Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The FBI said on November 25, 2025, that the Internet Crime Complaint Center (IC3) had received more than 5,100 account-takeover complaints since January, with reported losses exceeding $262 million. The scams commonly begin with an impersonated bank, payroll provider, financial institution, or technical-support representative who pressures a victim to disclose login credentials or a one-time security code.
AI can make these attacks more polished, personalized, and scalable. Holiday shopping adds fake stores, deceptive discounts, delivery messages, and sponsored search results. But the figures should not be combined: the FBI’s $262 million figure covers reported account-takeover losses, while its separate AI-related total and vendor observations about seasonal scams measure different things.
What the FBI’s $262 million figure measures
Account takeover (ATO) occurs when a criminal gains unauthorized access to an online account and uses it to steal money, redirect payments, change credentials, or obtain sensitive information. It is an outcome, not one single hacking technique.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →The FBI’s November 25, 2025 alert says IC3 received more than 5,100 ATO complaints since January 2025, representing more than $262 million in reported losses. The victims included individuals, businesses, and organizations. Targeted accounts included personal and commercial bank accounts, payroll systems, unemployment-related accounts, and health savings accounts.
Those numbers are based on complaints submitted to IC3. They are not a census of all ATO fraud: many victims do not report, and reported totals can be adjusted or revised. The FBI’s alert is specifically about impersonation of financial-institution support personnel, although ATO can also result from reused passwords, malware, stolen session credentials, infostealer logs, phishing pages, and other forms of credential theft.
#1 Best Overall
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Read the FBI’s account-takeover alert.
How the bank-support impersonation scam works
- Unexpected contact: A caller, text, or email claims to represent a bank, card issuer, payroll provider, or technical-support team.
- A manufactured emergency: The criminal says there has been a suspicious transaction, fraudulent purchase, account compromise, or other urgent problem.
- A request for secrets: The victim is asked for a username, password, security answer, MFA approval, or one-time passcode.
- A lookalike login page: The message may direct the victim to a site that copies a legitimate bank or employee self-service portal.
- Password reset and lockout: Using the captured information, the attacker enters the real service, resets the password, changes recovery details, or adds a new device.
- Money movement: The attacker transfers funds, changes beneficiaries or payroll destinations, and may route money through accounts associated with cryptocurrency wallets.
The FBI has also warned that criminals impersonate employee self-service websites to steal information and funds from payroll, unemployment, and health-savings accounts. Fraudulent search advertisements can send users to lookalike login pages even when the user thinks they are searching normally.
See the FBI’s employee self-service warning.
Why caller ID, logos, and MFA are not enough
Caller ID can be spoofed, and a familiar logo proves little. Even a correctly spelled company name in an email does not establish that the message is genuine. Search advertisements can also appear above the legitimate result and lead to a fraudulent site.
A bank or legitimate support representative generally does not need your password or one-time passcode. The safest response to an unsolicited account-security contact is to end the conversation. Then contact the institution independently through its official app, a bookmark you already trust, a card statement, or a phone number obtained from the institution’s official website.
Rank #2
- Auto-Fill Feature: Say goodbye to the hassle of manually entering passwords! PasswordPocket automatically fills in your credentials with just a single click.
- Internet-Free Data Protection: Use Bluetooth as the communication medium with your device. Eliminating the need to access the internet and reducing the risk of unauthorized access.
- Military-Grade Encryption: Utilizes advanced encryption techniques to safeguard your sensitive information, providing you with enhanced privacy and security.
- Offline Account Management: Store up to 1,000 sets of account credentials in PasswordPocket.
- Support for Multiple Platforms: PasswordPocket works seamlessly across multiple platforms, including iOS and Android mobile phones and tablets.
MFA remains valuable because it can stop many password-only attacks. It does not protect an account if a victim reads a code to an attacker, approves an unexpected push notification, or has a compromised recovery channel. Where available, passkeys or hardware security keys are generally more resistant to ordinary phishing than codes typed into a site.
What AI changes—and what it does not
The evidence supports treating AI as an accelerator rather than proof of a wholly new type of fraud. Criminals can use generative AI to:
- Write fluent, official-sounding messages in multiple languages.
