THE AI DECEPTION MACHINE: DEEPFAKES, CHATBOTS, AND THE NEW FRONTIER OF SENIOR FRAUD

Senate Aging (Temporary Special) Committee Senate July 29, 2026

Official record ↗ · Linked to the scheduled hearing

Full text of the official published hearing record. Extracted from the source document — verify against the official record for citation.

[Senate Hearing 119-513]
[From the U.S. Government Publishing Office]

 S. Hrg. 119-513

 THE AI DECEPTION MACHINE:
 DEEPFAKES, CHATBOTS, AND THE
 NEW FRONTIER OF SENIOR FRAUD
=======================================================================

 HEARING

 BEFORE THE

 SPECIAL COMMITTEE ON AGING

 UNITED STATES SENATE

 ONE HUNDRED NINETEENTH CONGRESS

 SECOND SESSION

 __________

 WASHINGTON, DC

 __________

 JULY 29, 2026

 __________

 Serial No. 119-34

 Printed for the use of the Special Committee on Aging
 
 [GRAPHIC NOT AVAILABLE IN TIFF FORMAT] 

 Available via the World Wide Web: http://www.govinfo.gov
 
 __________
 
 U.S. GOVERNMENT PUBLISHING OFFICE
64-451 PDF WASHINGTON : 2026
=======================================================================
 
 SPECIAL COMMITTEE ON AGING

 RICK SCOTT, Florida, Chairman

DAVE McCORMICK, Pennsylvania KIRSTEN E. GILLIBRAND, New York
JIM JUSTICE, West Virginia ELIZABETH WARREN, Massachusetts
TOMMY TUBERVILLE, Alabama MARK KELLY, Arizona
RON JOHNSON, Wisconsin RAPHAEL WARNOCK, Georgia
ASHLEY MOODY, Florida ANDY KIM, New Jersey
JON HUSTED, Ohio ANGELA ALSOBROOKS, Maryland
 ---------- 
 McKinley Lewis, Majority Staff Director
 Claire Descamps, Minority Staff Director
 
 
 C O N T E N T S

 ---------- 

 Page

Opening Statement of Senator Rick Scott, Chairman................ 1
Opening Statement of Senator Kirsten E. Gillibrand, Ranking 
 Member......................................................... 3

 PANEL OF WITNESSES

David Amron, MD, Founder & Medical Director, The Roxbury 
 Institute, Los Angeles, California............................. 4
Deborah Del Mastro, Victim of AI-Enabled Scam, Martinez, 
 California..................................................... 6
Paul Benda, Executive VP for Risk, Fraud and Cybersecurity, 
 American Bankers Association, Washington, D.C.................. 9
Matthew F. Ferraro, Esq., Partner, Crowell & Moring LLP, 
 Washington, D.C................................................ 11
Ben Winters, Director of AI and Privacy, Consumer Federation of 
 America, Washington, D.C....................................... 12

 APPENDIX
 Prepared Witness Statements

David Amron, MD, Founder & Medical Director, The Roxbury 
 Institute, Los Angeles, California............................. 32
Deborah Del Mastro, Victim of AI-Enabled Scam, Martinez, 
 California..................................................... 35
Paul Benda, Executive VP for Risk, Fraud and Cybersecurity, 
 American Bankers Association, Washington, D.C.................. 37
Matthew F. Ferraro, Esq., Partner, Crowell & Moring LLP, 
 Washington, D.C................................................ 49
Ben Winters, Director of AI and Privacy, Consumer Federation of 
 America, Washington, D.C....................................... 58

 Questions for the Record

Paul Benda, Executive VP for Risk, Fraud and Cybersecurity, 
 American Bankers Association, Washington, D.C.................. 85
Matthew F. Ferraro, Esq., Partner, Crowell & Moring LLP, 
 Washington, D.C................................................ 92
Ben Winters, Director of AI and Privacy, Consumer Federation of 
 America, Washington, D.C....................................... 94

 Statements for the Record

Alliance for Retired Americans Statement......................... 110
American Psychological Association Statement..................... 113
American Securities Association Statement........................ 118
Benjamin Riley Statement......................................... 121
Center for AI and Digital Policy Statement....................... 122
CFP Board Statement.............................................. 129
Defense Credit Union Council Statement........................... 133
Jill Hollander Statement......................................... 139
Lifespan of Greater Rochester Statement.......................... 141
National Academy of Elder Law Attorneys Statement................ 145
Pindrop Security Statement....................................... 148

 
 THE AI DECEPTION MACHINE:
 DEEPFAKES, CHATBOTS, AND THE
 NEW FRONTIER OF SENIOR FRAUD

 ---------- 

 Wednesday, July 29, 2026

 U.S. Senate
 Special Committee on Aging
 Washington, DC.
 The Committee met, pursuant to notice, at 3:43 p.m., Room 
562, Hart Senate Office Building, Hon. Rick Scott, Chairman of 
the Committee, presiding.
 Present: Senator Scott, Tuberville, Husted, Gillibrand, 
Kelly, and Alsobrooks.

 OPENING STATEMENT OF SENATOR
 RICK SCOTT, CHAIRMAN

 The Chairman. The U.S. Senate Special Committee on Aging 
will now come to order. Thank you all for being here today. One 
of the biggest issues I hear about from Floridians and seniors 
around the country is the growing threat of scams, fraud, and 
financial exploitation.
 Whether it is a phone call from someone posing as a 
grandchild in trouble, a suspicious investment scheme delivered 
through the mail, or an email from a government imposter 
threatening jail time, these criminals are targeting our 
seniors with increasing sophistication.
 Our seniors are often especially vulnerable to this kind of 
fraud. Sadly, for many older Americans, falling victim to a 
scam doesn't just mean losing money. It could also mean losing 
peace of mind, trust in others, and confidence in themselves 
while navigating daily life. As this Committee has heard many 
times before, this is a multi-billion dollar a year problem.
 In 2025, Americans over 60 lost a staggering $7.7 billion 
to scams, and that is just with scams that have been reported. 
The rise of artificial intelligence has offered scammers new 
tools to pursue their criminal schemes, and we must adapt and 
respond to these new threats. AI can be used to make fraudulent 
videos known as deepfakes, impersonating experts and 
celebrities to try to defraud our seniors in a variety of 
devious schemes.
 AI can also be used to clone someone's voice, a terrifying 
development that has been used in heartbreaking and evil ways 
to impersonate a loved one and deceive their family. AI has 
made existing scams more effective and lowered the barrier to 
entry for criminals.
 What once required real coding skill can now be done by 
anyone with an AI tool. Many of these actions are highlighted 
within the front section of our new report, Artificial 
Intelligence and Older Americans, Confronting New Threats, 
Unlocking New Opportunities. I am grateful to Ranking Member 
Gillibrand for working with me to put this report together.
 The report, which is available online at aging.senate.gov, 
includes helpful information educating on the new threats of AI 
and efforts you can take to protect yourself. Many seniors live 
on a fixed incomes and this kind of exploitation can be the 
difference between a secure, comfortable retirement and years 
of financial hardship, distress, and isolation.
 That is why we are focused on combating fraud at every 
level. We must empower seniors, families, and communities to 
protect themselves, and then we must act to fight back. That 
means understanding this new technology, supporting our law 
enforcement, educating the public, and getting innovative about 
how we protect vulnerable Americans. Understanding has to come 
first.
 That is why I introduced the bipartisan Aging with 
Artificial Intelligence Act of 2026 with Senators Mark Kelly 
and Roger Marshall. This bill directs the National Academies to 
study how older Americans are using AI, and to weigh both its 
benefits and its risk, including the various scams and fraud we 
are examining today.
 Before we can protect seniors from this technology, we need 
to understand how it is reaching them. I am grateful this 
effort has the support of groups like AARP, the American 
Medical Association, and the American Psychological Association 
but only understanding the threat is not enough.
 Seniors need an easy way to report it. That is why Senator 
Maggie Hassan, and I introduced the ReportScams.gov Act, a 
bipartisan bill that will establish a single federal portal 
where consumers can report scams, find information about 
available assistance, and have the report automatically routed 
to the relevant federal and state agencies. Seniors should not 
have to navigate a maze of bureaucracy just to be heard.
 Of course, a report is only useful if law enforcement can 
act on it. That is why I also joined Senators Katie Britt and 
Ranking Member Gillibrand to introduce the Guarding Unprotected 
Aging Retirees from Deception Act, known as the Guard Act, to 
expand existing federal grant programs. The bill funds 
specialized law enforcement training on elder fraud and 
provides tools to trace stolen cryptocurrency.
 Finally, these efforts must be coordinated. That is why I 
introduced the National Strategy for Combating Scams Act with 
Ranking Member Gillibrand to require the FBI to develop a 
unified national strategy informed by victims, law enforcement, 
nonprofits, and the private sector.
 The Federal Government has to coordinate its efforts to 
effectively combat these complex schemes. Each of these bills 
attacks the problem from a different angle, but they all share 
one goal, making sure seniors are never left to face these 
criminals alone. Today's hearing is part of that effort. We 
will hear from experts on AI policy, leaders from the financial 
sector who work to stop these thugs, and victims who have faced 
these crimes firsthand.
 Our goal is clear, we want to educate seniors about the 
rising threat of AI enabled fraud, show them how to defend 
themselves, and identify the policies the Federal Government 
can enact to help curb this threat. Seniors deserve to feel 
safe when answering the phone and opening the mail.
 They deserve to know that when they report fraud, they will 
be heard, and action will be taken. Protecting them isn't a 
partisan issue, and I am grateful for the partnership I have 
with the members of this Committee. I would now like to 
recognize Ranking Member Gillibrand for her opening statement.

