The Migration Thesis: Why Solving Fraud Relocates It
Most fraud reports tell you what happened last year. This one tells you where fraud is going, and why — because fraud is not an event. It is a migratory system.
The box score that explains nothing
Every January, the same document arrives in your inbox wearing a different logo. The State of Fraud. A number went up. Here are the categories it went up in. Here is a chart. The firms that publish these reports employ some of the most capable risk people in the industry, and the documents are still uniformly forgettable — because they are written under legal review, by committee, and a committee under legal review cannot afford a thesis. So it inventories instead. But inventory is not analysis. A box score is not the game.
Let me start where those reports stop. The FTC’s 2024 Consumer Sentinel data is the headline number everyone cited: $12.5 billion in reported consumer fraud losses, up twenty-five percent in a single year, a record. Investment scams led at $5.7 billion, imposter scams followed at $2.95 billion, and government-imposter scams specifically — the fake-federal-agent call that empties a retiree’s account — climbed to $789 million, up a hundred and seventy-one million dollars year over year.
Now the figure the headlines skipped, the one that actually matters. The volume of fraud reports barely moved — roughly 2.6 million, essentially flat against the prior year. What changed is that the share of people who reported actually losing money jumped from twenty-seven percent to thirty-eight. Read that twice. Attempts held steady. Fraud simply started connecting — landing, costing — far more often. That is not a story about more criminals. It is a story about fraud finding a softer surface.
And here is the single most important sentence in the entire dataset, the thread that unravels everything else: in 2024, consumers lost more money through bank transfers and cryptocurrency than through all other payment methods combined.
Hold that fact. We come back to it.
From pull to push
For thirty years, the card networks waged a quiet, expensive war against one specific thing: someone using a card that wasn’t theirs. Pull fraud — the criminal reaches into the system and pulls value out using stolen credentials. And they won that war, more or less. EMV chips gutted counterfeit-card fraud. Tokenization and machine-learning models squeezed the card-not-present channel that the chips pushed fraud into. The transaction can be reversed, the cardholder is indemnified, the loss falls on issuers who have built a century of apparatus to absorb it.
So the fraud did the only thing fraud ever does. It moved.
It moved off the instrument and onto the person. The dominant attack today is not “steal the card.” It is “convince the account holder to send the money themselves” — authorized push payment fraud, the scam, push instead of pull. And this single shift breaks the entire defensive model, because from the system’s vantage point there is nothing to detect. The customer authenticated correctly. The customer approved the payment. The fraud engine sees a legitimate, authenticated, customer-initiated transaction, because that is exactly what it is. Every control the card era produced is structurally blind to a transaction the real account holder genuinely authorized. You cannot authenticate your way out of a problem whose defining feature is that the authentication succeeded.
The crossover is already visible anywhere the data is clean. In Europe in 2024, fraud on credit transfers reached roughly €2.5 billion — about sixty percent of all payment fraud by value — against roughly €1.3 billion for cards. In the UK, authorized push payment fraud overtook card fraud as the largest category years ago, by both count and value. And FinCEN’s suspicious-activity filings for fraud rose a hundred and ten percent between 2020 and 2024, from about 553,000 to over 1.16 million — a second, independent instrument pointing the same direction.
This is why “we solved third-party fraud” is both true and dangerously incomplete. We did make it very hard to use a card that isn’t yours. And in doing so we did not reduce fraud. We relocated it — off the rails we had learned to police, onto the rails we hadn’t, and into the one attack surface no authentication system can ever harden: human judgment.
Verification is not coherence
Notice what the winning tools actually do. The technology that hardened the card — and now hardens the bank account, the Plaids and bank-verification engines and the credit bureaus — verifies components. Is this account real? Is it owned by the applicant? Does the cash flow support the stated claim? Each of those questions can be answered yes while the entity as a whole is a fabrication.
A synthetic business holds a real, fully verifiable bank account. It presents a clean cash-flow read. It passes every component check — for the same structural reason it passes the credit bureaus: the binding between a tax ID and a responsible human being is assembled from fuzzy, public, gameable data, not anchored to anything hard. Verification confirms that each part exists. It is silent on whether the parts belong together.
That gap — between a set of individually valid facts and a coherent whole — is where modern fraud now lives. It is an intent and coherence problem wearing the costume of a verification problem, which is precisely why throwing more verification at it doesn’t work. And it turns out we have known how to close that gap for five hundred years.
The five-hundred-year rhyme
In 1494, a Franciscan friar named Luca Pacioli set down in print the double-entry system that Venetian and Genoese merchants had been refining for generations. Double-entry does not verify that any single account is real. It verifies that the books balance — that every entry has a counterpart, and that misrepresentation, wherever it hides, eventually surfaces as an imbalance somewhere else in the system. It is, in the most literal sense, a coherence engine. The oldest one we have.
