Summary
- Rep. Andy Barr (R, KY-6) advocated for the STOP Fraud Act and TRACE Act to modernize funds availability rules and expand information sharing to combat sophisticated cybercrime.
- Patrick McDade (Senior Vice President for Fraud and Technology Risk Management, EverBank) testified that scams increasingly originate on social media, positioning financial institutions as the final defense.
- Rep. Bill Foster (D, IL-11) and Gay Dempsey (Chief Executive Officer, Bank of Lincoln County) discussed how Bitcoin ATMs facilitate untraceable romance and investment scams targeting vulnerable consumers.
- Rep. Maxine Waters (D, CA-43) accused the administration of gutting the CFPB, while Republicans argued that vague UDAAP standards prevent banks from deploying proactive, AI-driven fraud detection tools.
- Congress is considering the SCAM Act to hold social media platforms accountable for fraudulent advertisements while updating Regulation CC to provide banks more time to scrutinize transactions.
Topics Discussed
Transcript
Opening Statements
The subcommittee on Financial Institutions will come to order. Without objection, the chair is authorized to declare a recess of the committee at any time. Today's hearing is titled Fighting Fraud on the Front Lines: Challenges and Opportunities for Financial Institutions. Without objection, all members will have five legislative days within which to submit extraneous materials to the chair for inclusion in the record. I now recognize myself for four minutes for an opening statement. Good morning. Today's hearing continues this committee's work to combat the growing threat of financial fraud and scams harming American families, seniors, and small businesses across our country. Fraud and scam losses are not abstract statistics. They represent retirement savings wiped out, college funds drained, and small business savings accounts emptied overnight. The scope of the problem is staggering. According to the FBI, Americans reported $16.6 billion in cybercrime losses in 2024, a 33 percent increase over the prior year. Criminals are becoming more sophisticated, leveraging artificial intelligence, voice cloning, spoofed caller IDs, fake investment platforms, and coordinated money mule networks. They are exploiting social media platforms, telecommunications infrastructure, and cross-border networks to deceive Americans at scale. And yet, even as these schemes often originate outside the financial system and frequently outside our borders, banks and credit unions are often the last lines of defense. Financial institutions of all sizes are devoting substantial resources to fight fraud and scams. They are investing heavily in data analytics, machine learning, and artificial intelligence to detect suspicious activity within milliseconds. They are deploying real-time transaction alerts and customer education campaigns to encourage their customers to remain vigilant and spot common flags before funds have left their accounts. Community banks and credit unions, despite having fewer resources, are stepping up with employee training, enhanced check verification procedures, and partnerships with local and national law enforcement. The Trump administration has also taken significant steps to address this escalating problem. President Trump's executive order, Modernizing Payments to and from American Bank Accounts, directs Treasury to transition away from paper checks, which are far more susceptible to theft and alteration, and toward more secure electronic payments. The shift will help safeguard Americans' tax refunds and benefits while protecting taxpayer dollars from criminal activity. President Trump has also removed barriers to American leadership in artificial intelligence, recognizing that innovation is essential if we are going to outpace technologically savvy criminals. But despite these efforts, serious structural challenges remain. First, our legal framework for information sharing is outdated. Fraud today is networked, cross-institutional, and real-time. Yet privacy statutes, antitrust concerns, and uncertainty under consumer reporting laws limit the ability of financial institutions to share data in ways that could identify mule networks and coordinated fraud patterns. Second, funds availability rules under Regulation CC were written for a very different era, when the primary risk was banks holding checks too long, not criminals exploiting mandatory next-day availability to drain accounts before investigations can detect fraud. Third, our financial regulators often lack robust understanding of artificial intelligence and machine learning, preventing the establishment of clear guardrails for financial institutions. With well-defined expectations, financial institutions will be better positioned to confidently adopt these technologies or partner with innovative third parties to more effectively detect and prevent fraud. Lastly, law enforcement faces real constraints, including insufficient penalties for fraudsters, limited resources, and lack of coordination between federal and local officials. At the same time, we must also guard against proposals that could unintentionally fuel more scams. Placing liability on financial institutions when a customer mistakenly authorizes a payment or transfer, often referred to as scams, does not address the underlying root causes of scams and could worsen the problem by increasing instances of first-party criminal activity. It would also impose significant financial strain on smaller banks and credit unions, which lack substantial profits needed to absorb large scam-related losses. Our focus today is straightforward. How do we empower financial institutions to better deter, detect, and mitigate fraud without creating perverse incentives or unintended harm? I look forward to hearing from our witnesses and working with my colleagues to strengthen our nation's defenses against financial fraud and scams. With that, I yield back. I now recognize the ranking member of the subcommittee, Dr. Foster, for four minutes for an opening statement.
Thank you, Chair Barr, and to our witnesses. Today's hearing continues this committee's bipartisan focus on solutions to counter the growing threat of fraud and scams facing American consumers and financial institutions. Federal agencies, including the FBI and FTC, and numerous non-governmental organizations have increased their focus on frauds and scams in recent years. In each report, it's made clear that scams and losses from fraud are growing year after year. Scams are moving online, and the perpetrators are becoming more sophisticated. As Chair Barr noted, the FBI's last internet crime report in 2024 reported losses of a staggering $16.6 billion from cyber-enabled scams and fraud. During COVID, the U.S. taxpayer lost well over $100 billion to scams and identity scams. When encompassing offline activity like check fraud and information from victims that choose not to report their losses, the number is actually much greater. Today we're going to be discussing what can be done to support community banks and credit unions, which often find themselves as the last line of defense between consumers and scammers. We will discuss what more financial institutions and this committee can do to fight scams and fraud, the role agencies outside of our jurisdiction should play, and actions that can be taken by other industry sectors to eliminate common vectors for these activities. Old-school fraud persists, like check fraud, while scammers are quickly adopting new tools like artificial intelligence, deepfakes, to more effectively falsify documents, impersonate consumers, or create false presences that trick Americans into sending their hard-earned money to bad actors. Specifically, I worry about the role of impersonation and identity fraud in the scam system. In 2024, the Financial Crimes Enforcement Network, FinCEN, published a report identifying more than 1.6 million suspicious activity reports implicating more than $212 billion in transactions as linked to concerns with identity verification. I would like to thank Congressman Sessions for his partnership on H.R. 7270, the Stop Identity Fraud and Identity Theft Act of 2026, which would help states build the necessary infrastructure to offer a voluntary form of digital identification for Americans that want it. Digital identity tools are proven to be more secure and privacy-preserving than physical documents in an online environment, and our bill would take important steps to provide a peace of mind to Americans who worry that the person on the other end of the line may not be who they claim to be. It is essential to also recognize the role of the Consumer Financial Protection Bureau that it played in countering fraud and scams, particularly for our service members and older Americans. The CFPB long served as a resource for Americans affected by these criminals, providing assistance and operating their consumer complaint database, which provides important data regarding the types of scams and other illegal activities facing the public. This work is important, and this committee should put pressure to restore the CFPB so that it can continue that important work. Many members of this committee recognize that congressional efforts to counter fraud and scams cannot stop at the walls of this committee. Telecom service providers, social media platforms are common avenues for scammers to reach consumers. Fighting scams requires an all-of-government approach to be successful, and we should recognize that many times, much of the damage has been done by the time the consumer contacts the financial institution. Technological solutions, improved information sharing arrangements, and stronger federal coordination provide a start to addressing these issues. So I look forward to hearing the views of our witnesses on these topics and yield back.
The gentleman yields back. I now recognize the chairman of the full committee, Mr. Hill, for one minute for an opening statement.
Thank you, Chairman Barr, and this is Consumer Protection Week, and I think I want to commend you and Dr. Foster for holding this important hearing. Fraud and scams are not a new challenge, but the scale and complexity of the problem, as Bill just outlined, are increasing rapidly and posing greater costs on both American families and on the financial services arena and on our small businesses. Americans reported losses of $12.5 billion in 2024, a 25 percent increase. In communities like my own in Little Rock, I hear directly from bankers, small business owners, consumers who are grappling with check fraud, wire fraud, and increasingly sophisticated digital scams, and in our family, we've been the victim of check fraud ourselves. Our banks and credit unions serve on the front lines of this fight, working every day to safeguard their customers, and we need an all-of-government approach, and that's why I commend the work of this committee, and I yield back.
Witness Testimony: Community Banking Perspectives
Thank you, Mr. Chairman, and I commend your work as well and your focus on this issue along with Mr. Meuser, the chairman of our oversight subcommittee. Today we welcome the testimony of Mrs. Gay Dempsey, the CEO of the Bank of Lincoln County, Tennessee, here on behalf of the Independent Community Bankers of America. Mr. Patrick McDade, the senior vice president for fraud and technology risk management at EverBank, here on behalf of the Consumer Bankers Association. Ms. Kate McKune, the general counsel of Park Community Credit Union in the great Commonwealth of Kentucky, here on behalf of America's Credit Unions, and Kate and I have been friends for a long time, so it's great to see you in front of our committee, Kate. And Mr. Joseph Schuster, a partner at Ballard Spahr, and Mr. Adam Rust, the director of the financial services at the Consumer Federation of America. We thank each of you for taking the time to be here. Each of you will be recognized for five minutes to give an oral presentation of your testimony. Without objection, your written statements will be made part of the record. Mrs. Dempsey, you are now recognized for five minutes for your oral remarks.