 OPENING STATEMENT OF SENATOR 
 KIRSTEN E. GILLIBRAND, RANKING MEMBER

 Senator Gillibrand. Thank you, Mr. Chairman. I appreciate 
all the witnesses being here for such an important hearing. The 
question before us is not whether AI will transform our 
society. It certainly will.
 The question is whether we let it be turned against the 
people we love. Right now, criminals are using AI to steal from 
families and seniors, cloning voices, faking videos, and 
tricking honest people. Americans deserve to trust their own 
eyes and ears. That takes clear rules, honest labels, and real 
consequences.
 In just a few years, AI has become part of daily life for 
nearly every American, older adults included. AARP found that 
AI use among older adults nearly doubled between 2024 and 2025. 
That is no surprise. AI holds real promise to improve seniors' 
lives. In New York, the Office for the Aging is already 
connecting seniors with AI tools that fight scams, ease 
loneliness, and support caregivers.
 We should encourage those uses, but we must also put common 
sense safeguards in place, so this technology is never used 
against the people it is intended to serve. I often think about 
Pope Leo's first encyclical, Magnifica Humanitas, his call to 
safeguard human dignity in the age of AI. Pope Leo warns that 
technology is never neutral.
 The same tools that connect us can also be turned against 
the most vulnerable among us. Today, we will hear how that is 
already happening. Scammers use AI to generate deep fake 
images, clone voices, and launch phishing attacks that drain 
seniors' savings. In many cases, AI didn't invent these scams.
 It supercharged them, making old cons more convincing and 
far easier to pull off. AI deception takes other forms too. 
Tools that are built without real safeguards can hallucinate 
and feed older adults dangerously wrong information. Last year, 
Reuters reported an AI chatbot that repeatedly insisted it was 
human and invited a 76-year-old man to an address in New York 
City.
 He fell on his way to the train station and died of his 
injuries. This year, the New York Times reported that an AI 
tool gave a 75-year-old man bad medical advice, and he delayed 
his cancer treatment because of it. Even one case of AI fueled 
deception is too many. We can choose differently.
 We can decide how AI shapes our communities, our families, 
and the way we care for one another. This morning I sent a 
letter to leading AI companies, to the AI companion companies, 
including OpenAI, Meta, and X, asking them to explain how they 
safeguard their products for older adults and people with 
disabilities.
 I was glad to partner with Senator Kelly on this very 
letter, and I expect these companies to respond promptly and 
fully. That letter is just one step. It can't be the last. We 
need a bipartisan framework to govern AI, one that heeds Pope 
Leo's counsel by putting human dignity first and protecting the 
most vulnerable, including older adults. We must also confront 
the scams targeting our seniors head on.
 I have introduced two bipartisan bills to do exactly that, 
the National Strategy for Combating Scams Act, and the Guard 
Act. Both give federal agencies and law enforcement the tools 
they need to coordinate and to protect consumers from fraud.
 I look forward to working with Chairman Scott and my 
colleagues on this Committee to ensure that our older adults 
are protected from AI's harms and share in their benefits.
 The Chairman. Thank you, Ranking Member. I would like to 
welcome our witnesses today. They are here to help the 
Committee understand the landscape of AI driven fraud and share 
their experiences dealing with these types of scams. First, I 
would like to recognize Dr. David Amron, an internationally 
recognized Surgeon and the Founder and Medical Director of the 
Roxbury Institute.
 He joins us today because he saw firsthand how this 
technology can be turned against us. Scammers used AI to create 
a deep fake video of him endorsing a fake miracle cream, a 
product he never made and never endorsed.
 Thank you for being here. You may begin your testimony.