Ask why it appeared exactly then. Because late-medieval Mediterranean trade had just gone trans-regional on bills of exchange and letters of credit — a genuinely new technology for transacting with counterparties you would never meet, in cities you would never visit. Trust at a distance. And in the gap between that new reach and the institutions that could police it, fraud bloomed: forged bills, defaulting correspondents, the whole catalog. The response was not better verification of each individual merchant. It was the law merchant, reputation networks, and double-entry bookkeeping — coherence and reputation infrastructure, built to catch what point-checks could not.
The pattern, once you see it, repeats with almost insulting regularity.
In 1720, the South Sea Bubble. Joint-stock companies and paper credit were the new trust technology — ownership and value abstracted into transferable paper. Mania and fraud exploded into the gap, the bubble burst, and the centuries-long response was the slow scaffolding of securities regulation and corporate accounting.
Then the telegraph, and the American Gilded Age. Suddenly value and information moved faster than any institution could verify them, and fraud-at-a-distance got a new instrument: the bucket shop and the wire con, the swindle that ran on the lag in the wire itself — the literal mechanism later dramatized in The Sting. This is the era that gave us the phrase confidence man, the operator who works the gap between what can be claimed and what can be checked. And the immune response to that frontier, the Progressive-Era antibody, was — closing a loop with the very top of this essay — the creation of the Federal Trade Commission in 1914. The institution now tabulating today’s scam losses was itself built as a reaction to the last frontier’s fraud.
There is a darker variant worth one sentence, because it tells you what happens at the extreme. In Rome, under fiscal stress, the sovereign became the counterfeiter, debasing the denarius toward a silver-washed token to buy time, until monetary trust collapsed into the crisis of the third century — the reminder that when a system is stressed badly enough, the line between fraud and policy simply dissolves.
Extract the pattern and it is exact every time. A society expands trust at a distance. Fraud blooms in the lag between the new technology and the apparatus to police it. The system matures — never by perfecting verification, always by building coherence and reputation infrastructure. And then the fraud migrates to the next frontier and the cycle restarts on new rails. Never elimination. Maturation through trauma, then migration.
This is why history rhymes rather than repeats. The human drives underneath — greed, desperation, the impulse to misrepresent for advantage — have been constant since the Pleistocene, and that constancy is exactly what makes the rhyme possible. But the technology and the state of the defenses are never constant. Same drives. New costume. Every cycle.
Where the frontier is softening now
So where, precisely, are we standing? Early in a fresh turn, and structurally it looks like 1494, or 1720, or 1873, depending on which lens you hold up.
Instant payments and synthetic identity have just opened the newest trust-at-a-distance frontier. The new rails settle in seconds, irreversibly — no chargeback, no clawback window, the value gone before anyone can intervene. The synthetic entity passes the component checks because the binding underneath them was never hard to begin with. And the institutional response lags, because the institutional response always lags; the lag is not a failure, it is the shape of the curve. The FTC’s data-scramble, the new reimbursement regimes appearing abroad, the task forces — that is the immune system beginning, slowly, to wake.
Now the part the box scores never reach, the part that matters if your job is to underwrite rather than to read about underwriting. All that upstream consumer-scam money has to land somewhere, and it has to cash out. It lands in accounts. It launders through merchants. The merchant account is quietly becoming the cash-out and laundering layer of the entire scam economy — which means the consumer-fraud boom you keep reading about is, mechanically, demand generation for merchant-side abuse downstream: bust-out, transaction laundering, the misrepresentation of business type and volume to board an account that was never going to process what it claimed. The two stories the industry insists on telling separately — consumer scams over here, merchant risk over there — are one story. The money simply moves from the first to the second.
Which lands us back at coherence, because that is the only place this ever lands.
The institutions that weather this turn will be the ones that stop asking is this real? — a verification question the new frontier has already learned to defeat — and start asking does this cohere? Does the entity hold together across every signal at once, or is it a collection of individually valid facts that do not belong to the same business? That is the question Venice answered with a ledger and the Progressives answered with an agency. The rails are new. The answer is five hundred years old.
What this is
The Coherence Report exists to do the one thing the annual briefs structurally cannot: take a position. Each issue traces a single piece of the migratory system — where misrepresentation is moving next, why the current defenses are blind to it, and what a coherent response actually looks like. Not a chart of what happened. A thesis about where it is going.
The machines can tell you what the pattern says. They cannot write the part that comes next — the human read that insists the pattern was never destiny, that there is always another branch. That read is this report.
The pattern is the majority report. The human is the dissent.