A pension holder gets a text from her bank. Her account is locked. Call this number now.
A teenager in another country is told to keep the conversation going. He is not selling a product. He is being forced to run the script.
These are the same incident.
I keep hearing scam farms described as a fraud problem. That is incomplete. They are cyber operations built on human captivity. The person clicking send may be a victim. The person losing her savings is a victim. The platform that lets the operation scale has a responsibility too.
A scam farm is a cyber threat with a human operator under coercion.
That changes how we respond.
Start with the person behind the account
In the rooms where fraud controls get designed, we tend to see signals first. A new device. A burst of messages. A crypto wallet. A login from a new country. Useful signals. Still incomplete.
Behind those signals may be a young worker promised a legitimate job, then trapped in a compound and punished for missing a quota. The account may be active at three in the morning because someone is being watched. The writing may sound identical across hundreds of conversations because a supervisor is handing out scripts.
If we treat every account as a malicious actor, we miss the forced labor pattern. We also make it harder for survivors to come forward.
I want security teams to add a human-risk path to their playbooks. When a pattern suggests coercion, route it to people trained to assess exploitation. Preserve evidence. Do not expose the possible victim by abruptly cutting off the account without a safe handoff.
Fraud controls need a wider field of view
The CISO on a Sunday night may be looking at a rise in account takeover, payment fraud, or social engineering. The first instinct is to tune the model. Raise a threshold. Block a domain.
Do those things. Then ask three more questions.
- Are the same scripts, images, wallet addresses, or phone numbers appearing across victims?
- Does the activity connect to recruitment messages, forced work, or movement of people?
- Can our investigators share evidence with the right law enforcement, platform, and survivor-support partners without creating new danger?
A fraud model that only measures loss will miss the operation's structure. We need graph analysis, language patterns, payment trails, and reports from people who understand trafficking. Security data should help identify the network, not merely close the current case.
Platforms have design decisions to make
A platform that makes it cheap to create thousands of accounts, rotate identities, and move victims between channels is giving the operation room to breathe.
The answer is not blanket surveillance. It is deliberate friction where abuse concentrates. Stronger controls on bulk messaging. Better account recovery. Fast preservation of evidence. Human review for coordinated campaigns. Clear escalation paths when a report includes signs of captivity or forced labor.
Privacy still matters. So does speed. A victim does not experience a policy debate as an abstraction. She experiences a message, a deadline, and the fear that one wrong reply will cost her everything.
What I want leaders to fund this quarter
First, name cyber-trafficking in the enterprise risk register. Give it an owner across security, trust and safety, fraud, legal, and human resources. If the issue belongs to everyone, it belongs to no one.
Second, train investigators on the difference between an abusive account and a coerced operator. Build safe referral procedures with qualified organizations. Do not ask a survivor to prove her trauma inside a ticket queue.
Third, measure outcomes beyond blocked transactions. Count preserved evidence, disrupted networks, safe referrals, repeat victimization, and time to human review.
Technology will keep making these operations cheaper to run. Our response has to become more precise, more connected, and more human.
The question is no longer only, “How did this account get through?” It is also, “Who was forced to operate it, and what would a safe exit look like?”
That is the threat model I am watching this quarter. Fellow CISOs, how are you handling the human signals inside your fraud and abuse programs?
Lekshmy Sankar, PhD