Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Scammers Pose as Police, Threaten Arrest to Extort Victims in Nationwide Vishing Campaign

The FBI’s IC3 logged 6,833 complaints of phone‑based scams that impersonate police or federal agents, resulting in nearly $36 million in victim losses. The campaign highlights gaps in security‑awareness controls that many organizations rely on for audit readiness.

LiveThreat™ Intelligence · 📅 September 21, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Scammers Pose as Police, Threaten Arrest to Extort Victims in Nationwide Vishing Campaign

What Happened – The FBI’s Internet Crime Complaint Center (IC3) updated its 2022 alert to note a surge in phone‑based scams where actors impersonate police officers, federal agents, or foreign officials. Between January 2025 and July 2026, 6,833 complaints were logged and victims reported losses of nearly $36 million, with total fraud losses exceeding $1.6 billion.

Why It Matters for Trust & Control Assurance

  • This social‑engineering vector tests the effectiveness of an organization’s security‑awareness and training controls – a core control objective that maps to many frameworks (e.g., NIST CSF 2.0, ISO 27001).
  • Continuous monitoring of training completion, phishing‑simulation results, and incident‑response evidence provides the defensible audit trail law‑enforcement agencies expect.
  • Verisq’s Security Awareness capability supplies the evidence‑collection engine to prove that awareness programs are live, measured, and improving over time.

Who Is Affected – Medical practitioners, immigrants and international students, and the broader public who receive unsolicited “law‑enforcement” calls.

Recommended Actions

  • Verify that all staff understand that legitimate law‑enforcement agencies never demand payment via prepaid cards, cryptocurrency, or couriers.
  • Deploy regular vishing‑simulation campaigns and capture completion metrics as audit evidence.
  • Update incident‑response playbooks to include verification steps for phone‑based impersonation attempts.

Source: Help Net Security article

Technical Notes

  • Attack vector: phishing‑style voice calls (vishing) with spoofed caller ID, sometimes augmented by AI‑generated speech.
  • Payment methods: prepaid cards, wire transfers, cryptocurrency, cash couriers.
  • No known software vulnerability; the threat relies on social engineering and credential‑verification failures.

Source: Help Net Security article

📰 Original Source
https://www.helpnetsecurity.com/2026/09/21/fake-police-federal-agents-scams/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →