Mirela Ciobanu
01 Oct 2026 / 5 Min Read
As scam losses top USD 1 trillion globally, banks are quietly reimbursing victims even where regulation doesn't require it - a reputational fix, not a systemic one. Trace Fooshée makes the case for a ‘polluter pays’ model that holds telecoms, tech, and social platforms accountable too.
There is greater alignment across the financial services, telecommunications, and technology industries than ever before in terms of acknowledging the systemic nature of the scam threat. It’s also true that important steps have been taken to mobilise efforts within and across industries to develop and deploy countermeasures that seek to bolster consumer protections against scams. While each industry has agreed to shoulder some degree of the costs of the countermeasures that they choose to deploy, most observers of this threat would agree that the distribution of these costs is not even, nor are these costs proportional to the role that a company’s services play in enabling scams. Nowhere is this more evident than it is when considering who should bear the lion’s share of the burden of reimbursement liability.
Putting aside the argument over whether or not victims should be reimbursed for rhetorical purposes and assuming that in at least some cases, scam victims should be reimbursed for scam losses, most outside of the financial services industry are quick to suggest that FIs should bear the burden of such a liability. On the surface, the rationale seems reasonable and based on well established patterns of existing dispute resolution frameworks that place the liability for reimbursement for disputed payments on the company (usually an FI) responsible for executing the payment on behalf of the consumer. On close inspection, however, there are very specific provisions in these laws that were deliberately designed to distinguish between an ‘authorised payment’ and an ‘unauthorised payment’. The purpose of the clauses is to acknowledge the limits of an FI’s ability to strike a ‘commercially reasonable’ balance between fraud prevention and payment system usability.
Managing fraud risk is a balancing act between loss mitigation, client experience, and capital and operating costs (compliance also factors in, but unlike the other objectives, compliance is binary). You can dial down losses all the way to zero, but it’s unlikely to result in a pleasant client experience or for such an effort to come without substantial capital and operating costs. The clauses in the Uniform Commercial Code (UCC) and Electronic Funds Transfer Act (EFTA) in the US market that exempt FIs from reimbursement liability exist as an acknowledgement that if FIs were to be held liable for reimbursement for ‘authorised payment’ fraud (scams), then it would result in some combination of significant increases in costs for consumers resulting from the distribution of increases in reimbursement liabilities and in a degradation in service quality resulting from an inadequate capacity to accurately detect and prevent scam attacks.
Many in the financial services industry also observe that whether or not these outcomes become manifest, obligating FIs with reimbursement liability would do little to nothing in terms of influencing the existence, persistence, and pervasiveness of the problem. It would, in other words, simply provide a means of underwriting criminal activity which would do nothing to discourage criminality or to incentivise vigilance and accountability that consumers, social media, telecommunications, and technology companies should reasonably be expected to exercise in the presence of such threats.
This rationale, or something similar, guided Australia’s national approach to mobilising efforts to combat scams. In lieu of an approach popularised by the Payment Systems Regulator (PSR) in the UK market that places the totality of reimbursement obligation at the feet of the financial services industry, the Australian approach is based on what one observer refers to as a ‘polluter pays’ model. If, in the course of the forensic investigation of a scam dispute, an Australian FI discovers that the scam was made possible by an advertisement posted on a particular social media platform, then the company that owns the platform may be held liable for at least a portion of the reimbursement amount under the Australian program. While the details of how such a system are still being worked out and are generally expected to be complicated, the Australian anti-scam program has been designed from the ground up to be one that holds the whole of the ecosystem accountable for facilitating criminal activity is as inspirational as it is reasonable.
For most of the history of financial crime, authorised payment fraud - scams - occupied a peculiar blind spot in how financial institutions (FIs) managed risk. Unlike account takeover or card fraud, scams succeed not by compromising a system or stealing credentials but by convincing victims to willingly authorise the very transactions they later dispute. Because the customer technically approved the payment, most FIs have historically treated the resulting claims as outside the boundaries of their reimbursement obligations. That posture was defensible when scam volumes were modest, and the affected population was small enough to remain below the threshold of public attention.
