A research agenda, not completed reporting. These are the original topic questions and leads. Named companies, dates and outcomes require verification. Editorial operations and internal schemas remain private.

2. Fraud landscape and measurement

  • Unauthorized fraud (third party uses your credentials/card) vs. authorized push payment (APP) fraud (you are tricked into sending) vs. first-party fraud (customer misrepresentation, friendly fraud) vs. synthetic identity fraud vs. insider fraud
  • Loss by rail and product (cards, ACH, wires, checks, P2P, instant payments, crypto conversion as exit)
  • Loss by age group and contact method (FTC data — verify; older adults' higher median losses)
  • Scam economy: organized crime, scam compounds in Southeast Asia with trafficked workers (UNODC reports — verify), U.S. Treasury/OFAC sanctions on scam networks (verify, e.g., 2025 designations), crypto laundering routes
  • Measurement problems: underreporting, double counting, definitional differences across countries

3. Scam typology library (profile each)

For each: how it works (recognition level), typical channel, payment method demanded, victims most affected, official red flags, what to do, reimbursement prospects by jurisdiction, notable cases, and source.

  1. Bank impersonation ("fraud department" calls/texts, spoofed caller ID)
  2. P2P "accidental payment" and fake payment-confirmation scams
  3. Marketplace buyer/seller scams (overpayment, fake shipping)
  4. Romance scams
  5. Pig-butchering/investment confidence scams
  6. Fake investment platforms and "finfluencer" pump schemes
  7. Tech support and refund scams
  8. Government impersonation (IRS, HMRC, SSA)
  9. Toll/delivery smishing (e.g., unpaid toll texts wave — verify FBI/FTC alerts)
  10. Job and task scams ("paid to like videos")
  11. Rental and real-estate wire fraud
  12. Business email compromise and vendor invoice redirection
  13. CEO/CFO deepfake video/voice calls (e.g., Arup Hong Kong case, 2024, reported ~US$25M — verify)
  14. Grandparent/family emergency scams with voice cloning
  15. Account takeover via SIM swap and port-out fraud
  16. OTP interception/relay (social engineering for codes)
  17. Remote-access software scams
  18. Check washing and mail theft
  19. Money mule recruitment (including students and job seekers)
  20. Crypto ATM/kiosk scams (state kiosk laws — verify)
  21. Loan and debt-relief scams (advance fees)
  22. Fake fintech apps and cloned websites
  23. Charity and disaster scams
  24. Sextortion demanding payment (handle sensitively; link to support resources)
  25. "Infinite money glitch" style check-kiting trends on social media (Chase, 2024 — verify) — framed as fraud with legal consequences

4. Reimbursement and liability by jurisdiction

4.1 United States

  • Regulation E: unauthorized EFTs, consumer liability tiers ($50/$500/unlimited timing rules — verify), error resolution timelines; the authorized-transfer gap for scams
  • Regulation Z for credit cards
  • Zelle: bank network reimbursement policy for imposter scams (2023 — verify scope), Senate reports (verify), CFPB lawsuit against Early Warning Services, JPMorgan, Bank of America, Wells Fargo (December 2024) and dismissal (March 2025 — verify), New York AG lawsuit (2025 — verify), state legislation on P2P reimbursement (verify)
  • Cash App/Block enforcement (CFPB and state regulators, January 2025 — verify amounts and findings)
  • UCC Article 4A for wires; check fraud liability under UCC Articles 3 and 4
  • Elder financial exploitation: Senior Safe Act, FINRA Rule 2165 holds, state APS reporting, bank trusted-contact practices

4.2 United Kingdom

  • PSR APP mandatory reimbursement (October 7, 2024; cap £85,000; consumer standard of caution; excess — verify), CRM Code history, PSR data on reimbursement rates by firm (verify), Financial Ombudsman Service role, 2025–2026 reviews (verify)
  • Confirmation of Payee coverage; delayed-payment powers for suspected fraud (Payment Services (Amendment) Regulations 2024 — verify)
  • Online Safety Act fraudulent advertising duties (verify implementation)

