The email arrives on a Tuesday morning, from an address you have written to a hundred times. It is Dana, at the supplier you have used for six years. The company has changed banks; here are the new account details; please use them for this month's invoice. The signature block is correct. The thread underneath it is a real thread, and you can scroll back through two years of it. Because you are careful, you pick up the phone and call the number in the signature, and Dana answers, and Dana sounds exactly like Dana.
Every element of that story is genuine except the two that mattered. The mailbox was taken over the previous week and has been read quietly ever since. The voice on the phone was assembled from a conference panel recording that has been public since 2023. The payment goes out on Thursday, and by the weekend it has been moved through three accounts and is beyond anyone's reach.
Nothing in that sequence required the criminal to break encryption, defeat a firewall, or do anything a reasonably funded amateur could not do. What it required was one condition, and only one: that at no point did you actually see the person you were transacting with.
The Common Factor
We published a full accounting of American fraud losses earlier this year — where the money goes, and through which doors it leaves the financial system. The topline numbers are worth restating, because they are larger than most people expect. The FTC recorded $12.5 billion in consumer fraud losses in 2024, up 25% in a year. The FBI's Internet Crime Complaint Center put total cybercrime losses at $16.6 billion, up 33%. Losses among Americans over 60 reached $4.885 billion, averaging $83,000 per victim.
That article argued about channels — which rails carry the money, and why the answer is mostly the banking system's own. This one is about something the channel analysis does not capture. Look at the same losses broken out by scheme rather than by rail, and a different pattern appears.
| Scheme (2024) | Est. losses | Did the victim ever see the counterparty? |
|---|---|---|
| Investment scams | $6.6B | No — a fake broker, a trading dashboard, a chat thread |
| Imposter / business-email compromise | $2.95B | No — a spoofed address, a cloned voice |
| Romance / confidence scams | $1.9B | No — months of messages, no meeting |
| Tech-support scams | $1.46B | No — a phone call and a remote session |
Four categories, more than $12 billion, and a single structural feature running through all of them. In none of these cases did the victim ever confirm that a specific, real, live human being was on the other side of the transaction. They confirmed a display name. They confirmed a mailbox. They confirmed a voice, which is now the cheapest thing in the world to manufacture. They confirmed everything except the person.
This is not a small observation dressed up as a large one. It is the precondition for the entire category. A fraudster who must appear in person, holding a government ID with their own face on it, is a fraudster running a completely different and far more dangerous business — one with a witness, a photograph, and a physical presence at a known place and time. The economics that make remote fraud attractive are entirely a function of the fact that it is remote.
Commerce Used to Solve This by Default
For most of the history of trade, the question of who you were dealing with answered itself, because they were standing in front of you. When commerce began to outrun walking distance, people built substitutes — and it is worth noticing how much effort went into them. The letter of introduction existed so that a merchant in one city could vouch for a stranger arriving in another. The notary existed to witness that a particular person, verified by the notary's own eyes, signed a particular document. Bank signature cards existed so a teller could compare the hand in front of them to the hand on file. The requirement that certain contracts be executed in person exists in law to this day.
None of these were security theater. They were the accumulated machinery of several centuries of learning that the single most useful thing to establish before an irreversible transfer is that the counterparty is who they claim to be, and that they exist.
The internet dissolved all of it in about a decade, and — this is the part worth sitting with — we never replaced it. We built extraordinary substitutes for the other pieces. Encryption replaced the sealed envelope, and improved on it. TLS certificates replaced the letter of introduction for servers, so your browser can confirm the identity of a machine in another country in a few milliseconds. Digital signatures replaced the wax seal.
But for the human being at the other end of the conversation, we substituted an email address, a password, and a phone number, and then spent twenty years discovering that all three can be taken. The one link in the chain that centuries of commercial practice treated as essential is the only one the modern stack left unsolved.
The Objection That Has to Be Answered First
There is a strong objection to everything above, and it deserves to be met head-on rather than saved for the end.