- Personalize scams using publicly available information.
- Generate fake customer-support scripts, profiles, product listings, advertisements, and websites.
- Create synthetic audio or other impersonation content.
- Run more campaigns without the same level of writing or technical skill.
The FBI’s 2025 IC3 report recorded 22,364 complaints containing AI-related information and adjusted losses of approximately $893.3 million. That is a separate dataset from the more than $262 million in ATO losses. It does not establish that all ATO attacks used generative AI, or that AI caused the entire ATO total.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
- ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
- ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
- THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
- PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.
AI also does not eliminate the core warning signs: unsolicited contact, urgency, secrecy, requests for passwords or codes, unexpected MFA prompts, unusual payment instructions, and pressure to bypass normal procedures. The FBI previously warned that criminals use generative AI for social engineering, spear phishing, fictitious profiles, and financial fraud.
Read the FBI’s 2025 IC3 report and its generative-AI fraud advisory.
Why holiday shopping creates more opportunities
Shopping periods such as Black Friday and Cyber Monday give criminals a convenient setting for urgency and brand impersonation. Seasonal scams may involve:
Rank #4
- NEVER FORGET A PASSWORD AGAIN - Clever Fox password journal will help you create secure passwords and keep them safe and organized. This password book allows you to store all your passwords and other computer information in one place to find it easily.
- ALPHABETICAL A-Z TABS - Alphabetic tab system makes it easy to find any password you need. The book also has sections for most important passwords, wireless & email settings, software license information & additional notes.
- ELEGANT, SMART, PRACTICAL & SECURE PASSWORD ORGANIZATION - This password keeper book has been designed to be anonymous without an obvious title on the cover. For added security there is space to write hints instead of the password itself.
- POCKET SIZE & PREMIUM QUALITY - This internet address and password logbook with tabs comes in pocket size (4.0x5.5 inches). The password notebook has an eco-leahter hardcover, elastic band, pen loop, bookmark, pocket for notes, and thick 120gsm paper.
- 60-DAY MONEY-BACK GUARANTEE - We will exchange or refund your password organizer if you aren’t satisfied with your password organization for any reason. Reach out to us via message to refund your internet password logbook.
- Fake retailer websites and unusually large discounts.
- Sponsored search results that imitate major brands.
- Delivery, redelivery-fee, and package-confirmation messages.
- Gift-card requests or drained gift cards.
- QR codes leading to payment or credential-stealing pages.
- Fake prizes, holiday decorations, or limited-stock offers.
- Payment requests involving cryptocurrency, wire transfers, or peer-to-peer payments.
Google’s November 2025 advisory described fake storefronts, deceptive advertisements, brand-term hijacking, delivery impersonation, and urgent discounts. A report from The Hacker News, citing Fortinet/FortiGuard Labs, said the company observed at least 750 malicious holiday-themed domains registered over a three-month period. That is a vendor observation for a defined period—not a count of all malicious domains or proof that every site used AI.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Holiday scams and ATO overlap, but they are not synonymous. A fake store may steal card details without taking over a bank account. A bank-support impersonation scam may happen at any time of year and may target payroll or business accounts rather than shoppers.
Review the FBI’s holiday-scam guidance and Google’s seasonal fraud advisory.
Best Value
- Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More
- Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
- Enter one PIN number and have access to 400 accounts. Search function included.
- Unit auto locks for 30 minutes after 5 consecutive incorrect PIN attempts
- Includes mini stylus for easier keypad entry
Five signs an account-security message is fraudulent
- It arrived unexpectedly. You did not initiate the call, text, or email.
- It creates immediate pressure. The sender demands action before you can verify the claim.
- It requests a password, OTP, or MFA approval. Never disclose a one-time code to an inbound caller.
- It supplies the contact path. Do not use the phone number, link, QR code, or search result supplied by the message.
- It demands an unusual payment. Gift cards, cryptocurrency, wires, or payments to an unfamiliar account are major warning signs.
Protect accounts before an attack
For consumers
- Use a different, strong password for every banking, email, payroll, shopping, and payment account.
- Use a password manager to generate and store unique passwords.
