Social media posts were once viewed primarily as a privacy concern: sharing a birthday, holiday destination, employer or family photograph could reveal more than the user intended. Artificial intelligence has transformed that exposure into a scalable financial-crime risk.
Criminals can use information published on TikTok, Snapchat and other platforms to identify potential victims, understand their relationships and create communications tailored to their interests, routines and emotional triggers. Generative AI can then produce personalised messages, cloned voices, synthetic images, fraudulent profiles and apparently authentic videos at a speed that would have required substantial time and specialist skill only a few years ago.
The scale of AI-enabled fraud is becoming measurable. In 2025, the FBI’s Internet Crime Complaint Center received more than 22,000 complaints containing AI-related information, with adjusted reported losses exceeding $893 million. The affected typologies included business email compromise, investment fraud, romance scams, employment fraud and family-emergency schemes.
For a FinCrime audience, the central issue is not whether a scam originated on Snapchat or TikTok. It is how social-media data, trusted accounts, synthetic content and payment infrastructure are combined into a managed fraud journey—from victim selection and initial engagement to account compromise, manipulated payment and laundering through mule accounts.
Listen the podcast
Watch the video
Why social-media posts have become targeting intelligence
A single post may appear harmless. Several years of posts can reveal a detailed pattern of life.
Photographs, captions, comments and public interactions may identify family members, friendships, employers, schools, hobbies, travel plans, pets and significant life events. Even information that appears commercially unimportant can help a fraudster construct a credible approach.
A video mentioning an upcoming holiday can support a fake accommodation or airline message. A post about a new job can be followed by an impersonation of the employer’s human-resources team. Content about cryptocurrency can identify a potential investment-fraud target, while family videos may provide the names, faces and voices needed for an emergency scam.
The criminal does not need access to every piece of information. Credibility is often created through the accurate use of a few details. A message referring to a real relative, recent trip or known interest may feel too specific to be fraudulent.
Artificial intelligence changes the economics of this research. Instead of manually reviewing one profile, an offender can use automated tools to summarise public information, categorise potential targets and generate different messages for each person.
The underlying data may be public, but the resulting targeting capability is industrial.
How AI turns personal context into social engineering
Traditional phishing relied on volume. The same generic message was sent to thousands of recipients in the expectation that a small percentage would respond.
AI allows criminals to combine scale with personalisation. Language models can create messages suited to a victim’s age, interests, location, profession or recent activity. They can translate scripts, reproduce different tones and maintain prolonged conversations without obvious repetition.
This does not mean that every tailored scam is fully automated. Human fraudsters may use AI selectively: to research a target, improve grammar, respond persuasively or generate supporting content.
A criminal approaching someone who frequently posts about animals could imitate a charity, veterinary service or missing-pet campaign. A user sharing travel content might receive a fake hotel-payment request. A creator discussing business success could be targeted with a fraudulent sponsorship, investment or account-verification message.
The important change is that personalisation no longer requires a high-value target. Automation allows criminals to tailor lower-value attacks across large victim populations.
Synthetic profiles and manufactured relationships
AI-generated profile photographs, biographies and conversation scripts allow fraudsters to create convincing online identities rapidly.
These identities may be used for romance scams, friendship fraud, recruitment schemes, investment promotion or impersonation. A synthetic persona can maintain regular contact, refer to information from the victim’s posts and adapt its behaviour as the relationship develops.
The profile may not remain on the platform where contact began. Criminals often try to move conversations to another messaging service, private channel or investment application, reducing the visibility available to the original platform and separating the relationship from the account that first established trust.
Romance and friendship scams are particularly suited to AI-assisted interaction because their success depends on consistency and emotional engagement over time. Generative tools can produce affectionate messages, explanations for delayed meetings and plausible responses to questions from several victims simultaneously.
Synthetic content can also support a real fraud operator. Photographs, video calls and documents do not necessarily represent the person communicating. They may be generated, stolen or altered to maintain a false identity.
Voice cloning changes the meaning of familiarity
Short-form video platforms contain large quantities of clear speech. Family videos, livestreams, interviews and personal updates can provide the audio samples needed to imitate a voice.
Voice cloning can be inserted into traditional family-emergency scams. A victim receives a call apparently from a child, grandchild or close friend claiming to have been arrested, injured or kidnapped. The voice creates immediate emotional recognition, while the supposed emergency prevents careful questioning.