4.3 European Union

  • PSD2 unauthorized transaction refunds; gross negligence standard
  • PSR/PSD3 provisions on bank-impersonation spoofing refunds and platform cooperation (verify final text)
  • Verification of Payee under Instant Payments Regulation (link to Part 03)

4.4 Australia, Singapore, India, Brazil

  • Australia: Scams Prevention Framework Act (2025 — verify), sector codes for banks, telcos, digital platforms; ACCC National Anti-Scam Centre; Scam-Safe Accord (verify)
  • Singapore: Shared Responsibility Framework (December 2024 — verify), anti-scam account restrictions, Protection from Scams Act (verify)
  • India: RBI customer liability framework for unauthorized electronic transactions (2017); cyber fraud reporting (1930 helpline, Sanchar Saathi — verify); UPI fraud measures
  • Brazil: Pix MED/MED 2.0 (link to Part 03)

5. Account security

5.1 Authentication

  • Passwords, SMS OTP, email OTP, authenticator apps (TOTP), push approvals (and MFA fatigue), hardware keys, passkeys (FIDO2/WebAuthn, synced vs. device-bound)
  • NIST SP 800-63-4 Digital Identity Guidelines (final 2025 — verify) positions on SMS (restricted authenticator), phishing-resistant authenticators
  • FFIEC Authentication and Access to Financial Institution Services and Systems guidance (August 2021)
  • Bank and fintech passkey adoption (verify deployments; label announcements)
  • UAE and India moves away from SMS OTP (verify, e.g., UAE Central Bank directive; RBI authentication framework 2025–2026 — verify)
  • Behavioral biometrics and device binding

5.2 SIM swap and telecom

  • FCC rules on SIM swap and port-out fraud (adopted November 2023; effective July 2024 — verify), carrier account PINs and number-lock features
  • UK Ofcom and other regulators (verify)

5.3 Consumer security baseline (to produce)

  • Unique passwords with a password manager; passkeys where available
  • Phishing-resistant MFA over SMS where offered
  • Carrier port-out protection
  • Credit freezes at all three bureaus (free under 2018 law), ChexSystems freeze
  • Account alerts and card controls
  • Device updates and app-store-only installs
  • Never share OTPs; bank will not ask for them
  • Trusted contacts for older relatives

6. Identity verification, KYC/KYB, and AML

6.1 Concepts

  • CIP/KYC/CDD/EDD; beneficial ownership (FinCEN CDD Rule; Corporate Transparency Act BOI reporting narrowed to foreign companies in March 2025 — verify)
  • Document verification, selfie/liveness, database checks, eCBSV (SSA electronic Consent Based SSN Verification), device and behavioral signals, reusable/portable identity, mobile driver's licenses and digital identity wallets (link to Part 11)
  • Deepfake injection attacks against liveness checks (FinCEN alert on deepfake media, November 2024 — verify); document-forgery with generative AI
  • Synthetic identity fraud: Federal Reserve synthetic identity toolkit and definitions (verify)
  • AML transaction monitoring, SAR filing, sanctions screening (OFAC), Travel Rule for virtual assets
  • FinCEN AML/CFT program rule proposal (2024) and status (verify); FinCEN investment adviser AML rule (effective date postponed to 2028 — verify)
  • De-risking/debanking consequences of KYC failures and appeals

6.2 Vendor landscape (seed list — verify)

Identity/KYC: Socure (acquired Effectiv, Qlarifi — verify), Alloy, Persona, Jumio, Onfido/Entrust, Veriff, Incode, Trulioo, Au10tix, Prove, Mitek, Plaid IDV, Stripe Identity, ID.me, CLEAR, Middesk (KYB), Sumsub, Signzy (India), idwall (Brazil)

Fraud/AML: Sardine, Sift, Forter, Riskified, Signifyd, Feedzai, Featurespace (Visa), BioCatch, Unit21, Hummingbird, Hawk, ComplyAdvantage, Oscilar, Kount (Equifax), NICE Actimize, SAS, Quantexa, ThetaRay, Chainalysis/TRM Labs/Elliptic (crypto tracing context)

