The Deepfake Is Not Your Legal Problem. The Wire You Sent Is.

September 28, 2026 · David J.S. Madgett

When someone calls me after a fraudulent wire, the first thing they want to tell me is how good the fake was. The voice was his. The email came from the title company’s real address. The man on the video call looked exactly like the CFO. I understand the impulse, and it is almost never the question that decides who eats the loss.

Minnesota’s wire-transfer statute does not ask how convincing the impostor was. It asks who sent the payment order. If you sent it — because a flawless copy of your son’s voice was crying on the line, or because an email indistinguishable from your lender’s told you the account had changed — the order is yours, and in the ordinary case so is the money that left with it. The technology has made the lie perfect. The law still looks at the button, and at whose finger pressed it.

That is why every defense worth anything now is procedural, and why the procedure has to exist before the call comes in.

What changed, in the government’s own words

I do not rely on vendor statistics for this subject, and neither should you. The federal agencies have described the shift plainly.

The Federal Trade Commission warned in March 2023 that a scammer cloning a relative’s voice needs very little: “All he needs is a short audio clip of your family member’s voice — which he could get from content posted online — and a voice-cloning program.” In December 2024 the FBI’s Public Service Announcement I-120324-PSA added video, reporting that “Criminals generate videos for real time video chats with alleged company executives, law enforcement, or other authority figures.” By May 2025, in PSA I-051525-PSA, the Bureau had stopped pretending the average person can spot the difference. It told the public to listen for tone and word choice when distinguishing a known contact from “AI-generated voice cloning, as they can sound nearly identical”, and then conceded the point outright: “AI-generated content has advanced to the point that it is often difficult to identify.”

The Federal Communications Commission reached the telephone side in February 2024. Its Declaratory Ruling in CG Docket No. 23-362 (FCC 24-17) held that “AI technologies such as ‘voice cloning’ fall within the TCPA’s existing prohibition on artificial or prerecorded voice messages because this technology artificially simulates a human voice”, and it named the harm directly: “Voice cloning can convince a called party that a trusted person, or someone they care about such as a family member, wants or needs them to take some action that they would not otherwise take.” Under that ruling, a call placed with a cloned voice requires the prior express consent of the called party “absent an emergency purpose or exemption.” It does nothing to identify the caller, and I have explained separately why federal call-traceback rarely produces a defendant. Caller ID on your screen proves nothing about who is on the line.

The numbers are large. The FBI’s Internet Crime Complaint Center (IC3) logged 24,768 business email compromise complaints in 2025 with $3,046,598,558 in reported losses — second only to investment fraud by dollars. Complainants 60 and over reported $568,048,472 of that BEC loss. IC3’s definition of BEC expressly reaches fraud carried out “by compromising email accounts and other forms of communication such as phone numbers and virtual meeting applications”. Minnesotans filed 13,595 IC3 complaints of every type in 2025, reporting $248,892,986 in losses. On the consumer side, the FTC’s 2025 data show that people reported losing $3.5 billion to impostor scams, including nearly $1 billion to business impersonators, with the highest reported losses to bank impersonators.

IC3 also reported that “businesses reported losses over $30 million to BEC scams involving AI” and that victims “claimed losses over $5 million in 2025 to distress scams” using cloned voices. Read those two AI figures as floors. IC3 applies its “AI Related” tag when “Information reported contains a reference to artificial intelligence (AI)” — so a victim who never realized the voice was synthetic is not counted. The rest of what that federal data can and cannot show is set out here.

Five shapes, one mechanism

The schemes wear different costumes. Underneath, every one of them ends the same way: the victim moves the money personally.

The family emergency. IC3 describes “grandparent scams, or ‘distress’ scams, in which voice cloning technology is used to mimic the sound of a loved one in distress”, and notes that the scheme “is evolving to mimic other family members or close friends in different types of emergency scenarios.” The script is an arrest, a wreck, a kidnapping, and an instruction to pay now and tell no one. The FTC’s warning about payment method is the tell that survives a perfect voice: “If the caller says to wire money, send cryptocurrency, or buy gift cards and give them the card numbers and PINs, those could be signs of a scam.” The defense that beats a perfect voice is the FBI’s first tip: “Create a secret word or phrase with your family to verify their identity.” Then hang up and call the person back on a number you already had.

