2. Fraud landscape and measurement
- Unauthorized fraud (third party uses your credentials/card) vs. authorized push payment (APP) fraud (you are tricked into sending) vs. first-party fraud (customer misrepresentation, friendly fraud) vs. synthetic identity fraud vs. insider fraud
- Loss by rail and product (cards, ACH, wires, checks, P2P, instant payments, crypto conversion as exit)
- Loss by age group and contact method (FTC data — verify; older adults' higher median losses)
- Scam economy: organized crime, scam compounds in Southeast Asia with trafficked workers (UNODC reports — verify), U.S. Treasury/OFAC sanctions on scam networks (verify, e.g., 2025 designations), crypto laundering routes
- Measurement problems: underreporting, double counting, definitional differences across countries
3. Scam typology library (profile each)
For each: how it works (recognition level), typical channel, payment method demanded, victims most affected, official red flags, what to do, reimbursement prospects by jurisdiction, notable cases, and source.
- Bank impersonation ("fraud department" calls/texts, spoofed caller ID)
- P2P "accidental payment" and fake payment-confirmation scams
- Marketplace buyer/seller scams (overpayment, fake shipping)
- Romance scams
- Pig-butchering/investment confidence scams
- Fake investment platforms and "finfluencer" pump schemes
- Tech support and refund scams
- Government impersonation (IRS, HMRC, SSA)
- Toll/delivery smishing (e.g., unpaid toll texts wave — verify FBI/FTC alerts)
- Job and task scams ("paid to like videos")
- Rental and real-estate wire fraud
- Business email compromise and vendor invoice redirection
- CEO/CFO deepfake video/voice calls (e.g., Arup Hong Kong case, 2024, reported ~US$25M — verify)
- Grandparent/family emergency scams with voice cloning
- Account takeover via SIM swap and port-out fraud
- OTP interception/relay (social engineering for codes)
- Remote-access software scams
- Check washing and mail theft
- Money mule recruitment (including students and job seekers)
- Crypto ATM/kiosk scams (state kiosk laws — verify)
- Loan and debt-relief scams (advance fees)
- Fake fintech apps and cloned websites
- Charity and disaster scams
- Sextortion demanding payment (handle sensitively; link to support resources)
- "Infinite money glitch" style check-kiting trends on social media (Chase, 2024 — verify) — framed as fraud with legal consequences
4. Reimbursement and liability by jurisdiction
4.1 United States
- Regulation E: unauthorized EFTs, consumer liability tiers ($50/$500/unlimited timing rules — verify), error resolution timelines; the authorized-transfer gap for scams
- Regulation Z for credit cards
- Zelle: bank network reimbursement policy for imposter scams (2023 — verify scope), Senate reports (verify), CFPB lawsuit against Early Warning Services, JPMorgan, Bank of America, Wells Fargo (December 2024) and dismissal (March 2025 — verify), New York AG lawsuit (2025 — verify), state legislation on P2P reimbursement (verify)
- Cash App/Block enforcement (CFPB and state regulators, January 2025 — verify amounts and findings)
- UCC Article 4A for wires; check fraud liability under UCC Articles 3 and 4
- Elder financial exploitation: Senior Safe Act, FINRA Rule 2165 holds, state APS reporting, bank trusted-contact practices
4.2 United Kingdom
- PSR APP mandatory reimbursement (October 7, 2024; cap £85,000; consumer standard of caution; excess — verify), CRM Code history, PSR data on reimbursement rates by firm (verify), Financial Ombudsman Service role, 2025–2026 reviews (verify)
- Confirmation of Payee coverage; delayed-payment powers for suspected fraud (Payment Services (Amendment) Regulations 2024 — verify)
- Online Safety Act fraudulent advertising duties (verify implementation)
4.3 European Union
- PSD2 unauthorized transaction refunds; gross negligence standard
- PSR/PSD3 provisions on bank-impersonation spoofing refunds and platform cooperation (verify final text)
- Verification of Payee under Instant Payments Regulation (link to Part 03)
4.4 Australia, Singapore, India, Brazil
- Australia: Scams Prevention Framework Act (2025 — verify), sector codes for banks, telcos, digital platforms; ACCC National Anti-Scam Centre; Scam-Safe Accord (verify)
- Singapore: Shared Responsibility Framework (December 2024 — verify), anti-scam account restrictions, Protection from Scams Act (verify)
- India: RBI customer liability framework for unauthorized electronic transactions (2017); cyber fraud reporting (1930 helpline, Sanchar Saathi — verify); UPI fraud measures
- Brazil: Pix MED/MED 2.0 (link to Part 03)
5. Account security
5.1 Authentication
- Passwords, SMS OTP, email OTP, authenticator apps (TOTP), push approvals (and MFA fatigue), hardware keys, passkeys (FIDO2/WebAuthn, synced vs. device-bound)
- NIST SP 800-63-4 Digital Identity Guidelines (final 2025 — verify) positions on SMS (restricted authenticator), phishing-resistant authenticators
- FFIEC Authentication and Access to Financial Institution Services and Systems guidance (August 2021)
- Bank and fintech passkey adoption (verify deployments; label announcements)
- UAE and India moves away from SMS OTP (verify, e.g., UAE Central Bank directive; RBI authentication framework 2025–2026 — verify)
- Behavioral biometrics and device binding
5.2 SIM swap and telecom
- FCC rules on SIM swap and port-out fraud (adopted November 2023; effective July 2024 — verify), carrier account PINs and number-lock features
- UK Ofcom and other regulators (verify)
5.3 Consumer security baseline (to produce)
- Unique passwords with a password manager; passkeys where available