Chairman Barr, Ranking Member Foster, and members of the subcommittee, I am Gay Dempsey, the CEO of the Bank of Lincoln County, located in Fayetteville, Tennessee. We're a $225 million bank in southern middle Tennessee bordering Alabama. I'm a member of the board of directors for ICBA and a member of the Fraud and Scams Task Force. I'm also actively involved in the Tennessee Bankers Association, where I'm soon to be chairman. I testify today on behalf of ICBA and thousands of community banks across our country. Thank you for convening today's hearing. I'm a lifelong community banker, and I've witnessed firsthand the impact of fraud on our customers and community and have seen the financial ruin that fraud can produce. Community banks like mine are on the front lines, spending significant time and resources to educate customers and identify and mitigate fraud. Coordination among financial institutions, law enforcement, and government at every level is necessary to combat this urgent problem. My written statement contains legislative and regulatory recommendations, but I must stress that additional mandates on community banks would only harm our ability to fight fraud. I also provide a number of stories to illustrate the impact of check fraud, impostor scams, and other schemes. In recent years, we have seen a significant rise in check fraud. A common thread in these cases is a failure of mail security at a depositing bank that ignored red flags on account opening and accepting deposits of stolen checks for fake companies. In some cases, lost funds were recovered after much effort and delay. In others, we had to absorb the losses. We've also seen a rise in impostor scams enabled by unregulated social media platforms and Bitcoin ATMs. Our bank had an elderly customer with no family who fell victim to a romance scam and sold her house for $85,000. Spotting the red flags, we refused her request to wire the money to the scammer and tried our best to convince her that she was a victim, even showing her FBI reports. In the end, we could not refuse her request to make a cash withdrawal, which she deposited in a nearby Bitcoin ATM and transferred to the scammer. This was heartbreaking, a preventable crime enabled by the use of fake social media accounts. The SCAM Act, introduced by Representatives Meuser and Correa, would begin to hold social media platforms accountable for fraud like this. Fraud losses disproportionately impact community banks relative to our asset size. For a bank like ours, fraud fundamentally impacts our ability to serve our local community. Beyond the significant dollar losses, fraud is increasingly absorbing focus and attention, stealing valuable time that we should be spending with our customers. But maybe more dangerous is the intangible impact, the erosion of consumer trust in all banks. This, ironically, leads consumers to seek out unregulated non-bank alternatives that put them at even greater risk. Community banks are built on strong relationships. This sets us apart from larger transaction-oriented banks, and fraud jeopardizes these critical relationships. Given these high stakes, how are community banks responding? First, we are investing significant amounts into technology, including AI to detect fraud. These tools, which are important but not foolproof, add significant cost for our bank. One of the draft bills before this committee, the Bank Fraud Technology Advancement Act, would require a comprehensive agency study of the use of AI in fraud prevention. This study would be valuable. Second, we train our staff to spot fraud and report suspicious activity. Our staff are the point of contact and positioned to detect fraud early and intervene. Their training is critical, but so are the personal relationships and the knowledge they have. In our close-knit community, they are truly the first line of defense. At the industry level, ICBA created a fraud and scams task force that shares information and best practices, meets with regulators, and develops resources for our peers. My statement also contains recommended changes to Fed Regulation CC, which governs check clearance. This, along with the draft STOP Fraud Act, would help community banks mitigate check fraud by providing more flexible hold times. Finally, a third draft bill before this committee, the TRACE Act, would expand critical information sharing while providing safe harbors. Thank you for your work on the draft.
Thank you. I now recognize Patrick McDade for five minutes. Thank you.
Chairman Barr, Ranking Member Foster, and members of the subcommittee, thank you for the opportunity to testify. My name is Patrick McDade, and I am the Senior Vice President for Fraud and Technology Risk Management at EverBank. Before joining EverBank, I spent over a decade as a state and federal prosecutor. I also serve as the chair of the Consumer Banking Association's Fraud Management Committee. The CBA's broad membership has long been raising the alarm about the rise in fraud and scams that are inflicting deep financial and emotional harm on American consumers and small businesses. Banks invest billions of dollars and millions of hours to combat fraudsters and scammers each year. However, banks cannot face this growing threat alone. In 2024, the FBI received more than 850,000 IC3 complaints involving losses of over $16 billion, which was a 33 percent increase over 2023. However, while consumers expect a meaningful response to these complaints, GAO reports have revealed a lack of coordination among federal bodies to assist victims and prevent frauds and scams. Meanwhile, the criminals behind these frauds and scams are using AI, social media, and dark web platforms to coordinate with each other and improve their attacks and techniques. Historically, fraudsters have attacked the financial services industry through traditional bank fraud methods: identity theft, forging or altering checks, wire fraud, etc. More recently, these criminals have focused on emerging digital bank platforms, fraudulently accessing accounts online and making unauthorized payments. Banks hardened their digital controls, developed data-focused fraud tools, and strengthened digital security to combat these emerging threats. In response, today the criminals are focused on a new tactic: scams directed at our customers. Frauds and scams are often conflated, as both use complex schemes and deceptions to steal. However, it is important to understand the differences between fraud and scams. The key differences are who is being deceived and who is authorizing the transactions. As I described, in bank fraud, the criminals are trying to deceive the bank, and fraudulent transactions are sent. With scams, however, the criminal is not deceiving the bank, they're deceiving the customer. The customer believes they urgently need to move money to invest, to help a loved one, or to avoid a penalty. The customer then contacts the bank and authorizes a transaction to move money. Banks work hard to protect their customers and the Main Street communities they serve from these scams. Banks monitor unusual activity, educate customers about fraud and scams, and train their staff to recognize red flags that indicate a customer may be a scam victim. Banks are doing what they can to stop scams, but there are several important steps that policymakers can take to help. First, the federal government should establish a national strategy to combat fraud and scams. Because so much of the activity involving scams originates from social media, telecommunications, and other places outside the financial sector, this strategy must include cross-industry engagement. One step towards accomplishing this could be an executive order that includes unified coordination with the private sector. While my written testimony provides more detail, such an order could establish a centralized interagency reporting and data-sharing infrastructure to streamline complaint intake and response. This would provide immediate structural alignment across agencies while longer-term legislative reforms are developed. To that end, CBA strongly supports many bipartisan and bicameral efforts, including the leadership of Representative Nunn through the GUARD Act and the TRAPS Act, Representative Meuser through the SCAM Act, and other efforts such as Representative Kim's No More Scams Act represent important steps in interagency coordination. Congress should also expand safe harbor protection so financial institutions can share real-time fraud and scam threat intelligence without undue legal risk. Federal regulatory frameworks must also be modernized, including Reg CC. Customer education is equally vital. Banks commit significant resources to educate their customers about fraud and scams, but a national fraud and scam awareness campaign would make a substantive difference. Finally, fraud and scams are currently reported to the government through FinCEN's suspicious activity reporting process. Transitioning to a modern fraud signal report would lead to more valuable and actionable data gathering by the government. The fraud and scam epidemic confronting American consumers is not a series of isolated incidents, it's a rapidly evolving, technologically accelerated global threat that inflicts billions of dollars each year and affects millions of Americans in every district and Main Street consumer across the country. Thank you, and I look forward to your questions.
Thank you. Ms. McKune, you're now recognized for five minutes.
Good morning Chairman Barr, Ranking Member Foster, and members of the subcommittee. I'm Kate McKune, General Counsel of Park Community Credit Union in Louisville, Kentucky. I'm pleased to appear before you today on behalf of America's Credit Unions, where I serve on the fraud task force and the association's advocacy policy committee. We applaud the subcommittee for holding this important hearing today. Financial institutions operate in an environment where fraud and scams are becoming increasingly more prevalent. Fraud encompasses a wide range of criminal tactics. Scams, as a subset of fraud, often involve an element of impersonation or trickery. Both ultimately harm the consumer and the financial institution and fall under the broader scope of fraud being examined at this hearing today. Credit unions like mine must contend with a fraud environment where a large share of fraud and scams originate outside of the financial sector, and criminal sophistication continues to grow. Credit unions are the original consumer protectors, and that fact puts us at the forefront of looking out for our members. At the same time, consumers increasingly demand speed and convenience as a core part of their banking experience. Sometimes the only viable defense against fraud is preventing it before it occurs, a process that can be technologically demanding, expensive, and dependent on timely information sharing between law enforcement, federal regulators, and other payment system stakeholders. Despite significant investments in fraud detection tools, consumer education, and data security, credit unions report each year that fraud remains a top concern. For smaller credit unions, a significant fraud loss could impact the financial health of the institution. As a not-for-profit cooperative, if regulatory standards on liability for fraud were to shift the costs further to the institution, our members would ultimately bear the burden. Credit unions regularly work to adapt, innovate, and educate their members about the variety of fraud and different scams that can target them, although often times no amount of security investment or intervention can fully compensate for a consumer's decision to trust a scammer. One of the biggest challenges in combating fraud is that it can come in so many different forms. Romance scams can be difficult for a credit union to detect and prevent because manipulation of the victim can take place over a long period of time. Often victims of romance scams will genuinely believe that their online friend is a person they can trust and no amount of circumstantial evidence will change their mind. Fraudulent advertisements for fake goods and services are another common vector for defrauding consumers. Unfortunately, financial institutions have minimal control over how online or social media entities manage their advertising policies. As a result, we must resort to simply warning consumers that completely anonymous, online, sight-unseen purchases of goods could mean losing their money. Investment scams and business impersonation scams have also contributed to abnormally high fraud losses among consumers. Often these scams can involve cryptocurrencies or impersonators pretending to work for crypto companies. Check fraud has also increased in recent years. One way to combat this would be to modernize the funds availability rules under Regulation CC and create flexibility in the length of time funds may be held if there is concern about a check. While the NCUA also provides resources to assist credit unions and their members in the fight against fraud, America's Credit Unions supports greater interagency coordination, expanded information sharing authority, and close collaboration with law enforcement to address fraud. We believe a national strategy to mitigate fraud should include several key elements. First, improving information sharing and coordination. Bills such as the TRAPS Act and TRACE Act are important steps in this area that would improve cooperation between public and private sectors and law enforcement. Second, a national consumer education campaign and program from the federal government that partners with industry. Third, modernization of funds availability rules. Legislation such as the STOP Fraud Act would begin to make improvements in this area. And fourth, promotion of the use of technology, including AI to help combat fraud. The Bank Fraud Technology Advancement Act is an important first step. We also support the creation of technical assistance and grant programs to help smaller financial institutions access best-in-class technology. In conclusion, there's no magic bullet to stop fraud and scams. At Park Community, we're on the front lines trying to fight it and help our members, but the challenges are complex. Often criminals seek to manipulate the system and prey on human nature. There's only so much one institution can do alone. What is needed is a commitment at the federal level to work with credit unions and other financial institutions to help combat fraud and scams by using an all-of-government approach as outlined in my testimony. Thank you for holding this important hearing and the opportunity to appear before you today. I welcome any questions you may have.
Witness Testimony: Legal and Consumer Perspectives
Thank you. Mr. Schuster, you are now recognized for five minutes.
