85% of People Can't Tell Scams From Reality Any More — Up 19 Points in a Year
A Malwarebytes survey of 1,500 adults out today finds 88% struggle to tell what's real online — and the share who can't distinguish scams from genuine content jumped from 66% to 85% in twelve months. 'Spot the fake' has hit its ceiling.
- 0188% of people now say they struggle to tell what's real online, per a Malwarebytes survey of 1,500 adults across the US, UK, Germany, Austria and Switzerland, released 11 June.
- 0285% say scams are now hard to distinguish from the real thing — up from 66% a year ago. A 19-point jump in twelve months.
- 03Context: the FBI puts US losses to AI-powered scams at nearly $900M, with documented scam operations running live deepfake video calls and one network spanning 15,500 domains.
- 04'Spot the fake' education has hit its ceiling — the burden is shifting to provenance infrastructure (visible content credentials) and liability law.
- 05The deeper shift: the web is moving from assuming content is real unless flagged, to requiring authenticity to be proven.

The most important AI statistic of the week isn't a benchmark score. It's this: 88% of people now say they struggle to tell what's real online — and the number is getting worse, fast.
That's the headline finding of a survey released today by security firm Malwarebytes, which polled 1,500 adults across the US, UK, Germany, Austria and Switzerland. The detail that should worry policymakers most: 85% say it has become hard to tell scams apart from the real thing — up from 66% just a year ago. A nineteen-point jump in twelve months.
What changed
Nothing about people. Everything about the tools.
A year ago, most AI-generated scam content had tells — uncanny faces, stilted writing, video that fell apart on a second look. The generation of tools that shipped over the past year removed most of them. Voice cloning is now real-time and accent-faithful; video generation handles the eye contact and lip-sync that used to give deepfakes away; and large language models write phishing emails with better grammar than most legitimate corporate mail.
The result is an arms race the defenders are visibly losing. The FBI's recent figures put American losses to AI-powered scams at nearly $900 million — and that's only what gets reported. Earlier this year, investigators documented scam operations hiring so-called "AI models" — cloned personas — to close victims in live deepfake video calls, and a single AI-driven investment-scam network spanning 15,500 domains.
Why this is a policy story, not a tech story
The instinct is to treat this as a consumer-awareness problem: teach people the tells. But the survey's trajectory says the opposite — the tells are disappearing faster than people can learn them. When 85% of the population says they can't reliably distinguish synthetic from real, "spot the fake" education has hit its ceiling.
That shifts the burden to two places:
Provenance infrastructure. Content credentials (C2PA and similar) that cryptographically mark where media came from — supported in principle by the big platforms and AI labs, deployed in practice almost nowhere a consumer would notice. Surveys like this one are the strongest argument yet for making provenance visible by default, not buried in metadata.
Liability and regulation. If individuals can't tell real from fake, the legal question becomes who pays when they're deceived — the platform that delivered the deepfake, the AI company whose model made it, or no one. Courts and legislatures are starting to answer that question (a German court just held Google liable for AI-generated claims its systems produced; a federal AI framework is in discussion draft in Washington). Expect numbers like Malwarebytes' to be cited in every one of those debates.
The honest takeaway
There's a version of this story that's pure alarm, and it should be resisted: most online content is still real, most transactions still complete safely, and "98% can't tell" headlines often measure self-reported confidence, not tested ability. People may be better at spotting fakes than they believe — or worse.
But the direction of travel is not in dispute, and it's the same one every serious institution is now planning around: authenticity is becoming something that has to be proven, not assumed. The web spent thirty years assuming what you saw was real unless flagged. The next thirty will work the other way around.
Ask Relay — he reads every question himself and replies personally by email.
