AI 诈骗全景图 · 反诈防御地图 · 2026-07 · 只给结构与红旗,不含任何可复用话术Scams × AI · A defender’s map · Jul 2026 · Structure and red flags only, never a usable script
骗的不是智商,是状态
It targets your state, not your IQ
这张图只有一个判断需要先说清楚:AI 没有发明新的骗术,它把旧骗术做成了工业品。多家模型提供商的威胁情报得出高度一致的结论——尚未发现攻击者借助模型获得「新型进攻能力」,AI 的作用是提速、降门槛、去人化。但「只是提速」这句话,在一个边际成本决定规模的产业里,本身就是最剧烈的冲击。骗局拆开是七段流水线,而 AI 的渗透沿着它从 100% 陡降到接近 0%:获客与养熟已被彻底重构,钩子与放水被中度改造,洗钱与取现几乎没被触及——AI 打通了流水线的前半段,后半段仍是血肉之躯。这就是防御的全部地形。
One judgment comes before everything else here: AI invented no new scam; it turned old ones into industrial products. Threat-intelligence teams at several model providers converge on the same finding — no attacker has gained a genuinely new offensive capability from these models; what they gain is speed, a lower barrier, and fewer humans. Yet «merely faster» is the most violent possible change in an industry where marginal cost sets scale. Unfolded, a scam is a seven-station line, and AI’s penetration falls along it from 100% to nearly zero: acquisition and grooming are wholly rebuilt, hooks and seeding partly so, laundering and cash-out barely touched — AI completed the front half of the line; the back half is still made of flesh. That is the entire terrain of defence.
本图相信:冲击最深的是「信任建立」而不是「话术」——针对 145 名从业人员的访谈研究测得,诈骗团伙 87% 的人力工时耗在高度重复、脚本化的对话上,恰是模型最擅长复制的部分;同一研究的对照实验里,模型扮演的诈骗方顺从率 46%,反高于真人的 18%,而现有反诈检测工具对模型生成内容的识别率仅 0%–18.8%(A)。This map believes the deepest damage is to trust-building, not scripting — interviews with 145 practitioners found 87% of their labour hours went into highly repetitive scripted conversation, exactly what language models replicate best; in the same study’s controlled trial, model-played scammers achieved 46% compliance against a human’s 18%, while existing anti-fraud detectors caught model-written content at just 0%–18.8% (A).
本图不相信:「检测能追上生成」。2020 年深伪检测挑战赛黑盒集冠军仅 65.18%、2114 名参赛者无一突破 70%;2025 年用真实流通内容重做的评测里,开源顶尖模型 AUC 较原基准骤降 45%–50%——相隔五年、方法独立的两次评测得出同一结论,说明这不是「技术还不成熟」,而是生成-检测对抗的固有形态。也不相信「地下犯罪大模型」的叙事:多数所谓黑帽产品被证实是针对购买者本人的骗局(A/B)。It does not believe detection can catch generation. The 2020 deepfake detection challenge topped out at 65.18% on its black-box set, with none of 2,114 entrants clearing 70%; a 2025 re-run on genuinely circulating content saw leading open models lose 45%–50% of AUC against their original benchmarks — two independent evaluations five years apart, one conclusion: this is not immaturity but the permanent shape of a generation-detection contest. Nor does it believe the «underground criminal LLM» story: most claimed black-hat products turned out to be scams aimed at their own buyers (A/B).
主脊:一场骗局的七站(获客→养熟→钩子与换脸→小额放水→加码收割→洗钱出境→灭迹与二次收割),②③标红;三条结构带:灰色边界(同一条流水线,合法外衣)、受害者迷思 vs 实证、防御杠杆排序;判断层:防御方的最优策略已经不是检测——过去 24 个月最有效的干预全部是非技术的。姊妹:被冒充的那门生意→insure,资金与牌照边界→wealth,攻防同源→security,结算通道→crypto。
The spine: one scam, seven stations (acquisition → grooming → hook and face-swap → seeding → the squeeze → laundering → erasure and the second harvest), ② and ③ in red; three bands: the grey border where one line wears a legal coat, victim myths against evidence, and the ranked levers of defence; the judgment: the defender’s optimal strategy is no longer detection — every effective intervention of the past 24 months was non-technical. Sisters: insure, wealth, security, crypto.
54% = 54%
哈佛 101 名真人受试者对照实验:人类专家撰写的钓鱼点击率 54%,模型全自动生成同样 54%(传统模板仅 12%)——AI 已抹平「专家级」与「批量级」之间的质量差(A)A Harvard trial with 101 human subjects: expert-written phishing drew 54% clicks and fully automated model output drew the same 54% (templates managed 12%) — AI erased the gap between expert-grade and bulk-grade (A)
87%
诈骗团伙耗在脚本化对话上的人力工时占比——恰好是模型最擅长复制的部分;冲击落在「养熟」而非「话术」,这是全图最反直觉的定位(A)The share of scam-operator labour hours spent on scripted conversation — precisely what models replicate best; the blow lands on grooming, not scripting, this map’s most counterintuitive finding (A)
76%
FBI 主动外呼疑似受害者时,当场并不知道自己正在被骗的比例——这个数字直接证明主动干预的边际价值远高于被动宣传(B)The share of suspected victims who, when the FBI called them, did not know they were being defrauded — proof that outbound intervention beats passive awareness campaigns (B)
4.8%–32%
诈骗受害者的报案率区间(美/英不同口径)。羞耻感是这个产业的隐性补贴:它压低报案率、延长发现窗口、直接喂养二次诈骗——降低报案羞耻成本是零技术含量、高杠杆的防御投资(A/B)Victim reporting rates (differing US and UK bases). Shame subsidises this industry: it suppresses reports, extends the discovery window and feeds the second harvest — cutting the shame cost of reporting is a zero-technology, high-leverage defence (A/B)
口径裁判:绝不要把问卷外推的「全球 1.03 万亿美元」与案件核算的 UNODC 千亿量级并列比较——量级差异主要来自方法而非现实,且前者发布方后续已自我修正方法论、停止全球外推;中国「紧急拦截涉案资金」有 3151 亿 / 4529 亿 / 5518 亿三个流传版本,时间与统计范围不同,本图不采信单一数字;传销亏损率 99.6%(扣除成本口径)与 75%(含打平口径)并存;各安全厂商对「深伪欺诈增长率」给出 +58% 到 +2137% 的巨大差异,源于客户群、算法、窗口完全不同,这些数字不能相互印证,更不能叠加,本图一律不采用增长率类营销数字。Refereeing the numbers: never place the survey-extrapolated «$1.03 trillion globally» beside UNODC’s case-audited hundreds of billions — the gap is method, not reality, and the former’s publisher has since revised its methodology and stopped extrapolating globally; China’s «intercepted criminal funds» circulates as ¥315.1B, ¥452.9B and ¥551.8B on different bases, so no single figure is adopted here; MLM loss rates run 99.6% (net of costs) or 75% (counting break-even); vendors report deepfake-fraud growth anywhere from +58% to +2137% on wholly different client bases, algorithms and windows — these cannot corroborate one another, let alone be summed, so no growth-rate marketing figure is used.