Skip to main content

Evidence explained

What technology changes in romance scams

Scammers can use AI-generated identities to make deception harder to check, while investigators use software to flag suspicious material. But the studies reviewed here do not establish that these tools reduce victims’ losses, and how widely scammers use generative AI remains unknown (Cross & Layt, 2021; Dominguez Castillo, 2026; Vedhanayagam et al., 2026).

Explanation updated . This can reflect an editorial correction without a new evidence snapshot.

AI-assisted explanation · Automated editorial and source checks. Preparation and review details

Three different jobs for technology

Interpretation. Checking a photograph, classifying a website, and tracing money answer different questions. Their results cannot certify a person’s identity or establish that a service prevents fraud (Cross & Layt, 2021; Stern & Choi, 2026; Vedhanayagam et al., 2026).

Three different jobs for technology
FocusWhat the studies showWhat remains uncertain
Image searches Analysis of complainant reports

Complainants described searches that exposed photographs appearing under different names, helping them recognize that their online contact was not the person they claimed to be (Cross & Layt, 2021).

Interpretation. A search without a match does not authenticate someone; uniquely generated AI images may have no original source that an image search can find or compare (Cross & Layt, 2021).

Automated screening Machine-learning evaluation

One prototype reported 85% accuracy, 88% precision and 80% recall when categorizing websites and profiles associated with romance scams (Vedhanayagam et al., 2026).

Interpretation. The report describes a split between training and testing data but does not clearly tie all these scores to that split. Its authors also say performance depends on input quality and relevance. The scores do not establish prevented financial loss (Vedhanayagam et al., 2026).

Cryptocurrency tracing Blockchain-forensics case study

Researchers distinguished Bitcoin addresses—digital destinations for transfers—that received and redistributed funds from addresses that received funds with no observed outgoing transfers (Stern & Choi, 2026).

The case used U.S. sanctions records to select a network, so it cannot establish how widespread these transaction structures are across romance-investment scams. Traced routes also remain uncertain because Bitcoin transfers can include both payments and change returned to the sender (Stern & Choi, 2026).

Technology supports credibility, continued contact, and fake investments

Technology helps scammers establish credibility before any AI-generated content is involved. A qualitative analysis of fraudulent profiles explains how apparent mutual friends can lend credibility and how publicly visible social profiles let scammers investigate a potential victim (Kopp et al., 2016).

Research on cryptocurrency scams describes up to three applications being used during a scam. A separate review describes shifts from social media, websites, or apps to messaging apps such as WhatsApp, Google Chat, or Telegram, where there is less surveillance (Ordekian et al., 2024; Pope & Seto, 2026).

Interpretation. The interface can also become part of the deception. A scoping review describes fake investment dashboards displaying fabricated trading data and customer-service features. An apparently functioning trading screen therefore cannot, by itself, establish that the investment activity it displays is real (Gujarathi et al., 2026).

Image searches can expose reuse, not prove identity

Cross and Layt’s 2021 analysis illustrates how people use online checks when suspicious. Among 509 reports in the analysis, 239 described an internet search to help with decision-making, and 172 specifically mentioned reverse-image searches. Those counts describe actions within the reports, not a success rate for the technique (Cross & Layt, 2021).

In many cases, searches revealed that the contact was not the person they claimed to be; some exposed photographs associated with multiple names or profiles. Searches without useful results did not necessarily reassure complainants. These accounts distinguish finding evidence of a false identity from interpreting an absence of information (Cross & Layt, 2021).

Interpretation. AI changes the question a search can answer. A newly generated face may not be copied from anyone’s photograph, leaving no original source to find. Cross’s 2022 exploratory examination also describes realistic fake video. This is a reason to question visual reassurance, not evidence that every convincing online image is synthetic (Cross, 2022; Cross & Layt, 2021).

Automation does not mean an AI runs the whole relationship

In a 2021 study, researchers screened 2.5 million Android apps from Google Play and nine third-party markets, identifying 967 fraudulent dating apps in 22 groups based on similarities in their software code. They reported that most observed accounts used chatbots built around predefined conversation templates—not necessarily modern generative AI (Hu et al., 2021).

