Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do scams continue to outpace other cybercrime…
Threats, Abuse & Incident Response

Why do scams continue to outpace other cybercrime categories even when organisations focus heavily on ransomware prevention?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

Scams stay dominant because they exploit human trust, low-friction communication channels, and fast-moving targets such as social media, shopping periods, and crypto platforms. Unlike many technical attacks, they do not always need a vulnerable system. They succeed when attackers can initiate contact, impersonate authority, and pressure victims before verification steps can interrupt the exchange.

Why scams keep winning while ransomware defenses get the budget

Scams are resilient because they attack the decision path, not just the system path. Organisations can harden backups, patch exploit chains, and rehearse recovery for ransomware, yet still leave room for impersonation, urgency, payment diversion, and account recovery abuse. The gap is often between technical protection and the moment a person is persuaded to act.

That makes scams harder to suppress with a single control family. They move across email, SMS, social platforms, shopping flows, and financial channels, so defenders need both preventative friction and rapid verification where money, credentials, or authority are being requested.

Where scams gain an advantage over ransomware-centric security

Ransomware usually depends on a compromise path: exploit access, deploy payload, encrypt, and extort. Scams can succeed much earlier. If an attacker can create a believable pretext, they do not always need malware, privilege escalation, or a vulnerable server. They need attention, trust, and enough time to push the victim past a verification step.

That is why scams scale well in high-tempo environments. Seasonal shopping, payroll windows, tax periods, crypto volatility, and high-volume customer support all create moments where people expect fast communication and are less likely to slow down. The defender is not only protecting infrastructure, but also the interaction itself.

Common scam patterns also blend into ordinary business behavior. A request that looks like supplier onboarding, MFA reset, invoice correction, account recovery, or customer support escalation can trigger approval or disclosure without triggering malware defenses. CISA cyber threat advisories regularly show how abuse of trusted channels and social engineering remains a persistent threat pattern alongside more technical intrusion methods.

Why verification friction, not just prevention tooling, determines outcomes

Scams succeed when the attacker can compress the decision window. The practical issue is not whether the organisation has awareness training in place, but whether there is a mandatory pause before a high-risk action is completed. If a transfer, password reset, new payee setup, or account handover can happen in one uninterrupted flow, the scammer often wins before anyone checks the request independently.

Low-friction channels make this worse. Social media DMs, consumer messaging apps, SMS, and ad-driven marketplaces are built for speed and convenience, not controlled identity assurance. That is one reason scam volume stays high even when defenders invest heavily in endpoint security or ransomware playbooks.

In practice, the strongest controls are the ones that interrupt urgency. Channel-bound callbacks, out-of-band verification, step-up checks for payment changes, and limits on how much authority one interaction can convey all reduce the scammer's advantage. For guidance on building these checks into identity and access decisions, NIST SP 800-63 Digital Identity Guidelines is useful where an interaction depends on proving who is actually on the other end.

Why ransomware and scams are different control problems

Ransomware is usually a containment-and-recovery problem with a technical root cause. Scams are a trust-and-verification problem with a human root cause. That difference matters because an organisation can make strong progress on backup resilience, patching, and segmentation without materially reducing impersonation, social proof manipulation, or payment diversion.

Scams also exploit business processes that were never designed as security controls. Procurement, finance, HR, customer support, and executive communication often trust internal-looking messages more than they should. The scammer does not need to defeat every defense, only the part of the process that can create value quickly. For broader threat context across exploit-driven and social-engineering-driven activity, the CISA Known Exploited Vulnerabilities Catalog is still useful as a reminder of how technical compromise and human-targeted abuse often coexist in the same campaign ecosystem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63N/A — Digital Identity GuidelinesScams exploit weak identity proofing and verification at the moment of trust.
Recommendation — Add step-up verification before account recovery, payee changes, and other high-risk actions.
NIST CSF 2.0PR.AA-05 — Identity and Access ManagementScams often succeed when access decisions rely on a single unverified interaction.
Recommendation — Require stronger verification before granting or changing high-value access.
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingHuman-targeted scams depend on social engineering and manipulation of decision-making.
Recommendation — Train staff to verify urgent requests through independent channels.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential-reset scams and account takeover hinge on weak authenticator handling.
Recommendation — Harden authenticator reset and recovery workflows against impersonation.

Practitioner Guidance

What to prioritise: Focus on the actions that convert a message into loss, not just on blocking malicious messages. Payment changes, credential resets, vendor-bank detail updates, gift-card or crypto requests, and urgent support escalations deserve the most friction.

What to verify: Check whether high-risk workflows require an independent second signal before completion. If a scam can succeed through one email, one SMS, or one chat exchange, the control design is still too permissive.

Common mistake: Treating scam resistance as an awareness-only problem. Training helps, but the measurable improvement usually comes from forcing verification into the process itself and constraining what any single channel can authorize.

Practitioner takeaway: Ransomware defenses reduce one loss mode, but scams keep outpacing because they exploit trust at the moment of decision, so the real control objective is to slow, verify, and bound high-value actions before they can be completed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org