 STATEMENT OF DAVID AMRON, MD, FOUNDER

 & MEDICAL DIRECTOR, THE ROXBURY

 INSTITUTE, LOS ANGELES, CALIFORNIA

 Dr. Amron. Chairman Scott, Ranking Member Gillibrand, and 
distinguished members of the Senate Special Committee on Aging, 
thank you for the opportunity to testify before you today.
 My name is Dr. David Amron, and I am the Founder and 
Medical Director of the Roxbury Institute in Los Angeles, 
California, and the Founder and Chair of the Lipedema Society. 
For more than three decades, I have dedicated my career to 
treating patients with lipedema, a chronic and often 
misunderstood disease that affects millions of women worldwide.
 I am widely recognized as a pioneer of lipedema surgery in 
North America and have devoted my career to advancing 
treatment, educating patients, and advocating on behalf of 
patients to help them obtain insurance coverage for their care. 
As physicians, trust is the foundation of everything we do.
 Patients rely on us during some of the most vulnerable 
moments of their lives. I have spent more than three decades 
building that trust, yet scammers used artificial intelligence 
to exploit it in a matter of moments.
 Although I know AI was rapidly evolving, I never imagined 
how quickly it could be weaponized to deceive patients until it 
happened to me. We first became aware of the scam in the summer 
of 2025, with reports increasing significantly by early 
September. Patients began contacting the Roxbury Institute 
after seeing a video that appeared to show me endorsing a so-
called miracle cream, miracle lipedema cream.
 Many forwarded us the video, but by then, some had already 
purchased the product before realizing it was fraudulent, 
including several of my own patients. The video was 
disturbingly realistic.
 Scammers used actual footage from my YouTube channel and 
combined it with fully integrated, AI generated likenesses of 
my voice and my colleague, Dr. Karen Herbst, the head of 
research and director of diagnostic and preventive medicine at 
the Rocksbury Institute. As well as AI generated celebrity 
images and stolen media logos to create a polished 
advertisement that appeared entirely legitimate.
 As soon as we recognized it as a coordinated deepfake, my 
team immediately issued public advisories across social media 
platforms to warn patients, clarify that neither Dr. Herbst nor 
I had any involvement, and help our community recognize and 
report AI generated medical impersonations.
 Our web developer and digital marketing strategist 
immediately began investigating the scam as soon as patients 
alerted us. Before taking action, he investigated the company 
behind the product, Svelta Venastra, and quickly confirmed it 
was not a legitimate medical entity. He reported every version 
of the advertisement to Meta, the fraudulent accounts 
responsible for publishing it, the domain registrars hosting 
websites, and the major search engines directing consumers to 
the scam.
 Yet each time one version was removed, another quickly 
appeared. This continued over the course of 11 days. Despite 
these persistent efforts, the scam kept on recurring. It became 
quickly clear that existing reporting scams--reporting them was 
not simply enough to stop a coordinated AI enabled fraud 
campaign.
 After exhausting every avenue available to us, we realized 
we needed to bring national attention to what was happening. We 
then reached out to major television networks because we 
believed public awareness might accomplish what traditional 
reporting mechanisms could not.
 The Today Show responded, conducted its own investigation, 
and ultimately brought the scam to a national audience. The 
Today Show attempted to identify and contact the individuals 
behind Svelta Venastra, just as we had. Like us, they found no 
legitimate company, no accountable representative, and no one 
willing to respond.
 Although the fraudulent video was eventually removed, 
versions of the scam have since resurfaced, underscoring how 
persistent and difficult these AI enabled fraud schemes are to 
eliminate. What disturbed me most was not that somebody had 
misused my image. It was knowing that scammers had used my name 
and my reputation to deceive the very people I have dedicated 
my career to helping and protecting.
 The consequences extend far beyond financial loss. Patients 
may delay legitimate medical care for a progressive disease 
like lipedema, place their trust in unproven products and 
services, and allow the condition to worsen. Perhaps most 
damaging, these scams erode the trust patients place in their 
physicians. Once that trust is broken, patients no longer know 
whom they can trust.
 Artificial intelligence has fundamentally changed the 
landscape of fraud, giving scammers the ability to convincingly 
impersonate trusted physicians, fabricate endorsements, and 
deceive patients on an unprecedented scale. What happened to me 
is not an isolated incident.
 Physicians across our country are discovering their images, 
voices, and professional reputations are being used without 
their knowledge or consent to promote products they have never 
evaluated, recommended, or many times even heard of. The danger 
is clear, these scams put at risk and undermine the credibility 
of the medical profession. Older Americans are especially 
vulnerable because they often place tremendous trust in their 
physicians.
 Many also rely on the internet, including social media and 
online search results to learn about medical conditions, making 
them especially susceptible when fraudulent content appears to 
come from trusted medical professionals. When they see a 
realistic online video of a trusted physician recommending a 
treatment, they have little reason to question its 
authenticity. That is precisely what makes today's AI generated 
deepfakes such a powerful tool for deception.
 This problem is no longer theoretical. It is happening 
right now, and the consequences for patient safety, medical 
ethics, and the integrity of health care information are 
profound. If we do not act, more older Americans and other 
vulnerable patients will become victims of increasingly 
sophisticated AI enabled fraud.
 I respectfully urge Congress to strengthen protections 
against AI generated impersonation scams, improve 
accountability for those who create and distribute them, and 
ensure our laws keep pace with technology that and so easily be 
used to exploit trust for financial gain.
 Thank you for the opportunity to testify today. I look 
forward to answering your questions.
 The Chairman. Thank you very much. Very sorry that happened 
to you. Next, I would like to introduce Deborah Del Mastro. She 
is a Bay Area mother from Martinez, California, who became a 
public face of the growing AI voice cloning scam after 
criminals used artificial intelligence to mimic her daughter's 
voice.
 She is also a San Francisco Bay Area singer, voice coach, 
actress, and musician who has taught in voice, drama, and 
trumpet for over three decades, sharing her voice and her love 
of music with her community. Thank you for being here. Please 
begin your testimony.

 STATEMENT OF DEBORAH DEL MASTRO, VICTIM 
 OF AI-ENABLED SCAM, MARTINEZ, CALIFORNIA

 Ms. Del Mastro. Thank you. I am very honored to be able to 
come and share my story with you also. I think my main goal is 
to let people know that these criminals have, you know, 
technology that we don't know about. I call this the worst day 
of my life. It was Thursday, May 14th.
 The day started with a phone call in the morning. My 
husband and I were at the breakfast table, and I answered a 
phone from a local number. I get a lot of my work that way, you 
know, and I didn't think anything of it. I answered and said, 
"hello," and a male voice said, "hello, who is this?" I said, 
"who is this?"
 He said, "someone you need to talk to. I have your 
daughter. Is your daughter prone to panic attacks?" Again, I am 
sitting in my pajamas at the breakfast table, and I said, "my 
daughter? Yes." Then he put on--I could hear commotion in the 
background. He put on her voice--now I know her voice and not 
her--saying, I am so sorry, I am sorry, mom.
 I am so scared. I am so sorry, and crying, sobbing. It was 
her voice. It was absolutely her voice. Then he got back on and 
said that he had 10 pounds of cocaine in his trunk, and my 
daughter saw a deal go down that she shouldn't have seen, and 
that his boss was Mexican drug cartel, and his boss told him to 
take her.
 He says, his boss doesn't care who he kills, and that he 
wants $20,000 for the return of my daughter, or he will sell 
her for what is between her legs. He will kill me, my family, 
and my daughter if I don't do this, if I come up with the 
money. Now, we don't have that money. We just don't.
 I am incredulous with my jaw dropped. I couldn't speak to 
my husband. I quickly got dressed. I had him on the phone the 
entire time. As I left the house, I mouthed to my husband that 
she had been kidnapped. He didn't know where I was going or 
what was going on at all, but he could just tell it was 
serious. This man was barking orders to me about having to have 
the money right away or the boss will do something with her.
 He told me to bring a phone charger and not to let my phone 
die or else I would never see my daughter again. He made 
demands for the next five and a half hours. First to send 
$2,000 by Western Union to Mexico. He wanted $2,500. I told him 
I didn't have it, which was really true--just $2,000. He had me 
go to a local Walmart and that is where I used MoneyGram to 
send $2,000 to Mexico. I took a picture of it and texted him 
the receipt as he asked. Then he told me there was a problem 
with it and that there was an error, and I needed to send the 
money again. I told him I did not have the money.
 He said that I would be reimbursed. It would be fine. Just 
send it again. I said I did not have it. He wanted another 
$500. I said, all right. I went to my car and found that in my 
panic, I had locked my keys in the car. Then I had to call my 
husband to come pick me up, which also brought his bank 
accounts into play. My husband drove us around with his phone 
on GPS and my phone on with this person, listening to every 
moment of it.
 He ran us around to a bunch of different places, 20 miles 
away to another Walmart and to Martinez. Twice we were on the 
phone with this awful man the entire time, listening for every 
sound, asking where I was, what was going on if I was silent, 
threatening my family's lives, and telling me that he could 
sell my daughter right now. I tried our local Safeway to send 
it. It wouldn't work. Went to Walgreens. He told me not to 
speak during the entire time I was in any store doing these 
payments, and to leave the phone on so he could hear everything 
that happened.
 Again, I took pictures of the receipts and texted him, now 
a different number. All the time he was threatening, if I 
didn't hurry, there was going to be problems. Now he said he 
was going to drop my daughter off at the first place, then he 
was going to drop her in another place, then he was going to 
drop her off in another space. As we were driving to different 
places and sending money.
 We sent $5,400 altogether in four different transactions. 
When it was over, it was about five and a half hours. By the 
time they probably figured that we didn't have any more money 
to give them, he ended it. He said, it is over. We were now 
back 20 miles away at another Walmart, and he said that he had 
released my daughter at the front of the Walmart, and we were 
there.
 He said, go get her, go pick her up or call her, and hung 
up. I jumped out of the car. She was not there. I was in a 
total panic. Then I called her. She answered the phone and 
said, hi, mom. What is going on? I was never so happy in my 
life to be scammed, so relieved, and furious that we had fallen 
for this. I heard her twice. I had to be silent with--even in 
the car driving.
 There was one time I actually muted the phone so I could 
speak to my husband, and he started screaming not to do any--no 
funny business or I would never see her again. He threatened to 
harm us and my daughter saying that he had kids, and he would 
kill anyone that got in the way if his kids were at risk.
 His boss didn't care about anyone. He talked many times how 
he would sell Sarah for $20,000 or she could pay her way in 
other ways, hinting that she would be sex trafficked. That he 
was doing us a favor because we were respectful of him. He had 
me talk with Sarah again.
 I asked many times if I could speak to my daughter to make 
sure she was okay. He had me speak to her again after we had 
sent, I think, the third amount. He told me exactly what I was 
to say to her. He said, tell her that this nightmare is almost 
over. You are going to pick her up as soon as possible. I did 
that. I said exactly that. My daughter's voice said, I am so 
sorry, mom. I love you.
 After that, another man's voice came on, who was much more 
harsh--the enforcer--who threatened harm to us and Sarah if we 
didn't come up with more money. That is when we sent another 
$1,200. It was the last of our available, accessible money. It 
was a worst day of my life--and my husband, too.
 Yes, some people are just so broken. I am a Navy veteran. I 
am usually very, very calm and collected in the face of crisis. 
I always say I am the person that runs to the fire, not away 
from it. I was totally, totally convinced that this was my 
daughter's voice. Yes, you know, it is the perfect scam. It is 
the perfect scam to talk to family and tell them that you are 
going to kill them, sell them.
 You know, it is the perfect scam because you are willing to 
do anything to get your kids, get your daughter back. I spent 
most of that time in silence with my husband driving back and 
forth just trying to figure out how he is going to help her get 
through her life after an event like this and thank God it was 
a scam. Thank God it a scam. I had no idea that this was a 
possibility, that AI could clone the voice.
 Now, when I called my daughter, both my kids work in IT, my 
daughter said, mom, that was an AI clone of my voice. She knew 
it immediately. I said, I didn't know. There needs to be 
awareness about this, and there needs to guardrails.
 We need to find out how to protect those of us who don't 
know about this. Thank you. Thank you for letting me testify. I 
appreciate it.
 The Chairman. We are sorry. First--[technical problems]----
 Ms. Del Mastro. Yes.
 The Chairman. We are sorry this has ever happened to you.
 Ms. Del Mastro. Thank you.
 The Chairman. Next, I would like to introduce Paul Benda. 
He is the Executive Vice President for Risk, Fraud, and 
Cybersecurity at the American Bankers Association where he 
leads the association's initiatives in fraud, cybersecurity, 
fiscal security, and information security practices, and chairs 
the ABA fraud coordination group. Thank you for being here. 
Please begin your testimony