- Phishing-resistant MFA over SMS where offered
- Carrier port-out protection
- Credit freezes at all three bureaus (free under 2018 law), ChexSystems freeze
- Account alerts and card controls
- Device updates and app-store-only installs
- Never share OTPs; bank will not ask for them
- Trusted contacts for older relatives
6. Identity verification, KYC/KYB, and AML
6.1 Concepts
- CIP/KYC/CDD/EDD; beneficial ownership (FinCEN CDD Rule; Corporate Transparency Act BOI reporting narrowed to foreign companies in March 2025 — verify)
- Document verification, selfie/liveness, database checks, eCBSV (SSA electronic Consent Based SSN Verification), device and behavioral signals, reusable/portable identity, mobile driver's licenses and digital identity wallets (link to Part 11)
- Deepfake injection attacks against liveness checks (FinCEN alert on deepfake media, November 2024 — verify); document-forgery with generative AI
- Synthetic identity fraud: Federal Reserve synthetic identity toolkit and definitions (verify)
- AML transaction monitoring, SAR filing, sanctions screening (OFAC), Travel Rule for virtual assets
- FinCEN AML/CFT program rule proposal (2024) and status (verify); FinCEN investment adviser AML rule (effective date postponed to 2028 — verify)
- De-risking/debanking consequences of KYC failures and appeals
6.2 Vendor landscape (seed list — verify)
Identity/KYC: Socure (acquired Effectiv, Qlarifi — verify), Alloy, Persona, Jumio, Onfido/Entrust, Veriff, Incode, Trulioo, Au10tix, Prove, Mitek, Plaid IDV, Stripe Identity, ID.me, CLEAR, Middesk (KYB), Sumsub, Signzy (India), idwall (Brazil)
Fraud/AML: Sardine, Sift, Forter, Riskified, Signifyd, Feedzai, Featurespace (Visa), BioCatch, Unit21, Hummingbird, Hawk, ComplyAdvantage, Oscilar, Kount (Equifax), NICE Actimize, SAS, Quantexa, ThetaRay, Chainalysis/TRM Labs/Elliptic (crypto tracing context)
Consortium and network tools: Early Warning (Zelle risk), Visa/Mastercard scam-disruption and account-to-account protection tools (verify, e.g., Mastercard Consumer Fraud Risk in UK), UK Finance intelligence sharing, Australia Fraud Reporting Exchange (verify), cross-industry Tech Against Scams coalitions (verify)
6.3 Vendor evaluation protocol
- Documented detection claims and methodology; independent testing (e.g., NIST FATE/FRTE for face and liveness — verify program names; iBeta/ISO 30107-3 presentation attack detection certifications)
- Bias testing across demographic groups (NIST results)
- False-positive and customer-friction impacts
- Data retention, biometric privacy law compliance (Illinois BIPA litigation — verify cases)
- Explainability and audit trails for SAR decisions
7. Institutional security standards
- PCI DSS v4.0/4.0.1 with future-dated requirements effective March 31, 2025 (verify); scope reduction via tokenization
- SOC 2, ISO 27001
- NIST Cybersecurity Framework 2.0 (February 2024)
- SEC cybersecurity incident disclosure rules (8-K Item 1.05, December 2023)
- NYDFS Part 500 amendments (2023; phased through November 2025 — verify)
- EU DORA (applied January 17, 2025) including critical ICT third-party provider oversight designations (verify)
- UK operational resilience rules (March 2025 deadline — verify)
- Bank Service Company Act and 36-hour computer-security incident notification rule (2022)
- Third-party/vendor risk (link to Part 04)
- Quantum-safe cryptography planning (NIST PQC standards August 2024; financial-sector migration guidance — verify)
8. Incident database (seed list — verify each)
Arup deepfake transfer (2024); Evolve/LockBit (2024); Patelco ransomware (2024); Finastra (2024); Snowflake-linked thefts (2024); Coinbase insider-bribery data theft and extortion demand (2025); Bybit hack (2025, crypto context and laundering routes); CrowdStrike outage impacts on banks (July 2024); Capital One/other bank outages (verify); Cash App former-employee access (2022); Block BSA and Cash App fraud findings (2025); TD Bank BSA guilty plea (October 2024) for money-laundering failures; Starling and Monzo FCA financial-crime fines (2024–2025); Revolut Lithuania AML fine (2025); Robinhood breach (2021); MGM/Caesars social engineering (context); Change Healthcare (context for payment disruption, 2024); Chase "infinite money glitch" check-kiting wave (2024); Scattered Spider attacks on financial and insurance firms (2025 — verify); others through September 2026.
9. Workflows
Use the master workflow format for:
- Setting up account security on a bank or fintech app (passkeys, MFA, alerts, carrier lock)
- Responding to a fraudulent card transaction
- Responding to an account takeover
- Recognizing and reporting P2P and APP scams (U.S., UK, EU, Australia, India)
- Requesting reimbursement after an APP scam in the UK (step by step, FOS escalation)
- Freezing credit and ChexSystems; placing fraud alerts; using IdentityTheft.gov
- Protecting an older relative (trusted contacts, account alerts, conversation guide)
- Recovering from a SIM swap
- A small business responding to BEC/invoice redirection (recall request, law enforcement, IC3)
- A fintech startup's minimum viable fraud and AML controls (framework-level, not bypass guidance)
10. Timeline 2020–2026
- Pandemic unemployment and PPP fraud (2020–2021)
- FFIEC authentication guidance (2021)
- Zelle scam scrutiny; reimbursement policy; CFPB suit and dismissal; NY AG action
- UK PSR reimbursement regime launch and data releases
- Deepfake fraud milestones; FinCEN deepfake alert
- FCC SIM swap rules
- PCI DSS 4.0 future-dated requirements; DORA application; NIST CSF 2.0 and SP 800-63-4
- Australia SPF and Singapore SRF
- Scam compound sanctions and crackdowns
- Major breaches and outages