Skip to main content
Staff Training Won't Stop Scam-Coached CustomersFraud Typologies
4 min readFor Fraud Risk Managers

Staff Training Won't Stop Scam-Coached Customers

The Conventional Wisdom

When ANZ warned about the rise in scam-coaching, where criminals provide victims with scripts to deceive bank security measures, the industry's immediate response was predictable: enhance staff training programs. Train tellers to spot coached responses. Teach call center agents to recognize scripted language. Build better detection frameworks for unusual customer behavior.

This is the standard approach. A social engineering threat emerges, and the solution is to train humans to counter it.

Why This Approach Falls Short

Here's the problem: you're asking frontline staff to make real-time judgments about whether their customer is lying, confused, or being manipulated by a criminal with a script. That's not a training gap. It's an impossible position.

Consider what scam-coaching actually involves. The fraudster rehearses the victim on exactly what questions your fraud team will ask. They provide plausible answers for questions like "Why are you transferring $15,000 today?" They coach the customer to sound natural, not nervous. They tell them how to respond when asked, "Is anyone helping you with this transaction?"

Your staff member has maybe 90 seconds to decide: Is this customer genuinely buying a car from a private seller, or are they reading from a script while a criminal watches?

The conventional approach assumes staff can reliably detect deception during routine transactions. But deception detection is notoriously unreliable, even for trained interrogators. Studies consistently show that humans perform barely better than chance at identifying lies in real-time interactions. Your teller isn't going to outperform that baseline while processing a queue of waiting customers.

The Evidence

The scam-coaching tactic works because it exploits the limitations of human-dependent controls. When your primary defense is "train staff to notice something feels off," you're building security on intuition and pattern recognition that criminals can study and defeat.

In a coached scenario, the victim believes they're protecting their money or helping law enforcement. Their stress responses are genuine because they think the threat is real. The fraudster has already tested the script, refined the story, and prepared responses for your standard questions. They've optimized their approach based on previous attempts.

Meanwhile, your staff member is trying to balance fraud prevention with customer service and regulatory compliance with transaction speed. They're making judgment calls on incomplete information while the customer, who genuinely believes the cover story, provides consistent, rehearsed answers.

This isn't a training problem. It's a structural vulnerability in any security model that depends on human judgment during active manipulation.

What to Do Instead

Move the decision point away from the coached interaction. Your controls need to trigger before the customer reaches the script-reading phase or operate independently of what the customer says.

Implement mandatory cooling-off periods for high-risk transaction patterns. If a customer wants to transfer funds to a new payee they've never used before, especially for amounts above normal patterns, the transaction doesn't complete same-day regardless of their explanation. You're not asking staff to judge credibility. You're enforcing a structural delay that breaks the fraudster's time pressure.

Deploy behavioral analytics that flag deviation from established patterns, not suspicious answers to questions. Track: Is this the first time this customer has logged in from a new device today? Did they add a new payee 20 minutes ago? Are they attempting a transaction size 10 times their normal activity? These signals exist independent of what the customer says when asked about them.

Create automated friction for coached scenarios. When multiple risk indicators align (new payee, large amount, recent account access from a new device), require out-of-band verification that can't be coached in real-time. Send a verification code to the registered phone number with a 15-minute delay. Require in-person verification at a branch with ID. These controls don't depend on staff detecting deception.

Separate the authorization decision from the customer interaction. Your fraud team reviews flagged transactions asynchronously, with access to full account history, device fingerprints, and time to analyze patterns. They're not making snap judgments while the customer waits. They can see if this "car purchase" follows a pattern matching known scam typologies, check if the payee account has received similar transfers from other victims, and consult watchlists without time pressure.

When Staff Training Matters

Staff training is important, but not for real-time deception detection. Train your team to recognize situations that require additional controls, not to judge whether customers are lying.

Effective training focuses on identifying transaction patterns that warrant mandatory delays, knowing which scenarios require escalation regardless of the customer's explanation, and understanding that a plausible story doesn't override risk indicators.

Your staff should know that "I'm buying a car from someone I met online" triggers specific protocols, not because that statement is inherently suspicious, but because that transaction type appears in known fraud patterns. The response isn't "do they seem trustworthy?" It's "this transaction type requires these controls."

Training also matters for recognizing overt red flags: customers who appear to be reading from notes, who ask to use the phone during the transaction, who become defensive when standard security questions are asked, or who explicitly mention they're working with "law enforcement" or "bank security" on the phone. These aren't subtle deception cues. They're observable behaviors that should trigger immediate escalation.

But if your primary defense against scam-coaching is hoping staff will intuitively sense something's wrong during a coached interaction, you're giving fraudsters exactly the vulnerability they're designed to exploit. Build controls that work even when the customer delivers a perfect performance.

Social Engineering Attacks

You Might Also Like