 STATEMENT OF PAUL BENDA, EXECUTIVE VP

 FOR RISK, FRAUD AND CYBERSECURITY, AMERICAN

 BANKERS ASSOCIATION, WASHINGTON, D.C.

 Mr. Benda. Chairman Scott, Ranking Member Gillibrand, and 
members of the Committee, thank you for the opportunity to 
testify. I am so sorry what you went through. I think it proves 
the point why we are here today.
 We are all here to protect Americans from these, as you 
said, Senator, thugs--these despicable people doing these 
things. The central point in my testimony is straightforward, 
generative AI is not replacing traditional scams. It is 
industrializing them. Generative AI is making impersonation 
dramatically easier and more convincing. With very little 
technical skill, a criminal can mimic someone a victim trusts 
and use personal information gathered online to make the scam 
feel authentic.
 What once required significant time, skill, and resources 
can now be done quickly, cheaply, and at scale. These crimes do 
not succeed because older Americans are unsophisticated. They 
succeed because professional criminals are very good at 
exploiting trust, fear, urgency, and authority. AI simply gives 
them more powerful tools to do that. A recent FBI warning shows 
how this threat is evolving.
 The FBI reported that criminals are using AI generated 
videos of senior FBI officials, fake social media profiles, and 
spoofed government websites to impersonate the Internet Crime 
Complaint Center and target prior victims. In other words, the 
promise to recover stolen money becomes the mechanism for 
stealing even more.
 Bank impersonation scams are another serious example. Just 
last week, the FCC warned they produced the highest losses of 
any impersonation scam category and stressed one rule, banks 
will never ask you to move money to protect it. Additionally, a 
survey of 14 large banks found identified bank impersonation 
scams rose 150 percent from 2024 to 2025.
 The threat is growing rapidly, and much of the deception 
occurs before a bank ever sees the transaction. Banks are 
responding aggressively. They are using AI and advanced 
analytics to recognize behavior that may indicate fraud and to 
intervene before money leaves an account.
 Technology is only part of the defense. A trained banker 
may notice that a longtime customer is suddenly trying to send 
a large payment while appearing frightened, secretive, or 
coached by someone on the phone. In those moments, human 
judgment and the relationship between banker and customer can 
be just as important as any algorithm. Education is equally 
critical.
 More than 2,500 banks have participated in the ABA 
Foundation's Safe Banking for Seniors Program. The ABA and FBI 
have developed materials specifically addressing deepfake 
scams. We are also expanding training to help bankers intervene 
when a customer has been drawn deeply into a scammer's story. 
For consumers, the answer is not to become experts at spotting 
deepfakes.
 The better approach is to change how we react to unexpected 
requests for money. Seniors should pause before acting, verify 
the story through a separate, trusted channel. Families should 
consider establishing a private password for real emergencies. 
Remember, if it is a secret, it is scam.
 Criminals depend on urgency in isolation. They do not want 
the victim talking to a family member, a banker, or law 
enforcement. We also need to recognize where the scam 
lifecycle--where in the scam lifecycle banks enter the picture. 
We train consumers not to send money to someone they do not 
know and trust.
 The problem is that by the time they are ready to send the 
money, they often believe they know and trust the person on the 
other end. Generative AI is making it much easier for criminals 
to manufacture that trust. Increasingly accessible tools can 
alter a scammer's appearance in real-time video conversation to 
match the persona they are impersonating.
 AI can clone voices and translate conversations in real 
time allowing criminals halfway around the world to communicate 
convincingly with an American victim. By the time the bank sees 
the payment, that relationship may have been developing for 
days, weeks, or even months through telecommunication networks, 
social media, online advertising, or messaging platforms. The 
victim is no longer sending money to a stranger. In their mind, 
they are sending money to someone they know and trust.
 Banks will continue to intervene where we can, but 
responsibility has to extend upstream to the telecommunications 
and online platforms where the impersonation begins, and trust 
is manufactured. The best fraud prevention is to stop the 
criminal from reaching and deceiving the victim in the first 
place.
 My written testimony lays out a broad policy agenda. We 
need clear national leadership, which is why ABA is proposing a 
national office for scam and fraud prevention. We urge Congress 
to enact the Scam Act, led by Senators Gallego and Murillo, so 
online platforms have meaningful obligations to verify 
advertisers and rapidly respond to fraudulent ads.
 Stronger telecom safeguards are needed to keep criminals 
off calling networks and restore trust in caller ID. Federal 
support can help state and local authorities build specialized 
financial crime capacity. Older Americans should not be 
expected to distinguish on their own and in real-time between a 
loved one and a cloned voice, or between their bank and a 
criminal using their bank's name and telephone number.
 Banks will continue investing, educating, intervening, and 
helping victims recover, but durable progress requires every 
part of the scam ecosystem to help prevent the exception before 
the victims send money. Thank you, and I look forward to your 
questions.
 The Chairman. Thank you, Mr. Benda. Next, I would like to 
introduce Matthew Ferraro. He is a partner in Crowell & 
Moring's Privacy and Cybersecurity Group, where he helps 
clients address complex regulatory matters at the intersection 
of advanced technology, national security, and crisis 
management. Thank you for being here and please begin your 
testimony.

 STATEMENT OF MATTHEW F. FERRARO, ESQ.,
 PARTNER, CROWELL & MORING LLP, WASHINGTON, D.C.

