AI Scams in Peer-to-Peer Networks: Why AI Changed Trust Between Strangers

AI did not invent scams. It removed the labor, cost, and inconsistency that once limited how many believable identities a criminal could operate. The result is a trust crisis between strangers.

A buyer answers a marketplace listing. A landlord responds to a housing inquiry. A contractor offers to visit a home. A stranger on a dating app seems unusually attentive. In each case, the technology appears different, but the trust problem is the same: one person must decide whether the identity presented on a screen belongs to the person controlling the interaction.

For most of the internet era, people made that decision using a collection of informal signals. A long-standing social profile looked harder to fake than a new account. A live voice sounded more credible than text. A video call seemed to prove that a face belonged to a real person. A photograph of an identification document felt stronger still. None of those signals was ever proof. They were useful because convincing counterfeits required time, skill, access, and money.

Generative artificial intelligence changed that economic calculation. It can produce profile photos, personalized messages, translations, cloned voices, altered documents, synthetic video, and plausible social content at a speed and scale that were previously unavailable to ordinary criminals. AI did not create deception. It industrialized the production of evidence that looks like identity.

That distinction matters. The central problem is not simply that scammers have better tools. It is that peer-to-peer trust still depends on signals that live entirely as data - and data can now be generated.

The reported scale of the problem

The FBI received 1,008,597 complaints through the Internet Crime Complaint Center in 2025, with reported losses of $20.877 billion. Cyber-enabled fraud accounted for about 45% of complaints but roughly 85% of all reported losses. The same report introduced an AI-related descriptor covering more than 22,000 complaints and more than $893 million in adjusted losses.[2]

Reported measure2025 figureWhy it matters
All IC3 complaints1,008,597 complaints; $20.877 billion in reported lossesThe complaint volume averaged almost 3,000 reports per day.
Cyber-enabled fraud452,868 complaints; $17.697 billion in reported lossesFraud represented about 45% of complaints but 85% of all reported losses.
AI-related descriptor22,364 complaints; $893.3 million in adjusted lossesAI is now visible enough in complaints to be tracked as its own descriptor.
Social-media-originated scams$2.1 billion in reported FTC lossesNearly 30% of people reporting a scam loss said contact began on social media.

These figures should be read carefully. A complaint may contain several crime types or descriptors, and the AI category captures only cases in which AI-related information was recognized and reported. Many victims do not report at all. The numbers are therefore better understood as a documented floor than as a complete measurement of AI-enabled fraud.

AI changed the marginal cost of being someone else

Fraud has always been constrained by economics. A criminal operation can scale only when the expected return exceeds the cost of finding targets, building credibility, maintaining stories, and extracting value. Before generative AI, believable impersonation contained friction. A scammer had to write messages, maintain details across conversations, locate usable photographs, avoid obvious language mistakes, and sometimes recruit people capable of handling calls.

Generative AI compresses each of those tasks. A single operator can draft thousands of tailored opening messages, translate conversations into natural English, generate photographs of a person who does not exist, produce variations of that person in different locations and clothing, summarize prior conversations, and suggest emotionally effective replies. The technology can also help imitate a real person by cloning a voice, manipulating video, or generating messages that match the target's writing style.

The result is not merely a more convincing individual scam. It is a lower marginal cost for every additional identity, target, and conversation. That makes low-probability fraud economically viable at enormous scale.

Core ideaAI is most dangerous to interpersonal trust when it converts identity from a scarce, costly performance into an inexpensive stream of generated data.

What makes a network peer to peer

In an institutional transaction, a bank, employer, government agency, or regulated platform may verify identity, retain records, monitor suspicious activity, and absorb some responsibility for failure. In a peer-to-peer interaction, two private individuals are expected to do most of that work themselves.

Peer-to-peer networks include more than technical file-sharing systems. They include the social and commercial networks through which people meet directly: dating apps, local marketplaces, roommate boards, rental listings, neighborhood groups, caregiving arrangements, freelance platforms, real-estate showings, ticket exchanges, ride coordination, and person-to-person payment requests.

