They Didn't Exploit Our Weakness. They Exploited Our Virtues.

In 2025, Americans lost more than $20.8 billion to internet crime, a 26% jump in a single year, according to the FBI's IC3 Annual Report. Older Americans absorbed the worst of it. Adults 60 and over filed 201,266 complaints and reported $7.7 billion in losses, a 59% increase over 2024. More than 12,000 seniors each lost over $100,000.
A previous post on this site argued that those losses aren't happening because Americans are careless or technologically illiterate. They're happening because organized crime networks have learned to weaponize American culture: the politeness, the trust in authority, the willingness to help a stranger on the phone.
This post takes the next step. Because culture is only half of it.
The other half is the infrastructure we built around that culture, the speed, the privacy, the decentralization, the rule of law. Every one of those achievements has been turned against the people it was supposed to protect.
They didn't exploit our weakness. They exploited our virtues.
They Studied This Country the Way You Study a Lock
The people running these operations are not technical geniuses. They are systems analysts. They studied the United States, its banking infrastructure, its legal protections, its jurisdictional structure, its civic habits, and they found the gap between how the system was designed to work and how it actually works when someone deliberately bends it.
What they found was that everything we built right is also what makes us soft.
We answer the phone because we were raised to be polite. We trust authority because we built institutions worth trusting. We move money fast because we built the fastest financial system in the history of the world. We protect privacy because we wrote laws to keep our government from spying on us. We respect jurisdictional boundaries because we built them to prevent overreach.
Every one of those choices is correct. Every one of them is now an attack surface.
The Speed They Built For Commerce
Wire transfers and instant payment systems were built so a small business owner could make payroll on a Friday. So a contractor could pay a supplier without two weeks of float. So commerce could move at the speed of decision-making.
A criminal network does not need that speed for commerce. They need it because once they convince a 74-year-old retired teacher that the FBI has frozen her accounts and she needs to "secure" her savings, the entire fraud has to complete before her daughter calls to check in. The window from the first ring of the phone to the irreversible departure of the money is measured in hours, sometimes minutes.
And once that money leaves the account, it is gone. Wire transfers settle in minutes. They are considered irreversible by design. Cryptocurrency transactions, which accounted for $11 billion of the 2025 IC3 losses, settle in seconds and are immutable on the blockchain. Recovery is rarely just difficult. In the overwhelming majority of cases, it is structurally impossible.
The speed is not a flaw. The speed is the feature. That's what makes it so effective as a weapon.
The Privacy They Built For Citizens
We have privacy laws that prevent financial institutions from sharing transaction data without specific legal process. We wrote those laws to protect ordinary people from their own government. They are good laws. They serve real people in real situations.
They are also exactly what organized crime networks route their patterns behind. A pattern of suspicious transactions across three banks in two states cannot be assembled into a single picture without legal process that takes days or weeks. The criminal network moves faster than the legal process. By the time the picture is complete, the operation has moved to new accounts, new mules, new wallets.
The same applies to encryption, VPNs, and anonymized payment systems. We built encryption so a dissident in Tehran could talk to a journalist without getting killed. End-to-end and unbreakable, a miracle of engineering designed to protect the most vulnerable people on earth. Right now, somewhere in this country, a man is using that same encryption to coordinate the pickup of $40,000 from a retired postal worker who thinks the IRS is going to arrest her.
The technology works exactly the way it was designed to work. That is the problem.
The Jurisdictional Structure We Built Against Tyranny
The United States has more than 18,000 law enforcement agencies. Each one operates within its own jurisdiction, maintains its own databases, follows its own protocols, and protects its own case counts. That structure exists for a reason. We built it deliberately to prevent the concentration of police power that history has taught us to fear.
The criminal networks studied that structure too.
They route transactions across jurisdictional lines on purpose. They use mules in one state, call centers in another country, banks in a third, and crypto exchanges in a fourth, not because that's geographically convenient, but because every line the money crosses adds friction for investigators and zero friction for them. A detective in Los Angeles has no automatic way to know what a detective in Houston filed last week about the same phone number, the same wallet address, the same script. The information may exist. Getting it requires formal requests and processing times measured in days.
The criminal network moves across six jurisdictions in an afternoon. American law enforcement takes eleven days to share a phone number.
This is the asymmetry that has to break.
The Aftermath We Refuse to Call Violence
Under most current legal frameworks, financial fraud is a non-violent offense. That classification carries real consequences. It affects bail decisions, sentencing guidelines, diversion eligibility, and prosecutorial priority. A mule who picks up cash from a victim and drives it to the next drop can be arrested, processed, and released in hours under zero-bail policies that treat her conduct as non-serious because no one was physically struck.
She can be back at work the same afternoon.
The victims she left behind are experiencing something the research literature has begun to describe more honestly. A FINRA survey found that two-thirds of fraud victims report clinically significant emotional consequences: severe anxiety, sleep disorders, depression, and post-traumatic stress disorder. Peer-reviewed studies have documented PTSD symptoms persisting in investment fraud victims for up to two years after the incident, regardless of whether the financial loss was significant.