The criminal may then transfer the call to another actor impersonating a lawyer, police officer or doctor. Payment is demanded through a bank transfer, cryptocurrency, gift card or cash courier.
The strategic control is simple but important: a familiar voice is no longer proof of identity.
The recipient should end the call and contact the person through a known number. Families can also establish a verification question or phrase, although this should complement rather than replace independent reconnection.
Voice cloning can also support corporate fraud. A finance employee may receive an audio message appearing to come from a senior executive or supplier, requesting an urgent transfer or change to payment details.
Normal approval procedures should apply regardless of how familiar the voice sounds.
Deepfake endorsements and investment fraud
Short-form video is a powerful marketing format, making it equally useful for fraudulent promotion.
Criminals can create or manipulate footage of celebrities, financial commentators, business leaders and public figures to appear as though they are endorsing an investment opportunity. AI-generated audio can be synchronised with genuine video, while fabricated captions and logos provide additional credibility.
The content directs users to a website, messaging group or supposed investment adviser. Initial payments may be small, and a fraudulent dashboard displays profits to encourage larger deposits.
Some victims are allowed to withdraw a limited amount, reinforcing the impression that the platform is genuine. When they attempt a significant withdrawal, they are asked to pay additional tax, insurance, verification or anti-money-laundering fees.
AI can also sustain thousands of separate investment conversations. Each victim receives apparently personalised market commentary and reassurance, even though the underlying investment does not exist.
Social engagement should not be treated as validation. Comments, followers, likes and testimonials may be purchased, automated, generated or produced by other accounts controlled by the same network.
Hijacked accounts are more persuasive than fake ones
Not every scam operates through a newly created profile. Criminals also compromise established accounts belonging to creators, businesses and ordinary users.
A message or investment promotion from a recognised account may reach a large audience and inherit the trust accumulated by its genuine owner. Followers may assume that a giveaway, product offer or financial opportunity has been verified because it appears through a familiar profile.
Account takeover can begin with a fake copyright warning, sponsorship proposal, verification request or security message. The victim is directed to a phishing page that collects login credentials or authentication codes.
Once control is obtained, the criminal may change recovery information, contact followers, distribute malicious links or impersonate the account owner in private messages.
The compromised account can also become a source of additional intelligence. Private conversations, saved media and linked contact information may support further impersonation or extortion.
Protecting social-media accounts is therefore part of protecting financial identity.
Snapchat, trust and financial extortion
Snapchat’s emphasis on interpersonal communication can create a strong sense that a message comes from someone inside the user’s social circle. Criminals can exploit that expectation through fake friendship requests, compromised accounts and rapid relationship-building.
Financial sextortion is one particularly damaging model. A fraudster establishes contact, persuades the victim to share private material—or uses manipulated or synthetic imagery—and then demands money under threat of distribution.
Payment rarely ends the threat. Once a victim has shown that they can pay, further demands may follow. The offender may also threaten to contact relatives, friends, schools or employers identified through the victim’s social graph.
The correct response is not to negotiate or make repeated payments. The victim should preserve evidence, block and report the account and seek help from law enforcement or an appropriate safeguarding organisation.
Young users may be particularly reluctant to disclose what has happened. Platforms, financial institutions and families must ensure that reporting routes are supportive and do not blame the victim.
From social engagement to financial infrastructure
The social-media account is usually the acquisition channel, not the final destination of the money.
A purchase scam may direct the victim to a fraudulent checkout. An investment scam may lead to a cryptoasset platform. An employment scam may request an advance payment or recruit the victim as a money mule. An impersonation scam may end in a bank transfer to a supposedly safe account.
The proceeds then move through accounts controlled by mules, shell companies, compromised businesses or synthetic identities. Funds may be transferred onward rapidly, withdrawn as cash or converted into cryptoassets.
This is why platform abuse must be understood as part of the payment-fraud ecosystem. UK Finance reported that 66% of authorised push payment fraud cases recorded in 2025 originated online. Those cases accounted for almost one-third of recorded APP losses.
Preventing one malicious post is valuable. Identifying the recipient-account network can prevent losses across multiple platforms and financial institutions.
What a resilient personal control stack looks like
The first layer is exposure management. Users should review who can view posts, send messages, access friend lists and tag them in content. Public posts should be assessed not only for what they reveal individually, but for the wider profile they create over time.