The platform may introduce the parties, but the consequential decision often happens outside the platform. Should the buyer travel to a private address? Should the seller accept a payment link? Should the agent enter a vacant property alone? Should the dater share a phone number, workplace, or home neighborhood? The person making that decision rarely has institutional-grade identity proofing or a security team.

The old trust stack is made of data artifacts

Most people assess a stranger by stacking weak clues until the interaction feels credible. The account has photos. The person speaks naturally. The social profile has friends. The phone number has a local area code. The name appears in a search result. The video call looks live. Each clue may reduce uncertainty, but none necessarily binds the account to the claimed legal identity, device, or physical person.

A useful distinction is between an identity claim and identity evidence. A profile name is a claim. A photograph is a claim about appearance. A voice note is a claim about the speaker. A scanned license is a claim presented as a document. A phone number proves that someone can receive communications at that number; it does not prove the person's name, intent, or physical presence.

Generative AI weakens the entire stack because nearly every clue can be synthesized, edited, stolen, or routed through another person. As the Proof by Physics framework argues, a photograph is data, a voice is data, a video stream is data, and a scanned document is data. Whatever exists only as data can increasingly be reproduced at scale.[1]

How an AI-enabled peer-to-peer scam is assembled

1. Manufacture or hijack a persona

The attacker may generate a person who does not exist, steal the likeness of a real person, purchase an aged account, compromise an existing account, or combine real and synthetic material. A fabricated persona no longer needs one stolen photograph. It can have an entire visual history, including casual images, travel scenes, family-style photos, and work-related content.

2. Select targets with available personal data

Public profiles reveal interests, relationship status, employment, family connections, recent purchases, travel, and emotional context. AI can summarize that information and help tailor the approach. The scammer does not need to invent a universally persuasive story; the system can generate a story optimized for one person.

3. Sustain many conversations at once

Relationship-building used to be labor-intensive. AI can maintain tone, recall facts, produce affectionate or professional messages, and translate across languages. That permits one operation to cultivate hundreds or thousands of targets while preserving the appearance of personal attention.

4. Use synthetic media as reassurance

When a target becomes suspicious, the attacker can provide the very evidence people have been taught to request: a new photograph, a voice note, a brief video, a picture of identification, or a live call. The FBI has warned that criminals use AI-generated content to make profiles and scripts more believable, including images, voice cloning, and other synthetic media.[2][5]

5. Move the relationship to a weaker environment

The attacker often pushes the conversation from a marketplace, dating app, or social platform into text messages, encrypted messaging, email, or a payment service. This removes platform warnings, reporting tools, content moderation, and evidence from the original service while giving the attacker a more persistent route to the victim.

6. Convert trust into money, access, or vulnerability

The extraction may be a deposit, counterfeit payment, fake shipping fee, investment transfer, emergency request, account-verification code, intimate image, home address, or in-person meeting. The scam succeeds because the identity performance and the financial or emotional request arrive as one continuous relationship.

Where AI scams appear in everyday peer-to-peer life

Marketplace and local commerce

Synthetic buyers and sellers can operate convincing accounts, generate product images, produce fake receipts, imitate customer-service messages, and send realistic payment notifications. The transaction may move rapidly from a platform listing to a text conversation, where a fake link or overpayment story is harder for the platform to detect. A local-looking phone number and friendly voice add familiarity without adding identity assurance.

Housing, rentals, and real estate

A fraudulent landlord can copy a legitimate listing, generate supporting documents, conduct polished conversations, and demand an application fee or deposit. A supposed buyer can schedule a private showing with an agent while disclosing little more than a name and number. These interactions combine financial exposure with physical exposure, which makes identity uncertainty more consequential.

Home services, caregiving, and gig work

A stranger may be invited into a home to provide repairs, childcare, elder care, pet care, delivery, cleaning, or freelance services. Reviews and profiles can describe prior performance, but they may not reliably establish who arrives at the door. AI can make the account appear complete while the underlying operator remains unknown.

Dating and relationship-based investment fraud

A fabricated romantic identity can be cultivated for weeks or months before the conversation turns to an emergency, cryptocurrency, or an investment platform. The FBI reported $929.3 million in confidence and romance losses in 2025, and identified more than $19 million in romance-related losses with a likely AI nexus.[2] The emotional relationship is not separate from the fraud mechanism; it is the mechanism.

