Fraud
Imposter Scams
Consumer Protection
Payments
Risk Controls

Imposter Scams Are the Most Reported Fraud: The Playbook Behind the Numbers

The FTC says imposter scams were the most reported fraud category in 2025. Here is how the playbook works, why it converts, and where financial-crime teams can intervene.

RiskLex EditorialSeptember 17, 2026
Imposter Scams Are the Most Reported Fraud: The Playbook Behind the Numbers

The Most Commonly Reported Fraud Has a Trust Problem

The latest Federal Trade Commission data identifies a clear leader in reported fraud: imposter scams. In its June 2026 release covering 2025, the FTC said people reported imposter scams more than any other fraud category, with nearly one in three fraud reports involving an imposter.

Consumers reported losing $3.5 billion to imposter scams in 2025. That figure is material, but it needs to be read precisely: imposter scams were the most reported category, while investment scams generated the largest reported losses overall at $7.9 billion. Frequency and severity are different risk signals.

The FTC’s 2025 imposter-scam data shows why this fraud deserves attention from banks, payment providers, platforms, and fraud operations. It reaches people through text messages, phone calls, email, social media, search results, and other channels. The attacker does not need to compromise a sophisticated system if they can persuade a person to treat the attacker as a trusted institution.

How the Imposter Playbook Works

1. Borrow authority

The criminal presents as a bank, government agency, business, delivery company, technology provider, or another organization the target already recognizes. The message may use a familiar logo, a spoofed phone number, a lookalike domain, or details gathered from public profiles and previous breaches.

2. Create a time-sensitive problem

The target is told that an account is at risk, a payment is suspicious, a package is blocked, a tax issue needs immediate action, or an investigation requires cooperation. Urgency reduces the chance that the person will pause and verify the request through a separate channel.

3. Make the victim solve the attacker’s problem

One of the costliest patterns highlighted by the FTC starts with a fake bank security alert. The target is convinced to move money to “protect” it. Other variants request credentials, one-time codes, remote access, gift cards, cryptocurrency, or a payment to resolve the invented problem.

4. Move across channels

Imposter scams frequently begin in one channel and finish in another. A text can move the target to a phone call; a search advertisement can direct the target to a fake support line; a social-media message can lead to a payment page. This channel switching makes isolated controls less effective.

Why Imposter Scams Convert

Imposter fraud exploits three conditions at once:

  • Recognition: the target already knows the brand or authority being copied.
  • Uncertainty: the target cannot immediately tell whether the alert is real.
  • Pressure: the attacker frames delay as dangerous or non-compliant.

The result is a social-engineering attack that can bypass strong authentication. A customer may correctly enter a password and a one-time code, yet still authorize a transfer because the attacker has manipulated the decision around the transaction.

The FTC reported nearly $1 billion in losses to business impersonators in 2025, with bank impersonators producing the highest reported losses within that group. Government impersonation losses were about $920 million, up from $789 million in 2024. Those figures show why fraud controls cannot focus only on whether a login or payment technically authenticated.

Where Financial-Crime Teams Can Intervene

Detect the story, not just the transaction

Transaction monitoring should be connected to fraud signals that reveal the likely narrative: a new device, a recent password reset, a remote-access tool, a payee change, a sudden transfer to a new beneficiary, or a customer who is being coached during a call. Each signal may be weak alone. Together they can indicate an impersonation event.

Add friction at the right moment

Generic warnings are easy to ignore. A higher-risk payment should trigger a specific, plain-language interruption that names the known pattern: “Is someone claiming to be your bank asking you to move money to keep it safe?” The control should offer a trusted verification route and a clear way to pause the payment.

Use out-of-band verification

Do not verify an urgent request through the contact details supplied in the message or phone call. Route the customer to a known number, authenticated in-app support, or a branch process. For business payments, confirm new or changed beneficiary details using an established contact and a second approver.

Connect customer support and fraud operations

Support teams often hear the attacker’s story before the fraud team sees the transaction. Give agents a fast escalation path, structured capture fields, and authority to pause a suspicious transfer. The goal is to convert a conversation into a usable risk signal without making the customer repeat the incident across multiple teams.

Measure prevented harm

Track more than confirmed losses. Useful measures include suspicious-payment interventions, customer-reported impersonation attempts, time from first contact to account protection, repeat targeting, false-positive friction, and the share of escalated cases where the customer was coached to move funds.

A Practical Verification Checklist

Before acting on an urgent request, ask:

  1. Did the contact arrive through an expected channel?
  2. Is the sender asking for a password, one-time code, remote access, gift card, cryptocurrency, or a transfer to “protect” funds?
  3. Can the request be verified through a trusted channel that was not provided by the sender?
  4. Is the payment going to a new beneficiary or being made under unusual time pressure?
  5. Can the transaction be paused while the account or message is independently checked?

The FTC says it will never demand money, threaten consumers, tell them to transfer money to protect it, or promise a prize. Those are useful consumer guardrails, but institutions should also build them into product warnings, agent scripts, and payment decisioning.

The Practical Takeaway

Imposter scams are common because they attack trust at the moment a person is making a decision. The strongest response is not a single warning or a single model. It is a connected control system that combines channel intelligence, authentication context, payment behavior, customer support, and timely human intervention.

The data also gives teams a prioritization rule: start with the fraud story customers report most often, then separate how frequently it occurs from how much money it can remove. Read the FTC’s full 2025 imposter-scam release and use the agency’s fraud-reporting service when building customer education and escalation guidance.