Scams, money mules, and social engineering
Recognize deception across both the sender and receiver journeys.
The customer completed the authentication challenge correctly. They also sent their savings to an impersonator. The system verified the button press and missed the story behind it. Scam controls need to consider intent, destination, and the receiving network.
Separate unauthorized access from deception
Interrupt the story at the right moment
A warning works best when it addresses the action in progress. A generic fraud paragraph becomes background noise. A destination-change warning can explain that a real bank will not need a transfer to a supposed safe account. Keep messages clear and test comprehension.
Avoid revealing exact detection thresholds or implying that the customer caused the problem. Offer a safe pause and a verified support route. Measure completed safe resolutions, not only how many warnings were displayed. A customer who clicks through a warning may be confused, rushed, or under pressure; clicks alone do not prove informed understanding.
- Detect contextRecognize a relevant payment pattern
- Warn clearlyExplain the specific concern
- Provide exitOffer verified help and a pause
- Impressions
- Warnings shown
- Comprehension
- Users understand and can act safely
Warning evaluation
Illustrative data; not a real customer record or a prescribed policy.
- Shown1000
Exposure to the message
- Help used80
Possible safe intervention
- Confirmed understandingsampled
Separate evaluation measure
A visible message may still be ineffective
Test warning comprehension and safe exits. A visible message may still be ineffective.
- Failure mode 1avoid
- Count display volume as prevented fraud. Exposure is not an outcome.
- Failure mode 2avoid
- Expose exact rule thresholds. That needlessly reveals control boundaries.
- Failure mode 3avoid
- Use accusatory language. It can reduce cooperation and useful reporting.
Investigate receiver behavior
A receiving account can be used to move proceeds onward. Look at the relation between incoming funds, account history, outgoing destinations, and the stated purpose. A sudden rise in activity can have an honest explanation, such as a successful fundraiser.
Use the pattern to select a review, not to declare a person guilty. Preserve the transaction chain and seek relevant context through approved channels. Restrictions should have a legal and policy basis, a scope, and an owner. Do not assume all incoming funds have the same origin merely because one payment is disputed.
Receiver analysis requires care because a fast movement of money can serve many purposes. A marketplace seller, a payroll business, and a suspected mule account can all receive and forward funds. Compare the activity with the declared business, connected accounts, timing, and other reliable evidence. Do not turn one shared device or one unusual transfer into a conclusion about criminal intent. The investigation should preserve alternative explanations and identify the facts that would distinguish them.
- InflowObserve source and timing
- ContextCompare with account purpose
- OutflowTrace linked movement and evidence
- Rapid turnover
- Potential investigation signal
- Illicit proceeds
- Conclusion requiring supporting evidence
Receiver review
Illustrative data; not a real customer record or a prescribed policy.
- Prior activitylow volume
Baseline
- New creditsseveral unrelated senders
Pattern change
- Explanationunverified fundraiser
Plausible claim to test
Unusual movement is a lead rather than proof
Review the pattern with customer context. Unusual movement is a lead rather than proof.
- Failure mode 1avoid
- Label every fast transfer laundering. Speed alone is insufficient.
- Failure mode 2avoid
- Ignore the stated purpose. Context can distinguish legitimate activity.
- Failure mode 3avoid
- Assume all funds are tainted. Different inflows may have different evidence.
Connect fraud and AML without collapsing them
Fraud teams often focus on immediate loss and customer protection. AML teams examine suspicious activity and applicable reporting duties. Shared evidence can help both, but their decisions and access rules differ. A fraud refund does not automatically close an AML concern.
Create a controlled referral that carries transaction references, observed facts, and confidence levels. Keep protected reporting information out of general support tools. Track acknowledgment and ownership so the referral is not lost between queues. Each team should record its own conclusion under the relevant policy rather than inherit another team’s label as a legal determination.
- Fraud caseCollect loss and deception facts
- ReferralShare permitted evidence
- AML reviewApply the separate investigative duty
- Customer remediation
- Addresses the customer impact
- AML disposition
- Addresses suspicious-activity obligations
Cross-team referral
Illustrative data; not a real customer record or a prescribed policy.
- Factslinked transactions
Shared evidence
- Refundcompleted
Customer remedy only
- AML statusrestricted
Separate controlled record
The objectives and confidentiality rules differ
Keep distinct decisions with a controlled referral. The objectives and confidentiality rules differ.
- Failure mode 1avoid
- Close AML automatically after refund. Remediation does not resolve every suspicion.
- Failure mode 2avoid
- Copy protected reporting status into support. Access must respect confidentiality.
- Failure mode 3avoid
- Send an unowned email. The handoff needs acknowledgment and responsibility.
Build a compassionate incident intake
Scam victims may feel fear or shame. A clear intake helps gather better evidence and reduces repeated explanations. Record the timeline, destination, communications, and remaining account access. Separate immediate containment from later investigation.
Support should know how to protect credentials, escalate a recovery request, and preserve evidence without promising outcomes it cannot control. Use a single case reference across teams. Measure time to a useful first action and the quality of updates. A fast automated acknowledgment is not the same as contacting the right payment partner.
- ListenCapture the event without blame
- ContainAddress ongoing access and transfers
- CoordinateUse one case and clear updates
- Acknowledgment
- Confirms receipt of a report
- Useful action
- Changes exposure or starts the right process
Incident intake
Illustrative data; not a real customer record or a prescribed policy.
- Casescam-42
Shared reference
- Accessstill active
Containment concern
- Partner escalationpending
Needs an accountable owner
Each has a different immediate purpose
Separate containment recovery and investigation. Each has a different immediate purpose.
- Failure mode 1avoid
- Promise all funds will return. Recovery may be uncertain.
- Failure mode 2avoid
- Make the customer retell the story to each team. That adds friction and inconsistent records.
- Failure mode 3avoid
- Close after an automated acknowledgment. The substantive work remains.
Chapter connections
This chapter builds on Transaction risk and decision economics. Continue with First-party misuse, merchant abuse, and feedback to follow the next part of the system. Use the glossary for terminology and risk mathematics for formulas and worked calculations.