Skip to main content
24.1 Million Scam Victims, Zero Shared TaxonomyFraud Typologies
4 min readFor Fraud Risk Managers

24.1 Million Scam Victims, Zero Shared Taxonomy

The Growing Threat

In 2023, scams surpassed traditional identity fraud as the leading consumer fraud threat in the U.S. While 15 million Americans fell victim to identity fraud, 24.1 million were scammed. Despite this increase, there hasn't been a corresponding rise in defenses or standardized response protocols.

This isn't about a breach or system failure. The issue is structural: U.S. financial institutions lack a unified framework to categorize, track, or share intelligence about scams. When consumers report scams to the FTC, their bank, local law enforcement, or the IC3 Internet Crime Complaint Center, these reports remain disconnected. Each entity holds an incomplete view.

The Javelin Strategy & Research report identified over 16 distinct scam categories, noting that the list wasn't exhaustive. Without shared terminology, one institution's "romance scam" might be another's "impersonation fraud." This inconsistency makes recognizing patterns across institutions impossible.

Scam Trends Over Time

2020-2021: Scams surged during the pandemic as consumers turned to online shopping and social media. Digital channels became primary targets for both legitimate commerce and social engineering attacks.

2022-2023: Scam volumes dipped slightly as in-person activities resumed, but victim numbers stayed high. Some victims responded by closing accounts or avoiding digital banking.

2023: The Federal Reserve introduced the ScamClassifier Model, a voluntary framework for documenting scams and fraud trends. However, adoption is optional, and data sharing is limited.

Missing Controls

Lack of mandatory scam reporting standards. Unlike Suspicious Activity Reports (SARs) under the Bank Secrecy Act (BSA), scam incidents aren't required to be reported. Institutions decide whether to track, categorize, and share scam data.

No cross-institutional threat intelligence sharing. Institutions that track scams often don't share data with competitors. Proprietary concerns hinder collective defense, leading to uncoordinated responses to scam waves.

Insufficient real-time scam detection controls. Many institutions can't flag and block fraudulent transactions before settlement. Once a consumer authorizes a payment under false pretenses, the transaction proceeds normally. Post-settlement investigations rarely recover funds.

No standardized scam taxonomy. Without shared terminology, institutions can't aggregate threat intelligence effectively. Your "investment scam" might be another's "impersonation fraud" or "cryptocurrency fraud."

Inadequate consumer education frameworks. Without knowing which scams affect their customers most, institutions can't target education efforts effectively. Generic warnings don't address specific social engineering tactics.

Regulatory Gaps

The problem is clear: current standards don't address scams effectively.

The BSA requires SARs for suspicious transactions indicating money laundering or other crimes. Scams, where consumers authorize transactions under false pretenses, often don't meet SAR thresholds because the transactions aren't structurally suspicious.

PCI DSS focuses on cardholder data protection, not on authorized transactions initiated through social engineering. The consumer willingly provides card details, so no Account Data Compromise occurs.

FATF Recommendations require risk-based AML/CFT controls, but scam transactions typically involve the account holder's funds moving to an external party, appearing legitimate from a KYC perspective.

The Federal Reserve's ScamClassifier Model is voluntary, not regulatory. Institutions can choose to adopt it or not.

This regulatory gap explains why 24.1 million victims haven't triggered a coordinated response. No standard mandates action.

Action Items for Your Team

Implement an internal scam taxonomy now. Don't wait for regulatory mandates. Adopt the ScamClassifier Model or create your own system. Document every scam report consistently to allocate your fraud detection budget effectively.

Separate scam reports from fraud losses. Fraud loss metrics capture unauthorized transactions. Scams are authorized under false pretenses. Track victim reports even if you don't reimburse them.

Develop real-time scam detection rules. While you can't prevent consumers from authorizing payments, you can flag high-risk patterns: sudden large transfers to new payees, payments to known scam-linked accounts, or transactions following impersonation attempts. Block these before settlement.

Join information-sharing networks. Collaborate with competitors. The same scam ring can target multiple institutions simultaneously. Share threat intelligence to avoid blind spots. Consider joining industry ISACs or regional fraud networks.

Pressure your core banking vendor. If your system can't handle scam intelligence feeds or flag social engineering patterns, you're using outdated tools. Make scam detection a priority in vendor selection.

Educate based on your threat profile. Once you track scam categories consistently, you'll identify which types affect your customers most. Tailor your education efforts accordingly.

Advocate for mandatory reporting standards. The voluntary approach isn't working. Support efforts to establish scam reporting requirements similar to SAR obligations. You can't solve a problem you don't measure.

The 24.1 million victim count will grow unless financial institutions take scam defense as seriously as fraud prevention. Standardized taxonomy, shared intelligence, and real-time controls are essential. Start today by picking a taxonomy, logging every scam report, and sharing your findings. Don't wait for regulators to act after the numbers double.

You Might Also Like