The executive instruction. IC3’s 2025 report describes it precisely: “Chat generators can quickly create official-sounding emails mimicking a company’s CEO or other officials. These emails can contain phishing links or directions to wire funds.” The same page adds that voice cloning can be used “to request wire payment”. Add the live video call the FBI warned about in 2024, and the controller who insists on seeing the CFO’s face has been given exactly that. The request is always urgent, always confidential, and always routed around the person who would normally sign off.

The closing wire. A buyer expects to wire a down payment and receives an email from the title company, the lender, or the buyer’s own lawyer with “updated” instructions. IC3’s published examples from 2025 include a Missouri senior who “received a compromised email from the ‘title company’ containing wire instructions for over $1.3 million to a fraudulent bank account”, and a separate complaint from individuals who “were closing on a home when they received an email impersonating their legitimate attorneys” and sent a wire of more than $449,000. Real-estate money is the ideal target: large, scheduled in advance, and moved by people who do it once or twice in a lifetime.

The vendor redirect. A supplier you have paid for years sends a routine invoice with one change — a new bank. The invoice is real; only the account is not. Accounts payable has no reason to hesitate, because every other detail matches the vendor file.

The call from your bank’s fraud department. The FTC’s June 2026 release on 2025 data describes it: “Some of the costliest impersonation scams start with a fake security alert, often from a bank. People are convinced to move money to ‘protect’ it, with their losses often limited only by their available funds.” The display may show your bank’s name. The FTC’s advice, in its August 2025 release on these schemes, is flat: “Don’t trust the phone number or name they provide.”

A wire you sent is a wire you authorized

Start with which law applies, because most people guess wrong. The federal Electronic Fund Transfer Act and its Regulation E protect consumer accounts, but Regulation E excludes “[a]ny transfer of funds through Fedwire or through a similar wire transfer system that is used primarily for transfers between financial institutions or between businesses.” 12 C.F.R. § 1005.3(c)(3). The limiting clause describes the wire system, not the customer, so I read the exclusion to reach a retiree’s wire as surely as a manufacturer’s. The Bureau’s official interpretation confirms the point for consumers: for telephone-initiated Fedwire payments verified under a security procedure agreed “between the consumer and the receiving bank”, it states that “[t]hese transfers are not subject to Regulation E”. 12 C.F.R. pt. 1005, Supp. I, cmt. 3(c)(3)-2. Minnesota’s version of UCC Article 4A fills the gap from the other side: it “does not apply to a funds transfer any part of which is governed by the Electronic Fund Transfer Act”. Minn. Stat. § 336.4A-108(a). A domestic bank wire — a consumer’s or a company’s — lands in Article 4A.

Article 4A’s first rule is short:

A payment order received by the receiving bank is the authorized order of the person identified as sender if that person authorized the order or is otherwise bound by it under the law of agency.

Minn. Stat. § 336.4A-202(a) (emphasis added). When you, or your employee with authority to send wires, instructs the bank to send the money, the order is authorized. The lie that produced the instruction happened upstream of the bank, and apart from the misdescribed-beneficiary rule in § 336.4A-207(c)(2), discussed below, I read nothing in Article 4A that follows it there. The bank did what its customer told it to do.

The contrast is instructive. When someone else sends an order in your name — a criminal who has taken over your online banking — the analysis moves to subsection (b), and the default flips. The Eighth Circuit, which hears federal appeals from Minnesota, put the default in one sentence: “Generally, the bank bears this risk.” Choice Escrow & Land Title, LLC v. BancorpSouth Bank, 754 F.3d 611, 616 (8th Cir. 2014). The bank escapes only if the security procedure it agreed on with the customer was “a commercially reasonable method of providing security against unauthorized payment orders” and the bank proves it accepted the order “in good faith and in compliance with” that procedure. § 336.4A-202(b).

