Advanced AI is equipping cyber attackers with more sophisticated tools to commit fraud and scams against victims like financial institutions, businesses, and individuals. They’re using it to generate things like deepfake video, voice cloning, and more authentic-sounding phishing emails. But AI tools can also be used to spot patterns and fight back. Pairing advanced AI with safe harbor reforms for information sharing will let banks and technology companies share red flags and stop the defrauding of Americans.

Already, AI-related scams surged by 1,210 percent in 2025, and generative AI could enable fraud losses to climb from $12.3 billion in 2023 to $40 billion by 2027. And while this new level of sophistication is certainly making it more difficult to detect and foil fraud and scam attempts through traditional methods, AI has immense potential for enhancing efforts to combat these attempts. Still, these attackers have one big advantage over defenders: data unification.

Organized attackers have all their data in one place—every phone number, victim name, and script sits under one umbrella. Defenders are reliant on a fragmented landscape engulfed in underreporting, with information on attackers scattered across institutions like individual banks, state attorneys general offices, and federal agencies. AI is a powerful tool for countering these attackers, but lacking access to the data on them is like gifting someone a brand-new laptop without a battery. The tools are there, but the data is scattered. While legitimate data sharing protections have been expanded this year, under current law, companies like financial institutions, technology companies, telecommunications providers, and other businesses that encounter fraud and scam activity are still frequently incentivized to underreport and undershare, even with data containing no compromising personal information. Shielding select private sector players from excessive liability risk with targeted safe harbors can better equip defenders to use advanced AI to detect fraud and scam attempts in real time.

Localities Often Unequipped to Combat Scams

In 2020, a grandmother from Milton, Massachusetts, received a call from someone claiming to be her grandson. The caller told her that he had been in a car crash in Cancun, Mexico after hitting a woman’s car, pleading that he needed cash to pay for the damages now. He asked her to keep it a secret, saying, “I need you to not tell anyone, not even Mom and Dad.” Shortly after, she went to the bank, withdrew the more than $13,000, and left the cash with one of the scammers who showed up at her home and assured her that her grandson would be safely transported to the airport.

The next day, the scammers called again asking for more money, which she refused. Her family and local police were informed, but for the initial payout, it was too late. Despite an investigation by Milton police, “the money is gone,” CBS News reported at the time.

This is a story repeated in towns across America. Scammers seek out vulnerable people, pose as trusted friends or relatives, and create a sense of urgency. And oftentimes, once victims are convinced to pass along cash, it’s too late. For most, the instinct is to report these types of crimes to their local police departments, and like Milton, most of these police departments lack a dedicated scams unit.

Not only does this leave scam cases competing for a general detective unit’s attention, but it also renders local police departments largely unequipped for combating the ever-evolving nature of these types of crimes. This is not a knock on Milton or local police departments generally. Instead, a mismatch. Cases like this commonly aren’t just one-off scammers ripping people off from their basements. Many times, they are sophisticated, often foreign operations. Expecting one small-town detective to combat this level of organized crime is not only a substantial imbalance, but often outright beyond that detective’s jurisdiction.

Scams like this have already been linked to organized crime rings based beyond America’s shores. Just last year, 13 individuals were charged in connection with a “transnational elder fraud scheme” involving a scam call center operation based in the Dominican Republic. The investigation identified more than 400 victims with over $5 million in losses. The average victim age? 84. And uncovering the alleged perpetrators all started with a trend flagged by a rideshare company.

Pattern Detection Was Instrumental in Uncovering This Scam Ring

The investigation into the Dominican Republic-based call center ring was launched in large part due to Uber’s security team flagging suspicious activity after detecting it using what the company described as “anti-fraud technology.” “The elder fraud ring was brought to the attention of the U.S. Attorney’s Office and the FBI by the Uber Global Security and Investigations Team, which learned that the rideshare app was being used for these scams,” Boston.com reported, citing Ted Docks, the special agent in charge of the FBI’s Boston Field Office.

According to the relevant affidavit, once a victim was convinced to send the money, the alleged scammers would use rideshare services and ask “unwitting” drivers to pick up and deliver the cash, typically masking it as something else, like “university documents.”

“Most commonly, runners for Castanos Garcia’s [the scheme’s identified leader] operation used rideshare company drivers to pick up cash from victims and drop the cash off at the runners’ locations…” the affidavit reads, “…The runner would use a rideshare account (in his own name or in the name of a girlfriend or friend) to request that a rideshare driver pick up ‘documents’ from a grandparent.” In one example, the scammer preemptively offered to tip a driver.

When victims report these crimes to localities and scammers are arrested in isolation, the scammer’s larger ring is often left unlinked. In the case of the Dominican Republic-based call center ring, at least six of the involved scammers were charged for crimes in connection with the ring before the unsealing of the indictment, spanning nine jurisdictions across six states—two in California, three in Florida, and one each in Massachusetts, New Jersey, Nevada, and New York. Several of these defendants continued to scam victims following their arrests.


In the case of Rivera Cueto, a named runner in the scheme, the affidavit states that, after being arrested in April 2023 in Thousand Oaks, California, while attempting to pick up a package from a rideshare driver, the charges were dismissed in May 2024. Following his arrest, he continued to scam elderly victims. Another named scammer, Polanco Batista, also allegedly continued collecting cash from victims, with the affidavit stating a search of his phone revealed that, “Polanco Batista continued to use rideshare accounts (primarily in other individuals’ names) to pick up cash from elderly victims even after his December 2024 arrest.” This involved at least 13 victims, with stolen funds totaling at least $135,900 in January and February 2025.