Consortium and network tools: Early Warning (Zelle risk), Visa/Mastercard scam-disruption and account-to-account protection tools (verify, e.g., Mastercard Consumer Fraud Risk in UK), UK Finance intelligence sharing, Australia Fraud Reporting Exchange (verify), cross-industry Tech Against Scams coalitions (verify)

6.3 Vendor evaluation protocol

  • Documented detection claims and methodology; independent testing (e.g., NIST FATE/FRTE for face and liveness — verify program names; iBeta/ISO 30107-3 presentation attack detection certifications)
  • Bias testing across demographic groups (NIST results)
  • False-positive and customer-friction impacts
  • Data retention, biometric privacy law compliance (Illinois BIPA litigation — verify cases)
  • Explainability and audit trails for SAR decisions

7. Institutional security standards

  • PCI DSS v4.0/4.0.1 with future-dated requirements effective March 31, 2025 (verify); scope reduction via tokenization
  • SOC 2, ISO 27001
  • NIST Cybersecurity Framework 2.0 (February 2024)
  • SEC cybersecurity incident disclosure rules (8-K Item 1.05, December 2023)
  • NYDFS Part 500 amendments (2023; phased through November 2025 — verify)
  • EU DORA (applied January 17, 2025) including critical ICT third-party provider oversight designations (verify)
  • UK operational resilience rules (March 2025 deadline — verify)
  • Bank Service Company Act and 36-hour computer-security incident notification rule (2022)
  • Third-party/vendor risk (link to Part 04)
  • Quantum-safe cryptography planning (NIST PQC standards August 2024; financial-sector migration guidance — verify)

8. Incident database (seed list — verify each)

Arup deepfake transfer (2024); Evolve/LockBit (2024); Patelco ransomware (2024); Finastra (2024); Snowflake-linked thefts (2024); Coinbase insider-bribery data theft and extortion demand (2025); Bybit hack (2025, crypto context and laundering routes); CrowdStrike outage impacts on banks (July 2024); Capital One/other bank outages (verify); Cash App former-employee access (2022); Block BSA and Cash App fraud findings (2025); TD Bank BSA guilty plea (October 2024) for money-laundering failures; Starling and Monzo FCA financial-crime fines (2024–2025); Revolut Lithuania AML fine (2025); Robinhood breach (2021); MGM/Caesars social engineering (context); Change Healthcare (context for payment disruption, 2024); Chase "infinite money glitch" check-kiting wave (2024); Scattered Spider attacks on financial and insurance firms (2025 — verify); others through September 2026.


9. Workflows

Use the master workflow format for:

  • Setting up account security on a bank or fintech app (passkeys, MFA, alerts, carrier lock)
  • Responding to a fraudulent card transaction
  • Responding to an account takeover
  • Recognizing and reporting P2P and APP scams (U.S., UK, EU, Australia, India)
  • Requesting reimbursement after an APP scam in the UK (step by step, FOS escalation)
  • Freezing credit and ChexSystems; placing fraud alerts; using IdentityTheft.gov
  • Protecting an older relative (trusted contacts, account alerts, conversation guide)
  • Recovering from a SIM swap
  • A small business responding to BEC/invoice redirection (recall request, law enforcement, IC3)
  • A fintech startup's minimum viable fraud and AML controls (framework-level, not bypass guidance)

10. Timeline 2020–2026

  • Pandemic unemployment and PPP fraud (2020–2021)
  • FFIEC authentication guidance (2021)
  • Zelle scam scrutiny; reimbursement policy; CFPB suit and dismissal; NY AG action
  • UK PSR reimbursement regime launch and data releases
  • Deepfake fraud milestones; FinCEN deepfake alert
  • FCC SIM swap rules
  • PCI DSS 4.0 future-dated requirements; DORA application; NIST CSF 2.0 and SP 800-63-4
  • Australia SPF and Singapore SRF
  • Scam compound sanctions and crackdowns
  • Major breaches and outages