Choice Escrow shows how that plays out, and it is not comforting. A Missouri title company’s employee fell for a phishing attack; the resulting virus handed a criminal the employee’s credentials, and he used them to wire $440,000 to a bank in Cyprus. 754 F.3d at 613, 615–16. The bank had offered “dual control” — a second employee must approve every wire — and the title company had declined it in writing, twice. Id. at 614–15. The court held the title company bore the loss: “Choice knew that dual control provided a reliable safeguard against Internet fraud, and it explicitly assumed the risks of a lesser procedure notwithstanding the relative ease with which it could have implemented dual control.” Id. at 622. The case applied Mississippi’s enactment of Article 4A; Minnesota’s § 336.4A-202 contains the same allocation.

There is a statutory escape hatch for the customer, and it rarely opens for a phished business. Even when a verified order is effective against the customer, the bank cannot keep the payment if the customer proves the order was not caused by an insider or by a person who “obtained, from a source controlled by the customer and without authority of the receiving bank, information facilitating breach of the security procedure, regardless of how the information was obtained or whether the customer was at fault.” § 336.4A-203(a)(2). A password harvested from your employee’s inbox came from a source you control.

Three more provisions matter in a spoofing case.

A known email address is not a security procedure. In 2024 the Legislature rewrote the definition to say that “requiring a payment order to be sent from a known email address, IP address, or telephone number is not by itself a security procedure.” § 336.4A-201; 2024 Minn. Laws ch. 93, art. 5, § 2. The pre-amendment text, which the Court of Appeals quoted in 1998, excluded only signature comparison. Hedged Inv. Partners, L.P. v. Norwest Bank Minn., N.A., 578 N.W.2d 765, 773 (Minn. Ct. App. 1998). The Legislature has told every Minnesota business, in statute, that a familiar sender address proves nothing. The 2024 amendment also added that a security procedure “may impose an obligation on the receiving bank or the customer”. It did not need to add the telephone: “callback procedures” have been on the statute’s list of security devices since Article 4A’s 1990 enactment, and the 1996 text quoted in Hedged already carries them. Id.

The name on the account does not have to match. If a payment order names one person and gives an account number belonging to another, a beneficiary’s bank that “does not know that the name and number refer to different persons” “may rely on the number as the proper identification of the beneficiary of the order” and “need not determine whether the name and number refer to the same person.” § 336.4A-207(b)(1). A diverted closing wire that names your title company and routes to a stranger’s account can be paid to the stranger.

This is also the one place Article 4A follows a diverted wire back to the sender. When your own order named the real payee but carried the fraudster’s account number, and the beneficiary’s bank paid by number, a sender that is not a bank and proves the account holder was not entitled to the money “is not obliged to pay its order unless the originator’s bank proves that the originator, before acceptance of the originator’s order, had notice that payment of a payment order issued by the originator might be made by the beneficiary’s bank on the basis of an identifying or bank account number even if it identifies a person different from the named beneficiary.” § 336.4A-207(c)(2). The bank may prove that notice with any admissible evidence, and it carries its burden if the sender “signed a record stating the information to which the notice relates.” Id. So the question becomes what you signed when you opened the account or requested the wire. The rule does nothing if the fraudster had you name his account holder as well, because then name and number match.

The clocks are about your own bank, not about recall. A customer who fails to exercise ordinary care to discover and report an unauthorized order within a reasonable time “not exceeding 90 days” loses interest on any refund, not the refund itself. § 336.4A-204(a). And a customer who does not object to a debit “within one year after the notification was received” is precluded from contesting it. § 336.4A-505. Neither provision says anything about how long a stolen wire can be pulled back from the other end.

