Scammers Pose as Police, Threaten Arrest to Extort Victims in Nationwide Vishing Campaign
What Happened – The FBI’s Internet Crime Complaint Center (IC3) updated its 2022 alert to note a surge in phone‑based scams where actors impersonate police officers, federal agents, or foreign officials. Between January 2025 and July 2026, 6,833 complaints were logged and victims reported losses of nearly $36 million, with total fraud losses exceeding $1.6 billion.
Why It Matters for Trust & Control Assurance
- This social‑engineering vector tests the effectiveness of an organization’s security‑awareness and training controls – a core control objective that maps to many frameworks (e.g., NIST CSF 2.0, ISO 27001).
- Continuous monitoring of training completion, phishing‑simulation results, and incident‑response evidence provides the defensible audit trail law‑enforcement agencies expect.
- Verisq’s Security Awareness capability supplies the evidence‑collection engine to prove that awareness programs are live, measured, and improving over time.
Who Is Affected – Medical practitioners, immigrants and international students, and the broader public who receive unsolicited “law‑enforcement” calls.
Recommended Actions
- Verify that all staff understand that legitimate law‑enforcement agencies never demand payment via prepaid cards, cryptocurrency, or couriers.
- Deploy regular vishing‑simulation campaigns and capture completion metrics as audit evidence.
- Update incident‑response playbooks to include verification steps for phone‑based impersonation attempts.
Source: Help Net Security article
Technical Notes
- Attack vector: phishing‑style voice calls (vishing) with spoofed caller ID, sometimes augmented by AI‑generated speech.
- Payment methods: prepaid cards, wire transfers, cryptocurrency, cash couriers.
- No known software vulnerability; the threat relies on social engineering and credential‑verification failures.
Source: Help Net Security article