A fraud analyst sees the same pattern for the third time this week. New account. New device. Identical messages. A crypto wallet that appears in six complaints.

The case is closed. The queue moves on.

But what if the person behind that account is being forced to type?

We detect coordinated campaigns, trace payment flows, and freeze suspicious activity faster than we did a decade ago. We still miss one of the hardest signals to read: the operator may be a victim too.

A coerced account is a security signal and a human emergency.

That needs to change how we investigate.

The false binary in the fraud queue

Most operating models divide people into two groups. Victims on one side. Attackers on the other.

Scam farms break that model.

A teenager promised a customer-service job may arrive in a foreign country and find a locked compound. Her passport is taken. Her quota is set. If she misses it, someone threatens her family. She is told to open accounts, send messages, and keep targets talking.

To a platform, her activity may look like a malicious insider. To a bank, it may look like account takeover. To an investigator, it may look like a repeat offender.

The label is incomplete. The account is part of a criminal operation. The person operating it may be under coercion.

If our controls cannot hold both facts at once, they will produce bad outcomes. They may shut down a useful channel for a victim. They may erase evidence. They may send the person back to a trafficker who knows the account has been flagged.

Read the pattern before you close the case

I want fraud, security, trust and safety, and investigations teams to add a coercion review to their playbooks. Not for every suspicious account. For cases where the signals cluster.

Look for repeated scripts across many accounts. Sudden activity at the same hours. Identical language from people in different locations. A device pattern that changes while the writing stays the same. Transfers that connect recruitment, housing, and payment networks. Messages that mention quotas, punishment, withheld documents, or fear for family members.

No single signal proves trafficking. A cluster should trigger a safer question.

Who has control of this account?

That question is useful far beyond scam farms. It can reveal coordinated fraud, organized cybercrime, and the human cost hidden inside both.

Do not make the victim prove the case in a ticket

A person in a locked compound is unlikely to complete a normal abuse report. She may not have a private device. She may not speak the platform's language. She may be watched while she types.

The standard flow asks for details that can increase danger. Name. Location. Contact information. A full explanation of what happened.

Security leaders need a safer route. Preserve the relevant evidence. Limit who can access it. Use trained reviewers who understand exploitation. Build referral paths with qualified survivor-support organizations and law enforcement partners. Make the first response discreet and reversible when possible.

Incident response cannot assume that every operator has freedom of action.

What I want on the dashboard

Blocked transactions are useful. They are not enough.

I want four measures:

  • How many cases showed signs of coordinated coercion?
  • How quickly did a trained human review those cases?
  • How much evidence was preserved before accounts were closed?
  • How many people were referred to a safe support channel, and how often did the same network return?

These measures connect fraud operations to real-world harm. They also create better intelligence. A pattern that helps one survivor leave may help investigators find the next compound.

The platform decision matters too. Add friction to bulk messaging. Make account recovery harder to weaponize. Keep escalation paths visible. Share evidence responsibly. Do not turn every safety control into a surveillance dragnet. Precision matters because the wrong intervention can create a second injury.

The leadership decision

If cyber-trafficking is absent from your risk register, add it. Give one executive clear ownership across security, fraud, trust and safety, legal, and human resources.

Then run a tabletop. Put a real-looking case on the screen. Ask what happens in the first hour. Who preserves the data? Who decides if the account is coerced? Who contacts an outside partner? What does the person behind the account experience while your teams investigate?

If the answer is unclear, the gap is operational. Fix it before the next campaign arrives.

The strongest fraud program is not the one that closes the most accounts. It is the one that can distinguish a threat from a person being used as a tool.

That is the signal I am watching this quarter. Fellow CISOs, how are you building a coercion review into fraud and abuse response?

Lekshmy Sankar, PhD