Finally, do not expect a negligence count to rescue a claim Article 4A defeats. The Minnesota Court of Appeals held that “the exclusivity of Article 4A is restricted to situations that are covered by particular provisions of the Article and that principles of law and equity may be applied to disputes relating to funds transfers so long as those principles do not create rights, duties, or liabilities inconsistent with those stated in the Article.” Hedged Inv. Partners, 578 N.W.2d at 771. A theory that the bank should have caught a wire its customer authorized runs straight into § 336.4A-202(a).

Is a payment from a consumer account any different?

Sometimes, and the difference turns on a fact most victims never think about: who pressed send.

Regulation E defines an electronic fund transfer as one “initiated through an electronic terminal, telephone, computer, or magnetic tape for the purpose of ordering, instructing, or authorizing a financial institution to debit or credit a consumer’s account.” 12 C.F.R. § 1005.3(b)(1). An “unauthorized electronic fund transfer” is one “initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit.” § 1005.2(m). The Bureau’s official interpretation adds: “An unauthorized EFT includes a transfer initiated by a person who obtained the access device from the consumer through fraud or robbery.” 12 C.F.R. pt. 1005, Supp. I, cmt. 2(m)-3. And “access device” includes “personal identification numbers (PINs), telephone transfer and telephone bill payment codes, and other means that may be used by a consumer to initiate an electronic fund transfer”. Id. cmt. 2(a)-1.

Put those together against the fake-fraud-department call. If the caller talks you into reading him a code and then moves the money himself, the transfer was initiated by someone who obtained your access device through fraud — an unauthorized EFT, with Regulation E’s liability limits. If he talks you into moving the money yourself to an account he swears is safe, you initiated it. I read that as an authorized transfer, and Regulation E’s unauthorized-transfer protection does not reach it. Same caller, same script, same stolen dollars; a different legal result because of whose hands were on the keyboard.

Where Regulation E does apply, speed is money. Notice within two business days after learning of the loss or theft of the access device caps liability at the lesser of $50 or the transfers before notice. § 1005.6(b)(1). Miss that window and the cap becomes $500, subject to the rule’s conditions. § 1005.6(b)(2). And an unauthorized transfer that appears on a periodic statement must be reported “within 60 days of the financial institution’s transmittal of the statement to avoid liability for subsequent transfers.” § 1005.6(b)(3).

A consumer’s international transfer is a “remittance transfer” with its own rules only if it is “sent by a remittance transfer provider”, and not every bank or credit union is one. An institution that provided 500 or fewer remittance transfers in the previous calendar year, and provides 500 or fewer in the current one, is “deemed not to be providing remittance transfers for a consumer in the normal course of its business” and falls outside the definition. 12 C.F.R. § 1005.30(e)(1), (f)(2)(i). Where the sending institution is a provider, the most useful rule is short: it must honor a cancellation request “received by the provider no later than 30 minutes after the sender makes payment”, if the funds “have not been picked up by the designated recipient or deposited into an account of the designated recipient”, and must refund within three business days. § 1005.34(a)–(b). Thirty minutes is not much. It is more than Article 4A guarantees on a domestic wire, where cancellation after acceptance depends on the receiving bank’s agreement. At an institution under the 500-transfer threshold, the 30-minute right does not exist.

For a business, the exposure is its own paperwork

Commercial reasonableness under Article 4A “is a question of law to be determined by considering the wishes of the customer expressed to the bank, the circumstances of the customer known to the bank, including the size, type, and frequency of payment orders normally issued by the customer to the bank, alternative security procedures offered to the customer, and security procedures in general use by customers and receiving banks similarly situated.” § 336.4A-202(c). The next sentence is the one that decided Choice Escrow: a procedure the customer chose “after the bank offered, and the customer refused, a security procedure that was commercially reasonable for that customer” is “deemed to be commercially reasonable”, if the customer agreed in a record to be bound.