The phone-number and social-profile trap

When people sense uncertainty, they often ask for more contact information. That feels like verification, but it usually produces disclosure rather than assurance.

Moving to text gives the stranger a persistent phone number that may be linked to messaging accounts, contact-discovery tools, account recovery, data-broker records, and other parts of the user's digital life. The number proves control of a communications endpoint. It does not prove who controls it.

Asking for Instagram, Facebook, LinkedIn, or another social profile creates the opposite problem. It may reveal friends, family, employment, routines, locations, and years of personal context while still failing to prove who operates the account. The profile can be synthetic, purchased, compromised, or copied. The user exposes more and may learn very little.

That is the structural failure: people are forced to trade privacy for clues, even though the clues remain weak.

Why detection advice is no longer enough

Traditional advice often assumes a fake will contain visible defects: odd grammar, inconsistent photographs, a refusal to call, a recently created profile, or an image that appears elsewhere online. Those checks remain useful when they reveal a contradiction. They are not reliable proof when they reveal nothing.

A reverse-image search can identify a stolen photo, but it cannot prove that an original-looking image depicts a real account holder. A video call can expose some impostors, but it cannot guarantee that a stream is unaltered or that the person on screen is using their real identity. A long conversation can reveal inconsistencies, but AI can help preserve consistency. Detection remains an arms race in which ordinary users are expected to inspect increasingly sophisticated artifacts.

The better question is not, "Can I spot the fake?" It is, "What evidence would remain costly for a remote attacker to manufacture?"

A stronger model: graduated disclosure and proof anchored outside the data channel

A safer peer-to-peer system should not demand maximum disclosure at the beginning. It should allow assurance to increase in stages as the consequences of the interaction increase.

Controlled communication

The first stage should allow messaging, voice, or video without automatically exposing a primary phone number, personal social graph, home address, or other permanent identifiers. Communication is necessary; unrestricted access is not.

Defined verification signals

A label such as "verified" is useful only when the user knows what was verified. Did the person confirm an email address, control a phone number, pass a document check, bind a credential to secure hardware, or confirm physical presence? These are different claims with different strengths.

Hardware-bound continuity

A credential protected by secure device hardware can make account continuity harder to transfer or duplicate than a password or text-message code. NIST's 2025 Digital Identity Guidelines emphasize assurance levels, stronger authenticators, fraud controls, and defenses against forged media and injection attacks.[4] Institutional standards do not directly solve peer-to-peer trust, but they demonstrate that identity claims need explicit assurance semantics.

Mutual verification and co-presence

For higher-risk meetings, the system can bind a verified digital identity to a confirmed real-world interaction. Physical co-presence does not prove good intent, but it imposes time, travel, exposure, and accountability costs that a remote scam operation cannot reproduce at near-zero marginal cost. The Proof by Physics framework treats this embodied cost as a scaling defense rather than a promise of perfect safety.[1]

Accountable history

A history of confirmed interactions with independently verified people is more difficult to manufacture than a history of posts, likes, or purchased followers. The important distinction is not popularity. It is whether prior interactions are tied to accountable identities and events.

A practical decision framework for individuals

The amount of assurance should match the potential harm. A casual discussion does not require the same verification as a financial transfer, entry into a home, or an isolated in-person meeting.

  • 1. Low consequence: keep communication inside a controlled channel and avoid unnecessary personal disclosure.
  • 2. Moderate consequence: confirm consistent identity signals, use live communication as one layer, and resist pressure to move immediately to private messaging or payment.
  • 3. High financial consequence: independently verify payment instructions, platform identity, and the person or organization receiving funds. Do not treat screenshots, incoming messages, or caller ID as proof.
  • 4. High physical consequence: use mutual verification, a defined meeting plan, public or controlled locations, and an accountable record of who is expected to arrive.
  • 5. High emotional consequence: separate the feeling of familiarity from evidence of identity, especially when secrecy, urgency, investment advice, or requests for money appear.

