, finales, convention weekends, charity campaigns, and major casting news.
1. Acknowledge the report privately and avoid blaming the member.
2. Advise the member not to send more money, scan more codes, download more files, or continue private contact.
3. Remove or quarantine suspicious posts while preserving screenshots and links for reporting.
4. Check whether the account contacted other members and issue a community warning if needed.
5. Report the account to the platform and direct affected members to relevant official reporting resources.
6. After the incident, update community rules or pinned safety posts to address the tactic used.
Act quickly, but do not panic. Stop communicating with the suspected scammer and do not announce that you are investigating or reporting them. Do not send additional money, pay a supposed tax or recovery fee, scan another code, install another app, or share any new verification code. Preserve the conversation before blocking the account.
1. Contact the financial provider immediately. Use a phone number or website you locate independently—not contact information supplied by the scammer. Notify the bank, card issuer, payment app, wire-transfer service, or cryptocurrency exchange; ask whether a transaction can be stopped, recalled, disputed, or frozen. If cryptocurrency was sent, provide the wallet address, transaction hash, amount, date, and exchange used.
2. Secure the primary email account first. From a trusted device, change the email password, sign out unfamiliar sessions, review recovery addresses and phone numbers, remove unknown forwarding rules, and replace reused passwords on other accounts. Then secure banking, payment, social-media, cloud-storage, and fandom accounts.
3. Review authentication and device access. Change compromised passwords and authentication methods, revoke unfamiliar sessions or connected apps, and remove unknown devices. If a remote-access or unfamiliar app was installed, disconnect the device from networks until it can be evaluated by a trusted security professional or official support service.
4. Protect identity information. If identification documents, tax information, account numbers, or other sensitive records were shared, contact the relevant issuing organization and follow its identity-theft procedures. Monitor financial and online accounts for new activity, profile changes, password-reset notices, and unfamiliar applications.
5. Preserve evidence. Save screenshots, usernames, profile links, phone numbers, email addresses, QR codes, domains, app names, payment receipts, wallet addresses, transaction identifiers, dates, and message histories. Do not keep engaging simply to collect more evidence.
6. Report through official channels. Report the account and content to the platform, notify community moderators, and use independently verified government or financial-provider reporting channels. Tell moderators whether other members may have received the same link, QR code, payment request, or investment pitch.
7. Expect recovery scams. After a loss, another person may claim they can retrieve funds, identify the scammer, remove leaked data, or restore an account for a fee. Do not share passwords, authentication codes, recovery phrases, remote access, or additional payment with an unsolicited “recovery” contact.
Immediate danger or an active emergency: Call 911 or local emergency services. The National 911 Program explains when and how to call.
Cyber-enabled fraud, online scams, account compromise, or cryptocurrency fraud: File a complaint with the FBI Internet Crime Complaint Center (IC3). Preserve transaction details, wallet addresses, usernames, domains, and communications before submitting.
General fraud and scam reporting: Report the incident to the Federal Trade Commission at ReportFraud.ftc.gov. The report can generate situation-specific recovery steps and helps authorities identify patterns.
Identity documents or personal information exposed: Use IdentityTheft.gov for an identity-theft report, recovery plan, credit-protection steps, and sample letters.
Problems with a bank, card issuer, money-transfer company, crypto exchange, virtual-currency service, loan provider, or other financial company: Contact the company first, then submit a complaint to the Consumer Financial Protection Bureau if the issue is not resolved.
Unsure where to report: Use the USA.gov scam-reporting tool to identify the appropriate government agency or consumer organization.
Emotional crisis or overwhelming distress: In the United States, call or text 988 or use the 988 Suicide & Crisis Lifeline. Support is available for suicidal crisis, mental-health distress, substance-use crisis, or overwhelming emotional distress. If someone is in imminent physical danger, call 911 rather than 988.
These contacts are U.S.-based. Readers elsewhere should use their national cybercrime reporting portal, consumer-protection authority, financial regulator, identity-theft service, and local emergency or crisis line. Always reach reporting services through independently verified official websites.
For moderators: respond without blame. A useful opening is: “I’m glad you told us. You are not in trouble. Please stop sending money or information, preserve the messages, and use official support channels to secure any affected accounts.” Avoid asking the person to prove they were deceived before offering help.
Generative AI has not invented romance fraud, but it has reduced many of the friction points that once made scams easier to spot. The new playbook is more fluent, patient, visual, vocal, personalized, and technically integrated. Romance scammers can simulate attention at scale, use deepfake or synthetic media to weaken superficial identity checks, clone voices to deepen trust, groom victims into fake investment ecosystems, and turn affectionate links or QR codes into account compromise. [1, 2, 3, 4, 11] The antidote is a new safety culture: verify independently, slow down financial decisions, treat intensity as a signal rather than proof, and protect community spaces from tactics that exploit belonging.
