No. of Recommendations: 0
There are several different security problems here. Misrepresentation of identity, spoofing or side channel social attacks towards the party holding your information, or tricking someone to part with their money with their own consent (hclasvegas' point).
I can walk into a bank with fake id and in a disguise and try to pretend to be someone else, even if it's not very likely to work. Online it's a little earlier. If I hack a computer, guess a password, or trick someone into giving me their password then I can use it with a username and get access to their accounts. This is usually as easy as calling someone, telling them there's been fraud, and to please authenticate with their password, since people tend to be trusting and less likely to use caution when there is a sense of urgency.
The best way to avoid this is multi factor authentication (or MFA, sometimes two-factor auth, or 2FA). On a phone or dedicated device separate from the computer or other device with login credentials, a site will send a code (or synchronize on a seed value cryptographically cycling through keys based on the seed and the time since the unix epoch, or synchronize a cryptographic key pair used to verify a signed challenge message from the issuing site). The most secure way is the passkey or a yubikey but time-based one time passwords, or TOTP (like Google Authenticator et al) still prevent credential compromise from gaining access. Even SMS is better than nothing - it's considered bad because SMS is unencrypted, so a malicious party could potentially read it in transit and steal the code. Since TOPD and passkeys are based on one-time exchanges its a much smaller risk. Some sites will send single use codes over email, which at least almost universally goes over HTTPS.
Spoofing or side channels of the personal holding your information you can't control, it's the risk of a criminal saying they are the police or a vendor, and to give them your data. It's just worth being vigilant and this is the benefit of of putting account limits for transfers or having credit watches.
Finally, and the one that worries me most currently is the one that attacks the weak link that everyone here is talking about. It's the attacks on individuals to convince them to voluntarily access their accounts and legitimately send money to the malicious party. There is no barrier to entry making convincing, realtime video or audio pretending to be a loved one in need or distress with current AI capability. People are lonelier than ever and social media companies are incentivized to encourage increasing connections, resulting in connecting with the wrong people. Malicious actors can leverage agents to expand their reach, and scam many people at once. Given dark web information purchases from various leaks/hacked data or even just lax personal privacy, bots seeded with personal information can be alarmingly convincing. Worst of all, the "miracle of compounding" works for evil here, and the more profit is available, the more profit is available and the more spoils can be "invested" back into the effectiveness of the scamming endeavor
People should take the lesson of multi-factor authentication, and initiate a call back to a known good number when they get a suspicious inbound call or video.
Crypto makes it worse. It makes it easier to launder and hide scamming profits, given some sophistication. Many transactions are irreversible (no settlement lag, chargebacks; not even a technical mechanism to make it possible). The traditional financial system has its problems but its inefficiency can be its strength.
I contemplate the viability of a company that simply offers IT (managed accounts, devices) and fiduciary services for people that otherwise don't feel they are able to deal with this threat landscape. Like most half-assed ideas, I can't see how it resolves the liability and insurance issues.
Nothing I am aware of makes me think we are heading in the right direction currently.
ps - with respect to blocking ips of malicious people or areas, it is easy for a motivated party to work around this. Just like any VPN service, your packets go to one ip address own by a service that will move it somewhere else, and when it exits that service it appears to be from what ip address it exited (in another country, or wherever). You could say "well, I'll block the ip of that service" but the service could change their exit ip addresses (or egress points). "Whack-A-Mole" gets overused as an analogy but it fits here. And a malicious part can always go through multiple, chained services. And that doesn't even touch on dark web / TOR protocol. Where there is money to be made malicious actors can be resourceful.