The images in this article were generated with artificial intelligence. How we publish
The latest data from the United States Federal Trade Commission (FTC) show an alarming trend: in 2025, supplanting scams - when criminals pose as banks, public administration or legitimate companies - left Americans with reported losses close to $3.5 billion, almost three times what was lost in 2020 and almost one in three reports of fraud to the agency. These figures are not just numbers: they reflect a clear transition from attackers to channels where users trust and lower their guard, especially social networks.
The modality remains simple in appearance but very effective: a message or call that simulates a bank security alert or official notification pushes the victim to move money "for security" or to provide credentials. According to the FTC, imposters who pose for business cost close to $1 billion and those who pose as the government, around 920 million. The role of social platforms is remarkable: more than 2.1 billion in losses in 2025 were originally traced to social networks - an eight-fold increase over 2020 - with Facebook, WhatsApp and Instagram among the most common vectors.

Behind these numbers are technical and human factors. In technical terms, misleading advertising, false accounts and malicious links in private profiles or messages facilitate the triad of supplanting, social engineering and rapid transfer of funds. In humans, victims often react for fear - a warning of "suspicious activity" in an account - and act in a hurry, without checking official channels. The result is that relatively small activities of the attacker generate very high economic losses.
The regulatory response has been active: since the entry into force of the FTC's Preplanting Rule In April 2024 the agency has initiated dozens of legal actions and obtained over $70 million for the repair of consumers, as well as permanent prohibitions against scheme operators. FTC itself recently published a summary of losses and trends that serves as a call for attention to the magnitude of the phenomenon ( official note by the FTC).
What can a person do today to reduce the risk? First, distrust of the urgency imposed on messages or calls and do not follow links or calls of unknown numbers. Always check with the institution through the official channels on your card, legitimate website or official app, not by numbers or links sent by the alleged issuer. Never use money-sending services or cryptocouters at the request of a "representative" who came by message.

It is also crucial to protect credentials: active multifactor authentication(MFA) in all bank and mail accounts, check alerts and unusual movements periodically, and in case of any loss act quickly to freeze cards, change passwords and file claims. Keep screenshots and evidence of fraudulent communication and denounce it on official tracks; the FTC allows online reports and these complaints feed investigations and collective actions - start with report on the FTC site.
For companies and platforms, the implications are direct: optimizing the detection of false accounts, reviewing ad moderation processes, improving verification tools for official profiles and facilitating simple user reporting and blocking flows are urgent measures. Financial organizations should strengthen their official communications (for example, clearly indicate how to contact them and what the legitimate flow of alerts is) and design processes that make it difficult for a third party to convince an employee or client to transfer funds.
The increasing scale of these scams requires a shared strategy among users, companies and regulators: continued education on social engineering, accountability for platforms that monetize fraudulent ads and improvement in authentication and detection tools. In the meantime, the individual priority is simple but effective: verify, do not react and report. For more information and official resources, visit the FTC's note on the report and the rules of supplanting, and report any attempts on the agency's complaints portal.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...