The objection is this: identity verification is not free, and the internet without anonymity is a worse internet. A web where every interaction requires you to prove who you are is a web where dissidents, whistleblowers, abuse survivors, and people living under hostile governments lose the protection that anonymity gives them. It is also a web with a permanent record of who did what, held by companies with unremarkable security and a commercial interest in retaining it. We have written elsewhere about how casually that kind of record gets reached for once it exists. Anyone proposing more identity checks should have to answer for where that record goes.
We think this objection is correct, and it is the reason the conclusion here is narrow rather than broad.
The answer is not to verify everyone, everywhere, continuously. That is surveillance, and it fails for exactly the reasons the objection states. The answer is to verify at the irreversible step — the specific, rare, consequential moment when value is about to move in a way that cannot be undone, and the only thing standing behind that movement is the claim of a stranger you have never seen.
That is a very small number of moments. You do not need to know who someone is to let them read your blog, post in your forum, browse your catalogue, or hold an account. You need to know it before you wire money to a bank account that changed last week, release escrow on a transaction, hand over a credential that opens something, or change the payment instructions on a standing relationship. Those are the moments where the entire loss is concentrated, and they are a rounding error as a fraction of internet activity.
The Narrow Version of the Check
Narrowing the moment lets you narrow the check itself, which is where most of the privacy cost actually lives.
The question is not who is this person. That question requires a name, a database, a lookup, and a record — and it produces exactly the permanent identity trail the objection warns about. The question is much smaller: is there a live human on the other end of this, and are they holding a government ID with their own face on it?
That is a question you can answer without ever learning anyone's name, and without keeping anything afterwards. It does not tell you who they are. It tells you that they are real, that they are present right now, and that they are in possession of a credential issued to the face they are wearing. For the four scam categories in the table above, that is sufficient, because every one of them fails at exactly that step. A taken-over mailbox cannot hold up an ID. A cloned voice has no face. A chat account running a script against a thousand targets at once cannot stand in front of a camera, and a romance scammer working from a compound in another country will not.
It is also a question that can be asked and answered in under a minute, by a person with nothing more than the phone already in their hand.
What We Built
We have spent two years arguing that fraud gets stopped at its source rather than at its final step — that the crime happens in the call, the script, and the manufactured emergency, not at the machine where the money happens to leave. That argument is correct, and we will keep making it. But there is a fair response to it, which is that identifying a problem is easier than fixing one.
So we built the checkpoint. ByteVerify answers the narrow question and nothing beyond it: a live 3D face capture, compared against the portrait on a physical government ID, with the document checked to be a real card in a recognized format rather than an image on a screen. All three must pass. The result is verified, failed, or expired — no score, no confidence band, no reason code. The scan, the ID images, and the biometric template are destroyed when the check settles, within 24 hours at the outside. There is no face database, because a face database is the thing that leaks.
It costs two dollars, which is roughly what a bank charges to send a domestic wire. The check that protects the wire costs less than the wire.
We did not build it from scratch for this. It is the same liveness and document technology we already use to onboard our own ATM customers, running on servers we operate — which means we have been on the receiving end of every fraud pattern described in this article, at volume, for years. The underlying technology has been tested by NIST/NVLAP-accredited labs under ISO/IEC 30107-3 and ISO/IEC 19795-2. Those figures, which are published by the technology's vendor, describe the technology itself and are not an audit of our deployment of it; we would rather say that plainly than let a lab result do more work than it can carry.
What It Does Not Do
A verification product that oversells itself is worse than none, because it moves the decision-maker from careful to confident without changing the underlying risk. So, precisely:
A verified result does not establish that the ID is genuine or currently valid — there is no query to a DMV or an issuing authority, and a format match is not proof of issuance. It does not establish who the person is; no name is resolved, no record is consulted, and nothing is looked up. It says nothing about sanctions, watchlists, AML, KYC, credit, or background, and it must never be used for decisions covered by the Fair Credit Reporting Act. And it does not establish that the person is authorized to do what they are about to do. A match tells you a live human holds an ID bearing their own face. Whether that human is permitted to move your money is your control to run, not ours.
