What happened

The FBI's Internet Crime Complaint Center recorded close to 61,000 complaints of law enforcement and government impersonation between January 2025 and July 2026, with reported losses above $1.6 billion. The reporting by The Register puts the average loss per complaint at more than $26,000.

The largest category is also the crudest. Callers claim the target has been linked to a crime and demand payment to make the charges disappear, threatening arrest or prison time if it is not paid. Roughly 11 percent of complaints describe a jury duty or missed court date variant, 6,833 reports carrying losses of nearly $36 million.

Two other variants matter because they show the fraudsters doing research first. Medical practitioners have been told their licence is expiring or has been used in a crime, with payment demanded for renewal or to protect a professional reputation. That pattern appears in 3,322 reports with losses above $37 million. A smaller group, 496 complaints, covers claims that a driver's licence or passport had expired.

The most expensive approach targeted people in ethnic communities, foreign nationals and international students in the United States. Scammers posed as foreign police or diplomatic officials and threatened to cancel a home country passport or arrange extradition, sometimes on video calls with uniforms and sets built to resemble government offices. Those 1,809 complaints account for more than $140 million, close to 10 percent of total losses from less than 3 percent of complaints.

Why this is a GRC story

Impersonating authority is a control problem, not a gullibility problem. Every one of these schemes depends on a victim accepting an unverified claim about identity and acting on it under pressure. That is the same weakness behind invoice fraud, payroll diversion and help desk social engineering, and it is answered with the same design choices: out-of-band verification, a second pair of eyes on any payment above a threshold, and a clear route for an employee to refuse an urgent request.

The complaint data is also useful risk register material. It gives rough loss frequency and severity by scenario, it shows that one targeted variant loses far more per incident, and it names the pressure tactics involved. Registers built on generic labels age badly. Ones built on scenario detail hold up when someone asks why a control exists and what it prevents.

Impersonation is also a duty of care question for anyone serving a vulnerable population. Calls that land on elderly customers, or on staff in a clinical setting, are predictable enough to plan for. Awareness training that only tells people to be careful adds very little. Training that gives them a specific, fast way to verify a caller adds a control.

What to watch

The FBI's most recent annual figures put total cybercrime losses at $20.87 billion for 2025, the first time the number passed $20 billion, so expect this category to keep growing in volume and in reported losses. Watch whether telecoms operators and payment providers come under pressure over spoofed numbers, since caller ID remains the entry point for most of these calls. Watch too how banks set reimbursement rules for authorised push payment losses, because where liability sits changes the incentive to design better verification at the point of payment.

Attribution: Analysis based on The Register and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News