The screening could miss apps because its lists of keywords and software components used for in-app purchases may be incomplete. Its findings concern the apps studied, rather than all romance scams. Other research describes an operation in which software assigned multiple workers to each client. In that operation, software coordinated people rather than replacing them (Hu et al., 2021; Wang & Topalli, 2024).

Tests of AI safeguards answer a narrower question. A 2026 evaluation tested individual prompts rather than extended conversations. It counted replies as successes if they contained text, returned no error, and lacked recognized refusal wording. This measure does not establish that an output could sustain a persuasive scam. A separate analysis says the proportion of operations using large language models remains unknown (Dominguez Castillo, 2026; Parra et al., 2026).

A detection score needs a clear test

A 2026 study combined material from public romance-scam websites with information gathered through Maltego, a tool for linking digital information. It used logistic regression, a statistical classification method, to analyze features from emails and links, dividing the data 75% for training and 25% for testing (Vedhanayagam et al., 2026).

For the prototype detection system, the study reported 85% accuracy, 88% precision, and 80% recall. Precision describes how often a positive classification was correct; recall describes how much of the relevant scam material was found. The report does not clearly establish whether all these metrics came from the stated training/testing split (Vedhanayagam et al., 2026).

Reading private messages creates a separate trade-off

A separate research proposal would assess dating matches for possible risk and send tailored warnings. It could use conversation content to decide when to warn someone. This is a proposal to examine exchanges between matched users, distinct from the earlier prototype that categorized websites and profiles; the description does not show whether warnings change behavior (Dickerson et al., 2020; Vedhanayagam et al., 2026).

The authors acknowledge that triggers based on conversation content require examining private messages. Extracting only limited information still intrudes on the conversation, and people may object to being profiled as potential victims or threats. Whether users consider that trade-off acceptable remained an open question (Dickerson et al., 2020).

What platform and prevention teams should change

Interpretation. Assign responsibility for evaluating each proposed change, and decide in advance what evidence would justify keeping, revising, or stopping it. Include user acceptability in that review rather than treating it as a final approval step (Dickerson et al., 2020; Vedhanayagam et al., 2026).

  1. Stop treating an unmatched photo as clearance

    Explain that image searches can uncover reused photographs but cannot certify an identity. Keep the absence of a match separate from evidence of authenticity, especially when a unique synthetic image may have no source to discover (Cross & Layt, 2021).

  2. Ask what the detection scores measure

    Before adopting a detector, ask what material was used to test it and whether it resembles the service’s intended use. Request separate reporting of missed scams and incorrect flags, rather than accuracy alone (Vedhanayagam et al., 2026).

  3. Evaluate privacy alongside warning outcomes

    For message-based warnings, specify what information the system examines and what categories it assigns to users. Assess whether people accept those practices separately from whether warnings change behavior. Acceptance of message analysis does not show that warnings work, and a warning that changes behavior does not establish that users accept the privacy intrusion (Dickerson et al., 2020).

What claim would justify adopting the tool?

Are you buying a way to identify suspicious material, reconstruct transactions, or prevent losses? Require evidence for that specific purpose. A classification score or plausible transaction map can support an investigative task without proving that the tool protects people from financial harm (Stern & Choi, 2026; Vedhanayagam et al., 2026).

About the evidence

This explanation draws on selected sources from RSRC’s full synthesis. The full research record, its source list and version history remain available below.

Explore this topic’s methods and groups studied · Follow topic updates

Scope, preparation and limitations

Codex edited and reviewed this explanation from synthesis version 78. Changed passages were checked against preserved source excerpts; passing source checks were reused for unchanged passages. The editorial judgments are recorded as Codex review, not a new API grading run. They assess communication, not reader-test results or scientific certainty. No human or expert content review of this explanation is recorded.

The full synthesis preserves 42 publication records and 152 evidence statements. These counts do not establish the number of independent studies or the strength of a finding. Practical implications are editorial interpretations, with limitations explained alongside the evidence.

RSRC methodology
Sources cited in this explanation (13)

Links open the publication record or original work. Journal access may vary.