It is one signal, meant to sit inside your existing controls — account binding, device signals, transaction limits, confirmation through a channel you already trusted before today. It is a strong signal, and it is aimed precisely at the failure mode that produces the largest fraud categories in the country. It is not a guarantee, and anyone selling you a guarantee in this space is selling you something else.
The Shape of the Argument
Fraud losses in America are rising across every measure at once, and the reporting rate is somewhere between 2% and 6.7%, which means the real totals may run an order of magnitude above the published ones. Deloitte projects that AI-enabled bank fraud alone will cost institutions $40 billion a year by 2027. The tools for manufacturing a convincing stranger — a face, a voice, a history, a company — got radically cheaper in the last three years, and they are not going to get more expensive.
Against that, the defenses most organizations actually run are a callback to a number in a signature block and a moment of hesitation from whoever happens to be processing the payment. Both of those defenses are now trivially defeated, and the second one is not a control at all.
None of this argues for identity checks everywhere. It argues for one check, at the one step that cannot be taken back, answering the one question that every major scam category depends on you never asking. The machinery for asking it in person took several centuries to build and we let it lapse in about ten years. Rebuilding it for a screen is not a radical proposition. It is catching up.
Before you release the funds, make them hold up their ID. It is the oldest question in commerce, and nobody has yet found a better one.
Sources
FTC Consumer Sentinel Network Data Book 2024; FBI Internet Crime Complaint Center (IC3) 2024 Annual Report and 2024 Elder Fraud Report; Deloitte Center for Financial Services, generative-AI fraud projections; Byte Federal, Following the Money: America's 2024–2025 Bank Fraud Report, which carries the full citation list for the loss figures restated here. Laboratory figures for the underlying liveness and matching technology are as published by that technology's vendor from NIST/NVLAP-accredited testing under ISO/IEC 30107-3 and ISO/IEC 19795-2; they describe the technology and are not an audit of Byte Federal's deployment. ByteVerify is a supplemental risk signal and is not an identity, sanctions, AML, KYC, or background-screening service.
Frequently asked questions
What do the largest online scam categories have in common?
In 2024 the four largest categories — investment scams ($6.6B), imposter and business-email compromise ($2.95B), romance and confidence scams ($1.9B) and tech-support scams ($1.46B) — shared one structural feature: the victim never confirmed that a specific, live human being was on the other side. They confirmed a display name, a mailbox or a voice, all of which can now be manufactured cheaply.
Does stopping fraud require identity checks everywhere online?
No, and a web that requires identity for every interaction is a worse and more dangerous web. The argument is much narrower: verify at the irreversible step — the rare moment when value is about to move in a way that cannot be undone on the word of a stranger you have never seen. That is a tiny fraction of internet activity and where nearly all the loss is concentrated.
What question does a live face-to-ID check actually answer?
Not "who is this person," which requires a name, a database and a permanent record. The narrow question is whether a live human is present and holding a government ID with their own face on it. That can be answered in under a minute without learning anyone's name and without retaining anything afterwards, and it is the step at which a taken-over mailbox, a cloned voice or a scripted chat account all fail.
What does a verified result not tell you?
It does not establish that the ID is genuine or currently valid, because no issuer or DMV record is queried. It does not establish who the person is. It says nothing about sanctions, watchlists, AML, KYC, credit or background, and must not be used for decisions covered by the Fair Credit Reporting Act. It also does not establish that the person is authorized for your transaction. It is one supplemental signal to sit inside controls you already run.
Topics in this guide
- fraud-prevention
- identity-verification
- policy
- byteverify
- elder-fraud
- business-email-compromise
Use what you learned
Choose the Byte Federal product that fits your next step.