如果你或家人正在经历:中国大陆 96110 为反诈预警劝阻专线(接到必接) · 报警 110 · 国家反诈中心 App 可举报与预警 · 美国 ic3.gov · 英国 Action Fraud 0300 123 2040先报银行、再报案——向银行报案者 53% 追回大部或全部,未报案者仅 12%。任何主动联系你的「追损/维权」方,默认拒绝:执法机关连自己的举报中心都被冒充过。 If this is happening to you or your family: in mainland China call 96110 (anti-fraud intervention line) or 110; in the US ic3.gov; in the UK Action Fraud 0300 123 2040. Tell your bank first, then report — 53% of those who alert their bank recover most or all of it, against 12% of those who never report. Refuse by default anyone who contacts you offering to «recover» your money: even law-enforcement reporting centres have been impersonated.
AI 诈骗全景图 · 反诈防御地图 · 2026-07 · 只给结构与红旗,不含任何可复用话术Scams × AI · A defender’s map · Jul 2026 · Structure and red flags only, never a usable script

骗的不是智商,是状态 It targets your state, not your IQ

这张图只有一个判断需要先说清楚:AI 没有发明新的骗术,它把旧骗术做成了工业品。多家模型提供商的威胁情报得出高度一致的结论——尚未发现攻击者借助模型获得「新型进攻能力」,AI 的作用是提速、降门槛、去人化。但「只是提速」这句话,在一个边际成本决定规模的产业里,本身就是最剧烈的冲击。骗局拆开是七段流水线,而 AI 的渗透沿着它从 100% 陡降到接近 0%:获客与养熟已被彻底重构,钩子与放水被中度改造,洗钱与取现几乎没被触及——AI 打通了流水线的前半段,后半段仍是血肉之躯。这就是防御的全部地形。 One judgment comes before everything else here: AI invented no new scam; it turned old ones into industrial products. Threat-intelligence teams at several model providers converge on the same finding — no attacker has gained a genuinely new offensive capability from these models; what they gain is speed, a lower barrier, and fewer humans. Yet «merely faster» is the most violent possible change in an industry where marginal cost sets scale. Unfolded, a scam is a seven-station line, and AI’s penetration falls along it from 100% to nearly zero: acquisition and grooming are wholly rebuilt, hooks and seeding partly so, laundering and cash-out barely touched — AI completed the front half of the line; the back half is still made of flesh. That is the entire terrain of defence.

本图相信:冲击最深的是「信任建立」而不是「话术」——针对 145 名从业人员的访谈研究测得,诈骗团伙 87% 的人力工时耗在高度重复、脚本化的对话上,恰是模型最擅长复制的部分;同一研究的对照实验里,模型扮演的诈骗方顺从率 46%,反高于真人的 18%,而现有反诈检测工具对模型生成内容的识别率仅 0%–18.8%(A)。This map believes the deepest damage is to trust-building, not scripting — interviews with 145 practitioners found 87% of their labour hours went into highly repetitive scripted conversation, exactly what language models replicate best; in the same study’s controlled trial, model-played scammers achieved 46% compliance against a human’s 18%, while existing anti-fraud detectors caught model-written content at just 0%–18.8% (A).
本图不相信:「检测能追上生成」。2020 年深伪检测挑战赛黑盒集冠军仅 65.18%、2114 名参赛者无一突破 70%;2025 年用真实流通内容重做的评测里,开源顶尖模型 AUC 较原基准骤降 45%–50%——相隔五年、方法独立的两次评测得出同一结论,说明这不是「技术还不成熟」,而是生成-检测对抗的固有形态。也不相信「地下犯罪大模型」的叙事:多数所谓黑帽产品被证实是针对购买者本人的骗局(A/B)。It does not believe detection can catch generation. The 2020 deepfake detection challenge topped out at 65.18% on its black-box set, with none of 2,114 entrants clearing 70%; a 2025 re-run on genuinely circulating content saw leading open models lose 45%–50% of AUC against their original benchmarks — two independent evaluations five years apart, one conclusion: this is not immaturity but the permanent shape of a generation-detection contest. Nor does it believe the «underground criminal LLM» story: most claimed black-hat products turned out to be scams aimed at their own buyers (A/B).