  1. Cross, C. (2022). Using artificial intelligence (AI) and deepfakes to deceive victims: the need to rethink current romance fraud prevention messaging. Crime Prevention and Community Safety, 24(1), 30–41. https://doi.org/10.1057/s41300-021-00134-w
  2. Cross, C., & Layt, R. (2021). “I Suspect That the Pictures Are Stolen”: Romance Fraud, Identity Crime, and Responding to Suspicions of Inauthentic Identities. Social Science Computer Review, 40(4), 955–973. https://doi.org/10.1177/0894439321999311
  3. Dickerson, S., Apeh, E., & Ollis, G. (2020). Contextualised Cyber Security Awareness Approach for Online Romance Fraud. 2020 7th International Conference on Behavioural and Social Computing (BESC), 1–6. https://doi.org/10.1109/besc51023.2020.9348307
  4. Dominguez Castillo, L. (2026). Industrialized heartbreak: how generative AI enables romance fraud at scale. AI and Ethics, 6(3). https://doi.org/10.1007/s43681-026-01129-9
  5. Gujarathi, P., Verma, S., & Nair, V. V. (2026). Pig Butchering Scams as Cyber-Enabled Financial Crime: A Scoping Review of Dimensions, Modus Operandi, and Victim-Offender Dynamics. Deviant Behavior, 1–16. https://doi.org/10.1080/01639625.2026.2677691
  6. Hu, Y., Wang, H., Zhou, Y., Guo, Y., Li, L., Luo, B., & Xu, F. (2021). Dating with Scambots: Understanding the Ecosystem of Fraudulent Dating Applications. IEEE Transactions on Dependable and Secure Computing, 18(3), 1033–1050. https://doi.org/10.1109/tdsc.2019.2908939
  7. Kopp, C., Layton, R., Sillitoe, J., & Gondal, I. (2016). The Role of Love stories in Romance Scams: A Qualitative Analysis of Fraudulent Profiles. Zenodo (CERN European Organization for Nuclear Research). https://doi.org/10.5281/zenodo.56227
  8. Ordekian, M., Papasavva, A., Mariconti, E., & Vasek, M. (2024). A Sinister Fattening: Dissecting the Tales of Pig Butchering and Other Cryptocurrency Scams. 2024 APWG Symposium on Electronic Crime Research (eCrime), 136–148. https://doi.org/10.1109/ecrime66200.2024.00016
  9. Parra, Y. J., Chi, H., Alo, R. A., & Lima, V. (2026). Evaluating Jailbreak Vulnerabilities in LLMs: A Taxonomy and Comparative Analysis in Romance Fraud Scenarios. 2026 IEEE 5th International Conference on AI in Cybersecurity (ICAIC), 1–6. https://doi.org/10.1109/icaic67076.2026.11395743
  10. Pope, T., & Seto, C. H. (2026). From swipe to swindle: a narrative review of research on older adult victims of romance fraud. Journal of Elder Abuse & Neglect, 38(4), 423–443. https://doi.org/10.1080/08946566.2026.2690996
  11. Stern, M., & Choi, K.-S. (2026). Three-Tier On-Chain Transaction Architecture in a Sanctions-Linked Pig-Butchering Network: A Blockchain-Forensics Case Study. International Journal of Cybersecurity Intelligence & Cybercrime, 9(2). https://doi.org/10.52306/2578-3289.1249
  12. Vedhanayagam, P., Singh, M., Dadhania, A. P., & Ikram, S. T. (2026). Forensic footprints in digital love: Unveiling romance scams with Maltego and machine learning. AIP conference proceedings, 3449, 020278. https://doi.org/10.1063/5.0298575
  13. Wang, F., & Topalli, V. (2024). The cyber-industrialization of catfishing and romance fraud. Computers in Human Behavior, 154, 108133. https://doi.org/10.1016/j.chb.2023.108133
Full synthesis and revision history

