Background & Motivation — sender identity verification project

What sender anonymity costs Americans

Nothing on a phone call, text, or email proves who actually sent it — and that single gap drains billions of dollars a year from families, seniors, and the companies whose names get borrowed without permission.

A caller ID, an email header, and a text message sender field can all say whatever the sender wants. The numbers below are why that gap matters, and why a verified sender identity standard is worth building.

According to the FBI IC3 group at www.ic3.gov

$16.6B
Total reported fraud losses, all ages, 2024 (FBI IC3)
$4.885B
Losses reported by victims age 60+, 2024 (FBI IC3)
$789M
Losses to government-impersonation scams, 2024 (FTC)

The Overall Picture

The FBI's Internet Crime Complaint Center (IC3) received 859,532 complaints in 2024, reporting losses exceeding $16.6 billion — a 33% increase over 2023. Almost none of this requires technical sophistication on the attacker's side; it requires only that the victim trust who appears to be contacting them.

Elder fraud

Older adults are the most targeted and the most damaged group in these figures, and the trend is accelerating.

147,127
Complaints from victims 60+, 2024 — up 46% from 2023
43%
Year-over-year increase in losses reported by this group
$83,000
Average loss among the roughly 7,500 elder victims who each lost over $100,000

Tech support fraud, romance scams, and cryptocurrency fraud were the top categories affecting older adults. Each of those categories typically opens with a message or call impersonating someone the victim has reason to trust — a company, a romantic interest, or an advisor — which is precisely the trust that sender verification is designed to make harder to fake.

Government impersonation calls

A specific, high-volume slice of this problem: calls and messages spoofed to look like they're coming from a federal agency.

Americans reported losing $789 million to government-impersonation scams in 2024, up $171 million from the year before — and older adults were 36% more likely than younger people to report losing money this way.
Social Security Administration
Callers claim a victim's Social Security number has been "suspended" or linked to crime, and pressure them to move money or share verification codes to fix it. The SSA Office of Inspector General tracks this as one of its largest ongoing scam categories, receiving tens of thousands of allegations per quarter.
IRS impersonation
Callers pose as IRS agents demanding immediate payment for supposed back taxes or penalties, often insisting on gift cards or wire transfers and threatening arrest. This was one of the original large-scale phone impersonation scams and remains a recurring seasonal spike around tax season.
Medicare / HHS impersonation
Callers pose as Medicare or Health and Human Services representatives to harvest personal and insurance information, frequently bundled with the same infrastructure used for Social Security impersonation calls.

In every case, the caller relies on the same weakness: nothing in today's phone, data, or messaging systems cryptographically proves who is actually calling. Caller ID can be spoofed outright. A verified sender identity standard closes exactly this gap — the enduser's device can confirm the sender's claimed identity before the victim ever has to decide whether to trust a stranger's voice.

Impersonation of large commercial brands

The same trust gap is exploited against companies, not just consumers. Robocall operations record a message that name-drops an airline, hotel chain, or travel site the victim already trusts, then route anyone who engages to an unrelated call center. The brand did nothing wrong and has no way to stop its name from being used — there is no verified sender field standing between the caller and the enduser's phone.

$30B
Estimated annual cost of fraudulent and robocall traffic to U.S. businesses and consumers combined (2021)
$2.5B
Estimated annual U.S. business productivity losses attributable to robocalls
$120M
FCC fine — the largest in agency history — for a single scheme spoofing Marriott, Expedia, Hilton, and TripAdvisor
Between October and December 2016, one operator placed roughly 96 million spoofed robocalls advertising fake "exclusive" vacation packages under the names of major airlines' hospitality partners and travel brands, routing answers to unaffiliated timeshare call centers in Mexico. TripAdvisor's own fraud investigation — triggered by a wave of angry customer reviews the company had done nothing to earn — is what led the FCC to the operator. The case remains the agency's largest-ever robocall fine, at $120 million.

Airlines sit in the same exposed position: a recorded call claiming to be "your airline" about a delayed flight, a fare refund, or a loyalty-account issue is functionally indistinguishable to the enduser from a real one, because nothing on the call cryptographically ties it to the airline's actual identity. The airline absorbs reputational damage and customer-service costs from calls it never placed, on top of whatever the victim loses to the scam itself. A verified sender identity standard would let an airline's calls (and a bank's, an airline partner's, or a government agency's) carry a check the enduser's device can confirm — collapsing the exact gap that made the Abramovich, TripAdvisor, and Marriott case possible.

This is a solvable problem

STIR/SHAKEN proved that call authentication works at carrier scale. Extending a verified sender identity standard — to phone, text, and email alike — is a policy and engineering choice, not a technical impossibility. The FCC's Call Authentication Trust Anchor docket (WC Docket No. 17-97) is the open, active proceeding where that extension is being decided right now.