What are scams (social engineering fraud)? | Transmit Security

Glossary

What are scams (social engineering fraud)?

Scams are social-engineering attacks that manipulate victims into handing over money, data, or access. Learn the main types and why they’re so hard to stop.
by Transmit Security

Scams are social-engineering attacks in which fraudsters psychologically manipulate victims into voluntarily handing over money, sensitive information, or access, rather than breaking in technically. The target isn’t a system; it’s a person. And because the victim acts of their own accord, scams bypass most defenses built to stop unauthorized access.

Scams work because they attack the human layer, which is far harder to patch than software. As authentication and fraud detection have hardened, fraudsters have shifted to manipulating the legitimate user into doing the damage themselves.

The main types of scams

  • Impersonation scams: posing as a bank, government agency, employer, or trusted brand to extract money or data.
  • Authorized push payment (APP) scams: manipulating a victim into authorizing a payment to the fraudster.
  • Investment and crypto scams: fake opportunities promising unrealistic returns.
  • Romance scams: building a fake relationship to extract payments over time.
  • Phishing, smishing, and vishing: deceptive emails, texts, and calls that harvest credentials or push action.
  • Tech-support and "safe account" scams: convincing victims their money or device is at risk and must be "protected."

Why scams are so effective

Scammers exploit universal human triggers: urgency, fear, authority, greed, and trust. A convincing story ("your account is compromised, move your money now") short-circuits careful judgment. Generative AI has made scams sharper and more scalable: flawless phishing messages, cloned voices of loved ones or executives, and deepfake video that lends false credibility. The democratization of these tools means more scammers running more convincing scams than ever.

Why they’re hard to stop

The defining challenge is that the victim is a willing participant. Controls that verify identity or block unauthorized access don’t fire, because the real customer is authenticating and authorizing. Traditional fraud detection asks the wrong question. Stopping scams requires detecting the manipulation (behavioral signs the customer is acting under coercion or a coached script, remote-access tools controlling their device, out-of-pattern payments to new payees) and intervening in real time with warnings or friction before the damage is done.

The defense against scams

Because scams span channels and exploit the human layer, defense combines behavioral analytics (spotting coached or out-of-character activity), device and session intelligence (detecting remote access and manipulation), transaction monitoring (flagging risky payments as money moves), and real-time intervention (interrupting with a warning or step-up at the critical moment). Industry frameworks and regulations (anti-scam accords and reimbursement rules) are also mobilizing banks collectively. No single control stops scams; the layered, identity-and-fraud-fused approach that watches behavior across the lifecycle is what gives institutions a fighting chance against an attack aimed squarely at their customers’ minds.

The scale of the scam epidemic

Scams have grown from a nuisance into one of the defining fraud threats of the era. As banks hardened logins and payments against unauthorized access, fraudsters pivoted to the softer, unpatched target: the customer. Losses to scams now run into the tens of billions annually across major markets, and the trend is upward, not down. Two forces drive it. The shift of life and money online gives scammers endless reach, and the democratization of AI tools lets even unsophisticated criminals run convincing, scaled campaigns. Regulators have taken notice, which is why reimbursement rules and anti-scam accords are appearing: the losses have become too large and too visible to leave to individual vigilance.

Educating customers vs. protecting them

A common instinct is to fight scams with customer education, warnings, awareness campaigns, "your bank will never ask you to…" messaging. Education helps at the margin, but it’s not a solution, and leaning on it too heavily shifts blame onto victims who were expertly manipulated. Scammers are professionals exploiting universal psychology, often against people in a moment of fear or urgency; expecting every customer to out-think them is unrealistic. The more durable approach treats protection as the institution’s job: detect the manipulation with behavioral and device signals, and intervene in real time, rather than relying on the victim to catch a con designed specifically to fool them. Education and protection work together, but technology that interrupts the scam mid-flight does the heavy lifting.

Frequently asked questions

How big is the scam problem?

Scam losses run into the tens of billions annually across major markets and are growing, driven by digital life and AI-powered manipulation.

Is customer education enough to stop scams?

No. It helps marginally, but scammers exploit expert manipulation; real-time behavioral detection and intervention do the heavy lifting.

What is a scam in fraud terms?

A social-engineering attack that manipulates a victim into voluntarily giving up money, data, or access.

Why are scams so hard to prevent?

The victim willingly participates, so controls that block unauthorized access don’t trigger; you must detect the manipulation instead.

How is AI making scams worse?

Generative AI produces flawless phishing, cloned voices, and deepfakes, making scams more convincing and scalable.

How do you defend against scams?

Behavioral analytics, remote-access and device detection, real-time transaction monitoring, and timely intervention, plus industry anti-scam frameworks.

Related: Authorized Push Payment (APP) Fraud · Phishing · Social Engineering · Deepfakes · Behavioral Analytics · Scam-Safe Accord

Request a Demo

By clicking the button, you agree to the Terms and Conditions