I’m directing a feature documentary about deepfakes, synthetic identity, and what happens when verifiable personhood begins to fail. The number I can’t stop thinking about isn’t $20 billion. It’s $893 million — and the gap between them.
In its 2025 Annual Report, the FBI’s Internet Crime Complaint Center reported more than one million complaints and $20.877 billion in losses, crossing the $20 billion threshold for the first time. Buried inside that figure is a smaller one that may be more revealing: 22,364 complaints referencing artificial intelligence, representing $893.3 million in adjusted losses.
That $893 million is not the size of the AI fraud problem. It is the size of the AI fraud problem that victims and investigators could recognize.
Everything else is a ghost. And no one counts the ghosts.
This is the attribution gap. It sits on top of a much older one: a trust gap we have been living inside for years, and whose floor is now falling out.
A floor, not a ceiling
For the first time, the IC3 report includes a dedicated section on artificial intelligence in cybercrime. That’s progress. But the $893 million number is a floor, not a ceiling, because the FBI’s data relies on victim reporting.
If a victim doesn’t recognize that the “person” they were interacting with was a synthetic clone or an AI chatbot, they cannot report it as an AI crime.
Consider the $7.2 billion lost to cryptocurrency investment fraud in 2025, largely driven by “pig butchering” schemes. These are increasingly operated by transnational criminal syndicates that use AI to generate scripts, fake profiles, and deepfaked celebrity endorsements. They scale emotional manipulation across thousands of victims at once. Yet only a fraction of those losses were officially attributed to AI.
The ultimate success of a deepfake is that the victim never knows it was a deepfake at all.
The human perimeter
This brings us to the name of this publication.
For decades, cybersecurity was about gates and walls. You protected the network, the endpoint, the application. But the consensus among CISOs has shifted: identity is the new perimeter. Firewalls protect networks. They don’t help when an attacker walks through the front door wearing a trusted face and a familiar voice.
The attack surface is human. And humans were never designed to authenticate synthetic scale.
Vijay Balasubramaniyan, the CEO of Pindrop Security, put it to me plainly in an on-camera interview last month at the RSA conference in San Francisco. “For the longest time, the last bastion was our humanity,” he said. “And then AI came around and fundamentally blurred the line between what it is to be human and what it is to be machine.”
That is the quieter crisis underneath the fraud numbers. We have spent a decade watching trust collapse in institutions, in media, in each other. What we had left was live human presence. The person across the table. The voice on the phone. The face on the Zoom call. That was the floor. That was the last thing you could verify with your own senses. And it is being taken.
Human senses do not scale against this. Controlled studies show human detection rates on some synthetic media fall near or below chance. Pindrop’s own internal testing has found humans detecting deepfakes at roughly 38% accuracy, which its CEO describes as “worse than a coin flip.” We are asking front-line retail workers to adjudicate synthetic identity documents, HR managers to spot deepfaked remote job candidates, and elderly citizens to recognize whether the panicked voice of their grandchild on the phone is actually a machine.
It is an unfair fight. In 2025, victims over the age of 60 lost $7.7 billion to fraud, a 59% increase over 2024.
Two victims, one call
The moral weirdness of this moment is that the person on the other end of the fraud may also be a victim.
UN and law-enforcement reports have documented people trafficked into scam compounds across Southeast Asia, held under coercive conditions, and forced to run online fraud at industrial scale. Not every fraudster is trafficked. But the scam-center economy has created a double victimization: the person being deceived, and in many cases the person forced to do the deceiving. A recent Wall Street Journal investigation into “Scambodia” detailed the aftermath of a police raid “at a hastily emptied compound 60 miles southwest of Chrey Thom [Cambodia], abandoned suitcases and clothes littered the corridors. In open-plan offices filled with rows of computers, detailed notes on potential victims remained scattered on desks.”
Neither the financial ledger nor the official statistics capture either side of that captivity.
The crisis of knowing
UNESCO calls this a “crisis of knowing,” the point at which the volume of synthetic media begins to erode shared reality itself. I think the phrase is too polite. What is actually eroding is the last checkpoint we had for deciding whether another person is real. Fake news asked us to doubt what we read. Fake people ask us to doubt what we see and hear in real time, from someone looking us in the eye.
That is the existential stake of my film’s title, The Only Human in the Room. You sit down at the Zoom call, or answer the phone, or walk into the interview. The horror is not that the others might be lying to you. It is that the others might not exist at all.
How do we rebuild trust in identity when identity itself has been industrialized into a lie?
The Human Perimeter will serve as a real-time investigative dispatch as we produce the film. We are not just documenting the problem. We are tracking the scam supply chain from isolated victims back to the threat actors. We are testing the provenance tools that try to prove what’s real, including in my own footage. And we are profiling the Defenders: the digital forensics experts, policymakers, and cyber-investigators racing to build guardrails faster than the technology can destroy them.
The attribution gap is not a measurement error. It is a warning. We are losing the ability to recognize when identity itself has been manipulated. That failure of recognition may prove more expensive than any line item in the FBI’s report. The official ledger captures the losses. It cannot see the ghosts.
If you are a CISO dealing with synthetic applicants or executive impersonation, a cyber-investigator tracking scam infrastructure, a researcher studying synthetic identity, or someone who has been targeted by this kind of fraud, I want to hear from you. I will not publish identifying details without consent.
Subscribe to follow the investigation, and welcome to The Human Perimeter.