The strongest supported claim is that AI is making romance scams more scalable, polished, and harder to detect. ABA Banking Journal reports that AI-powered romance scams were identified among top 2026 fraud trends, with bots able to respond convincingly, build trust over time, and manipulate victims with emotion. [13] The Global Cyber Alliance similarly describes AI-generated profiles, deepfake imagery, automated messaging, and hybrid human-plus-bot workflows as making romance scams more persuasive and scalable. [2]
The document should avoid saying that classic red flags are “completely obsolete.” A more accurate framing is that they are less reliable. Traditional warning signs still matter, especially pressure to move off-platform, secrecy, money requests, investment pitches, refusal to meet in person, and attempts to isolate the target from trusted people.
The claims about LLM-driven personas should be qualified. CETaS research finds that LLMs can replicate structured fraud narratives and automate initial outreach, but also notes that multi-turn conversations remain a weakness and that human oversight is often still needed. Therefore, the most evidence-based description is not “fully automated months-long flawless relationships,” but “hybrid scam operations that use automation to scale outreach and maintain plausible conversation while humans intervene at key escalation points.” [1]
The financial grooming section is strongly supported. CFTC, FBI, SEC Investor.gov, and FinCEN materials describe relationship-investment scams, pig-butchering tactics, fake trading platforms, early withdrawals to build confidence, later lockouts, and demands for additional fees or taxes. [4, 7, 8, 9, 10]
The deepfake and voice-cloning sections are credible but should remain carefully worded. FBI and IC3 guidance supports the use of AI-generated text, images, fake social profiles, synthetic identification materials, AI-generated videos, and voice cloning in fraud. [3] However, public evidence is stronger for deepfake media and AI-assisted impersonation generally than for the claim that real-time face swapping is routine in romance scams at scale. [6]
The quishing section should remain cautious. QR-code phishing is a real threat, and romance or fandom pretexts are plausible social-engineering lures. However, the document should not imply that scanning any QR code automatically installs malware or bypasses two-factor authentication. The more accurate claim is that QR codes can hide destinations and lead users to malicious pages, credential theft, fraudulent payments, or unsafe downloads. [11, 12]
1. CETaS, ‘Automating Deception: AI’s Evolving Role in Romance Fraud,’ https://cetas.turing.ac.uk/publications/automating-deception-ais-evolving-role-romance-fraud
2. Global Cyber Alliance, ‘Too Perfect to Be Real | AI and Modern Romance Scams,’ https://globalcyberalliance.org/too-perfect-to-be-real-ai-and-the-modern-romance-scams/
3. FBI IC3, ‘Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud,’ https://www.ic3.gov/PSA/2024/PSA241203
4. FBI, ‘Cryptocurrency Investment Fraud,’ https://www.fbi.gov/how-we-can-help-you/victim-services/national-crimes-and-victim-resources/cryptocurrency-investment-fraud
5. Alan Turing Institute, ‘AI scaling up romance scam operations globally,’ https://www.turing.ac.uk/news/ai-scaling-romance-scam-operations-globally
6. European Parliament Research Service, ‘Scam calls in times of generative AI,’ https://www.europarl.europa.eu/RegData/etudes/ATAG/2025/777940/EPRS_ATA%282025%29777940_EN.pdf
7. CFTC, ‘Romance Frauds,’ https://www.cftc.gov/LearnAndProtect/romancefrauds
8. Investor.gov, ‘Relationship Investment Scams,’ https://www.investor.gov/protect-your-investments/fraud/types-fraud/relationship-investment-scam
9. CFTC, ‘Customer Advisory: Six Warning Signs of Online Financial Romance Frauds,’ https://www.cftc.gov/LearnAndProtect/AdvisoriesAndArticles/RomanceScam.html
10. FinCEN, ‘Alert on Prevalent Virtual Currency Investment Scam Commonly Known as “Pig Butchering,”’ https://www.fincen.gov/sites/default/files/shared/FinCEN_Alert_Pig_Butchering_FINAL_508c.pdf
11. FTC, ‘Scammers hide harmful links in QR codes to steal your information,’ https://consumer.ftc.gov/consumer-alerts/2023/12/scammers-hide-harmful-links-qr-codes-steal-your-information
12. FBI, ‘North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns,’ https://www.fbi.gov/file-repository/cyber-alerts/north-korean-kimsuky-actors-leverage-malicious-qr.pdf
13. ABA Banking Journal, ‘AI, romance, machine-to-machine scams among top 2026 fraud trends,’ https://bankingjournal.aba.com/2026/01/ai-romance-machine-to-machine-scams-among-top-2026-fraud-trends/