 Mr. Ferraro. Chairman Scott, Ranking Member Gillibrand, and 
members of the Committee, thank you for the opportunity to 
appear before you today on this critical issue. My name is 
Matthew F. Ferraro. I am a partner at the law firm Crowell & 
Moring, where I counsel on artificial intelligence, 
cybersecurity, and regulation.
 I also previously served in government, most recently as 
Senior Counselor for Cybersecurity and Emerging Technology to 
the Secretary of Homeland Security, and previously as a U.S. 
Intelligence Officer. I have been working on the policy and 
legal issues related to AI generated media or deepfakes since 
2019. I should say I appear today in my personal capacity.
 My views do not represent those of my firm or any of my 
clients. Let me begin with a rhetorical question. How often 
today have you relied upon the voice of a loved one or the 
image of a trusted figure before sharing something of value? 
Perhaps your daughter called from college this morning to ask 
for a few hundred dollars and you sent it.
 Maybe you had a video call with a tech support worker and 
shared your account information. Tonight, you may scroll 
through social media and see a video of a doctor endorsing an 
herbal supplement and decide to purchase it. Now consider, what 
if those representations were all fake?
 Not your daughter, not the technician, not a doctor, but 
voices and images forged by AI. Welcome to the world of 
deepfakes. It is a world we have been living in for several 
years where AI can create realistic audio, images, and videos 
that appear true to life but are forgeries. Nearly anyone can 
access this technology, often for free, and their creations can 
be sent around the world instantly.
 While AI generated media has legitimate creative uses, 
deepfakes can supercharge scams and cyber frauds, especially 
those targeting senior citizens. In the first quarter of 2025 
alone, financial losses from deepfake enabled fraud exceeded 
$200 million, according to an industry report. Deloitte 
projects that generative AI could enable fraud losses to reach 
$40 billion in the United States alone by 2027.
 Older adults bear a disproportionate burden. They are five 
times more likely to lose money in a scam than younger people, 
and according to the AARP, the top digital risk for seniors is 
scams and frauds.
 The forms these scams take are varied. For example, 
fraudsters use AI to generate fake ads featuring the likenesses 
of celebrities and trusted professionals to sell a range of 
goods from cryptocurrency to medical cures, as we have heard. 
Scammers have also cloned the voices of family members telling 
their victims their loved ones have been kidnapped and 
demanding ransom, as Ms. Del Mastro testified so powerfully to 
a few minutes ago.
 Romance scammers can use AI generated imagery to build 
ersatz, emotional relationships with victims, before stealing 
their money and their personal information. What can we do 
about it? I offer three recommendations.
 First, we must prioritize education and awareness for all 
digital media consumers, especially seniors. We should deliver 
that education through trusted community channels, like senior 
centers, physicians, community groups, and houses of worship.
 We must cultivate the appropriate level of skepticism and 
of discernment. Given the deluge of AI generated media that has 
and will come, the surest defender against deepfake dupes lies 
between our ears. Second, we should seek greater coordination 
across federal and state agencies and with industry. Existing 
laws already give regulators meaningful tools. The principle 
applies, if it is illegal without AI, it is illegal with AI.
 Better knowledge sharing among policymakers, law 
enforcement, and industry can promote efficiency, improve 
threat mitigation, and bolster effective enforcement. Third, we 
should invest in technology. We should promote the use of both 
AI detection tools and provenance technology that tags media as 
human created or AI generated.
 Integrating those tools into our daily lives, much as we do 
with email spam filters, can help all Americans, and especially 
seniors tell facts from fakes. I want to close on this note. We 
should not succumb to cynicism.
 New technologies, married to ancient vices require 
responses, but they should neither slake our appetite for 
innovation and creativity, nor extinguish our faith that we 
can, with the right steps, navigate the digital world with 
confidence.
 Thank you. I look forward to your questions.
 The Chairman. Thank you. Now, I would like to recognize 
Ranking Member Gillibrand to introduce the next witness.
 Senator Gillibrand. Thank you, Chairman Scott. I want to 
introduce Ben Winters. Mr. Winters is the Director of AI and 
Privacy at the Consumer Federation of America, where he leads 
CFA's advocacy efforts regarding data privacy and AI to 
advocate for consumers.
 Previously, Mr. Winters worked as an Attorney Advisor for 
the Civil Rights Division of the Department of Justice and 
Senior Counsel at the Electronic Privacy Information Center. 
You may begin.

 STATEMENT OF BEN WINTERS, DIRECTOR OF

 AI AND PRIVACY, CONSUMER FEDERATION

 OF AMERICA, WASHINGTON, D.C.