That threshold has now been crossed decisively. The Global Anti-Scam Alliance estimates that global scam losses exceeded USD 1.03 trillion in 2024. In the United States and most other markets, no regulatory mandate compels FIs to reimburse scam victims - but the accumulation of victims has grown large and visible enough to attract sustained attention from news media, consumer advocates, legislators, and, increasingly, the C-suites and boardrooms of financial institutions themselves. The reputational arithmetic has shifted: being known as an institution that routinely denies claims from victims of sophisticated deception is no longer a cost-free posture.
The market pressure this has created is reflected in the data. Datos Insights' research shows that the share of fraud executives reporting that their institutions do not reimburse scam victims fell from 10% in 2024 to just 3% in 2025 - not because of a regulatory mandate, but because FIs are recalibrating their tolerance for the reputational risks that come with a policy of blanket denial. That recalibration, however, creates its own challenge: if FIs are going to absorb more of the financial consequences of successful scam attacks, they have a far more urgent incentive to prevent those attacks from succeeding in the first place.
The growing urgency around scam risk is forcing fraud leaders to confront an uncomfortable reality: the control frameworks that FIs have built and refined over decades to detect and prevent conventional fraud are poorly suited to the unique mechanics of authorised payment fraud. Conventional fraud controls are engineered to detect the fingerprints of unauthorised activity such as account takeovers and other forms of third-party fraud like check fraud. Scams, by design, leave few of those fingerprints. The customer is present, authenticated, and acting voluntarily, even if that volition has been manufactured through deception.
This distinction has profound implications for how FIs must organise their response. Effective scam risk management requires capabilities that span the full customer journey - from proactive education that reduces susceptibility before an attack occurs, to real-time behavioural analytics that can detect the behavioural signatures of a customer being coached through a fraudulent transaction, to specialised interdiction techniques designed to break the psychological hold a scammer has established over a victim, to inbound detection that identifies when an institution's own accounts are being used to receive and move illicit proceeds. No single capability is sufficient on its own, and most of these capabilities require coordination across organisational functions that have rarely worked together in conventional fraud programs.
For most FIs, formalised scam risk management programs are genuinely new territory. Institutions have always maintained procedures for handling customer disputes, but the accumulated scale of the scam threat has created urgency around developing deliberate, comprehensive approaches that go far beyond scattered policies buried in terms and conditions. FIs that establish clear accountability at the C-suite level for scam risk management and break down silos between fraud operations, compliance, marketing, legal, and customer service will be better positioned to respond to this challenge.
Yet here is where the conversation must take an important turn.
Stronger, more deliberate scam risk management programs at FIs are necessary but insufficient. Such programs would address only the final few moments of what is often a weeks - or months-long deception. If scams are a mile-long journey, FIs occupy the last few feet - the point at which the victim has already been convinced, coached, and is executing the fraudster's instructions. Almost all scams are initiated on - and spend the overwhelming majority of their lifecycles well outside of - an FI's scope of visibility. The primary stages of attack occur on social media platforms, over telecommunications networks, and through technology services where victims are first identified, groomed, and manipulated into believing the fraud is legitimate.
Scams are a systemic threat to consumer safety that spans an entire ecosystem, yet in most markets, there seems to be an emerging consensus that financial institutions should absorb the entirety of reimbursement costs. Most in the financial services industry are understandably miffed as to how such a conclusion can be made. They struggle to understand how obligating the last stop in the scam lifecycle with all of the costs and risks that accumulate throughout the ecosystem does anything but underwrite criminal activity and discourage the kind of vigilance and accountability that are reasonable to expect not only of consumers but of the many other service providers that fraudsters depend on to execute their scams.
The question regulators and policymakers must reconcile is not simply ‘Should financial institutions reimburse scam victims?’ but rather ‘How should the costs of a threat that originates and perpetuates outside the financial system be distributed across the ecosystem?’