Download the full synthesis PDF

Reviewed, human‑curated evidence indicates that social‑network services, dating platforms, and social media are common initial contact venues for relationship‑based fraud and that offenders frequently shift conversations from public platforms to less‑monitored messaging channels to continue grooming and seek payments. Readily available generative‑AI and deepfake tools can produce realistic synthetic faces, voices, and video at lower technical thresholds than earlier methods; investigators and reviewers report these capabilities can undermine provenance‑based checks (for example reverse‑image searches) because synthetic images may have no external source to match. Evidence about automation is heterogeneous: experimental and corpus studies document signatures consistent with partial automation in initial acquisition phases (templated or nearly identical replies), while offender‑facing and convicted‑case analyses document organized, multi‑worker operations that employ algorithms, worker assignment, background files, VPNs, and foreign phone numbers, indicating substantial human mediation in many high‑loss or sustained scams. Hybrid romance→investment schemes (“pig‑butchering”) repeatedly use fabricated trading dashboards, fake apps/websites, and offender‑controlled crypto flows; blockchain forensic case studies describe three‑tier transaction role structures and extensive recirculation and swapping that make deterministic attribution inferential. Researchers have developed OSINT and prototype detection workflows with promising in‑sample metrics in some studies, but authors emphasize that algorithm effectiveness depends critically on input‑data quality and representativeness and highlight privacy and acceptability concerns for message‑scanning approaches. Common methodological patterns across the corpus—reliance on purposive, complaint‑derived, forum‑sourced, or small qualitative samples and enforcement‑selected forensic cases—provide detailed operational insight but limit population‑level generalization and precise prevalence estimates. Key evidence gaps identified by authors include the empirical measurement of how extensively LLMs/generative AI are used in live scams and whether they operate end‑to‑end, real‑world validation of detection systems with platform and private‑message data, and field‑tested deepfake‑detection and platform mitigation strategies that preserve privacy and legal rights (Cross, 2022a, 2022b; Dickerson et al., 2020; Dominguez Castillo, 2026; Franceschini et al., 2023; Grace Carvalho Fernandes et al., 2023; Griffin & Mei, 2024; Gujarathi et al., 2026; Huang et al., 2015; Jakobsson, 2016; Kassem & Carter, 2023; Ko et al., 2026; Pope & Seto, 2026; Rabby & Chowdory, 2024; Sorell & Whitty, 2019; Stern & Choi, 2026; Vedhanayagam et al., 2026; Wang & Topalli, 2024).

Platform ecology and channel shifting

Multiple studies using complaints, corpora, and case evidence identify social‑network services and dating platforms as common initial contact venues for relationship‑based fraud; after rapport is established, scammers frequently redirect conversations to less‑monitored messaging apps or phone/VoIP channels to continue grooming and seek payments (Ordekian et al., 2024; Pope & Seto, 2026; Wang & Kelsay, 2025; Yan, 2024).

Platform affordances—public profile content, friend networks, and searchability—are repeatedly reported to enable tailored targeting and personalized scripts; social‑media visibility of apparent wealth or shared connections can also be used to normalize deceptive behavior or recruit accomplices in some operations (Barnor, 2024; Cross, 2022a; Kopp et al., 2016; Ohu & Jones, 2025).

Evidence is context sensitive: platform rankings and dominant contact channels vary by country and over time (for example, Facebook, Instagram, and country‑specific messengers such as KakaoTalk or WeChat are salient in regionally focused studies), so platform‑specific prevention measures should reflect local usage patterns (Amirkhani et al., 2024; Cantin et al., 2025; Choi et al., 2024; Corpuz et al., 2025; Yan, 2024).

Authors report that offenders commonly use multiple applications during a single scam and often move victims to less‑surveilled channels (for example WhatsApp, Telegram, or other messaging services) after trust is established, a tactic linked to isolation from platform monitoring and continued solicitation (Ordekian et al., 2024; Wang & Kelsay, 2025).

AI, deepfakes, and verification challenges

Several conceptual reviews, case reports, and forensic observations document that readily available generative‑AI and deepfake tools can produce realistic synthetic faces, voices, and video at lower technical thresholds than earlier methods; these capabilities can undermine provenance‑based checks (for example reverse‑image searches) because synthetic images may have no external source to match (Cross, 2022b; Cross & Layt, 2021; Kassem & Carter, 2023).

Investigative case material and media‑documented incidents attribute large losses to scams that reportedly used AI‑generated media (including deepfake videos and voice cloning) in some instances, and authors explicitly call for empirically validated, accessible detection tools rather than assuming existing provenance checks suffice (Choi et al., 2024; Cross, 2022b; Mouri, 2024).