In other words, the treasury-management agreement your office manager signed when the account was opened is the document that allocates your loss. Most business owners have never read it. The official comment, quoted by the Court of Appeals in Hedged, shows how much a customer can bargain for: “The customer may provide the bank with a list of authorized beneficiaries and prohibit acceptance of any payment order to a beneficiary not appearing on the list.” 578 N.W.2d at 773 (emphasis omitted) (quoting U.C.C. comment).

What I tell a business to put in place, in writing, before anything goes wrong:

Accept dual control. If your bank offers a second approver for wires, take it. Choice Escrow is what declining it costs.

Call back on a number already in your file. Any new or changed payment instruction — vendor, title company, executive — gets verified by a voice call to a number you had before the request arrived, placed by someone other than the person who received it. Never the number in the email. Never the number the caller gives you.

Impose a waiting period on changed instructions. A new account number does not get paid the day it arrives. A day’s delay costs a legitimate vendor nothing and costs a fraudster the whole scheme.

Treat urgency and secrecy as the tell. The one thing a cloned voice, a spoofed address, and a live deepfake cannot change is the demand that you act now and tell no one. A real executive can wait an hour for a callback.

Read your bank agreement and ask for a beneficiary list or payment limits. Since the 2024 amendment, § 336.4A-201 says a security procedure “may impose an obligation on the receiving bank or the customer”. Negotiate the obligations you want the bank to carry.

The first hours after a bad wire

IC3’s own instruction is the one to follow, and it contains no deadline I can responsibly convert into a number: “If you discover a fraudulent transfer, time is of the essence. Immediately, contact your financial institution and request a recall of the funds along with any necessary indemnification documents.” It continues: “Regardless of the amount lost, file a complaint at www.ic3.gov. Be sure to include the full transaction details in your report.”

  1. Call the sending bank’s wire or fraud department at once — on the number from your card or statement — and ask for a recall and for the bank to ask the receiving bank to hold the beneficiary account. Understand what a recall is. Once the receiving bank has accepted the order, cancellation “is not effective unless the receiving bank agrees or a funds-transfer system rule allows cancellation or amendment without agreement of the bank.” § 336.4A-211(c). The statute does allow cancellation of an order issued “because of a mistake by a sender” that sent money to “a beneficiary not entitled to receive payment from the originator,” § 336.4A-211(c)(2), but even then the receiving bank has to agree, and a sender whose cancellation the bank accommodates is liable for the bank’s resulting “loss and expenses, including reasonable attorney’s fees”. § 336.4A-211(f). I read that exposure as the reason banks ask for the “indemnification documents” IC3 mentions.

  2. File at ic3.gov the same day, with every transaction detail. IC3’s Recovery Asset Team runs what it calls the Financial Fraud Kill Chain, coordinating with banks to freeze funds. In 2025 it initiated 3,900 of those actions against $1,163,919,846 in attempted theft and froze $679,013,183, which IC3 reports as a 58% success rate. Frozen is not the same as returned, but frozen money is money that can still be fought over. In one IC3 example, the recipient bank confirmed that “the full amount was still in the account and on hold.”

  3. Report the impersonation. Consumer impostor fraud goes to the FTC at ReportFraud.ftc.gov. File a police report with your local department as well.

  4. Complain about the bank’s handling, if it earns one. The Consumer Financial Protection Bureau accepts complaints about money transfers at consumerfinance.gov/complaint, sends them to the company, and reports that “[m]ost companies respond within 15 days.”

  5. Preserve everything before anyone cleans up. Export the full headers of every email in the thread, not a forward. Keep call logs, voicemails, texts, the video-call invitation, the wire confirmation, and the bank’s notification of the debit. Do not reply to the fraudster.

Can you sue anyone?

Rarely the person who deserves it. The FBI reported in 2024 that BEC has been reported “in all 50 states and 186 countries, with over 140 countries receiving fraudulent transfers.” The author of the lie is usually anonymous and usually beyond a Minnesota court’s practical reach.

