A new survey by Nexus Pesquisa e Inteligência de Dados, a Brazilian data intelligence firm, shows that scammers in the country are moving away from traditional password theft toward 'cloning' people using artificial intelligence tools. The research, which analyzed social media mentions of digital security issues between January and July 2026, was released this week, and G1 reviewed several of the victim reports it draws on.
According to the study, criminals already use AI to reproduce a real person's voice or appearance from photos, videos and other content found online. With that material, they build fake identities or impersonate someone the victim knows, making the approach far more convincing than older, more generic scam tactics.
Nexus tracked 39,700 social media mentions of digital security problems faced by consumers during the period. Of those, 2,800 mentions, or 7.3%, dealt specifically with the manipulation of personal data. The survey also logged 9,100 mentions of Pix, Brazil's instant payment system, tied to fraud concerns. Pix has become a favorite target for scammers since its adoption became near-universal among Brazilian bank customers.
'The study also reveals a contrast: while criminals already use AI tools to impersonate other people in increasingly convincing ways, Brazilians are still trying to understand what a deepfake is and how these new types of scams work,' said Marcelo Tokarski, Nexus's CEO, in comments to G1. A deepfake uses artificial intelligence to create or alter images, videos and audio realistically, for instance placing one person's face on another's body or simulating someone saying something they never said.
Scams mapped by the study
Among the fraud schemes identified is 'SIM swapping,' in which criminals pose as the victim to request a new SIM card from a mobile carrier, claiming the original was stolen or damaged. Once the swap goes through, the victim's chip stops working and the phone number begins receiving calls and messages on a device controlled by the scammers, who can then intercept SMS codes and attempt to reset passwords for accounts on apps like Instagram and WhatsApp. Another scheme involves fake profiles built with stolen personal data to advertise nonexistent concert tickets, targeting social media users who post that they are looking for tickets to a show.
Tokarski said 'identifying this gap between the advance of technology and society's familiarity with the subject is the first step to protecting the digital environment.' The study does not detail, so far, how much money victims of AI cloning scams have actually lost, but it echoes warnings already raised about deepfakes in other contexts, including election-related propaganda.