Teams should not treat a broad decline in crypto crime as a reason to relax monitoring. The article shows impersonation scams declined far less than scams overall and transfer counts increased, which means victim pressure can intensify even when total loss value falls. Prioritise stronger identity verification, beneficiary screening, and escalation playbooks for authority-impersonation patterns.
Why falling scam revenue should not relax controls
A decline in total scam revenue can mask a worsening operating pattern. For compliance teams, the more important signal is whether impersonation scams are still producing pressure on victims and payment flows, because that can indicate higher attempt volume, better scam adaptation, or more effective social engineering even when aggregate losses ease.
That is why teams should read revenue trends alongside behavioural indicators such as transfer counts, beneficiary changes, and repeat-contact patterns. When impersonation remains resilient while other scam types cool, the control objective shifts from broad suppression to sharper detection of authority-claiming interactions and faster intervention at the point of payment.
Where an evidence base is needed, NHIMG’s Ultimate Guide to NHIs underscores the scale of identity risk in modern environments, including the finding that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. That figure is not about scam typologies directly, but it reinforces the broader point that identity abuse, not just loss value, is often the real control failure.
Controls that matter most when impersonation persists
When the loss profile changes, the control stack should change with it. Strengthen beneficiary verification, authority-claim challenge steps, and manual review for high-pressure transfer requests, especially where the payer is being coached to bypass normal channel controls. Screening should focus on patterns that imitate banks, exchanges, regulators, support desks, or law enforcement.
- Verify the beneficiary through an independent channel before release.
- Flag first-time recipients, urgent-transfer language, and account takeover cues.
- Require elevated review when the request depends on secrecy, fear, or time pressure.
- Correlate scam reports with repeated destination wallets, devices, and contact pathways.
Teams should also tighten escalation playbooks so front-line analysts know when to pause payment, not just when to file a report. If the scam depends on impersonated authority, the practical question is whether the organisation can interrupt the transaction before the victim completes the transfer.
For governance and control design, ISO/IEC 27002:2022 Information Security Controls is a useful control baseline for access, authentication, and monitoring discipline, while FATF Recommendations, AML and KYC Framework is directly relevant where scam proceeds move through customer due diligence, suspicious activity reporting, and virtual asset oversight.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6.3 — Access Granting and Revocation | Beneficiary and authority-claim controls depend on limiting and reviewing access paths used in scam execution. |
| 8.7 — Audit Log Management | Impersonation scams require traceable transfer, review, and exception records for detection and response. | |
| Recommendation — Review and restrict transaction approval paths that enable coercive or impersonated payments. Retain and monitor logs for beneficiary changes, escalation events, and payment exceptions. | ||
Practitioner Guidance
What to prioritise: Treat impersonation scams as a live fraud-control problem even if headline revenue falls. The operational signal to watch is not just aggregate loss, but transfer frequency, beneficiary churn, and how often victims are being steered into exceptions.
Decision rule: If the pattern shows authority impersonation, fast transfer pressure, or channel bypass, move the case into a higher-friction review path rather than relying on ordinary fraud thresholds. That is the point where prevention, not post-event reporting, provides the most value.
What to measure: Track blocked impersonation attempts, time-to-intervention, first-time-beneficiary approvals, and repeat-wallet exposure. Those indicators tell you whether controls are actually catching coercive scam behaviour before funds leave the platform.
Practitioner takeaway: Lower total scam revenue does not justify lower scrutiny, because impersonation scams can remain operationally aggressive even when the overall loss curve improves.
Related resources from NHI Mgmt Group
- What breaks when retail crypto participation falls even as overall transaction volumes keep rising?
- How should crypto compliance teams screen transactions tied to sanctioned scam networks in practice?
- How should crypto teams adapt compliance and risk controls as APAC markets mature at different speeds?
- How should investigators and compliance teams prioritise crypto crime cases when volume is high and criminal tactics keep changing?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org