Thank you and good morning. Chairman Barr, Ranking Member Foster, and members of the subcommittee. Thank you for the opportunity to testify today. My name is Joseph Schuster and I'm a partner in Ballard Spahr's Consumer Financial Services Group, where I advise banks, credit unions, payment companies, and technology providers on federal and state consumer finance laws. A substantial portion of my practice focuses on fraud and scam related matters, including payments fraud, identity-based fraud, account takeover, check and wire fraud, scam topologies, loss allocation, and legal and operational frameworks governing fraud detection and response. Throughout my testimony, two themes are going to be pervasive. The first is the challenge of sharing information effectively to prevent fraud. The second is the constraints financial institutions face when deploying new tools to combat rapidly evolving fraud schemes. Fraud prevention today is inherently collaborative. It depends on coordination among financial institutions, their service providers, law enforcement, and in many cases, cross-industry information sharing networks. Yet these efforts take place within a layered legal and supervisory framework. Fraud mitigation is shaped not only by statutory regimes such as the Fair Credit Reporting Act and the Expedited Funds Availability Act, but also by regulatory guidance, supervisory expectations, and the practical realities of examinations and investigative oversight. Financial institutions must navigate federal and state compliance expectations and requirements while simultaneously responding to increasingly sophisticated and fast-moving fraud threats. The interaction between federal and state law can create uncertainty in areas such as information sharing, funds availability practices, fraud-related holds, consumer dispute handling, and the use of advanced analytics. Institutions operating nationally must reconcile these overlapping regimes while responding to fraud schemes that do not respect jurisdictional boundaries. My testimony today reflects a legal practitioner's perspective across institutions of varying sizes and business models. Fraud has evolved rapidly in recent years. At the same time, many elements of the legal and supervisory framework were developed in an era when fraud was slower, more siloed, and certainly less technologically advanced. The result is a growing tension between the speed and scale of emerging fraud trends and the structure of the regulatory architecture governing prevention efforts. I appreciate the committee's attention to these issues, and I look forward to discussing how policymakers can support effective fraud mitigation while preserving consumer protections, privacy, and fair access to financial services. Thank you.
Thank you. The gentleman yields back and last but not least, Mr. Rust, you are now recognized for five minutes.
Chairman Barr, Ranking Member Foster, and members of the committee, thank you for the opportunity to testify today. My name is Adam Rust. I'm Director of Financial Services for the Consumer Federation of America. CFA is a nonprofit organization dedicated to serving the consumer interest with 250 nonprofit coalition members across the country. And we house Veteran Saves and Military Saves to help approximately 240,000 individuals build wealth. Today I want to talk about scams, which are among the most serious threats facing consumers today. You've heard about the large numbers of losses. The numbers are truly much larger because so many scams are never reported. Scams affect people in every congressional district of every age, young, old, urban, rural, civilian, and service member. I want to focus my testimony on five things Congress can do. First, attacks on the CFPB must end. The CFPB is the primary federal agency with the mandate and expertise for consumer financial protection and authority for EFTA and UDAAP. Its complaint database receives complaints from harmed consumers. This information can be shared with law enforcement and other concerned parties. When consumers are harmed, the CFPB has sent a clear signal. When companies offer unsafe products, there will be consequences. But that signal has been silenced by dropping enforcement, gutting supervision, and firing staff. The consumer's champion has been taken off the beat. And Congress overturned the rule requiring supervision of payment apps and digital wallets. Consumer relief rates have dropped precipitously from approximately 50 percent two years ago to now less than one percent. Second, EFTA is broken for scam victims. EFTA was written in 1978 when electronic theft meant a stolen ATM card. Today's criminals coerce victims into authorizing transfers where there is little recourse under the law. CFA supports the Protecting Consumers from Payment Scams Act, which would expand coverage to wires, call for shared liability, and create protections against induced transfers. The bill will modernize EFTA to actually address how scams work now. Third, every company across the payment journey should be accountable and a part of the solution. For every scam, there is a destination, a bank or a payment app of the criminal. Criminals deliberately target FIs with weak fraud detection to help them find ways to open accounts and receive funds and then later move it on for funnel accounts. SAR filings on funnel accounts have increased fourfold since 2020. And bank-fintech partnerships, such as the example of the Synapse case, are a critical point of vulnerability. True, send-side FIs don't have the full picture. Receive-side FIs and payment networks have a unique line of sight with directory information as well. Let's connect those sight lines. More use of real-time AI, better information sharing, and possibly the expulsion of stubbornly risk-leaning FIs would improve the ecosystem's safety for everyone. The UK has shown that shared liability works. The problem has many surfaces and every actor, banks, non-bank apps, networks, platforms, telcos, all must have skin in the game. Fourth, we must bridge the gap between illicit finance enforcement and consumer protection. The types of criminal organizations that have historically been the subject of BSA and AML violations are now open for a new line of business, scamming Americans. Yet BSA enforcement actions and consumer protection work have been in siloes. That should change. The CFPB should be in the room and penalties resulting from violations should include remedies for scam victims. Fifth, we should make efficient use of SARs. Much of the most useful information in a SAR is buried in narrative fields where law enforcement have difficult times to access it at scale. To help law enforcement, FinCEN should migrate more data to structured formats, add a scam checkbox with device and account identifiers to permit appending and tracking across financial institutions. The dark web is not calling for higher reporting thresholds, neither should we. It would be blind for law enforcement to many transactions, including some that affect lower dollar transactions such as teen sextortion. The tools to fix this problem exist. Restoring the bureau, sharing liability, removing siloes, and making better use of SARs will strengthen our defenses. Thank you.
Regulatory Frameworks and UDAAP Authority
Gentleman's time has expired and we will now turn to member questions. I recognize myself for five minutes for questioning and I'll start with Mrs. Dempsey. The recommendation of the Stop Fraud Act or updates to Reg CC to allow for exceptions in terms of holds, allowing more holds for scrutinizing wire transfers or suspicious checks. You know, we hear a lot about, especially from community banks, concerns about rewards in payment stablecoins. This seems to kind of go in the opposite direction, but I think banks will always and credit unions frankly, all community financial institutions will always be here even with the advent of blockchain technology and stablecoins because of the fraud prevention that you all and the trust that you all create and why are even more important in the ecosystem with the advent of stablecoins. Can you talk about that and does this, I think it's a good idea to give you more flexibility on holds, but does that work at cross purposes in terms of the concern about disintermediation?
It's a broad question. On the Reg CC side for holds, yes, definitely giving more leeway there for the banks. The language right now is a little vague on if you have a reasonable cause to place a hold for longer, a longer period of time. And so when you get and so a lot of banks are not apt to use that to extend their hold times when they see those fraudulent checks when they come in. And you know, with Check 21 years ago, everybody thought checks were just going to clear instantly and that you would be able to catch those fraudulent checks that were presented into the system. But we still see that it can take several days sometimes for a check to clear. And also it takes a lot of time, especially when you're talking about altered checks that have occurred in the mail for the small businesses that they may have been stolen out of the mail and then come out of their account. I would love for them to check those accounts every single day and to make sure that the payee matches who they sent it to, but unfortunately they just don't. And even with the education that we provide to those small businesses, we host small business luncheons to train on fraud and scams and to show them what to look for. But when you extend that hold time, it gives that customer even more time to check their online banking, to look at those accounts, and then for us to return those because that's one of the hardest things is the midnight return that we have with checks and dealing with trying to mitigate those and to solve those.
Well, we're at just to sum up where we are embracing the innovation of moving towards a more frictionless payment system obviously with the Genius Act, but banks and credit unions will always be needed I think to build in wanted and needed friction to prevent fraud. Mr. Schuster, I've heard from financial institutions that when they implement robust fraud controls, they can face allegations of unfairness or abusiveness under CFPB's UDAAP authorities, especially when interventions might create necessary friction for customers. My Rectifying UDAAP Act requires the CFPB to provide clear standards for what constitutes a UDAAP violation, giving financial institutions the clarity they need to serve customers, including protecting them from fraud and scams. From a legal perspective, how does UDAAP risk currently influence institutions' willingness to deploy proactive risk-based fraud controls and do you think that greater clarity in the form of my bill, the Rectifying UDAAP Act, would reduce hesitation around reasonable good faith fraud interventions?
Thank you. It's a great question and yes, your act would certainly help financial institutions. They right now face the decision of am I going to address this fraud or scam as it currently exists under existing statutory law, but risk being criticized from an unfairness or an abusive perspective from their regulators and supervisors. And they will many times look at the potential financial impact to them of a compliance rating versus providing money to an individual who's been taken advantage of by a scam. And when they're implementing tools, it's the same thing that there are regulators are not looking at how artificial intelligence works, advanced technologies work, and they have an aversion to doing that and there is a belief that that is unfair, that that is abusive, and they need to look at that and your bill certainly helps.
Ms. McKune, I know your testimony was that Park Community Credit Union prevented more than a million in fraud losses for your members. That's fantastic. Can you describe in more detail what those fraud attempts look like on a day-to-day basis and the staff time, compliance oversight, and technology investment that's required to manage all of this?
Thank you, Chairman. We work every day to run investigations quickly. We have full-time fraud staff. We have deployed technology to catch and alert and indicate to us where there might be suspicious activity. We have obviously a compliance team that works hand in hand with the fraud team to ensure that we're meeting our compliance and regulatory obligations in that regard. But there's a sign in our fraud department that says how many days since the last fraud incident and it never leaves zero because what we do every day is keep vigil and work to investigate to see whether we are having an individual problem, whether we are seeing multiple members affected by a scam. And so we're very conscientious of balancing their needs with the burden on our side to ensure we're protecting them.
Thank you. I know it's a very costly enterprise. My time is expired. Dr. Foster's recognized for five minutes.
Digital Identity and AI in Fraud Prevention
Thank you, Mr. Chair. Mr. McDade or Mr. Rust, as I mentioned in my testimony, identity fraud and impersonations are really the they're crucial to every one of these of these scams. And they're becoming a greater threat to American consumers, particularly with the proliferation of artificial intelligence and deepfakes. Not only are the scammers able to reach more potential victims by automating these, but their scams are much more more sophisticated. You know, the old schemes of having typo-ridden emails claiming you're the beneficiary from a distant relative have sort of been replaced by very sophisticated impersonations which can be, you know, online videos, things like that. And it's only going to get worse. The rise of agentic AI is going to engender a huge new wave of these frauds where you're, you know, when my agent starts talking to your agent to do a business deal or to just communicate, the very first question's going to be how do I know you are who you say you are and not some scammer? And so I think that that having a secure digital identity that for Americans that want to be able to to prove they are who they say they are is going to be a crucial tool. I worry that America is falling behind the rest of the world in this because by the end of this year every citizen of the EU, if they wish, will have a tool to get out of their cell phone, smile at it, do the biometric login, present a identity app that proves they are who they say they are. That in in the absence of any action by the by the federal government, states are rolling out digital drivers licenses. You know, sort of ironically, it is the National Institutes of Standards and Technology, the U.S. standards that are being deployed all around the world. They're in every iPhone and every Android, but we're not using them federally to prevent identity scams. And so I think that's a real missed opportunity that we'd like to. Also, Ms. Dempsey, you you highlighted Bitcoin ATMs. And I would urge every member of this committee to just go look at their hometown and then do on Google Maps and then go do a search for Bitcoin ATMs. Then maybe do a search for where all the nearby fentanyl deaths have been and see if it the maps look kind of similar. These are these are tools by drug dealers, they're tools by scammers. And and we have to do something about that. During the previous Trump administration, actually, Secretary Mnuchin had the simple suggestion that why don't we have mandatory KYC on all crypto wallets, which I think would, you know, solve a big part of this problem anyway. So any thoughts you have on that, Ms. Dempsey, what what should we do about the Bitcoin ATMs because they are not a small problem?