The second layer is account security. Social-media and email accounts should use unique passwords and multifactor authentication. Recovery details and logged-in devices should be reviewed regularly, particularly after an unexpected security message or login alert.
The third layer is independent verification. Requests involving money, credentials, account access or confidential information should be confirmed through a known channel. A familiar profile, face or voice is not sufficient.
The fourth layer is payment discipline. Users should not leave recognised platform payment systems without a clear reason, transfer money to unrelated personal accounts or send cryptocurrency in response to unsolicited investment approaches.
The fifth layer is rapid response. Suspicious accounts, adverts and messages should be reported through the platform. Anyone who has disclosed credentials or sent money should contact the relevant bank, card provider or cryptoasset business immediately.
Evidence—including usernames, messages, payment details, website addresses and screenshots—should be preserved before the account is blocked or content disappears.
What platforms and financial institutions need to detect
TikTok and Snap prohibit fraud, impersonation and deceptive activity and use combinations of automated detection, account enforcement and human review. The challenge is that criminal operations adapt their content, accounts and infrastructure rapidly.
Platforms need to connect apparently separate indicators: repeated use of the same device, telephone number, payment destination, external domain, synthetic media or messaging script across multiple accounts.
Account-takeover controls should identify unusual logins, recovery changes and sudden shifts in posting or messaging behaviour. High-reach accounts require particularly strong protection because their compromise can expose large audiences quickly.
Financial institutions should monitor the payment patterns generated by platform-enabled fraud. Relevant indicators include new recipients receiving money from unrelated customers, rapid pass-through activity, sudden cryptocurrency purchases and customer behaviour suggesting live coaching or manipulation.
Interventions should reflect the scam narrative. Asking whether an online contact promised guaranteed returns or instructed the customer to conceal the payment is more effective than displaying a generic fraud warning.
Cross-sector intelligence sharing is essential. Platforms may identify the initiating account, hosting providers the fraudulent domain and banks the mule-account network. Each sees only part of the operation.
The limits of synthetic-media detection
AI-content labels and provenance technologies can improve transparency, but they are not complete fraud controls.
Synthetic content may lose its label when copied, edited or re-recorded. Detection systems can produce uncertain results, while legitimate AI-generated material is not inherently fraudulent.
More importantly, many scams do not require synthetic media. Criminals can use genuine photographs, stolen videos, real voices and compromised accounts. A technically authentic piece of content can still be presented within a false narrative.
Controls must therefore evaluate behaviour, identity, relationships and payment intent rather than asking only whether a video was generated by AI.

What this means for financial crime leaders
The original concern—that scammers could analyse Snapchat and TikTok posts to produce targeted messages—has developed into a broader industrial model.
Public content can support victim profiling, voice cloning, synthetic identities, fraudulent endorsements and personalised social engineering. Compromised accounts provide distribution, while mule networks and cryptoasset channels convert deception into criminal proceeds.
For FinCrime leaders, AI-enabled social-media fraud should not be treated solely as a content-moderation or customer-awareness issue. It connects platform security, identity fraud, account takeover, APP scams, investment fraud, extortion and money laundering.
The strongest response will combine account and device intelligence, synthetic-media signals, customer behaviour, payment monitoring and recipient-network analysis.
Artificial intelligence gives criminals the ability to manufacture familiarity at scale. Defeating that model requires institutions to recognise that a trusted profile, familiar voice or personalised message may be the beginning of a coordinated financial-crime journey—not evidence that the person behind it is genuine.




AI-enabled social-media fraud succeeds by transforming ordinary online activity into targeting intelligence. Public posts, videos, personal relationships and compromised accounts can help criminals create tailored messages, imitate familiar voices and manufacture identities that appear credible enough to influence financial decisions.
For users, the strongest protection is independent verification. A recognised profile, familiar face or convincing voice should not be treated as proof of identity when money, credentials or sensitive information are requested. Social-media and email accounts should also be protected with unique passwords, multifactor authentication and carefully managed privacy settings.
Platforms and financial institutions must look beyond individual fraudulent posts or payments. Effective prevention requires account-takeover detection, device intelligence, identification of synthetic and coordinated activity, targeted customer interventions and recipient-side monitoring for mule accounts.
Ultimately, AI has made personalised deception faster, cheaper and more scalable. Reducing the threat requires coordinated controls across social platforms, banks, payment providers, cryptoasset businesses and law enforcement—from the first manufactured interaction to the account used to receive and launder the proceeds.