What platforms should change

Platforms that introduce strangers should stop treating trust as a private problem that begins after the match, listing, or booking. They do not need to subject every user to maximum proofing. They do need to describe verification honestly and add friction where risk increases.

  • Use clear assurance labels instead of a single ambiguous verified badge.
  • Allow users to communicate without disclosing phone numbers or social profiles.
  • Escalate verification before high-risk transitions such as deposits, private-address exchanges, in-home services, or offline meetings.
  • Bind important account actions to stronger authenticators and device continuity.
  • Preserve user privacy by disclosing only the attributes needed for the interaction.
  • Support mutual verification rather than placing the entire burden on one party.

How SOCYiD changes the introduction

SOCYiD is designed around the idea that communication, identity assurance, and personal disclosure should be separate decisions. A person can share a SOCYiD instead of immediately sharing a phone number or personal social account, communicate in a controlled environment, and increase verification according to the risk of the interaction.

That approach does not promise that every verified person will behave honestly or safely. No identity system can predict character. It can reduce a different problem: the uncertainty about who is behind the interaction and the unnecessary exposure created by today's workarounds.

Frequently asked questions

Are AI scams a separate category of crime?

Usually not. AI is a capability used inside familiar crimes such as impersonation, investment fraud, romance fraud, phishing, marketplace fraud, and account takeover. The FBI tracks AI-related information as a descriptor because the technology can appear across many crime types.[2]

Can a video call prove that someone is real?

A video call can provide useful information and may expose a low-effort fake, but it is not conclusive identity proof. The image can be manipulated, the person can be acting under a false identity, or the call can be performed by someone other than the account's usual operator.

Does a long-standing social account prove identity?

No. Account age and social history can increase plausibility, but accounts can be compromised, sold, repurposed, or populated with generated material. A profile is evidence about an account, not automatically evidence about the person controlling it now.

Does identity verification guarantee safety?

No. Verification can reduce identity uncertainty and increase accountability. It cannot guarantee honesty, product quality, financial validity, compatibility, or future behavior.

What is the most important change users can make?

Stop treating the exchange of a phone number or social profile as verification. Preserve privacy first, then increase assurance in proportion to the financial, emotional, professional, or physical consequences of the interaction.

The new trust question

The internet taught people to ask whether an account looks real. Generative AI makes that question less useful every day.

The stronger question is whether the identity claim is supported by evidence that cannot be cheaply generated, copied, or operated at scale. Peer-to-peer trust will not be repaired by expecting every person to become a deepfake analyst. It will be repaired by building better infrastructure for controlled communication, graduated disclosure, mutual verification, and accountability.

AI did not eliminate trust. It eliminated the excuse for building trust on appearances alone.

References

[1] Wesley B. Little, Proof by Physics: Peer-to-Peer Identity Verification in the Age of Generative AI, SOCYiD Inc., July 2026. https://www.socyid.com/trust-lab Research foundation supplied by SOCYiD.

[2] Federal Bureau of Investigation, 2025 IC3 Annual Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf See complaint totals, crime-type tables, cyber-enabled fraud, and the AI-used-in-cybercrime section.

[3] Federal Trade Commission, Reported losses to scams on social media eight times higher than in 2020, April 27, 2026. https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2026/04/reported-losses-scams-social-media-eight-times-higher-2020 FTC Consumer Sentinel reporting for 2025.

[4] National Institute of Standards and Technology, NIST SP 800-63-4: Digital Identity Guidelines, July 2025. https://csrc.nist.gov/pubs/sp/800/63/4/final Final Revision 4 guidance and companion volumes.

[5] Federal Bureau of Investigation, Think Before You Click: Romance Scam Warning From FBI Jacksonville Ahead of Valentine's Day, 2026. https://www.fbi.gov/contact-us/field-offices/jacksonville/news/think-before-you-click-romance-scam-warning-from-fbi-jacksonville-ahead-of-valentines-day Federal warning on generative AI, language translation, synthetic images, and scam believability.

Back to the Trust Lab

Start sharing your SOCYiD.

Stop handing strangers your phone number and socials — share your trusted identity instead.