Minnesota’s consumer-protection statutes were built for merchants. The Prevention of Consumer Fraud Act reaches deception “with the intent that others rely thereon in connection with the sale of any merchandise”. Minn. Stat. § 325F.69, subd. 1. A fake bank fraud department sells nothing. The Deceptive Trade Practices Act reaches conduct “in the course of business, vocation, or occupation,” Minn. Stat. § 325D.44, subd. 1, and its private remedy is an injunction, § 325D.45, subd. 1. The private attorney general statute, Minn. Stat. § 8.31, subd. 3a, carries damages and attorney fees but comes with a public-benefit requirement I have explained elsewhere; who those statutes actually pay is its own question. Against an intermediary that knowingly sold the impostor a service, they may fit. Against an anonymous impostor, they are a judgment you cannot collect.

The more realistic target is the account the money landed in. Article 4A itself points there: where a beneficiary’s bank rightfully pays the person identified by account number and that person was not entitled to the money, the amount “may be recovered from that person to the extent allowed by the law governing mistake and restitution”. § 336.4A-207(d). Be prepared for what you find. In IC3’s $1.3 million closing example, the account owner “was a victim of an overpayment scam” who had been instructed to forward $1 million to Hong Kong. Recovering from a second victim is hard; recovering from a knowing participant runs through conspiracy and aiding-and-abetting theories, and a conversion claim over a wired balance is narrower than it sounds.

On the criminal side, Minnesota added “a forged digital likeness” to the identities protected by its identity-theft statute in 2026, 2026 Minn. Laws ch. 97, art. 3, § 3; that amendment is criminal only and gives the person who lost the money no new civil claim, as I set out in detail here. If someone is ever convicted, restitution interacts with any civil recovery in ways worth understanding before you settle anything.

What I tell clients

The FBI told the public in 2025 that AI-generated voices “can sound nearly identical” to the real person. Take that at face value. Every sensory tell people relied on — the accent that was slightly off, the stilted grammar, the face that did not quite move right, the unfamiliar number — is gone or going. You will not out-listen a machine that has been trained on your daughter’s voice.

What the machine cannot do is produce a code word it was never given or answer a phone number it does not control. That is the entire remaining defense. It is procedural, and nothing about it depends on how good the fake is.

I want to emphasize the part people skip. The procedure has to be agreed in advance, when nobody is frightened and nobody is in a hurry, because the entire scheme is designed to make you abandon it in the moment. A rule you invent during the phone call is a rule the caller will talk you out of. Write it down, tell your family and your staff, and give everyone permission to hang up on you — the real you — if you ever ask them to break it.


Madgett Law, LLC represents Minnesota individuals and businesses in disputes with banks and payment providers over fraudulent and fraud-induced transfers, including claims under UCC Article 4A and the Electronic Fund Transfer Act, and advises businesses on the payment controls and bank agreements that decide who bears a loss before one happens. If money has left your account because of an impersonation, send us a message or call 612-470-6529.

