Article

When the Customer Is Telling the Truth — and Still Being Robbed

Article 8 min read Originally on LinkedIn ↗

When the Customer Is Telling the Truth — and Still Being Robbed
The fastest-growing category of financial crime isn't stolen identity. It's coerced consent — and our fraud systems can't see it.

Every fraud system ever built rests on a single assumption: that the legitimate account holder and the criminal are two different people. Catch the imposter, stop the fraud.

That assumption is now wrong often enough to cost hundreds of billions of dollars a year.

The fastest-growing financial crimes don't involve a stolen identity at all. They involve a real customer, correctly authenticated, knowingly authorizing a transfer — because someone has made them afraid not to. The person on the camera is exactly who they claim to be. The password is right. The face matches. And the money is gone.

The scale of the problem

Authorized fraud — where the victim themselves initiates the payment — has become the dominant loss category in digital banking. Estimates of the global toll vary widely by definition, but none of them are small. The Global Anti-Scam Alliance put worldwide scam losses in the hundreds of billions of dollars for 2025. UK Finance reported that more than half a billion pounds was lost to authorized push payment scams in a single year, with AI lowering the barrier to entry for criminals. Across the US, UK, and India alone, APP fraud losses are projected to roughly double by 2026.

Within that, one subcategory is both the most disturbing and the most invisible to current defenses: fraud driven by fear and coercion.

Three flavors of coercion, one blind spot

Virtual kidnapping. A parent gets a call. A voice that sounds like their child is screaming. A "kidnapper" demands an immediate wire and warns against hanging up or calling police. The FBI has warned for years that these schemes use fear, panic, and urgency to rush victims into hasty payments, almost always by immediate wire transfer. No one has actually been kidnapped — but the victim doesn't know that, and the terror is real. Criminals are now using AI-generated photos and videos as fake "proof of life," and US losses from generative-AI-enabled fraud are projected to reach $40 billion by 2027.

Express and "app-enabled" kidnapping. In parts of Latin America, criminals physically detain victims and force them to drain their own accounts on the spot — through ATM withdrawals and bank transfers made under duress.

Wrench attacks. The crypto-native version, named for the old joke that the cheapest way to break encryption is to hit someone with a wrench until they hand over the keys. CertiK's 2025 report documented 72 verified physical-coercion incidents worldwide, a 75% jump over 2024, with kidnappings up 66% and physical assaults up 250%. Europe now accounts for over 40% of incidents, and documented losses exceeded $40 million. In January 2025, Ledger co-founder David Balland and his partner were kidnapped from their home; the attackers severed one of his fingers to pressure a €10 million ransom before police rescued them.

The case that put this in front of the tech world arrived in November 2025. A man posing as a UPS driver talked his way into a San Francisco home shared by Lachy Groom — a venture capitalist and former partner of OpenAI's Sam Altman — pulled a gun, bound the resident with tape, and over roughly 90 minutes forced him to drain his own crypto wallets, taking around $11 million in Bitcoin and Ethereum.

Read that last detail again. The victim operated the wallet himself. Every cryptographic check passed. Every signature was valid. The keys were held by exactly the right person. And none of it mattered, because the one thing the system couldn't see was the gun.

Why current defenses miss it

The entire fraud and identity stack is built to answer two questions: Is this the right person? and Is this a normal-looking transaction? Coercion defeats both. It is the right person. And to a transaction-monitoring engine, a high-net-worth individual moving a large sum can look entirely consistent with their profile.

The industry has tried to address duress directly before. Duress PINs — a secret alternate code that silently signals coercion — have existed as a concept for decades. But a 2010 FTC study found they had never actually been implemented in any ATM, concluding the deployment costs outweighed their likely deterrent value. The reason they fail is human: a terrified person, watched closely by an attacker, cannot reliably remember to enter a special code, and attackers know to watch for exactly that.

Which means the signal can't depend on the victim doing something. It has to come from what the victim cannot hide.

What a State of Mind signal actually adds

This is the gap RTScale was built for. The State of Mind Signature (SoM Sig™) captures a cryptographically signed, multimodal reading — facial emotion, vocal prosody, microexpression — at the moment a high-stakes transaction is authorized, produced on-device and bound to the transaction itself. It doesn't ask whether the right person is present. It asks whether that person is acting freely.

The key concept is variance. A SoM Sig isn't a lie detector and it isn't a verdict. It's a measurement of how far an authorization moment deviates from that person's own established baseline — the affective equivalent of an anomaly score. Acute fear, duress, and coercion are physiologically expensive states. They are very hard to suppress completely, and very different from the calm familiarity of a routine transfer. A signature captured under a gun, or during a terrifying phone call, does not look like one captured on an ordinary Tuesday.

Crucially, that variance is not meant to replace the fraud engine — it's meant to feed it. Today's behavioral-biometrics and transaction-monitoring systems already fuse dozens of signals to score risk. SoM variance becomes one more input, and a uniquely high-value one, because it speaks to the dimension every other signal is blind to: the customer's state of mind. A high-variance signature doesn't freeze an account on its own. It raises the risk score, and lets the institution's existing policy engine decide what friction is warranted.

And friction, applied at the right moment, is exactly what breaks these crimes:

  • A step-up verification or mandatory cooling-off period interrupts the urgency that virtual-kidnapping scripts depend on — schemes that work precisely by keeping the victim on the phone, where ransom demands often drop at the first sign of resistance.
  • A time-lock on a large crypto withdrawal — already an industry-recommended defense — turns an irreversible 90-minute drain into a delay that buys time for guardian alerts and intervention.
  • For banks operating under reimbursement regimes, a documented, signed duress signal is also evidence — the kind of contemporaneous record that reimbursement decisions increasingly turn on.

None of this requires the victim to remember a secret code, press a panic button, or do anything except be present. The signal is in the face and the voice, captured before it can be hidden, sealed in hardware, and handed to the systems already trying to protect them.

The honest limit

A State of Mind signal would not have pulled the gunman out of that San Francisco home. No software stops an armed intruder. But the moment the attack moved from the physical world into the financial one — the moment the victim was forced to operate the wallet — is precisely the moment a high-variance signature could have fired, tripped a time-lock, and turned an instant, irreversible $11 million transfer into something with a pause button and an alarm.

For two decades we have invested enormous effort in proving people are who they say they are. We have largely succeeded. The criminals noticed, and moved to a target we left undefended: not the customer's identity, but their will.

This isn't theoretical. The approach builds on patented foundations: RTScale holds a granted US patent (No. 11,151,385) for multimodal deception detection across face, voice, and micro-expression signals — the technical core of affective verification for fraud prevention — with a further patent pending on the State of Mind Signature itself, the consent-provenance layer described here.

It's time to verify the moment, not just the identity.

That's what we're building at RTScale.

— Peter Walker is Founder & CEO of RTScale.AI and co-inventor of US Patent No. 11,151,385. RTScale holds a granted US patent for multimodal deception detection and has a patent pending on its State of Mind Signature (SoM Sig™) technology.

rtscale.ai

#FraudPrevention #APPFraud #FinancialServices #RegTech #PaymentSecurity #AIGovernance