Current liability frameworks in the United States - governed by the Uniform Commercial Code (UCC) and the Electronic Funds Transfer Act (EFTA) - reflect an acknowledgment of the need to place boundaries around the scope of liability. These frameworks deliberately distinguish between ‘authorised payments’ and ‘unauthorised payments’ because they recognise that managing fraud risks is a balance between loss mitigation, client experience, and operational cost.
An FI can theoretically dial fraud down to near-zero, but doing so requires friction that degrades customer experience and incurs substantial capital and operating costs. The liability exemptions for authorised payment fraud exist because policymakers recognised that obligating FIs to prevent or absorb losses from attacks that are not ‘commercially reasonable’ to control would result in degraded payment services at higher costs.
If scams originate outside the financial system, then effective countermeasures must also extend beyond it. Placing liability entirely on FIs - or exclusively on the platforms and services where scams actually begin - distracts attention away from the problem rather than solving it. A truly proportional approach requires that accountability be distributed across all parties who enable scams to succeed.
One emerging national approach to addressing the scam problem offers a promising alternative. Australia's anti-scam framework is based on what observers call a ‘polluter pays’ approach. Under this model, if forensic investigation reveals that a scam was materially enabled by a social media advertisement, a telecommunications vulnerability, or a technology platform's failure to implement known protections, then the company responsible for that gap may be held liable for a portion of the reimbursement. The framework acknowledges that while FIs have a responsibility to protect their customers, they should not bear the entire burden for threats that originate and are sustained outside their systems.
This does not absolve FIs of accountability. Rather, it distributes it proportionally. Financial institutions remain responsible for:
But telecommunications companies, social media platforms, and technology providers become responsible for:
For financial institutions, it’s important to invest in deliberate, formalised scam risk management programs. Not because FIs can eliminate scams through controls alone- they cannot, but because prevention is always preferable to reimbursement, and because customers expect their institutions to be vigilant against known threats.
The conversation must expand beyond what FIs should do internally. Regulators and policymakers should examine models like Australia's carefully. They should consider liability frameworks that distribute costs and risks across the whole ecosystem rather than exclusively on financial institutions. Such an approach would incentivise the kind of ecosystem-wide accountability that would most effectively reduce scams.
As scam volumes continue to rise and regulatory pressure intensifies across markets, the institutions best positioned to navigate this landscape will be those that build comprehensive internal scam programs while advocating clearly for systemic accountability models that reflect the reality of where scams originate and function.
The question is not whether FIs will be held accountable for scams. The question is whether the rest of the ecosystem will be held accountable alongside them.

Trace Fooshée has served as a Strategic Advisor in Datos Insights’ Fraud & AML practice since 2019. Mr. Fooshée’s background includes experience as a management consultant for EY and Deloitte and more than 11 years with SunTrust Bank, where he served most recently as Head of Fraud Strategy. Mr. Fooshée has been an active member in various industry groups, including the ABA and the Bank Policy Institute’s BITS Fraud Reduction Steering Committee.

Datos Insights is the leading research and advisory partner to the banking, insurance, securities, and payments technology industries - both the financial services firms and the technology providers who serve them.
In an era of rapid change, we empower firms across the financial services ecosystem to make high-stakes decisions with confidence and speed. Our distinctive combination of proprietary data, analytics, and deep practitioner expertise provides actionable insights that enable clients to accelerate critical initiatives, inspire decisive action, and de-risk strategic investments to achieve faster, bolder transformation.
The Paypers is a global hub for market insights, real-time news, expert interviews, and in-depth analyses and resources across payments, fintech, and the digital economy. We deliver reports, webinars, and commentary on key topics, including regulation, real-time payments, cross-border payments and ecommerce, digital identity, payment innovation and infrastructure, Open Banking, Embedded Finance, crypto, fraud and financial crime prevention, and more – all developed in collaboration with industry experts and leaders.
Current themes
No part of this site can be reproduced without explicit permission of The Paypers (v2.7).
Privacy Policy / Cookie Statement
Copyright