Sources: Minn. Stat. § 336.4A-108(a) (Article 4A does not apply to a funds transfer any part of which is governed by the Electronic Fund Transfer Act); Minn. Stat. § 336.4A-201 (definition of security procedure; callback procedures, in the text since 1990; obligations on bank or customer, and known email address, IP address, or telephone number not by itself a security procedure, both added in 2024), as amended by 2024 Minn. Laws ch. 93, art. 5, § 2; Minn. Stat. § 336.4A-202(a) (authorized order), (b) (verified order; commercially reasonable procedure; good faith and compliance), (c) (commercial reasonableness a question of law; factors; deemed-reasonable rule for a refused procedure); Minn. Stat. § 336.4A-203(a)(2) (customer’s proof that order was not caused by an entrusted person or by one who obtained information from a source controlled by the customer); Minn. Stat. § 336.4A-204(a) (refund and interest; ordinary care; reasonable time not exceeding 90 days); Minn. Stat. § 336.4A-207(b)(1), (c)(2), (d) (beneficiary’s bank that does not know name and number identify different persons may rely on account number; non-bank originator not obliged to pay absent notice, satisfied by a signed record; recovery under the law of mistake and restitution); Minn. Stat. § 336.4A-211(c), (c)(2), (f) (cancellation after acceptance requires receiving bank’s agreement or a system rule; beneficiary not entitled to payment; sender liable for bank’s loss and expenses); Minn. Stat. § 336.4A-505 (one-year preclusion); Minn. Stat. § 325F.69, subd. 1 (consumer fraud in connection with the sale of merchandise); Minn. Stat. § 325D.44, subd. 1 (deceptive trade practices in the course of business); Minn. Stat. § 325D.45, subd. 1 (injunctive relief); Minn. Stat. § 8.31, subd. 3a (private remedies); 2026 Minn. Laws ch. 97, art. 3, § 3 (adding “forged digital likeness” and “voice or likeness” to Minn. Stat. § 609.527, subd. 1), all from revisor.mn.gov. 12 C.F.R. § 1005.2(m) (unauthorized electronic fund transfer); § 1005.3(b)(1) (electronic fund transfer), (c)(3) (wire transfer exclusion); § 1005.6(b)(1)–(3) (liability limits; two business days; 60-day statement rule); § 1005.30(e)(1), (f)(1), (f)(2)(i) (remittance transfer; remittance transfer provider; 500-transfer safe harbor); § 1005.34(a)–(b) (30-minute cancellation; three-business-day refund); Supplement I to Part 1005, comments 2(a)-1, 2(m)-3, and 3(c)(3)-2, all from ecfr.gov. 28 U.S.C. § 41 (Eighth Circuit includes Minnesota), from uscode.house.gov. Choice Escrow & Land Title, LLC v. BancorpSouth Bank, 754 F.3d 611, 613–16, 622 (8th Cir. 2014); Hedged Investment Partners, L.P. v. Norwest Bank Minnesota, N.A., 578 N.W.2d 765, 771, 773 (Minn. Ct. App. 1998). Federal Communications Commission, Declaratory Ruling, Implications of Artificial Intelligence Technologies on Protecting Consumers from Unwanted Robocalls and Robotexts, CG Docket No. 23-362, FCC 24-17 (released Feb. 8, 2024), ¶¶ 2, 5–6. Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 IC3 Annual Report (cyber-enabled fraud top five by loss at p. 9; Recovery Asset Team guidance and 2025 Financial Fraud Kill Chain figures at p. 17; recovery examples at p. 23; state complaint counts and losses at pp. 28–29; AI-related BEC and distress-scam losses at p. 39; losses reported by complainants 60 and over at p. 46; BEC definition at p. 59; “AI Related” descriptor at p. 61; BEC complaint count at p. 7 and loss at p. 8). FBI PSA I-120324-PSA, “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud” (Dec. 3, 2024); FBI PSA I-051525-PSA, “Senior US Officials Impersonated in Malicious Messaging Campaign” (May 15, 2025); FBI PSA I-091124-PSA, “Business Email Compromise: The $55 Billion Scam” (Sept. 11, 2024). Federal Trade Commission, Consumer Alert, “Scammers use AI to enhance their family emergency schemes” (Mar. 20, 2023); FTC press release, “FTC Data Show a More Than Four-Fold Increase in Reports of Impersonation Scammers Stealing Tens and Even Hundreds of Thousands from Older Adults” (Aug. 7, 2025); FTC press release, “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025” (June 15, 2026). Consumer Financial Protection Bureau, “Submit a complaint”, consumerfinance.gov/complaint.

This article is general information about Minnesota and federal law. It is not legal advice, it does not create an attorney–client relationship, and no outcome is promised or implied. Whether a particular loss can be recovered depends on the facts, the payment channel, and the agreements in place, and those require a lawyer’s review.

Get new guides by email

Plain-English guides to Minnesota law, sent when a new one is written. No schedule, nothing for sale.

Used only to send these guides. Unsubscribe from any email. This is attorney advertising — subscribing does not create an attorney–client relationship.

← All news & articles