- Enable MFA on banking, email, payroll, cloud, and marketplace accounts.
- Choose passkeys or security keys when the service supports them.
- Turn on login, new-device, password-change, and transaction alerts.
- Review active sessions, authorized devices, recovery addresses, forwarding rules, beneficiaries, and linked payment methods.
- Reach financial institutions through their official apps, saved bookmarks, or trusted statements—not search advertisements.
- For online purchases, check the domain character by character. HTTPS encrypts a connection; it does not prove that the store is legitimate.
- Use a credit card where appropriate, since it may provide dispute protections that some other payment methods do not.
For small businesses and payroll administrators
- Require independent callback verification before changing payroll destinations, bank details, beneficiaries, or wire instructions.
- Use dual approval for high-value transfers and account-recovery changes.
- Keep administrative privileges separate from ordinary email accounts.
- Use phishing-resistant MFA for finance, payroll, identity, and cloud administrators.
- Monitor unusual locations, new devices, impossible-travel events, mailbox-forwarding rules, and sudden payment-instruction changes.
- Train staff that a bank or help-desk representative should not receive an OTP verbally.
- Maintain a written fraud-escalation procedure with 24-hour bank contacts.
- Test whether the response team knows who can request a wire recall or payment freeze.
What to do after clicking or disclosing information
Act immediately. Do not wait to determine exactly what happened.
- Call the bank, card issuer, payroll provider, or other affected institution using a trusted contact method. Ask it to secure the account, investigate suspicious activity, and stop, recall, reverse, or freeze fraudulent transactions where possible.
- Change the compromised password from a trusted device. Change it anywhere else it was reused.
- Revoke unfamiliar sessions, devices, app authorizations, recovery methods, and forwarding rules.
- Secure the email account connected to the financial account. If the device may contain malware, use a different trusted device for password changes and contact the relevant support provider.
- Preserve the evidence: messages, phone numbers, URLs, screenshots, transaction IDs, recipient details, and cryptocurrency wallet addresses.
- File a detailed complaint with the FBI’s IC3. Include “Account Takeover” or “SEO poisoning” in the description when relevant.
If money was wired or transferred, speed is critical. Ask the sending institution for a recall or reversal and provide the amount, date, recipient information, transaction identifiers, and any intermediary details. The FBI says rapid reporting and complete transaction information can improve the possibility of recovery, but no recovery is guaranteed.
Where to report the scam
- Financial institution: Report the fraud immediately and request account protection and transaction-recovery action.
- IC3: Submit a detailed report at ic3.gov.
- Impersonated company: Notify the bank, payroll provider, retailer, or support brand being copied.
- Payment provider: Report fraudulent card, wire, cryptocurrency, gift-card, or peer-to-peer activity to the relevant provider.
- Law enforcement: Contact local law enforcement where appropriate, particularly when there is immediate risk or substantial loss.
What these numbers do not prove
The three most easily confused indicators are:
| Figure | What it represents | What it does not establish |
|---|---|---|
| More than $262 million | Reported losses in more than 5,100 ATO complaints since January 2025, according to the FBI’s November 25 alert. | All ATO fraud, all phishing, or the portion caused by AI. |
| Approximately $893.3 million | Adjusted losses associated with 22,364 IC3 complaints containing AI-related information. | A total that can be added to the ATO figure, or proof that every loss was caused by AI-generated content. |
| At least 750 domains | Fortinet/FortiGuard Labs’ reported observation of malicious holiday-themed domains over three months. | A complete count of malicious domains or evidence that all seasonal scams led to ATO. |
The FBI also cites more than $503 million in 2025 losses from non-payment and non-delivery scams and $282 million in credit-card fraud on its holiday-scams page. Those are separate fraud categories. The figures should be read as parallel indicators of risk, not one combined holiday-AI-ATO loss total.
The practical conclusion is narrower and more useful: criminals are combining familiar social engineering, credential theft, account recovery abuse, and rapid money movement with better content-generation and seasonal pressure. The strongest defenses remain independent verification, unique credentials, MFA—preferably phishing-resistant methods—and immediate reporting when something goes wrong.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