At the same time, complaint‑based analyses and observational casework report many instances where reverse‑image searches or other identity checks exposed stolen or reused photos and helped substantiate suspicions, although authors also note cases with no positive matches where the absence of a footprint raised concern (Botha et al., 2025; Cross & Layt, 2021; Khukhunaishvili, 2024).

Because evidence shows both successful image‑search detections and plausible use of uniquely generated synthetic images that lack linkable provenance, authors call for development and validation of accessible deepfake‑detection methods and image‑authentication tools as a research and operational priority (Cross, 2022b; Cross & Layt, 2021).

Automation, semi‑industrialization, and LLM risks

Evidence of automation is heterogeneous. Large email‑corpus and experimental studies document signatures consistent with partial automation during acquisition phases—e.g., highly similar replies, low click/response rates, and template‑driven messages—while operational and convicted‑case analyses emphasize substantial human mediation for sustained grooming and high‑loss operations (Hu et al., 2021; Huang et al., 2015; Jakobsson, 2016; Robinson & Edwards, 2024).

Qualitative offender‑facing studies and court‑file analyses show organized, multi‑worker operations that use algorithms, worker assignment, background files, VPNs, and foreign phone numbers—practices that can be supported by but are distinct from fully autonomous LLM‑driven end‑to‑end scams; the reviewed corpus does not provide validated estimates of the proportion of operations that are end‑to‑end LLM‑automated (Abubakari et al., 2026; Dominguez Castillo, 2026; Ogunleye et al., 2020; Pope & Seto, 2026; Wang & Topalli, 2024).

Experimental evaluations of LLM safety in romance‑fraud contexts show model susceptibility to jailbreak prompts under specific conditions, but authors caution generalization is limited by prompt choice, single‑turn designs, and evaluation criteria—evidence that LLMs present both opportunities to scale malicious content and limits in current operational use (Parra et al., 2026).

Authors note an empirical gap: the precise proportion of romance‑fraud operations using LLMs rather than traditional scripted techniques remains unknown, and measurement of live operational LLM use requires targeted empirical designs reported as a research priority in multiple sources. This gap constrains confident claims about end‑to‑end automation prevalence (Dominguez Castillo, 2026; Sorell & Whitty, 2019).

Pig‑butchering, blockchain forensics, and crypto‑enabled schemes

Multiple case studies and mixed‑method analyses characterize pig‑butchering as a hybrid long‑duration trust‑building process that funnels victims into fabricated trading dashboards, fake apps/websites, or offender‑controlled exchanges; distribution commonly uses web links or QR codes rather than legitimate app‑store channels (Franceschini et al., 2023; Gujarathi et al., 2026; Wang & Zhou, 2022).

Blockchain‑forensics case studies document structured role‑based transaction architectures (for example hub, intermediary, and holding tiers) and extensive recirculation and swapping of funds across addresses and cryptocurrencies, tactics that impede tracing and make attribution inferential rather than deterministic (Griffin & Mei, 2024; Stern & Choi, 2026).

Authors recommend combining on‑chain and off‑chain evidence in living forensic collaborations and real‑time analyst partnerships to improve interpretability and to keep pace with evolving laundering techniques; several sources frame these cooperative approaches as necessary given enforcement‑selected or partial sampling frames in forensic case work (Gujarathi et al., 2026; Stern & Choi, 2026).

A blockchain-forensics case-study using OFAC sanctions as an enforcement-based sampling frame analyzed a 29-address OFAC sample and found extensive recirculation and swapping of funds across addresses and cryptocurrencies, which impedes tracing and obscures fund origins. Because the analysis is limited to that partial OFAC-based sample, the authors caution against generalizing this single-case forensic structure to all pig-butchering networks without comparative replication (Griffin & Mei, 2024; Stern & Choi, 2026).

Detection prototypes, OSINT workflows, privacy, and methodological patterns

Researchers have developed prototype detection approaches and OSINT workflows—examples include Maltego‑based link analysis and TF‑IDF/logistic‑regression classifiers—that report promising in‑sample performance or high inter‑annotator agreement in validation datasets, though dataset, labeling, and external‑validation details vary across studies (Ko et al., 2026; Vedhanayagam et al., 2026).