 Mr. Winters. Thanks. Good afternoon, Chair Scott, Ranking 
Member Gillibrand, and members of the Committee. Thanks for the 
opportunity to talk to you today. I am Ben Winters, Director of 
AI and Privacy at the Consumer Federation of America, a 
nonprofit membership organization serving consumers since 1968.
 Online scam losses have been an unacceptable rate for years 
but have exploded since generative AI became commercially 
available and aggressively marketed in 2023. Losses reported to 
the FBI have ballooned from $3.5 billion dollars in 2019 to 
$12.5 billion in 2023, to $21 billion last year in 2025.
 Again, that is just to the FBI, that is just reported, and 
that is just online scams. CFA estimates in our true cost of 
scams report that the real number is closer to $150 billion 
lost just last year, with Americans over 60 losing $55 billion. 
Given this prevalence and scale, it is not surprising that 
older Americans describe scams as unavoidable, in that it takes 
just one minute of distraction to fall victim.
 Generative AI is not the sole cause of rising scam losses, 
but it is right now a scammer's dream. It makes scams easier, 
more effective, and harder to trace. This is just one part of 
multiple trend lines converging to this record losses. AI 
companies that aggressively push tools with no regard for harm, 
an executive branch that refuses to hold tech companies 
accountable, and confusion and uncertainty around health care 
eligibility, benefits, and economic security that scammers are 
exploiting in real time.
 Scammed content generated by AI systems are just one part 
of the puzzle. Unregulated and underregulated technology is 
pervasive across the entire flow of how a scam is created, 
targeted, delivered, and carried out. CFA calls this the scam 
stack. This is everything from data brokers that sell detailed 
personal data, enabling hyper targeted scams based on sensitive 
characteristics like--and this is a real example--lists of 
people battling Alzheimer's.
 This goes to mass communication methods like robotexters, 
robocallers, and social media companies like Facebook through 
ads and feeds that allow obvious scam content to remain despite 
having the technology to detect it. This goes the payment 
platforms, banks, and crypto wallet providers that let the 
money go and allow obfuscation of the chain of custody.
 Last, reporting mechanisms on phones and social platforms 
that are ineffective, inconsistent, buggy, and disconnected 
from other reporting mechanisms, like at the government 
agencies who can do enforcement.
 My written testimony goes into further detail about how 
generative AI enables elder fraud at each level of that scam 
stack and the harm caused by its unchecked growth but it is not 
just scams. AI systems like chatbots mislead by pretending to 
be real, sounding authoritative, trying to get you hooked, or 
giving dangerous medical or financial advice, and are also used 
by third parties to flood the information ecosystem with 
convincing falsehoods.
 That matters especially for older adults, isolated people, 
and those under health or financial stress. At scale, AI 
generated misinformation erodes trust in everything people see 
and hear. It is hard to avoid using these online platforms and 
scammy content, scams, and falsehood fueled by AI are hurting 
us all.
 I want to be clear that the devastating deception we are 
seeing is not a result of technological ineptitude for older 
users, the exclusive domain of the dark web, or overseas scam 
compounds, but rather a crisis emboldened by the biggest tech 
companies we know, paired with a failure to rein them in.
 This is not an issue of personal responsibility, but 
something Congress is uniquely positioned to address. My 
written testimony details more than a dozen legislative and 
oversight recommendations with specific bills that have already 
been introduced, but I want to spend a few minutes talking 
about that today--a few of them, sorry.
 One, Congress should hold platforms accountable for 
spreading, delivering, and targeting scams by passing a bill 
like the Scam Act, introduced by Senators Moreno and Gallego. 
We should pass comprehensive data privacy laws, data 
minimization, and bans on the sale of sensitive data, so it is 
no longer allowed to be able to sell lists of people battling 
Alzheimer's for targeting.
 Pass bills improving the reporting and statistics status 
quo with a bill like ReportScams.gov Act by Chair Scott and 
Senator Hassan but would recommend improving that to require 
platform participation. It is outrageous how complicated the 
answer is to what do I do when I have been scammed. Reject any 
provisions that prohibit states from regulating technology or 
ones being pushed by tech companies right now to limit their 
liability.
 Legislation must be paired with sustained oversight of 
enforcement agencies like the FTC, CFPB, and FBI to ensure key 
authorities are focused on collaboration, investigation, and 
choking out the scam upstream, not just chasing individual 
scammers after the fact. There is no silver bullet for fixing 
this crisis, but continued inaction only hurts Americans.
 Thank you again for the opportunity to testify, and I am 
happy to answer any questions.
 The Chairman. Thanks for being here. I bet your last job 
was interesting too. Fascinating what they do. Okay, Senator 
Tuberville, would you like to start?
 Senator Tuberville. Thank you, Mr. Chairman. We have got a 
mess. We know it. You know, technology is bringing us more and 
more every day. We have heard the problems. My solution is 
education at a young age. Baby boomers are in trouble because 
we are all going to get scammed one way or another, and not 
just domestically, but internationally.
 I mean, we are going to--it is big time. I hear a lot of 
problems with that. Mr. Ferraro, how do we fix this? We got the 
problem. Give us a solution. I am going to ask everybody this, 
so get your solution ready.
 Mr. Ferraro. Senator, there is no silver bullet, as Mr. 
Winters said, but I do think that education is very powerful. 
If you are looking for an example, I would point the Committee 
to the example of Finland, which has been very aggressive in 
teaching both young and old, this is in my written testimony, 
about disinformation more broadly, but synthetic media 
particularly.
 They have found that it works, that you can actually 
instruct people to be on lookout for false media too, as Mr. 
Benda said, pause before you send any money, double check, and 
do all the things that we should do before we make any rash 
decisions. I do think education is quite important.
 As I said, I think from a government perspective, 
interagency cooperation is key here. This is an area where 
there isn't now a quarterback, to use a metaphor, in the 
government on these issues, and I think that is something that 
the Committee might want to consider. I know that there are 
some bills pending for the Committee on those issues.
 Third, as I mentioned in my testimony, I think the 
technology piece is important as well. I mean, just draw the 
analysis or the analogy rather to email spam. You receive 
thousands of pieces of spam every day.
 You just don't happen to see them because they are filtered 
out by spam filters. One could imagine a situation where 
similar technology operates in the background on your browser 
or on your phone to either tag or remove AI generated media. 
The technology largely exists now. It is just a matter of 
integrating it. I would offer those.
 Senator Tuberville. Well, if you do anything in life, you 
know, the big thing is when you get a manual, you get ethics 
with it first. The same thing with AI. We have to teach our 
kids ethics. Again, a lot of us are lost and gone, but our 
young kids can learn it. Mr. Benda, you have worked for DHS and 
DOW. Give us your solution.
 Mr. Benda. Absolutely. I think you are right, education is 
the key pillar. I think you start out young. I think having a 
national campaign on how to fight AI deepfakes, how to fight 
scams and fraud is important.
 ABA runs financial literacy programs for children. 
Integrating the AI threat into that and scam threat into that 
is something that we are looking at doing. I think the national 
campaign could address people of all ages. I have hope for 
boomers, sir. I have some boomers that I love, my mother-in-law 
in one particular.
 I think the focus needs to also be on safe banking for 
seniors. How do we get the message to them in channels that 
they respect, and they use? Whether it is directly from a 
banker or from people they trust.
 The other piece I would point to is we have to enable and 
stop the tech companies from allowing the impersonation that 
happens out there. You should be able to trust what is on your 
caller ID.
 If you put a name and number on there, the telecom should 
be held accountable if it is not the right person calling. The 
social media platforms need to stop the impersonations and 
scams that are out there.
 They shouldn't be allowed to post the videos that the good 
doctor talked about. Those types of things, I think, we need 
more controls and I think there is some legislative solutions 
that are out there.
 Senator Tuberville. Yes. Ms. Mastro, I feel your pain. My 
mother-in-law got scammed. This is internationally. She got a 
call from my granddaughter. She was in Europe. Please send 
$10,000. I need it bad. I am broke. I have got to get out of 
this situation. She sent it.
 She wasn't in trouble, other than the fact she just needed 
the money. It sounded just like her. What kind of legislation 
do you think we need to do for something like this? Have you 
talked to anybody since your debacle?
 Ms. Del Mastro. I have not spoken to any legislators until 
right now. I have spoken to a few experts in the field though, 
and I believe that--I mean, there are plenty of courses and 
education out there on how to use AI.
 That is something you see on social media all the time, 
those ads, how to learn--take this class, learn how to use it. 
There is nothing out there on how to protect yourself from AI. 
There is nothing out there, so that needs to happen.
 We need to know how to recognize it and how to protect 
ourselves from it, besides having a safe word, not answering 
the phone, you know, all the things that everybody immediately 
goes to.
 There has got to be an awareness that for senior citizens, 
certainly, you know, all of us don't know how to hand the 