Yes, I'm the Bitcoin ATMs in my opinion are just nefarious and there's nothing good in our community taking place at a Bitcoin ATM. There's no need for them. And to your point, once they enter that, they're gone. There's no tracking there for where we stand, there's no getting that back. And so I know there are several states that have enacted laws, our state is currently entertaining some laws dealing with Bitcoin ATMs and placing limits on them and placing warnings on them to help educate the consumers and to protect them.
Yeah, but that's not going to help someone who's been scammed and is, you know, a romance scam and they're I know I'm familiar with a bar owner who was given a couple hundred bucks a week to put a Bitcoin ATM in their bar and after a couple weeks he said get this the heck out of my bar because he was sick and tired of seeing elderly people pouring their life savings down the Bitcoin ATM crying as they did it.
Yeah. If and if there were regulations even if they did point it in the ATM where they had a certain amount of time to get it back, even things of that nature could help protect them when they fall victim to those scams.
Yeah. Mr. Rust, how would you generally rate the the position of U.S. citizens in terms of being able to, you know, prove they are who they say they are, to know that the person they're talking to is the real person in an online environment? How does that?
So this problem is is not working now and getting worse. You can imagine with deepfakes and voice cloning that fraudsters are going to gain new advantages to harm people. So that's that seems inevitable. And the probably the best way Michael Hsu made the point that the best way to fight AI fraud is with AI technology, supervisory tech, but we need to invest in that. We need to be able to buy those for regulators to have the tools that the fraudsters have.
Yeah. Does anyone else have comments on where AI? The thing that interests me are these personal AI assistants that everyone's going to use, which could be the last and best line of defense. So when you get that first phishing scam mail, you have your personal AI assistant say warn you so that your elderly parents will never even receive that that scam communication. Are there efforts ongoing to to make personal assistants that will filter that stuff properly? Or is that another missed opportunity?
I mean, this is about having bots to stop bots and with more platform involvement, it'll be more urgent.
Thank you. I yield back.
Chairman yields back. The gentleman from Arkansas, the chairman of the full Financial Service Committee, Chairman Hill, is now recognized for five minutes.
Thank you, Mr. Meuser, appreciate that. Let me start with you, Mr. Schuster. This has been a good discussion so far, but I wanted to get into this idea of collaborating to fight fraud. So under Fair Credit Reporting Act, entities that aggregate consumer information and provide outputs used to make eligibility determinants are often deemed consumer reporting agencies. Which carries a lot of compliance regulations and compliance burden, which is probably right, you know, and including responsibility for accuracy and dispute resolution and things of that nature. But we're also are seeing a lot of financial institutions explore this kind of consortium-based fraud fighting. When I was a banker, we had a phone call every Wednesday in my hometown and it was an off-the-record phone call that probably doesn't comply with federal law or regulation, but it was essentially the ops people in every bank in town saying have you seen somebody wander in the lobby that is doing this. And it's an early warning system and it's like classic American protecting the community, working with each other in a consortium basis, but were we to do that on, you know, in an analytic way using some sort of a more formal system, do you see that people are afraid to do that because of the falling under that shared information falls under that consumer reporting agency designation? What what could we do about that?
It's a great question. And fraud identification is inherently pattern recognition. The more information and data that you have, the easier it is to identify patterns that are abnormal, where there's fraudulent activity happening. Currently, the Fair Credit Reporting Act has very broad definitions and financial institutions, their service providers, technology providers are hesitant to share data that they have that could be used for that pattern recognition, the fraud identification earlier. If there were clarity or a safe harbor under the Fair Credit Reporting Act about sharing data for fraud or how that data could be shared, it would vastly improve financial institutions and all these other companies' ability to share that data and have it available to prevent fraud.
Thank you, that's helpful. If you've got specific ideas of how one might craft a safe harbor like that, hope you'd share those with the with the committee. Ms. McKune, let me turn to you for the from an institution point of view. We know that scamming as we've all heard today has become more sophisticated using AI and deepfakes and forged documents and and we've got people wandering in courthouses and wandering in Bitcoin ATMs and wandering into banks, we know all that and we're all trying to come up with the best whole of government approach to fighting that, but a lot of it falls right back to those financial institutions. Are you trying to use these promising technologies to fight against the scammers that are using technology and do you have comfort with that? Do you have the lack of training, do you have a lack of talent in your institutions? Tell me a little bit about that.
Thank you for your question, Mr. Chairman. We certainly are trying to use technology technology prudently, cautiously, thoughtfully. We want to make sure that we are at least trying to keep pace with the fraudsters. There's always a question in small financial institutions of the cost and of the adoption and of the relative sophistication of both our members and the the fraud community that in which we sit. But we do want to be able to respond faster and all of those tools, the all of government approach, the regulatory reforms, possibly safe harbors, would play into our layered approach. Technology is a piece of it, but one of the things that we try to pride ourselves on as credit unions is our ongoing member-to-member our relationship with our members and our ability to to see them and see what is an aberrant an aberrant transaction and and try to use our judgment.
On a shared draft passing a check that's been washed, for example, are you seeing good cooperation in in for filing a police report in your area? Is are you seeing postal inspectors being helpful or local Secret Service? Tell me about that.
We're always grateful for the law enforcement engagement that we have. We often run up against law enforcement's limitations in terms of resources and their ability to drill in on the harms that we're seeing. One of the things I think is really important to note is that the the amount of resources that law enforcement can invest often is tied to the amount of the loss. And and the the amount of the loss could be absolutely ruinous and devastating for our individual members and not be of a size or of a frequency that that law enforcement can really lean in.
Thank you very much. I yield back, Mr. Chairman.
Chairman yields back. The gentlewoman from California, the ranking member of the full committee, Ms. Waters, is now recognized for five minutes.
Thank you very much. Absolutely delighted to be here at this hearing. And I'm so surprised that the opposite side of the aisle have decided to talk about fraud and abuse. Since Trump and his return to the White House, Trump and his family have made billions thanks to their growing meme coin schemes. At the same time, families are more vulnerable than ever to financial abuse as Trump pushes a reckless deregulatory agenda. He's dismantled the CFPB, that is the Consumer Financial Protection Bureau, rolled back consumer protections and dropped lawsuits against big banks and crypto scammers, making it easier to cheat everyone from retirees, students, and working families while he and his family cash in. And Mr. Barr's bill would weaken UDAAP, that is U-D-A-A-P, authority to the detriment of consumers. And of course we need stronger protections, not less. And I just want to raise a question about all of this that we see coming at the very top of government. Mr. Rust, we've been getting mixed messages from President Trump, where on one hand he claims to care about the affordability crisis and says Congress should enact a law to cap excessive credit card interest rates at 10 percent. But on the other hand, he says it's a hoax and has worked with congressional Republicans to slash the budget of the Consumer Financial Protection Bureau, the federal watchdog for consumers in the financial marketplace. They have also blocked rules like curbing excessive credit card fees. So Mr. Rust, when the CFPB issued its larger participant rule to supervise big tech payment apps, banking groups were supportive of the effort as a way to level the playing field. Should Congress revisit this issue and require the CFPB to immediately begin examining the large payment apps and mobile wallets provided by big tech? Could this help identify payment scams happening on these apps sooner?
Thank you for the question. Yes, absolutely. Congress should restore the CFPB's authority to supervise payment apps and digital wallets. This is a sort of the baseline way to address scams. Access to looking at the activity on these networks is how regulators can spot things, how law enforcement can spot things. UDAAP is the tool we have if EFTA isn't restored to protect consumers. UDAAP was the tool used for the Zelle enforcement action. Again, the CFPB needs to be back in the game.
Well thank you very much. I'm going to go back to the CFPB because... Well thank you very much. I'm going to go back to the CFPB because many of us have worked so hard in Dodd-Frank, we gave the CFPB authority to stop unfair, deceptive, and abusive acts and practices by bad actors. So if the Congress of the United States wanted to do something about fraud, unfair, deceptive, and abusive acts, why don't we just make sure that the CFPB can do what we organized it to do rather than being attacked constantly by the opposite side of the aisle and the President of the United States of America? Wouldn't it be just simple to allow them to do what we organized them to do?
We should immediately restore full funding for the CFPB.
Are you aware of the CFPB and how much money they have returned to consumers?
The CFPB has returned over $19 billion to consumers. That is a direct way to benefit consumers. I can't think of something that makes a greater difference than when you've been harmed and an agency is as responsive the way the CFPB is.
I consider this one of the most dangerous things that have been done by the President of the United States of America with a clear message to consumers to say that he cares about the big boys who are ripping off and who are creating this fraud and does not care about the consumers whom we on this side of the aisle have tried to protect. We've worked very, very hard. I'm so pleased that you're here today, that everybody's here today. Let the truth come out. Let the truth come out and people know where the fraud is really coming from and what the opposite side of the aisle is not doing a darn thing about it.
Well, reforming UDAP would be helpful. The gentleman from Texas, Mr. Williams, is now recognized.
Thank you, Mr. Chairman. Thank all of you for being here today. And I'm a small business owner in Texas and for 57 years community banks and credit unions have kept me going every single day. Many scams targeting small businesses involve criminals impersonating vendors, bankers, or contractors, and these scams often start through spoofed phone calls, email promises, PR social media messaging before the transaction even reaches the banking system. Once the payment is sent through wires or peer-to-peer transfers, it can be extremely difficult, as we've heard already, to recover these funds. So Mr. McDade, how frequently are banks seeing this type of fraud against their small business clients like myself? And what warning signs would small businesses look out for?