Detection researchers caution that algorithm effectiveness and accuracy depend heavily on the quality and relevance of input data. Proposed research directions include developing detection profiles from communication and payment patterns, while a scoping review recommends living evidence syntheses and real-time collaboration with forensic analysts to maintain relevance. These are cautions and research recommendations, not demonstrations of real-world detection effectiveness (Gujarathi et al., 2026; Sorell & Whitty, 2019; Vedhanayagam et al., 2026).

At the same time, dynamic analysis of private messages or behavioral profiling raises clear privacy, acceptability, and governance concerns; the evidence emphasizes participatory evaluation of user acceptability, transparency, and bias mitigation before deploying message‑scanning or automated warning systems (Dickerson et al., 2020).

Across the corpus, common methodological patterns include reliance on purposive, complaint‑derived, or forum‑sourced samples, small qualitative samples, single‑case or forensic case studies, and secondary‑data syntheses; these designs provide rich operational detail but limit population‑level generalization and precise prevalence estimates (Abubakari, 2023; Dickinson et al., 2023; Grace Carvalho Fernandes et al., 2023; Vedhanayagam et al., 2026).

Authors repeatedly identify key evidence gaps that constrain confident conclusions: (a) empirical measurement of how extensively LLMs/generative AI are used in live scams and whether they operate end‑to‑end, (b) real‑world validation of detection systems with platform and private‑message data, and (c) field‑tested deepfake‑detection and platform mitigation strategies that preserve privacy and legal rights (Cross, 2022b; Dominguez Castillo, 2026; Rabby & Chowdory, 2024; Sorell & Whitty, 2019; Vedhanayagam et al., 2026).

Recommended future directions supported in the evidence include: developing living evidence syntheses and real-time collaboration with forensic analysts to keep pace with evolving tactics and laundering technologies; investing in native-language datasets and addressing platform moderation gaps that may limit AI-driven detection; acknowledging that dynamic analysis of private conversation content raises privacy concerns; and encouraging researchers and civil-society actors to produce comprehensive, technology-focused analyses to establish scale and guide anti-trafficking initiatives (Amirkhani et al., 2026; Dickerson et al., 2020; Gujarathi et al., 2026; Luong & Ngo, 2024).

Reported experimental evaluations of the prototype logistic‑regression classifier achieved 85% accuracy, 88% precision, 80% recall, and an F1 score of 0.84. The authors note that algorithm effectiveness and accuracy depend heavily on the quality and relevance of input data. Inter-annotator agreement was very high across identifier categories (Cohen’s κ: wallet addresses 0.978, platform URLs 0.988, loss amounts 0.969). The authors also invite NGOs, civil‑society organizations, and academics to provide comprehensive analyses—particularly on technology-related issues—to help establish scale and guide anti-trafficking initiatives (Ko et al., 2026; Luong & Ngo, 2024; Vedhanayagam et al., 2026).

Related-work reviews characterize romance-scam research as limited, fragmented, and inconsistent because victim–scammer data are not readily available. Future interdisciplinary research should develop detection profiles from recognisable scammer strategies, jurisdictions, grooming stages, communication patterns, and payment patterns (Sorell & Whitty, 2019; Vedhanayagam et al., 2026).

References

This AI-assisted synthesis is based on reviewed evidence records. It may contain errors or omissions. Follow the publication and DOI links, consult the original works, and make your own judgment about the evidence.

Revision history

  1. Version 78

    Current public version

    Incremental evidence update. A small revision is required to claim 19 because two cited dataset limitations have been removed. Remove those citations and narrow any dependence on synthetic benchmarks, label validity, or platform metadata to what retained evidence actually supports. The added convicted-case excerpts support fabricated identities but do not establish AI use, automation, or population prevalence. The corrected excerpt on changing scam scenarios supports the existing emphasis on evo...

    • Publications: 42 (-1)
    • Evidence statements: 152 (-11)
    • Cited sources: 42 (-1)

    Sources removed: Synthetic Dialogue Dataset for Romance Scam Detection.

  2. Version 77

    Automated claim-level support repair round 2, correcting 1 passage from synthesis version 76.

  3. Version 76

    Automated claim-level support repair round 1, correcting 4 passages from synthesis version 75.

View full revision history

Looking for reporting or support information? Visit the RSRC resource list. RSRC does not provide direct support.

Request a correction