主脊:一场骗局的七站(获客→养熟→钩子与换脸→小额放水→加码收割→洗钱出境→灭迹与二次收割),②③标红;三条结构带:灰色边界(同一条流水线,合法外衣)、受害者迷思 vs 实证、防御杠杆排序;判断层:防御方的最优策略已经不是检测——过去 24 个月最有效的干预全部是非技术的。姊妹:被冒充的那门生意→insure,资金与牌照边界→wealth,攻防同源→security,结算通道→crypto The spine: one scam, seven stations (acquisition → grooming → hook and face-swap → seeding → the squeeze → laundering → erasure and the second harvest), ② and ③ in red; three bands: the grey border where one line wears a legal coat, victim myths against evidence, and the ranked levers of defence; the judgment: the defender’s optimal strategy is no longer detection — every effective intervention of the past 24 months was non-technical. Sisters: insure, wealth, security, crypto.

54% = 54%
哈佛 101 名真人受试者对照实验:人类专家撰写的钓鱼点击率 54%,模型全自动生成同样 54%(传统模板仅 12%)——AI 已抹平「专家级」与「批量级」之间的质量差(A)A Harvard trial with 101 human subjects: expert-written phishing drew 54% clicks and fully automated model output drew the same 54% (templates managed 12%) — AI erased the gap between expert-grade and bulk-grade (A)
87%
诈骗团伙耗在脚本化对话上的人力工时占比——恰好是模型最擅长复制的部分;冲击落在「养熟」而非「话术」,这是全图最反直觉的定位(A)The share of scam-operator labour hours spent on scripted conversation — precisely what models replicate best; the blow lands on grooming, not scripting, this map’s most counterintuitive finding (A)
76%
FBI 主动外呼疑似受害者时,当场并不知道自己正在被骗的比例——这个数字直接证明主动干预的边际价值远高于被动宣传(B)The share of suspected victims who, when the FBI called them, did not know they were being defrauded — proof that outbound intervention beats passive awareness campaigns (B)
4.8%–32%
诈骗受害者的报案率区间(美/英不同口径)。羞耻感是这个产业的隐性补贴:它压低报案率、延长发现窗口、直接喂养二次诈骗——降低报案羞耻成本是零技术含量、高杠杆的防御投资(A/B)Victim reporting rates (differing US and UK bases). Shame subsidises this industry: it suppresses reports, extends the discovery window and feeds the second harvest — cutting the shame cost of reporting is a zero-technology, high-leverage defence (A/B)
口径裁判:绝不要把问卷外推的「全球 1.03 万亿美元」与案件核算的 UNODC 千亿量级并列比较——量级差异主要来自方法而非现实,且前者发布方后续已自我修正方法论、停止全球外推;中国「紧急拦截涉案资金」有 3151 亿 / 4529 亿 / 5518 亿三个流传版本,时间与统计范围不同,本图不采信单一数字;传销亏损率 99.6%(扣除成本口径)与 75%(含打平口径)并存;各安全厂商对「深伪欺诈增长率」给出 +58% 到 +2137% 的巨大差异,源于客户群、算法、窗口完全不同,这些数字不能相互印证,更不能叠加,本图一律不采用增长率类营销数字。Refereeing the numbers: never place the survey-extrapolated «$1.03 trillion globally» beside UNODC’s case-audited hundreds of billions — the gap is method, not reality, and the former’s publisher has since revised its methodology and stopped extrapolating globally; China’s «intercepted criminal funds» circulates as ¥315.1B, ¥452.9B and ¥551.8B on different bases, so no single figure is adopted here; MLM loss rates run 99.6% (net of costs) or 75% (counting break-even); vendors report deepfake-fraud growth anywhere from +58% to +2137% on wholly different client bases, algorithms and windows — these cannot corroborate one another, let alone be summed, so no growth-rate marketing figure is used.
中心装置 · 检测输了,摩擦赢了The central device · Detection lost; friction won
军备竞赛的失衡是结构性的,但失衡的方向被普遍误读了:真正的转折不是「检测跟不上生成」,而是防御方的最优策略已经不再是检测The arms race is structurally lopsided, and the direction is widely misread: the real turn is not that detection trails generation but that detection is no longer the defender’s best move at all.
技术检测:天花板已经量出来了Technical detection: the ceiling has been measured
2020 年深伪检测挑战赛:2114 名参赛者,冠军公开集 82.56%、黑盒集仅 65.18%,全部参赛者无一突破 70%,主办方定性为「远未解决的问题」。2025 年用 2024 年真实流通内容重建评测集(45 小时视频、56.5 小时音频、覆盖 88 个网站、52 种语言):开源顶尖模型 AUC 视频 −50%、音频 −48%、图像 −45%;最好的商用检测器 82%,针对性微调后仍约 81%,未达人类取证分析师水平。更硬的边界:跨域性能再降 15%–20%,白盒对抗攻击成功率超 80%;水印也不是终局——顶会论文的标题就是「不可见图像水印可被生成式 AI 可证明地移除」。五年、两次方法独立的评测,同一结论:这不是技术不成熟,是对抗任务的固有形态。The 2020 detection challenge: 2,114 entrants, 82.56% on the public set and 65.18% on the black box, with nobody clearing 70% — the organisers called it very much an unsolved problem. A 2025 benchmark rebuilt from genuinely circulating 2024 content (45 hours of video, 56.5 of audio, 88 sites, 52 languages) cost leading open models 50% of video AUC, 48% of audio, 45% of images; the best commercial detector reached 82% and still only ~81% after targeted fine-tuning, below a human forensic analyst. Harder still: cross-domain costs another 15%–20% and white-box attacks succeed over 80% of the time; watermarks are no endgame either — a top-conference paper is titled, plainly, that invisible image watermarks are provably removable. Five years, two methodologically independent evaluations, one conclusion: not immaturity — the permanent shape of an adversarial task.
制度性摩擦:效果证据最扎实的那一层Institutional friction: where the evidence is strongest
英国收款人核验上线后累计超 25 亿次核验、日均 210 万次,覆盖两大支付轨道的 99%,相关欺诈案件下降近 60%——这是本图效果证据最扎实的单项干预,澳大利亚已投入 1 亿美元跟进。72 小时延迟支付权(英,2024-10-30 生效)让银行在合理怀疑时可暂停调查;新加坡责任共担框架设 12 小时新设备冷静期;英国 强制报销把激励对齐到有能力做风控的一方(2024 年赔付 2.671 亿英镑、约 59%,同期案件量降 20% 创五年新低)。FBI 主动外呼联系疑似受害者,早期统计 76% 当时并不知道自己在被骗,挽回约 2.856 亿美元、42 人被转介自杀干预。这一层不要求任何人保持警觉——这正是它跑赢检测的原因。Britain’s Confirmation of Payee has run over 2.5 billion checks at 2.1 million a day, covering 99% of both payment rails, and cut related fraud cases by nearly 60% — the best-evidenced single intervention on this map, now being copied in Australia at a A$100M build. A 72-hour payment delay right (UK, effective 30 Oct 2024) lets banks pause on reasonable suspicion; Singapore’s shared-responsibility framework adds a 12-hour cooling period for new devices; Britain’s mandatory reimbursement aligns incentives with whoever can actually run risk controls (£267.1M repaid in 2024, ~59%, while case volumes fell 20% to a five-year low). The FBI’s outbound calling reached suspected victims of whom 76% did not yet know, recovering some $285.6M and referring 42 people to suicide intervention. None of this asks anyone to stay vigilant — which is exactly why it beats detection.
判词Verdict制度性摩擦跑赢了算法检测。这既是好消息(防御有路可走),也是坏消息(这条路依赖立法与跨境协调,而这两者都很慢)。防御侧真正的战略转向不是「造更强的检测器」,而是改变谁承担损失——这是理性的撤退,不是投降。Institutional friction outran algorithmic detection. That is good news — there is a road — and bad news, because the road runs through legislation and cross-border coordination, both slow. The defender’s real strategic turn is not a stronger detector but changing who bears the loss: a rational retreat, not a surrender.
Reading the Map