Thank you for the question. Banks are unfortunately seeing this very often and it's only increasing. Recently we've seen very specific impersonation scams that are related unfortunately to the PPP loans that were taken out to help small businesses during COVID. A lot of that information is posted publicly in many places. And so the scammers are able to go out on the web and locate where these small businesses bank through their PPP loans. They can even go so far as to get who the individuals are in many cases working at these small businesses, their information. They can then call the banks representing that they're that person and learn who their relationship manager is. They will then spoof the bank's phone numbers and try to contact these small business people to perpetrate fraud. They'll get a text message saying, did you send this wire to another company? Yes or no. They'll respond no, and they'll immediately get a call from somebody representing that they're the very bank that they bank with. Unfortunately, they're talking to a scammer. And this scammer then will tell them to make sure you are who you say who you say you are, please read back the code that I'm sending you. And that code will be, unfortunately, a one-time passcode as the scammer's trying to access the person's account online and do an account takeover. This sort of activity is becoming rampant. And these impersonation scams are especially dangerous because they're also eroding the trust between the financial institutions and our own customers. What banks are doing in response is we're educating our customers. Our specific bank reached out to all of our PPP customers and let them know about this scam. We encourage them, if you ever get a call or a text from our bank that doesn't seem correct, call your relationship manager back directly and talk to that person. And I can tell you from my experience on the CBA's fraud management committee, it isn't just our bank. It's all the banks on the committees who have small business relationships are seeing this exact same thing, and the collaboration that the CBA brings between us is really helpful.
Okay, thank you. Community banks play an important role in protecting their customers from fraud, but they also dealing with a growing wave of check fraud, including checks stolen from the mail, altered checks, and counterfeit cashier's checks. When fraud occurs, smaller institutions often have to spend significant time and resources investigating claims, navigating liability disputes between financial institutions, and attempting to recover funds, and that puts people like me in the back burner to get a loan that we may need. So Mrs. Dempsey, when a community bank spends time and resources dealing with check fraud disputes, what does that mean for their ability to focus on serving customers like our small business people across this country and lending in their communities?
Thank you for the question. You're correct. Check fraud, especially in a small bank like mine, takes a tremendous amount of time. And the majority of the check, as Ms. McKune referred to, so many times the checks are of an amount that it's not going to engage law enforcement and it's also not going to warrant us fighting legal battles to try and get that money back. So it's taking all that time to work through that process. I will say for our bank, if you had had a check stolen out of the mail, we give you money, give you credit back immediately to your account when you identify that. So we work really closely with our customers to not put them in the position of not having access to those funds. But you're correct, it takes a tremendous amount of my time from the CEO down to all of our operations department, to our front line in dealing with that daily and in working with those customers to do that. And that is time that we could be used working with our small business owners, showing them new AI, new things that they can use, new payment systems that they can use to help them be more efficient and to grow their businesses.
Thank you. Ms. McKune, I'm a short time to go here, but your testimony you highlighted the importance of consumer education. What types of outreach have credit unions found most effective in helping members recognize fraud attempts?
Thank you, Congressman. We have tried to use multiple approaches to ensure that different messages are getting through and that the most important messages don't get lost in a lot of communications. So we often will put information in our social media, we will put information about active scams as banners on our website, as landing pages on our online banking. But we also do a lot of work where a community development financial institution and we do a tremendous amount of work in our communities to try to ensure that folks understand what risks are out there and how their accounts really work.
Thank you. My time is expired.
Gentleman yields. The gentleman from Georgia, Mr. Scott, is now recognized for five minutes.
Yes, thank you, Chairman. Mr. Rust, let's get to the heart of the matter. In your opinion, what is the level of damage this is doing to our overall economy? And you mentioned a lot of this, Rust, and what you referred to as this critical gap. What do you mean by that? What is the level of economic damage that our failure to address this critical gap that you talk about? What is the damage? Go ahead.
Thank you for the question. We see reports of $16 billion in fraud losses, but research suggests that that's possibly even 20 times less than the actual number because people feel shame, people don't know where to go, so they don't report it. But the impact on their household is destabilizing, possibly crushing, so that affects our economy. The critical gap, I see a critical gap between the work that's occurring to stop some of these overseas criminal organizations that are already working to move money, move money laundering, human trafficking. They're also doing scams, right? That's their new line of business. And we should be eliminating silos between consumer protection agencies and those agencies. And possibly we should also be thinking about when there's enforcement penalties for BSA/AML violations that if there are scam victims involved, that that should be a way that they receive a remedy.
And what do you feel we here in Congress can do about this? I mean, are we doing enough? Do we address this critical gap through legislation? Is this a money problem of us not punishing these persons who are doing this wrongness?
Yes sir, I believe this is a bipartisan solution. I believe there's bipartisan interest to fix this. Congress can do a number of things. So they should refund the CFPB to begin with. They should restore the payment app rule. That would make a big difference. And I think they should look at, you know, many of the solutions you've heard about information sharing and giving more line of sight between institutions because all of this involves networks. This never is just the send side, it's always receive side as well. So we can make changes. Congress can do a lot.
Yes, so you feel there's nothing more that we need to do as far as dealing with the Bank Secrecy Act itself? Is there things we need to do to make it stronger? Or do you feel that the Act is doing enough?
Well, there's plenty that could be done on that side because that's where law enforcement, where those organizations are sharing information, receiving SARs, assessing problems, and highlighting it for other organizations. So for example, the conversation about SARs is really central here and providing ways for that information to highlight scams, I think is critical.
Well, thank you very much. And I think we need to really focus on what we can do about this because if we can't deal with this, the critical gaps that you're talking about here, there're things we got to do here in Congress to address this. So I appreciate your comments. Thank you.
Thank you, sir.
The gentleman yields. The gentleman from Michigan, the vice chair of the committee, Mr. Huizenga, is now recognized.
Thank you, Chairman Barr. With readily available information and images that are out in the general public on internet and other places, there are many, many people who are victims as both scam targets and as vehicles to go after those victims. A couple of years ago, our office heard from someone whose mother was in an online relationship with an individual. I'll call that individual individual A. Well, using AI, the scammers put individual A's face on a decorated military officer's body, put that face on someone who was being cared for in a hospital. And it's amazing, really truly unbelievable how authentic the images looked because I was individual A. To be clear, there was no online relationship. It was someone who had taken my readily available information and my images and had used AI. And I think it just demonstrates that, frankly, no one is above being caught up in those scams that are going on right now. And sadly, the individual's mother had sent thousands of dollars to someone in Vietnam. We worked with Facebook where the images had appeared and to have them removed, but they kept reappearing. And Mr. Schuster, I'm curious, how much fraud originates actually outside the banking system entirely, such as with social media, telecom networks, or overseas criminal operations?
It's a great question. I think the majority of it. Financial institutions at the end of the day are just where the funds ultimately derive for the scams, for the fraud that originates elsewhere. What used to be in a physical place that somebody was obtaining money is now all digital. Payments are faster than they've ever been. Those technologies that you're talking about are what are used to start fraud and financial institutions need the abilities to do that pattern recognition. They need clear guidance. Their regulators need to permit them to use these technologies from a UDAAP perspective and other things so that if there is something that's happening that happened upstream from the financial institution, which is where it originates, they can address it.
And if most scams originate outside of financial institutions and payment networks, is it fair to place the majority of regulatory burden on those banks and payment providers?
I think it would be great if we gave those financial institutions and payment providers more tools even before we think about liability. I think that we're thinking about liability after a fraud or a scam has occurred. But if there's something that they can do to help people prevent these types of things, that would be great. But I also think that looking at some of those other areas that you've been discussing, social media and elsewhere, that is where there should be focus too.
And I do want to hear from our bankers as well, but very quickly, how do you think we can improve consumer education and outreach on fraud and scam?
I think that it's something that if financial institutions are given the tools or less restraints with respect to how they can look at these items and what they can do to communicate with their customers from data that they have from other institutions, from their service providers, from financial institutions, they'll be able to share more specific information and education with consumers that will be extremely helpful.
How about Mrs. Dempsey and Ms. McKune? By the way, Ms. McKune, I'm going to take a point of personal pride here. My future daughter-in-law happens to be from Danville, Kentucky. For those of you not aware, Danville is a quite small town as I understand. So I'm looking forward to having her in the family soon. But what is your experience with your customers?
One of the things that we think is really key is the ability to share information more broadly. When we're constrained even in just dealing with our respective counterparts in the banking realm and financial institutions, the information we can share is limited and the information that would be helpful is often out of our reach. We're talking about a very time-sensitive exercise and we're talking about something that happens really quickly and with regulatory constraints on how long we can find a pause, that's difficult. But I think it's worth exploring information sharing that goes beyond thinking about financial institutions because so much fraud originates in spaces for which we don't have a vantage point.
Mrs. Dempsey, 10 seconds.
I just concur. More information sharing is critical between banks. We've had experience with banks where we call and they won't give us any information just because of fear of sharing the information even though it should fall under the current regs now that they're able to share with us and they don't. And then you mentioned consumer education. We are constantly educating whether it's through in-person, whether it's through luncheons, online, face-to-face. I've been on the radio. We have weekly articles in our local newspaper. So we're doing everything that we can to make consumers aware of the frauds and scams that are out there, but they change every day.
Thank you. I yield back.
The gentleman from California, Mr. Sherman is now recognized.
Consumers face two kinds of rip-offs. Those from big institutions that do provide a useful service, but sometimes engage in misleading and confusing practices. The chief defense here was the CFPB, which provided almost $20 billion in return money, $5 billion in civil penalties, $363 million back to veterans. And that's just the retribution part. Think of the deterrence. Think of all the scams that never happened. Think of all the corporations that said, we'll never get away with that. So we should not defund those who police our streets, we cannot defund those who police the suites, the corporate suites. But today's hearing tends to focus on the full-time criminals who provide no useful services at all, just rip people off. Mr. Rust, thank you first for the work of the Consumer Federation of America over the many decades. And you've talked about the suspicious activity reports that financial institutions file and the need to allow law enforcement to see patterns, to look not at just one item but what's happening across the country. We could provide that the suspicious activity report include at least two identifiers, both a driver's license number and a Social Security number or a passport number. We could reduce the importance of the narrative portion of the report that can't be correlated with other reports and go more to structured fields. What can we do to make sure that a suspicious activity report doesn't just tell you about one instance, but allows you to link it with what's happening elsewhere?