remote to the kids to change things.
 I mean, we need to be aware--if I had been aware that my 
daughter's voice could possibly be an AI clone, I would have 
responded differently, but I did not know. I think we need--
education is key, is key, and awareness is key.
 Senator Tuberville. Just think about, we are just now 
beginning AI. Just think of how much more they are going to be 
able to fool people and it is going to get worse and worse. 
Thank you very much. Thank you, Mr. Chairman.
 The Chairman. Senator Kelly.
 Senator Kelly. Thank you, Mr. Chairman. Thank you for 
having this hearing. As I think all of us know, AI has a very 
real potential of changing everything about our lives. It is 
changing how we work, how we make decisions, how entire 
industries are operating, reshaping our economy, energy 
systems, and national security.
 It is affecting people's daily lives. While it brings 
enormous opportunity, it also introduces risk that demands some 
serious oversight. That is why we are here today. Over the past 
year, I have been thinking a lot about how we make AI work for 
all Americans, not just a few big companies. That is what led 
me last year to put out a roadmap called AI for America.
 The ideas behind the roadmap are pretty simple. That is, if 
AI is going to transform our economy, we need to have a real 
plan to make sure Americans aren't left behind and that the 
technology is developed and used responsibly. Here is the 
thing, these systems are evolving very quickly, even just 
quickly in the last few weeks. There is a lot that we don't 
know, and there is a lot that the developers themselves don't 
know about what some of these products are capable of.
 Older Americans need to be included in this conversation 
and not treated as just some afterthought as these products are 
developed and deployed. About one in five Arizonans in my state 
are over the age of 65, and when I hear from seniors in my 
state, they tell me they are concerned about what is real and 
what isn't real.
 Ms. Del Mastro, you certainly have experienced that, and I 
am so sorry for what happened to you and your family. Seniors 
are seeing more convincing phishing scams and AI generated 
scams and other forms of online fraud. Sometimes people don't 
know if they are talking to a bot or a real person. Just 
yesterday, I was on the phone with my cable company. I called, 
and I was convinced that this was an artificial person.
 I still think it may have been. It may have been augmented 
by a real personal. When I started questioning whether or not 
the person was real, it became the real person. I think there 
are systems where one person, where you can have the AI 
overlaid and there is somebody monitoring. Anyway, we sorted it 
out. I got the real personally eventually. These are real fair 
concerns, and it affects everybody. I share them and I do 
spend--in my former career as somebody who used a lot of 
technology.
 Last week, I introduced legislation with Senator Justice 
called the Senior Chatbot Protection Act. This bill will 
require companies to clearly disclose when consumers are 
interacting with AI and safeguard sensitive conversations and 
address deceptive design practices in their products that put 
people at risk.
 We want to help people make informed decisions while 
supporting not replacing human judgment and trusted 
relationships. Today, Ranking Member Gillibrand and I are 
asking the leading AI companies directly, how are you making 
sure your products are safe for older adults? Are you designing 
products with them in mind? Do you even know how many older 
adults are using your products?
 If we want to make sure AI will help rather than harm, we 
need to know about, you know, who is using it, how they are 
using it, and how it reacts in the real world. That is the 
purpose of my bipartisan aging with AI act which the chairman 
mentioned, which we introduced, Chairman Scott and I, in June. 
It will help us build the evidence we need by supporting 
research into how seniors use AI and its risks and benefits. We 
have a lot of work ahead of us.
 AI companies have a responsibility to make their products 
safe, to be honest about their limitations, and protect our 
constituents who use them. Congress has a responsibility to set 
clear rules, demand accountability from tech companies, and 
make decisions based on science, data, and facts.
 We have an opportunity to get ahead of these problems. We 
often do not here in Congress, but we should, and we have to in 
this case because the window is not going to stay open forever 
on this. We have got to get this right now.
 In my remaining time, which I have none--maybe the chairman 
can give me another 45 seconds--Mr. Winters, based on the harms 
you have seen and talked about during your testimony, how would 
the protections in the Senior Chatbot Protection Act make AI 
chat bots and voice assistance safer for older Americans? And 
is it important for Congress to do this?
 Mr. Winters. Yes, thank you, Senator, for the question. I 
think that some of the provisions in that bill are 
extraordinarily useful, right. As you mentioned, it is nonsense 
to not be able to feel confident that you are actually talking 
to a person or not, right, so that feels like an absolute 
baseline thing we can do.
 We can also sort of, you know, integrate significant 
restrictions on the way the chatbots are actually sort of 
looking to the user, right, to make it more obvious that it is 
a chatbot, to make it clear what the choices from those 
companies are. I think one thing, not to take up too much time, 
that I want to underline is that the chatbot products 
especially are products.
 Their tech companies have choices about what gets spit out 
by those chatbots, how they are built, and sort of how you 
interact with them. I think that there are a number of pieces 
of legislation, including the Senior Chatbot Protection Act, 
that would be absolutely a positive step forward in making sure 
those tech companies are pulling their weight and helping here.
 Senator Kelly. Thank you.
 The Chairman. Thank you, Senator Kelly. Dr. Amron, you 
discovered a deepfake video using your face and voice to sell a 
product you never made and never endorsed. Can you walk through 
what you had to do to report it and what the process of trying 
to get it down was like?
 Dr. Amron. Yes. It was not easy, and it continued to go on. 
I am going to have to refer back to some notes I have by my 
team that got involved with this. There was a lot of effort 
that went in to try to get this down, putting pressure on Meta 
to respond.
 It took eleven days to get a response back from them. The 
team never got transparency in terms of answers, and any 
timeline, and things like that. It was a very non-transparent 
process with it. There was no meaningful followup to get the 
Facebook ads down.
 The responses we got back were very generic. You never 
actually knew that you were actually communicating with a real 
human being with this. We eventually got, at least the Meta 
ads, down in eleven days. The websites continued to be up 
there. Then it reappeared weeks and months later again, so it 
is just a perpetuating process.
 The Chairman. All right, thank you. Ms. Del Mastro, what 
did you do immediately after realizing that you had been 
scammed? Were you able to recover any of the funds that were 
lost? How did losing those funds affect you and your husband's 
financial situation?
 Ms. Del Mastro. Well, thank you. We are senior citizens 
living on Social Security and our gigs that we do. It affected 
us greatly. It was all of our available, accessible money. It 
was all of it.
 What happened immediately--as I said, my daughter works in 
AI. When I called her, she told me that is what probably had 
happened, that it was an AI clone of her voice. After that, we 
went to the police, the local police.
 The next morning, when I was a little calmer, I posted on 
social media. I posted our experience on Facebook and said, let 
this be, you know, a warning to all of my friends and fans and 
everyone that these criminals have high-tech capability now. 
Forgive me, I am still completely traumatized by this. It has 
been a couple of months.
 The Chairman. Take your time.
 Ms. Del Mastro. It just, yes----
 The Chairman. What happened is, you talked to your 
daughter. Then the next step is you are probably--you are happy 
she is fine.
 Ms. Del Mastro. Yes.
 The Chairman. You are furious that you lost all your life 
savings, because you basically lost all your life savings.
 Ms. Del Mastro. Yes.
 The Chairman. Did you go--you called the police department, 
or you went down there?
 Ms. Del Mastro. We went to the police department. When my 
husband and I went home, my daughter got off work and came 
over. You know, I hugged her and sobbed for a while. Then we 
went to the local police office and reported it right away.
 The Chairman. Did they act like they would even be able to 
help you?
 Ms. Del Mastro. You know, the officer, the detective in 
charge that we spoke to said that they see this by the 
hundreds. They see these kind of things all the time. That 
probably it was out of the country, you know, a call center out 
of country and that the money was definitely gone. The money 
was gone.
 The Chairman. How did you send the money?
 Ms. Del Mastro. MoneyGram and Western Union, both.
 The Chairman. There was no--even though you had a record of 
it?
 Ms. Del Mastro. Cash pickup within ten minutes anywhere in 
Mexico. That is what these all were, so that money was gone by 
the time we got off the phone.
 The Chairman. No ability--and they take no responsibility?
 Ms. Del Mastro. Absolutely. Absolutely. When you go to do 
these transactions, there are signs everywhere that tell you, 
you know, don't--you know, if you think this is a fraud, don't 
do it. However, you have someone on the phone with you right 
here saying, you know, don't speak to them, be discreet.
 You know, you got it right there. It is a scare tactic. It 
is absolutely terrifying. You know, because again, when you 
hear--I mean, how we understand--when you answer the phone and 
you hear someone's voice, you know that person by their voice.
 The Chairman. Right. You get your guard down.
 Ms. Del Mastro. Right. If you have an AI clone of a loved 
one's voice, you don't know. You don't know anymore. Yes, like 
I said, it is terrifying.
 The Chairman. During the whole process, you were just out 
trying to solve the problem.
 Ms. Del Mastro. Yes.