从这张图带走的五条规律Five patterns to take away

立场声明:本图是反诈防御地图,只给产业结构、阶段模型、红旗信号与防御杠杆,刻意不含任何可复用的话术脚本、工具获取途径或操作步骤——这限制了某些细节的具体度,是有意的取舍。所列黑产组织与工具均为已被起诉、制裁、判决或公开研究的案例,标注其执法状态,不构成任何形式的指引或推介。受害者画像部分引用同行评审研究,目的是破除「贪心的蠢人才被骗」这一迷思——它压低报案率、喂养二次诈骗,本身就是这个产业的隐性补贴。若你或家人正在其中,请看页首的求助渠道:报案不丢人,沉默才是产业的补贴。本图不构成法律或投资建议。Stance: this is a defender’s map. It gives industry structure, stage models, red flags and defensive levers, and deliberately contains no reusable script, tooling route or operational step — a chosen trade-off against specificity. Criminal organisations and tools appear only as prosecuted, sanctioned, adjudicated or publicly researched cases, with their enforcement status noted; nothing here is guidance or promotion. Victim profiles cite peer-reviewed work in order to break the myth that only greedy fools get scammed — a myth that suppresses reporting, feeds the second harvest, and thereby subsidises the industry. If this is happening to you or your family, use the help lines at the top of this page: reporting is not shameful; silence is the subsidy. Not legal or investment advice.