Right, so this is about appending data and being able to see patterns. Structured information is great for searching. If you're familiar with the Home Mortgage Disclosure Act, that database, everything in it is searchable, it's all structured. If you're a local law enforcement agency working in a state, the ability to search for where that scam occurred, very valuable. The ability to see where funds have transferred across financial institutions, you need to be able to track account numbers, device IDs, things like that. Those are tools that law enforcement needs to build cases against these kinds of situations, right? And so SARs are a tool where the underlying facts can lead to subpoenas that can lead to stopping the problems.
Thank you. And I want to commend our ranking member for his idea that we do need know your customer to apply to all of the wallets, crypto wallets. One issue comes up where an entity impersonates a financial institution. Reuters claim that Meta had 10 percent of its revenue, roughly $16 billion, derived from advertisements for scams and banned goods. Credit unions came to my office and identified a system where a scammer pretends to be your credit union or your bank, so you trust them and all of a sudden you're wiring $500, you're giving out information. And a lot of this comes from advertisements where Meta will let you pretend to be a financial institution when you're really not. Mr. McDade, what can be done to make sure that Meta and similar organizations aren't running ads in the name of a financial institution when it's really a criminal?
Well, I would first point to the SCAM Act sponsored by Representative Meuser. And the reality is we're absolutely correct that one of the largest threats that we have as banks is the misinformation that happens outside of our control environment. And most of the scams...
And you live with know your customer and Meta doesn't know anything about its advertiser.
Well, that's correct. And the study that you cited specifically notes that it is a situation where Meta is putting forth knowingly fraud information into the ecosystem.
Got it. I want to get one other thing and that is we need payee matching so that when you wire money to account number 12345 because it's supposed to go to Santa Barbara Escrow, that that is an account of Santa Barbara Escrow. Because we have seen again and again people lose their down payments, somebody's impersonating the escrow company, the title company, and all they have to do is scam you into their numbered account. Britain has payee matching, we need it too and several chairs of the Fed have said they'd work on it, they still haven't.
Gentleman's time has expired. The gentleman from Georgia, Mr. Loudermilk, the vice chair of the subcommittee is now recognized.
Thank you, Mr. Chair. Before my remarks, I'd like to submit this letter from the American Securities Association into the record. The letter stresses the importance of closer collaboration between financial institutions and law enforcement to combat fraud and scams. I'd like to submit that for the record.
Without objection.
Thank you, Mr. Chairman. I'd be remiss if I didn't bring up something that this committee has already done to help reduce fraud by removing the noise of non-applicable data when it comes to looking for suspicious activities. And that was my Financial Thresholds Modernization Act, which modernizes the CTR and SAR process to reduce the burden on financial institutions so you can focus on what is actually suspicious activity versus what you identify as normal activity. And it reduces the proverbial haystack within the government so we can actually find the needle. And so I encourage my colleagues on the other side to get on board and help us move through the House this important piece of legislation that I think will go a long way to help identify fraud. I've heard a lot about data sharing here today and that is extremely important when it comes to collaboration between financial institutions and law enforcement and other entities, especially when we live in a day and age that the amount of data is unprecedented that is available and out there. And when I worked in IT and security and in intelligence, it wasn't the thought of if the data was going to be hacked or disclosed, it was when. And the idea is to just make sure that your data is more secure than the other data so they will go after the other person. And so I think we have to be extremely vigilant. Mr. McDade, how can we strike the right balance between promoting necessary data sharing and avoiding excessive centralization of sensitive information, which could actually amplify the amount of sensitive data compromised in a breach?
Thank you for the question. First, I would echo some of my colleagues saying a safe harbor for banks to share this essential information. When banks are interacting in the fraud space, we're all on the same team and our fraud fighters are all working together to try and stop a fraud or scam from happening. And if we're prevented due to the amalgam of privacy laws that are being promulgated at the state level instead of the federal level, it really creates a difficult situation for us to be able to communicate with each other. Additionally, one of the recommendations I made in my brief was to, and I believe Mr. Rust spoke to this as well, revise the SAR policy so we have a fraud signal report. And this would not be something that is a lagging indicator, but as soon as we're aware of fraud happening, have a concise way to get the metadata associated with that fraud reported to law enforcement. And if all the banks did that in the same fashion, they could immediately cross-reference that essential data and see the patterns and actually reach out and warn other banks that they might have fraudulent accounts, or even go upstream to the telcos and the social media accounts and let them know, we're seeing fraud on this phone number or on this account, please take it down.
Well, thank you. One thing that I'd learned throughout my time in information technology and security is you don't have to protect data that you don't have. And so only collect and hold that which you actually need, which again goes back to the modernization of CTRs and SARs. But what role can technology such as anonymizing or otherwise protecting sensitive data play to help mitigate concerns over information sharing?
I think it's essential to be able to anonymize the data in a way that protects the consumers while still giving the key data that is what we call in the industry fraud signals. These signals are pieces of information that if they're shared across can show a pattern of fraudulent activity and point back to the source where that fraudulent or scam activity is coming from. So while anonymizing our consumers' data is very important, the IP address, MAC address, and some of the other data coming from a fraudster's computer attacking our resources is something that we should be able to share with law enforcement at least, if not other banks.
All right, thank you. I don't think I have time for other questions, so Mr. Chairman, I'll deposit my remaining time in hope that maybe I'll earn interest for a future hearing.
So deposited. The gentleman from Illinois, Mr. Casten, is now recognized for five minutes.
Crypto ATMs and Pig Butchering Scams
We may have to apply a Howey test to that deposit. Thank you, Mr. Chairman. Thanks to all the witnesses for being here. I want to follow up on some questions that Dr. Foster raised at the start about Bitcoin ATMs. The FBI's reported that Americans lost a third of a billion dollars in crypto scams, crypto ATM scams in 2025. That was a 33 percent increase from the year before. These scams, as I think many of us know, particularly target seniors. I actually, this became personal, I got a call from a constituent earlier this month whose brother had lost $190,000, essentially all of their wealth, to one of these pig butchering scams. I don't know the details of theirs, but for people who are watching, it's more or less as you described, Mr. Schuster. It starts in a social media, maybe it's a dating app, maybe it's your Facebook page, I want to be friends, I'm really attractive, you should talk to me, I have an investment plan, and you build these relationships. And then pretty soon you need a little help to get out of a jam or you've got an investment opportunity, please go to the local crypto ATM and transfer me some money now that you trust me. And it's really, I think, taken advantage of the fact that social media is almost perfectly designed to make people believe impossible things, and crypto ATMs are almost personal perfectly designed to monetize that lie. Because once you put it in there, the transaction is immediate, it's irreversible, it can use the ecology of the crypto system through mixers, through chain hopping, through anonymous wallets to make it untraceable. And the stories are painful, and I don't know, Mrs. Dempsey, Ms. McKune, I'll let the two of you argue it out who wants to take this, but I'm curious how your members are dealing with this, because presumably they have to come to one of your banks to withdraw real money in the first instance. Any of you want to comment?
Yes, thank you for the question. And as I mentioned in my written testimony and today, it's rampant. And we deal with it on the front lines like I mentioned. We have had multiple experiences where we have sat down with a customer and we've pulled up, we've literally pulled up Facebook and showed them the photo, and they've told us, oh, they told us you were going to do that. We've shown them FBI reports. We do everything that we can from our end when we identify those to stop it and to inform them. And as I mentioned, they're changing every week, and I know every one of us could tell story after story of whether it's a pig butchering, an investment, whether it's romance, whether it's your child, your grandchild is in jail, all the things. We see it every single day.
So you, and I don't want this to sound the wrong way, I'm sure you do that for good and ethical reasons. You also do that because you're bound by know your customer rules, right? So if they're going to withdraw the money, you need to know something about who is the identity, what's the, you know, all the registration and reporting requirements. Would you be supportive of rules that said let's apply those same rules to crypto ATMs, make them go through the same KYC rules so this isn't all on you and your local bankers?
Personally, yes. I think everyone should have to know their customers because I think if you know your customers, there's a lot of fraud that could be stopped at the point of origination.
Okay. I want to just point out that the Trump administration has made some positive noises about this, but everything that they've done so far has been voluntary. And I think it's pretty clear that the voluntary standards aren't working. We're seeing evidence that if one state has good rules and the other state has bad rules, the scammers will say, hey, don't do this in Illinois, but drive across to Hammond, Indiana and maybe use the crypto ATM over there. So I would agree we need some policies, some federal policies. Mr. McDade, if you'll forgive me, I was looking on your website before we got here, and I saw that at EverBank, you don't allow people to do ATM withdrawals of more than $2,000 a day, I think a bit more if it's a PIN-based transaction. Is there any reason we shouldn't employ those same standards for crypto ATMs?
Every institution has their own risk tolerances and sets those risk tolerances appropriately for their institution. My view would be similar to what was just said as far as the crypto ATMs. The difficulty is us being able to inform our customer that they're sending money to the right place and the right account, and the KYC rules assist with that so on the other end we can see that this is going to a legitimate place.
Well, I, you know, just close with one last story and I would welcome any of your input. We're trying to work on some legislative fixes and if you have good ideas, please share them. One of the smaller towns that I represent does not have a super strong local economy. The mayor struggles to come up with enough money to pave the roads, and most of their tax revenue comes from a very small set of convenience stores. And one of the convenience store owners, his primary source of, his biggest source of revenue was a Bitcoin ATM. And he took it out in spite of its importance to that community because he just kept watching seniors come in every day and make deposits and then come back later and ask how to get it out. And I don't know how the people who do that look at their kids at the end of the day and say you can be proud of what dad did today. But as our former colleague Elijah Cummings was fond of saying, we're better than this. Thank you, I yield back.
The gentleman from Pennsylvania, Chairman Meuser, who's done a lot of great work on this issue, is now recognized for five minutes.
Thank you, Chairman, very much. And thank you certainly to our witnesses. The FTC reported $12.5 billion which was reported in fraud losses last year. We of course know the real number is far higher. By the way, between 2021 and 2024, CBO reported scams and fraud was up 110 percent under the CFPB's oversight. So doubling down on failure is pretty much the last thing that we're going to do to solve this crisis. Fraud and scam roundtables have been held by our committees. Telecom companies have been invited in, tech platforms hosting tele-town halls with community banks, working with our U.S. Attorney General's office as well as state Attorney General's offices. We've been working at it since the beginning of this Congress and we are making progress and we are as determined to fight this crisis situation as you folks clearly are. Ms. McKune, I'd like to start questioning with you. By the way, great testimony, really appreciated what you had to say. From your experience, how effective is consumer education preventing scams before money ever leaves a customer's account?
