Imposter scam losses reported in the United States surpassed $1 billion in a single quarter of 2025.
The Victim Authorised The Transaction
That is what separates this category from everything else in the corpus. No account was compromised, no credential stolen, no system breached. The person was persuaded — that their bank had detected fraud, that a relative was in trouble, that a government agency required payment — and they sent the money themselves.
Which means the protections this database keeps invoking do not engage. There is no unauthorised transaction to dispute, no chargeback, no issuer liability. The payment was legitimate in every technical sense.
And It Is The Same Technique As The Enterprise Files
A caller impersonating IT persuades an employee to authorise a connected application at 25-0806. A caller impersonating a bank persuades an individual to authorise a transfer. The identical mechanism, applied to a different authority level.
This desk has filed the enterprise version as sophisticated adversary tradecraft and the consumer version as, implicitly, something that happens to careless people. That distinction does not survive putting them next to each other.
The Corpus Systematically Under-Covers This
Scams generate no breach notification, no named organisation, no case file and no leak-site listing. There is no defendant, so there is no litigation of the kind at 25-1228. Nobody is required to publish anything.
A billion dollars in a quarter, with an incident record of essentially zero, is the largest single blind spot this database has — and it is a structural consequence of building a corpus from disclosures, because a scam has nobody to disclose it.
Graded medium: the figure is drawn from reported losses, which 25-0509 establishes are a fraction of actual losses, and scam under-reporting is likely worse than average because victims frequently feel at fault.
Built on published reporting of FTC data, listed below. Reported losses are a floor. Corrections: corrections@forensicpost.com.