“None of us is as smart as all of us.” – Ken Blanchard
The United States Government Accountability Office’s (GAO) recent testimony before the Joint Economic Committee may not have said it quite so elegantly, but it arrived at a fairly similar conclusion – the federal government is still trying to fight scams like a loose association of agencies rather than like a unified government.
The study, bluntly titled “Government-wide Strategy Expeditiously Needed to Counter Scams,” outlines that scams are proliferating, increasingly sophisticated, and often devastating to victims, with some consumers losing tens of thousands of dollars – or, in the worst cases, their entire life savings. It also stresses that – as many of us in the community banking world are becoming increasingly aware – these are not quaint one-off cons run out of a basement anymore. These scams are often tied to organized criminal networks operating both domestically and abroad, and they move money through the usual modern channels (e.g., P2P apps, gift cards, wire transfers, cryptocurrency, and electronic payments through bank accounts) where interdiction (i.e., the ability for the bank to “get in there and stop it”) is virtually impossible. The visuals in the report make that point especially clear, with charts laying out the basic scam pipeline, from contact, to deception, to payment, to laundering – as well as giving the now-familiar lineup of scam types – impersonation, tech support, grandparent, romance, investment, business email compromise, and lottery / inheritance scams.
As the report title suggests, GAO’s central criticism is coordination – or, more precisely, the lack of it. At least 13 federal agencies (including all of our favorite regulators – FDIC, OCC, FRB, and even CFPB and FinCEN) are involved in some aspect of scam prevention, detection, education, investigation, or response, but they are still largely operating within their own lanes and authorities. Nearly a year ago, GAO proposed a government-wide anti-scam strategy, recommended that the FBI lead the effort, and urged CFPB and FTC (and “other agencies”) to work alongside it on a common definition of scams, as well as “consumer complaint reporting; related types/granularity/aggregation of data, risks, and responses; a government-wide estimate of this type of crime; and coordination of federal and business activities.”
Yet in its latest update to Congress, GAO makes clear that little of that (in fact, very little of that) has actually materialized. The FBI and FTC have raised concerns about the recommendations, citing differing authorities and mandates, while CFPB has essentially said it will “wait and see” what the others do before deciding whether to act at all. So, it could be argued that the core problem is the same as before – lots of agencies, lots of activity, lots of overlap, but still no unified federal playbook. GAO therefore reiterates its earlier recommendation that the FBI lead a coordinated federal effort, and while the FBI has now sketched out some preliminary steps – a multi-agency working group, possible legislative and regulatory changes, collaboration with private-sector and consumer groups, and requests for added funding, tools, staffing, and analytic capacity – GAO’s message is, effectively: “yeah, okay – but ya really should have done something by now.”
The second major theme is (complaint) data – and here the report seems equally unimpressed. CFPB, FBI, and FTC all collect scam-related complaint information, and several agencies publish reports, but the testimony says that data is too fragmented and inconsistent to produce anything like a single, government-wide estimate of scam volume and losses. The FBI’s IC3 system, for example, does not use predefined scam fields and instead relies heavily on narrative descriptions, which makes clean aggregation difficult. CFPB can estimate some scam complaints involving P2P platforms, but not associated losses because it doesn’t require consumers to include dollar-loss information. FTC has broader fraud-loss estimates, but not a scam-specific, government-wide total. Underreporting only makes matters worse, as the DOJ has estimated that only a small share of fraud victims report to law enforcement, and FTC-cited research suggests only a tiny fraction of mass-market consumer fraud victims complain to a BBB or government agency.
That is seemingly why GAO keeps returning to the need for a common definition of scams. The testimony points to the Federal Reserve’s work group definition – “the use of deception or manipulation intended to achieve financial gain” – as at least a plausible baseline, while acknowledging that it has not been adopted government-wide. In a true “apples and oranges” type-scenario, GAO’s view is that without a common definition, agencies cannot reliably compare data, aggregate results, measure trends, or build a coherent national strategy. Said differently, if agencies aren’t even counting the same thing, it would be difficult to ultimately claim that they are jointly solving the same problem.
GAO therefore reiterates four core recommendations for CFPB, FBI, and FTC:
“1. explore ways to harmonize data collection to better identify scams,
2. use the agency’s data collection and analysis to produce and report an estimate of the number of complaints it receives and the associated financial losses resulting from scams,
3. collaborate, develop, and report on a single, government-wide estimate of the number of consumers affected by, and a dollar losses resulting from, scams, factoring in an estimate of incidents not reported and
4. develop a government-wide definition of scams.”
The FBI agreed with the first two but not as much with the government-wide estimate and common-definition pieces as framed; FTC raised its own concerns about adopting the Federal Reserve’s definition and leaned on the practical difficulty of harmonization; CFPB, true to form, initially “did not provide comments,” but then, as mentioned earlier, largely said it would watch what the others do before deciding on further action.
It’s worth noting that GAO isn’t asking for “more enforcement” in the abstract, or some other lofty, ethereal goal. It is asking for something more basic – a federal government that can define the problem consistently, count it coherently, assign agency roles clearly, identify needed resources honestly, and then act like all of those pieces belong to the same strategy. That omission might be all the more striking given how publicly (and at times relentlessly) federal agencies have spent the last several years talking about fraud, scams, and consumer harm. The testimony even points to Australia’s National Anti-Scam Centre as an example of a centralized, coordinated model that reportedly helped reduce scam losses. Or, in other words, other governments have apparently put a center of gravity around this issue; the United States, at least according to GAO, is still mostly passing the file around.
We all know that scams are growing, scam tactics are evolving with technology, the victim counts and loss figures are still incomplete – and the federal response remains fragmented. GAO is essentially telling Congress that the current model – multiple agencies, partial coordination, inconsistent data, no common definition, and no government-wide strategy – is not good enough for a threat environment this large and this adaptive. Or, put a little more plainly – if Washington wants to say it is “fighting scams,” it may first need to agree on what a scam is, how many there are, and who is actually in charge of doing something about them. It doesn’t exactly sound like rocket science – but then again, none of us is as smart as all of us.
Written by:

Brett Goodnack, JD, CAMS
Compliance Advisor