I have sat across from these victims. I have watched a 78-year-old woman try to describe, with her hands shaking, the voice of the man who took everything she had. She didn't say "I was scammed." She said she couldn't afford to eat the way she used to. She said she had to choose between her medication and her groceries. She said her daughter offered to help but she wouldn't take it because the shame was worse than the hunger.
Nobody hit her. So under current law, what happened to her is non-violent.
We need new language for that.
What Has to Change
Telling people to "be more careful" is not a strategy. Neither is publishing tip sheets, running awareness campaigns, or telling a retiree she should have known better. If we are serious about reducing fraud losses in this country, four things have to change. The first one matters most, because the others depend on it.
Stop treating every scam report as an individual incident. They are not individual incidents. They never have been. When a retired teacher in Alhambra wires $40,000 to a man claiming to be from the FBI, what happened to her is not a single case. It is one transaction inside a continuous operation that has hit a thousand other people that month, in a hundred other zip codes, with the same script, the same caller ID spoofing, the same mule accounts, the same crypto wallets. The retired teacher is the visible end of an infrastructure. Investigating her loss as a self-contained event (opening a report, attempting to trace one wire transfer, closing it when the trail dies in a foreign exchange) is, with rare exceptions, a recipe for doing nothing useful. Agencies have to consolidate cases. Federal, state, county, and municipal investigators need to be pooling reports, transaction data, phone numbers, mule identifications, wallet addresses, and call center signatures into shared investigative pools and working those pools as integrated cases. The honest part of this, the part nobody likes to say out loud, is that not every victim is going to get personalized investigative attention. There is no version of the current resource model in which that is possible. What can happen is that those reports stop being filed and forgotten and start being aggregated into something that lets investigators see the infrastructure. Disrupt the infrastructure and you protect thousands of future victims at once. Chase individual transactions one at a time and you protect almost no one, including the people sitting in front of you trying to describe what just happened to them.
Sentencing and bail frameworks have to account for aggregate harm. A mule who participates in a network that has stripped a dozen retirees of their life savings has caused measurable, documented, irreversible harm. The fact that she used a wire transfer instead of a weapon does not make the victims' PTSD symptoms any less real or their grocery calculations any less brutal. "Non-violent" is doing too much work in the current legal framework. It needs to do less.
Real-time data sharing between agencies has to become the default. The FBI's IC3 portal and the FTC's Consumer Sentinel Network are useful repositories, but real-time cross-jurisdictional intelligence sharing on active fraud operations remains fragmented. Dedicated financial crime task forces that span jurisdictional lines, modeled on the most effective joint terrorism task force structures, should be standard, not exceptional. This is the machinery that makes the first reform possible.
Financial institutions need legal pathways to delay suspicious transactions without liability exposure. A version of this is pending in Congress as the Financial Exploitation Prevention Act, which would let institutions pause transactions that exhibit exploitation patterns, particularly for older account holders. It cleared committee. It has not passed into law. It should.
Why I'm Writing About This
I'm Pete Hish. I'm an active sergeant at a large Southern California law enforcement agency, where I've supervised the cyber fraud team for the last ten years. The team exists because I founded it; no one else was going to. I see this every week. Real people, sitting across from me, trying to explain how they lost everything to a voice on the phone. Smart, careful people who did everything right their whole lives and got caught in a machine they didn't know existed.
I'm also writing a novel called Fleeced Nation that explores this world from the ground: the detectives who investigate these cases against institutional resistance, the victims who carry the shame long after the money is gone, the criminal networks that operate like corporations with org charts and quotas and supply chains. The book is fiction. The mechanics in it are not.
The title isn't a metaphor. It's a description.
Americans are being fleeced, systematically and at scale, not because we are weak, but because the people doing it have read our infrastructure more carefully than most of us ever have. They didn't break into the country. They walked in through doors we built and propped open because we believed, correctly, that decency, speed, and trust were good things.
Decency, speed, and trust are still good things. The reform isn't to abandon them. The reform is to organize law enforcement around the reality that the people exploiting them are not 10,000 isolated criminals committing 10,000 isolated crimes. They are an industry. We have to start responding to them like one.
Sources
- FBI Internet Crime Complaint Center, 2025 IC3 Annual Report: ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- Federal Trade Commission, Consumer Sentinel Network Data Book 2024: ftc.gov/reports/consumer-sentinel-network-data-book-2024
- FINRA Investor Education Foundation, fraud victim emotional impact survey, via AARP: aarp.org/money/scams-fraud/mental-health-impact
- International Journal of Environmental Research and Public Health, "The Mental Health Impacts of Internet Scams," 2025: pmc.ncbi.nlm.nih.gov/articles/PMC12192844
- Financial Exploitation Prevention Act (H.R. 2478 / S. 2840), 119th Congress