14. Federal Trade Commission, “Lights, camera, scam! Spot virtual casting call scams,” https://consumer.ftc.gov/consumer-alerts/2025/12/lights-camera-scam-spot-virtual-casting-call-scams
15. Federal Trade Commission, “How to make your World Cup experience scam free,” https://consumer.ftc.gov/consumer-alerts/2026/03/how-make-your-world-cup-experience-scam-free
16. Federal Trade Commission, “Refund and Recovery Scams,” https://consumer.ftc.gov/articles/refund-and-recovery-scams
Source | Best use | Reliability assessment | Accessed |
ABA’s 2026 fraud-trend forecast claim only. | 3.5/5: Credible trade publication; short secondary summary of an Experian forecast. | September 14, 2026 | |
Practical synthesis on AI-enabled profiles, messaging, synthetic media, scale, and changing warning signs. | 4/5: Strong cybersecurity nonprofit synthesis; not original empirical research. | September 14, 2026 | |
Automation, personalization, synthetic personas, scale, workflow, limitations, and human oversight. | 4.5/5: Original applied research and briefing paper; directly relevant but not peer reviewed. | September 14, 2026 | |
Accessible summary of synthetic personas, fabricated histories, reverse-image-search limits, audio/video, and translation. | 4.5/5: Authoritative institutional summary of its own CETaS research; not independent corroboration. | September 14, 2026 | |
Fraudulent profiles, AI-generated text, translation, synthetic images, voice cloning, and believable video interactions. | 5/5: Authoritative FBI/IC3 threat advisory for documented techniques; not a prevalence study. | September 14, 2026 | |
Pig-butchering mechanics, dating and social-media contact, fake platforms, withdrawals, lockouts, fees, taxes, and reporting. | 5/5: Authoritative FBI guidance within cryptocurrency-investment fraud scope. | September 14, 2026 | |
Relationship-investment grooming, fake trading success, and victim-protection guidance. | 5/5: Authoritative regulator guidance within investor-protection and market-fraud scope; not an incidence study. | September 14, 2026 | |
Private messaging, crypto claims, fake sites, early withdrawals, lockouts, and added fees. | 5/5: Authoritative primary CFTC advisory within its stated financial-fraud scope. | September 14, 2026 | |
Long-con investment scams, online trust-building, crypto pitches, and investor protection. | 5/5: Official SEC investor-protection guidance within relationship-investment fraud scope. | September 14, 2026 | |
Formal mechanics, criminal-organization context, virtual-currency fraud, and institutional reporting indicators. | 5/5: Authoritative primary financial-crimes alert; aimed principally at financial institutions. | September 14, 2026 | |
Real-time synthetic voice and video impersonation and limitations of video verification, not romance-scam prevalence. | 4/5: Strong institutional analysis; not primary romance-fraud research. | September 14, 2026 | |
Concealed QR destinations, spoofed sites, credential theft, malicious downloads, and verification guidance. | 5/5: Authoritative FTC consumer-protection alert within general QR-phishing scope. | September 14, 2026 | |
Session-token theft and possible MFA bypass only in documented targeted Kimsuky spearphishing. | 5/5: Authoritative primary FBI technical alert; narrowly scoped and not romance-scam-specific. | September 14, 2026 | |
Virtual casting-call scams, upfront fees, requests for bank information, unexpected outreach, and independent verification. | 5/5: Authoritative FTC consumer-protection alert directly addressing casting-call scams. | September 14, 2026 | |
Fake tickets, copycat websites, screenshot risks, authorized sellers, resale protections, and event-related urgency. | 5/5: Authoritative FTC consumer-protection alert; event-specific but directly applicable to ticket fraud patterns. | September 14, 2026 | |
Secondary targeting after an initial loss, impersonation of agencies or law firms, upfront recovery fees, and requests for personal or financial information. | 5/5: Authoritative FTC consumer-protection guidance directly addressing refund and recovery scams. | September 14, 2026 |
Reliability scale: 5/5 = authoritative government or regulator guidance, alerts, or reports within the source’s stated scope; this does not imply peer review, independent validation, or evidence of prevalence beyond that scope. 4.5/5 = original applied research or an authoritative institutional summary with stated methodological or independence limitations. 4/5 = strong institutional synthesis or analysis. 3.5/5 = credible secondary reporting or a short summary of another organization’s forecast.
Comments