What Does Fraud Look Like in 2026? The Same as It Did in 2022.

This morning I got a call from USAA's main support number. Fraud charges at a Walmart in Los Angeles. After 24 years as a member, I recognized the number. But the questions that followed felt wrong — too many, too fast, too interested in my answers when they should have been interested in blocking the charge. I started asking questions back.

They hung up.

Here's the part that's hard to admit: I've spent 25 years in security. I know how these attacks work. And depending on how my day was going — if I'd been distracted, if I'd been between meetings, if my kid had just called — I could have fallen for it. Not because I'm careless. Because the attack was built to exploit trust, not ignorance. Twenty-four years of recognizing that number is exactly what they were counting on.

I called USAA directly. Their number is being actively spoofed. I asked whether they had a formal FTC complaint or regulatory filing open against the campaign. After checking with fraud and management — no. No formal process. An email to customers.

I'm not singling out USAA. Swap in any major bank and you'd hear the same answer. This isn't an institution failure. It's a system failure. And "I've been in security for 25 years" is not a scalable defense.

The fix exists. It endorsed a deepfake.

The FCC mandated a framework called STIR/SHAKEN — cryptographic signatures on phone calls so carriers can verify the number is real before it reaches you. The idea is sound. Verify the call, flag the fakes, protect the customer.

During the 2024 New Hampshire primary, a carrier processed an AI-generated deepfake of the sitting president's voice through that framework. It passed. Full verification. The highest trust level the system offers — granted to a fake.

The carrier didn't break the process. They followed it. The process just doesn't have identity verification built into its bones. It's bolted on. Optional. A step that can be checked or skipped depending on how the carrier's day is going.

Sound familiar?

David Frankel, who runs one of the robocall surveillance platforms the FCC itself relies on, said it directly: the FCC is working to fix gaps in a framework we're not even using correctly yet.

We built the verification system. We mandated it. A deepfake of the president sailed through it. And we're still debating compliance timelines.

We keep solving the wrong problem

Every generation of this attack gets the same response — patch the transport layer. Spoofed phone numbers, add signatures to calls. Spoofed emails, bolt on SPF, DKIM, DMARC. Each fix helps. None of them solve it. The reason is always the same.

We're applying transport-layer fixes to an identity-layer problem.

The phone network was built in the 1970s on the assumption that only carriers had access. Email was built on the assumption that only universities would use it. Neither was designed to answer the question "is this person who they claim to be?" We keep asking infrastructure that was never built to carry identity to authenticate it — and every time, we end up technically compliant and practically exposed.

Now add AI voice cloning. The number is verified. The voice is fake. We validated the channel. We still didn't validate the person.

What actually fixes this

Identity can't keep living as a bolt-on. It has to be intrinsic — structural to the interaction, not a step in a workflow that someone can skip or a carrier can rubber-stamp. Something that travels with the communication regardless of the channel, regardless of whether the underlying transport was designed in 1975 or 2025. The channel shouldn't matter. The identity should.

The people building the next generation of identity architecture — tokenized, decoupled from the transport layer, privacy-native by design — are working on the right problem. Whether the industry listens before or after the next deepfake campaign will tell us whether 2028 looks any different from today.

I filed an FTC complaint this morning. I'm writing this so it exists as a record. And I'm asking the people in my network who live in telecom, carrier policy, or identity architecture: is the path forward better enforcement of what we have, or do we need to stop patching and start rebuilding?

Because from where I'm sitting, we've been answering the right question at the wrong layer for a very long time.


This article was originally published on LinkedIn on February 24, 2026.