Thank you for the question. We see this as an essential piece of how we're protecting our consumers. We absolutely have to have educated consumers because many times, as Mr. Rust has noted, there's so much shame involved in admitting that you've been scammed. That's one layer of the problem. The other is that these are, they call it social engineering for a reason, right? These are manipulations of people's vulnerabilities and the things that they worry most about. And so if we're in a position where they are not going to answer our questions, they're not going to tell us what's happening, the best tool we have really, the very first tool has to be fundamental understanding and sophistication in consumers about the risks of fraud. And it's why we're really supportive of an all-of-government approach and a top-down consumer education movement because we do really see it as the essential first step.
Yes, all government, all the private sector, very holistic, and that's that is definitely the strategic plan. Mrs. Dempsey as well, great opening testimony, thank you so much. When a customer walks into one of your branches after they've been deceived online, what options do you and other community banks realistically have to stop loss at that point?
Well, if they've already sent it, there's not a lot that we can do at that point if it's been outside our bank. And to Ms. McKune as well, just the education, the ongoing education of trying to inform them before of when they're coming in to get the money, of being bold enough, like I mentioned, we've got really strong relationships with our customers so we know them. So our tellers do an incredible job of really just asking questions. What are you doing with this? Why do you need to take this much out of the bank? And things of that nature. I know we've talked too about just an overall approach, and so I want to highlight like with the ICBA, one thing we did with the U.S. Postal Inspection Service was to come up with an in-branch handout to give to consumers to educate them and to start a conversation on fraud and scams. And so hundreds of thousands of those have been given out at almost 1,000 banks, and so anything that we can do to bring attention to it and to stop it before it happens.
Thank you very much. Mr. McDade as well, excellent testimony. How important would it be for social media platforms were required to verify advertisers and quickly remove scam ads once they've been reported? A number of you have referenced the SCAM Act. The SCAM Act will certainly be requiring this of social media companies with penalties that are appropriate. Go ahead, please.
I would say it's essential. The reality is these scams originate outside of our bank's control environment. They most of them, I believe there's a study out of Britain that said 80 percent of the scams that they were seeing in that country they alleged came from Meta as a platform. So when you take a look at that, we need to do something in order to have correct accountability in those places.
Okay, excellent. You know, I was in New York City, we visited BNY Mellon and JP Morgan's fraud and scam prevention centers spending millions, if not with a B, billions on tracking and preventing scams. Do you believe telecom providers and social media platforms are making the same level of investment to stop scams?
Unfortunately they're not. And while we do try to partner as well as we can with the telcos and the social media, the reality is since they don't bear any of the liability, they don't bear the responsibility as far as they're concerned. We've actually reached out to the telcos and asked them to have a, this is a scam email alert on the phone just like you get this is the spam. The truth of the matter is they're regulated for spam, they're not regulated for scams, and so we haven't gotten the response that we need.
Thank you. I'm almost out of time. Mr. Schuster, I had a question for you on what else regarding preventing scam calls and texts from reaching consumers in the first place, but I am out of time. Perhaps we can talk about that offline. I yield back, Mr. Chairman.
The gentleman from Massachusetts, Mr. Lynch, is recognized.
Thank you very much, Mr. Chairman. First of all, I want to thank the panelists. You've all been terrific and thank you for your work on this issue. Honestly, I feel though that if this is Consumer Protection Week, we should probably drape the Capitol in black crepe because consumer protection is dead. It really is based on what's been happening here lately. I honestly think that President Trump is ushering in the golden age of fraud with all the actions that he has done. Since January of 2025, this is just his second term, we're not going to touch the stuff in his first term, the Trump administration has undertaken unprecedented efforts to undermine the Consumer Financial Protection Bureau through systematic dismantling. The one agency that is charged with protecting the consumer. This is the one agency that Congress has identified and structured to protect the consumer. And yet the administration moved immediately to effectively shut down CFPB by declaring its funding structure unconstitutional, unlawful in November 2025, and it refused to seek additional funding from the Federal Reserve, which just would have starved the agency. On February 10, 2025, Acting Director Russell Vought issued a stop work order instructing all CFPB employees to stop protecting American consumers and to not perform their work tasks as the agency announced it would run out of money by early 2026. The administration also moved to terminate nearly all CFPB staff. This is during the DOGE scourge. And they canceled the administration canceled about $100 million in employment contracts for those employees whose job it was to protect consumers. Although a federal judge eventually ordered a pause of those actions in February, many of those employees who were very valuable, very capable and qualified employees were placed on administrative leave and were unable to perform their duties and eventually many of them left because they felt they had such uncertainty. And remember, this is the agency that CFPB returned $19.7 billion from people who had scammed consumers. Put that money back in Americans' pockets. $5 billion, the amount of money that CFPB had imposed in civil money penalties on companies and individuals that violate the law. And especially, and this is key, we do a lot of work at Fort Hood and some of these big bases, they recovered $363 million in monetary relief resulting from 39 public enforcement actions that involved harm to service members. They're not being paid enough to begin with and these are a lot of young families that are barely making it and also veterans, including six enforcement actions for violation of the Military Lending Act. So that's what Trump is eliminating, that ability. And this is all I'm not even going to get into what the Trump family themselves are doing. This is the same time so the Trump family launched Liberty Financial. This is Trump's sons, all of them, also Zach Witkoff, who is Steve Witkoff's son. And they launched that at the same time that the Trump administration eliminated the Crypto Crimes Enforcement Unit. So he goes into the business in crypto and then he eliminates the Crypto Crimes Enforcement Unit. Tell me that's not connected. He dropped enforcement on a ton of actions at the SEC and the CFPB. He rolled back a bunch of rules curbing scams at payday lenders. He delayed the implementation of the fiduciary duty rule. So he's done all this to, as I say, to launch the golden age of fraud removing enforcement. So Mr. Rust, what do you think about our ability to conduct current enforcement actions and guardrails in order to protect consumers? Where do we stand right now given all that I've said?
Well, it's true. It's been gutted, right, in so many ways. I think in the brief amount of time I want to highlight how they're not helping service members, which is one of the things the Bureau has always done. There has not been a visit to a military installation. There have been no market monitoring reports to prevent scams targeting service members and veterans. No annual report to understand priorities or complaint trends. The dropping of the Navy Federal Credit Union enforcement action and the MoneyLion settlement pennies on the dollar and their most recent RIF plan would have left the Office of Servicemember Affairs with no staff.
Thank you. Thank you, Mr. Chairman. I yield back.
Gentleman's time is expired. The gentlewoman from California, Ms. Kim, is now recognized for five minutes.
Interagency Coordination and Law Enforcement
Thank you. Thank you, Chairman, for holding this hearing and I want to thank our witnesses for joining us today. You know, in California, we are in the golden age of fraud with more types of fraud than Baskin-Robbins has flavors of ice cream. Sadly, our Governor Gavin Newsom has done little to stop this crisis. That is why I introduced the No More SCAMS Act that would create a federal strike force dedicated to investigating fraud involving federal dollars, bringing fraudsters to justice and clawing back stolen taxpayer dollars for the American people. I believe that we can learn a lot from the private sector and the great tools that you have employed or deployed to combat fraud and scams to put the consumers first. So I want to ask the first question to you, Mr. McDade. How do banks leverage third-party fraud tools to work across financial institutions and prevent scams and fraud?
Thank you for the question. In banks the size of EverBank, we're a mid-sized regional bank, we do have a national presence and we do have a presence specifically in California. When we look at it, we don't necessarily have the resources to build our own AI constructs, we don't have the data scientists necessarily to do that. So we depend on groups like LexisNexis, AWS, and other consortium-based tools to help us find the fraud signals out in the environments that they touch, report those signals to us so we can collaborate back and forth and risk rate transactions and risk rate potentially fraudulent customers that are trying to break into the fraud ecosystem and they're essential partners for us.
Sure. That's exactly why we need to do something similar at the federal level to streamline those efforts, right? And then there are third-party fraud fighters who are successful because they can dialogue with different financial institutions and connect different pieces of puzzle. Similarly, the task force that I envision through this legislation, No More SCAMS Act, will be able to utilize the resources of the different federal agencies and combine both the manpower and the information to track down those fraud. Mr. McDade, how does improved coordination across agencies can stop scams in the banking system?
So we are calling for a national task force on fraud and we think that one of the things we need is alignment across all the different agencies and all the different law enforcement entities. The reality is as I talked about in my testimony, when a fraud report is made by a consumer, there isn't necessarily a specific agency that they can point to to pick it up because different agencies have different mandates and then you have the local law enforcement. I would say something that could be done in that direction would be the GUARD Act that's being talked about, which is similar to the HIDTA program that I worked with as a prosecutor where we allow the federal resources to partner with the state resources for these $20,000 to $50,000 scams that are hitting our banks that don't rise to the level of federal prosecution but are multi-jurisdictional and so there's a difficulty with law enforcement approaching them.
Thank you. Thank you. You know, one type of financial fraud that I've seen particularly focused on is the credit repair scams. And you know, I serve as the co-chair of the Financial Literacy and Wealth Creation Caucus and I've seen the damage of those scams on consumers who are exploited by false promises involving their credit scores. To that end, I'm co-leading the Ending Scam Credit Repair Act to help end those types of scams and prevent bad actors from stealing money from hardworking American families. So Mr. Chairman, I would like to ask for unanimous consent to submit this letter that I got from American Financial Services Association emphasizing the need to end the need for this type of legislation.
Without objection.
And I also have another letter from SIFMA to also support.
Without objection.
Thank you very much. Let me shift the gears now. I want to also focus on romance scams and the work that is being done to crack down on them. I was proud to lead the effort to have the Treasury Department identify romance scams facilitators in Cambodia as money laundering entities and while that was a great step in the right direction to cracking down on bad actors, we must also focus on ways to prevent those scams at the point of attack as well. So Ms. McKune, how are credit unions like Park Community using methods such as consumer education to prevent romance scams before before the money gets taken?
This is part of our broad consumer education efforts. We are aware that romance scams are a problem, not to make light in any way of the way our members are victimized, but Keanu Reeves might need to come before the committee. Keanu Reeves is someone who gets pulled out as people posing as Mr. Reeves and we've had multiple members who believed that they were in a relationship with Mr. Reeves. We know about them, we try to educate our members and we move as quickly as we can when we see the the signs of those.