Had Uber not detected and flagged the pattern among participants in the Dominican Republic-based call center ring, it likely would have taken much longer to connect the dots, or they may not have been connected at all. In isolation, it is remarkably difficult for individual localities to detect patterns like this when scammer operations span the country or cross borders. Unless otherwise brought to the attention of each jurisdiction, Attleboro, Massachusetts, and Thousand Oaks, California, are unlikely to be regularly cross-checking cases with each other or with local officials in a foreign country, nor should they be expected to.

Uber used “anti-fraud technology” to successfully uncover a pattern among those participating in this call center ring. This wouldn’t have been possible if Uber couldn’t cross-check these rides. The ensuing investigation uncovered a ring that scammed victims out of a collective $5 million. Uber was the company that flagged the rideshare pattern to the FBI, but Lyft is named in the affidavit as being used by the ring too. In examples like these, information sharing between companies may speed up the pattern detection process.

Say, hypothetically, it takes ten related instances to identify a pattern. At a given time, seven involve Uber and three involve Lyft. To reach that threshold, Uber would need to detect at least three more occurrences and Lyft seven more. In other words, three or seven more incidents, respectively, of grandparents falling victim to scams would need to take place before either company reaches the threshold. Had the two rideshare companies been sharing relevant information about these occurrences, the pattern could have been established at that point.

Safe Harbors Can Bolster AI-Powered, Private Sector Coordination

Advanced AI will only make scam rings like the one in the Dominican Republic case increasingly sophisticated. Alarmism, fear, and resistance to AI adoption won’t change that, but using AI as a response can make a meaningful difference. With the current fragmentation of the scams reporting landscape, AI is constrained in its ability to connect the dots, with the current liability landscape making it difficult for private sector players to coordinate.

Concerns about potential legal and civil liability risks associated with voluntary business-to-business information sharing incentivize companies to withhold even legitimate data sharing not containing the personal information of consumers. Existing and proposed safeguards surrounding consumer data sharing, debanking, and blacklisting are well-intentioned and important. To address these concerns, under any expanded safe harbor for information sharing, a few things must be attached.

First, shared indicators must be used to inform investigations, not to trigger unilateral action against customers. Second, scam patterns can be shared, but victim and consumer identities remain with sending firms. Third, sharing must only be protected for scam-fighting purposes. Shared data used for other purposes, like marketing or credit evaluations, would remain under full liability exposure. With these safeguards attached, targeted safe harbors aimed at insulating relevant private sector players from excessive exposure would be a useful step.

Imagine there is a crime ring based in The Bahamas paying ten people across ten states to commit targeted scams in the United States. All are targeting event space venues, all pose as catering vendors, all invoices range between $5,000 and $10,000 each, and invoice descriptions differ but use similar structures. For a standing appetizer invoice, one scammer uses “serving platters” with one accounts payable (AP) platform. Another uses “presentation trays” with another AP platform. If both scammers used identical terminology, ordinary keyword matching would be likely to pick it up once the platforms were able to share information. The safe harbor lets this information get shared. But without frontier technology, the connection is missed since different terms were used.

An AI model can catch these similarities in seconds if platforms can cross-check red flags with each other, even with personal information, like venue names and other identifying data, omitted. In isolation, each of these similarities (invoices ranging between $5,000 and $10,000 are extraordinarily common, for example) is likely to produce an overwhelming list of false positives. But together, AI can flag them as unusual enough to consider further investigation.

Continuing with The Bahamas example, in coordination, the two AP platforms report their findings to the FBI, giving investigators a lead connecting activity across jurisdictions. The ensuing law enforcement investigation recognizes this as larger than a one-off incident, and the investigation can refocus its efforts toward identifying other ring participants and their links to The Bahamas as one coherent federal case. This both boosts the chances of halting the ring’s operations and helps victims pursue claims surrounding restitution and recovery.

Updated guidance issued in June 2026 by the Financial Crimes Enforcement Network (FinCEN), a bureau of the U.S. Department of the Treasury, was a welcome step toward strengthening safe harbor protections. The Bank Policy Institute, a trade group representing leading U.S. banks, later lauded the interpretation and urged Congress to expand related safe harbors. The guidance clarifies that an existing safe harbor includes information sharing for suspected scams, but has its limitations. First, it’s just an interpretation. Any future administration can revise it with the stroke of a pen, and this itself will be built into the risk analysis of those covered in the private sector.

Second, its scope leaves out essential links in the larger scam discovery chain. The safe harbor remains limited to select financial institutions like banks, casinos, insurance companies, and precious metal dealers. The safe harbor does not protect, say, rideshare companies or even some AP platforms. And, ironically, these AP platforms (among other tech companies) are permitted to form and operate an association of participating financial institutions, but are not themselves protected in a way that would let them participate. Thinking back to the Milton example, this safe harbor would have done little to uncover this scam. The transaction wasn’t particularly unusual. The victim legitimately authorized a cash withdrawal of her own money. What may have caught it was information sharing between rideshare companies.

Expanding this safe harbor to encompass more of the scam chain and codifying it in statute would empower the use of frontier technologies to help halt existing rings and advance restitution efforts for victims. Technological advancement is a two-way street and isn’t going anywhere. It is indeed making scam attempts more sophisticated, but properly enabled and wielded, frontier technologies can vastly strengthen the fight against them, too.