The gentlelady's time is expired. The gentleman from Texas, Mr. Green, is now recognized.
Thank you, Mr. Chairman. Mr. Chairman, a better name or better title for this hearing would be Fighting Fraud on the Front Lines: Challenges and Opportunities for Trump, the Trump administration to engage in corruption. Let me start by asking unanimous consent that certain articles be introduced into the record. The first is styled Melania Trump's meme coin architect accused of pump and dump fraud in lawsuit. The second one is styled Trump meme coin down 96 percent as Bitcoin and meme coins slide. And then I have a third. The third one has to do with Kristi Noem. Firm tied to Kristi Noem secretly got money from 220 million DHS ad contracts. Allow me to go through these articles very quickly. I think they paint a picture of corruption. The first is in The Guardian, the one styled did I get unanimous consent, Mr. Chair, to introduce my articles? Mr. Chairman, Mr. Chairman.
Without objection. Thank you.
The article from The Guardian styled Melania Trump's meme coin architects accused of pump and dump fraud in lawsuit. Reading it in various portions, we find the language the dollar sign Melania coins were released for just a few cents each on 19 January, the day before Donald Trump was inaugurated. I'm paraphrasing. And then it goes on to say within hours this coin price soared to $13.73. Then it goes on to read, however, it then collapsed almost as quickly and is now worth about 10 cents, less than one percent of its peak price. Goes on to add that at its peak it was worth $45.47. It goes down to $5.79. Article goes on to indicate the Trump family has pocketed more than $1 billion, more than $1 billion in pre-tax profits from several cryptocurrency-related products over the past 12 months. Then we have the second one, Trump meme coin down 96 percent as Bitcoin and meme coins slide. Reading in part from the article, last February the coin's market capitalization stood at 3.5 billion, already well below its 14.5 billion peak on the eve of his second inauguration. Today it has fallen to 1.78 billion. And then it reads in part that the scale, we're talking about a pump and dump scheme here, it talks about the scale of this pump and dump scheme involving at least 15 cryptocurrencies included the dollar Melania currency. And it indicates that of course the coin is down 96 percent in this scam. Now let's move over to Secretary Noem. Secretary Noem. Article styled firm tied to Kristi Noem secretly got money from 220 million, 220 million DHS ad contracts. 143 million has gone to a mysterious LLC Delaware company created just days before it was awarded a deal. The corruption that this administration has imposed upon the public, pocketing big money from pump and dump schemes is unbelievable. When you read it, it's almost like reading a corruption story in some magazine. I'm going to yield back the balance of my time, Mr. Chairman, but I think that these things have to be further investigated.
Gentleman's time is expired. The gentleman from South Carolina, Mr. Timmons, is now recognized.
Thank you, Mr. Chairman, and thank you to the witnesses for being with us today. Financial fraud and scams are becoming one of the fastest growing financial crimes facing Americans. Increasingly these schemes are carried out by large-scale criminal networks operating overseas, often using sophisticated technology, coordinated infrastructure, and social engineering tactics to target Americans at scale. As these operations evolve, financial institutions are often the first line of defense. Banks and credit unions are responsible for detecting suspicious activity, protecting their customers, and coordinating with law enforcement. But as fraud networks grow more complex and increasingly operate across borders, it raises serious questions about whether our current legal and regulatory frameworks are fully equipped to support the institutions working to stop these crimes. Mr. McDade, in your testimony you noted that the FBI received more than 850,000 IC3 complaints involving over $16 billion in losses last year alone. Based on your experience both in the banking sector and as a former prosecutor handling complex fraud cases, would you agree that a significant portion of these modern scams are being conducted by large organized criminal operations operating in foreign jurisdictions?
Yes, the evidence is very clear that that's happening. We get phone spoofs that are coming from overseas phones. Our bank is a primary digital bank and we're able to often detect whether or not things are coming from overseas and a large number of the fraud accounts that we see attempting to be opened are from overseas. And there's been some very strong media coverage about that, the New York Times and The Economist showing scam compounds as massive organized crimes larger than in some cases the drug trade in Southeast Asia and Africa.
Thank you for that. How do these operations differ from the more traditional fraud schemes we saw a decade or two ago?
Well, the reality is they're able to leverage at scale some of the techniques that used to be done piecemeal. They're gathering data from data breaches, they're gathering data from as I said earlier publicly available resources such as the PPP lending site and they're cross-referencing those, we believe using artificial intelligence and machine learning in order to create profiles that they're able to know a great deal about the individual customers they're approaching and take a focused effort with knowledge of how that customer normally transacts in order to fool them into believing that they're trusted sources they approach them.
So technology is largely to blame for the more sophisticated version of scams and frauds?
The scammers and fraudsters are using technology at scale is what we're observing.
And is it fair to say that 20, 30 years ago if you were to engage in this, it's going to be on a small scale and you're going to have a higher propensity of getting caught by law enforcement?
I would say that it is much easier for them to avoid law enforcement because they can have anonymity online as they're doing this work.
Well, it's not that they have anonymity, it's that we don't have the jurisdiction to pursue criminal charges and hold them accountable. Is that fair?
That is fair to say when they're multinational it's much more difficult to have prosecution.
So but we can use the resources that we have to address attribution. It's not easy, but we have the ability to figure out who is engaging in certain scams. Is that correct?
At time it is possible that we can point to specific areas and specific individuals overseas.
Do you know of any other area of crime that the United States government just doesn't enforce? I mean, we have the ability to hold these people accountable in foreign jurisdictions, we just don't do it. I mean, is that fair to say? I mean, we could figure out who is engaging in $16 billion worth of fraud and we could hold them accountable but we choose not to.
I can't really speak to the specific efforts that are happening there, but I would agree that everybody agrees that more attention to fraud and scams and a more significant approach is absolutely necessary.
Obviously education to make Americans protect themselves better is huge, but I mean everyone is susceptible to a certain degree and I just feel like the federal policy should address this and should say if you're engaging in organized crime, we're going to attempt to arrest you and if you're in a non-extradition country, we actually have other tools in our toolbox. The president's favorite word is tariffs and he could say, all right, we're going to make the victims whole and then we're going to impose tariffs to recoup our losses or you can just give us the person that committed the crime. I mean, so we do have the ability to hold these people accountable and to make the victims whole, but we choose to not do that. I mean, we could hold organized crime accountable in Eastern Europe and Southeast Asia, but we choose not to. Is that fair?
I would just say that banks would welcome any resources the federal government wanted to bring to bear to help stop this epidemic of fraud and scams.
Well, I couldn't agree, we need to get our act together and I appreciate you all being here today. With that I yield back. Thank you.
The gentleman yields. The gentleman from Wisconsin, Mr. Fitzgerald, is recognized.
Thank you, Chairman. Thank you for being here today. I know it's been a couple hours, so I appreciate that. So I was at a bank in my district last week, prominent bank in Southeastern Wisconsin and we had a very good discussion with staff at that bank about fraud. And then we had credit unions this week in DC, so I talked to a number of people about I don't think this topic came up, maybe it did, maybe it touched on it this morning, I've got Judiciary going on as well, but in both of those instances, there was a component of this which is related to family members that actually are part of the fraud or sometimes bilking for the most part the targets are adults and it's another family member is having a discussion about one of their accounts and it's not until kind of the front line, which is oftentimes the person working at the credit union or the bank that's in a teller position that kind of realizes something isn't right. So I was just wondering if I could just get a thought on the family aspect of this and certainly law enforcement, I mean they don't want to get involved in any of these fraud-related scams that are nationwide, but when it includes a family member, it's even more hands-off is what I'm being told. I'm wondering if that if you believe that is the case and Mrs. Dempsey.
Not in our community and that falls for us it sounds like more under adult protective services when we see family members that are taking advantage of an elderly grandparent or aunt or uncle of things of that nature. I'm not sure if that's what you're implying.
Yeah, that's what the discussion is.
Yes, or a caregiver, you know that's gotten control as an authorized signer on their account or something of that nature. So for us in Tennessee, we've also got very good laws to help us with elder abuse and prevention and protection. So we have a good relationship with our law enforcement and with adult protective services when we recognize that and see it happening.
Very good. Mr. McDade.
I would echo the fact that we would approach adult and family services within our elder care program when we do detect something that could indicate that someone's being taken advantage of by somebody close to them. There are processes to do that. It's usually through the state's attorney general's office in the various states that we do business in and we regularly make those reach outs when it's appropriate.
Very good. Ms. McKune.
I want to note that one of the things that I think can give law enforcement some trepidation is how very complex these situations are. They rely heavily on us to try to unwind and figure out what's going on. We lean into our tellers and our branches when they have good relationships and know some of the dynamics, but it's unquestionably true that vulnerable folks are vulnerable and that that can be family members, that can be people they've designated as powers of attorney, etc. And so we do as much as we can to package the information to say this is why we believe this is what's going on.
Very good. Mr. Schuster.
Thank you. It's a great question and I think you're hearing that financial institutions are doing a lot to identify these frauds. They're many times on the front lines identifying where there is family fraud, potential elder abuse and reporting that and that helps. This is not something that the CFPB is doing. This is financial institutions themselves and having laws that restrict their ability to stop these types of things are where there is impediments to continuing to help consumers.
Very good. Mr. Rust, I don't know if you have a comment on that topic.
I'd agree with much of what's been said, but I also want to emphasize that the size of reporting, you know, if the amount is only two or three thousand dollars, which is still plenty, that needs to be routed up to law enforcement. I think a whole of government approach to public infrastructure surrounding complaints, people shouldn't have to know which agency they should complain to, right? That information should be if it ends up in the wrong agency shared with the correct agency with the kind of customer service relationship work that the Bureau has always shown.
Very good. Thank you so much. I yield back, Chairman.
Gentleman yields back. I would like to thank all of our witnesses for their testimony today. We've come to the end of this hearing. Without objection, all members will have five legislative days to submit additional written questions for the witnesses to the chair. The questions will be forwarded to the witnesses for the response. Witnesses, if you could please respond no later than April 9th if you do get such written questions. And again, I want to thank all of our witnesses for your excellent testimony and contributions. I think we heard a lot of good recommendations here today to deal with this multi-billion dollar problem for the American people and hopefully we can make progress. And thanks for all the great work that you all do protecting your customers and the American people. This hearing is now adjourned.
Same-day access
Read every hearing transcript the day it happens
Paid seats unlock fresh transcripts immediately, including synced video and clear summaries.