 The Chairman. They had gotten you.
 Ms. Del Mastro. Absolutely.
 The Chairman. Hook, line and sinker.
 Ms. Del Mastro. Five and a half hours, yes. Yes, I was 
bound and determined to get my daughter back, one way or 
another. I was bounded and determined.
 The Chairman. I think we all would, right.
 Ms. Del Mastro. Yes. Yes, absolutely. Like I said, it is a 
perfect scam. It is an old scam with new technology, you know. 
We just need to know that this is out here. After it happened, 
and I posted it, I had many people that are friends and fans 
and family that sent me money to help replace the money.
 They said, do a GoFundMe. I did a GoFundMe. I set it up a 
couple of days later, just for the amount of what we lost. The 
people at GoFundMe read my story and asked if the local media 
could contact me.
 That is why I am here today because local media--I was 
interviewed by a station where the actual broadcaster who 
interviewed me had an AI fraud like a month and a half before 
that with a video of her daughter asking for money.
 Now, her daughter was next door, so she knew it was a 
fraud, but they had a video of her daughter. Yes, it is 
frightening. It is really frightening.
 The Chairman. Were you able to raise the money on GoFundMe?
 Ms. Del Mastro. Yes.
 The Chairman. Isn't that nice? There are a lot of wonderful 
people in the world, right?
 Ms. Del Mastro. Yes, they are--I mean, I have a very, very 
wonderful, supportive community of friends and fans and 
families. It is--I am very blessed in that way.
 The Chairman. There are a lot of good people out there. 
There is evil people out there, but there are some good people.
 Ms. Del Mastro. Yes, there certainly are. We need to 
protect all of them, yes.
 The Chairman. I agree. Senator Gillibrand.
 Senator Gillibrand. Senator Alsobrooks, I am going to give 
you my time, but I will give you a minute to get set up. Okay, 
you can go ahead then.
 Senator Alsobrooks. Thank you so much to Chair Scott and 
Ranking Member Gillibrand for hosting today's hearing.
 I want to thank you as well to all of our witnesses for 
being present. There is an old warning that many of us learn 
from our parents. It goes like this. If it sounds too good to 
be true, then it probably is. That warning assumes that we 
recognize when something is not real.
 Artificial intelligence is making that much harder. For 
older Americans, the harm from a senior scam does not end with 
stolen money or identity. It ends with stolen dignity. These 
scams can make our elders afraid to answer the phone. They 
cause distrust and paranoia that cuts off real communications 
from our family.
 I know this firsthand. I am a part of the sandwich 
generation, and I have been horrified watching my mother, who 
is at home during the day--the predatory calls are absolutely 
unbelievable that she receives all day long. They take away not 
only from those individuals a sense of safety and independence, 
but they also frighten the families, and it is not easily 
restored.
 AI has the potential to help older adults remain 
independent, we understand that supports caregivers, and even 
improve health care but left unchecked, those tools have been 
bold and bad actors and made our seniors especially vulnerable 
to scams.
 Congress, I believe, has a responsibility to set clear 
rules, require meaningful safeguards, and hold companies 
accountable when they ignore known risks. We know this harm is 
already happening, and we should not wait for more families to 
suffer. Ms. Del Mastro, my first question is for you.
 I was able to watch your testimony, and I want to thank you 
so much for being here and for being willing to share what 
happened to you. I am also the mother of a daughter, so I can 
only imagine the true trauma that you experienced that day. I 
know it is not easy to relive those five hours, and I am so 
sorry for what you and your family had to endure. Now, I want 
to be clear. I want to just ask you a few questions.
 I know you believed your daughter was in danger, and you 
did what any parent would do, which is everything you could to 
protect her. The people who targeted you counted on your 
motherly reaction.
 If you are comfortable sharing, what has stayed with you 
most since that day, if you can say, and how did you feel upon 
learning that these seasoned criminals manipulated your 
emotions to create a sense of false urgency and emergency?
 Ms. Del Mastro. Yes, well, I was absolutely furious when it 
was over. Absolutely furious. I am quite certain I screamed in 
the parking lot of that Walmart. I am certain I did. However, 
and again, and I was so incredibly relieved that it was a scam, 
so relieved it was the scam.
 Senator Alsobrooks. What would you say the part that has 
stuck with you the most has been?
 Ms. Del Mastro. Is how--I think what stuck with me the most 
is how real it was, absolutely how real it was. It was her 
voice. It was--it was her voice, even though they never spoke 
to her. I mean, they more than likely got that off of--got her 
voice off of social media would be my guess but yes, it is 
frightening how precise it is.
 Senator Alsobrooks. Yes. Now, once you realize what 
happened, would you say that the institutions that you turned 
to for help were able to provide appropriate resources? Or were 
you left to navigate the aftermath largely on your own? With 
the way that the system is set up now, what should victims be 
able to expect in those first critical hours?
 Ms. Del Mastro. Yes, well, like I said, I went to the 
police immediately afterwards. Actually, my daughter and I went 
to see that same detective a couple of times. It was pretty 
clear there was nothing he could do. It was clear that they 
were not going to find these people. There was no way to get 
the money back from it. It was clear.
 Senator Alsobrooks. Nothing to do----
 Ms. Del Mastro. Yes.
 Senator Alsobrooks. Well, let me just quickly go to Mr. 
Benda. My time is going quickly. In 2025, over 4,500 
Marylanders aged 60 and older filed complaints of internet 
crime and reported more than $176 million in losses.
 When an older customer tells a bank that they were deceived 
into sending money, the question is what happens next, and how 
quickly can the bank act, and where does its ability to trace 
or recover the money depend on. Does it depend on another 
institution or law enforcement?
 Mr. Benda. Thank you, Senator. That is a great question. I 
think it is--one of the challenges that we have is following 
that money. A lot of it depends on where they report. I know a 
lot of folks are focused on reporting law enforcement, but the 
best chance to get that money back is to report directly to 
your bank.
 The stopping the flow of funds happens in financial 
institutions, not through law enforcement. We highly recommend 
the first place to report to is your bank. Your bank can 
potentially reach out if it is another financial institution, 
such as a bank, or even a credit union.
 We can reach out to them and there are wire recall 
procedures, ACH return procedures that can be done. ABA itself 
is investing in resources to allow banks to freeze funds faster 
in those instances. If it goes to a crypto firm or some other 
fintech firm, it becomes a lot more challenging.
 The structures aren't there. If it goes to a money service 
business like Western Union or other places, the rules are 
different as well and it becomes an instant transfer and 
becomes even more difficult. It varies depending on what 
institution is handling the transfer.
 Senator Alsobrooks. Thank you.
 The Chairman. Senator Gillibrand.
 Senator Gillibrand. Thank you all for your testimony. Ms. 
Del Mastro and Dr. Amron, I am furious on your behalf. I am 
stunned with how much injustice there is around these types of 
scams. I have personal friends who got targeted and winds up 
sending money in a crypto machine to some unaware unknown 
place.
 My aunt was scammed into paying $5,000 because somebody 
told her she didn't pay her taxes right and that they were 
going to send the FBI to arrest her. I have taken--I have 
traveled all across New York and listened to our seniors about 
what has happened to them. I have heard about the boyfriend 
scam, the girlfriend scam. I have hurt about the child scam, 
the grandchild. Every--I mean, it is endless.
 These are seasoned, sophisticated, criminal networks from 
all over the globe, targeting our family members, targeting our 
loved ones, to just separate them from their hard earned money, 
and it is a disgrace. I think it is incumbent on Congress and 
this Administration to do a hell of a lot more than we are 
doing today to protect Americans. It is not acceptable that 
this has metastasized into a cancer that is harming New 
Yorkers, harming Americans every day.
 I am furious with the President for deleting so many of the 
organizations and personnel that are supposed to protect you, 
to actually stand between you and the scammer.
 Okay, so since taking office, President Trump has taken a 
hacksaw to the very agencies that protect Americans from 
scammers and bad actors, barring the CFPB from bringing 
enforcement actions, moving to shut down the CFPB entirely. 
Slashing CISA funding and workforce. Dismantling the organized 
crime drug enforcement task forces.
 These are all terrible outcomes. I don't know who is 
supposed to protect who at this point. Let me just start with 
you, Mr. Winters, and I am going to talk to you all about this 
situation that is just unacceptable. How have these policy 
changes affected our ability to stop scammers?
 Mr. Winters. Thank you, Senator. Everything that we all 
talked about today was the problem and already in place before 
this Administration did all of those things you talked about. 
Before that, there were people at the CFPB helping chase down 
the money they lost.
 There were people with the Federal Trade Commission that 
were getting that upstream actor, like Riter, that had their 
case sort of reversed after this AI generated thing. All of 
these actions have devastated and sort of failed Americans, 
right. This is only going to get worse because of the lack of 
those cops on the beat, so to speak. We need more, not less.
 Senator Gillibrand. Mr. Benda, from your perspective, what 
investments and what protections should we put in place so that 
we have more safeguards for people who are being scammed?
 Mr. Benda. Thank you for the question, Senator. I share 
your rage at this instance. I think a great example is, as Ms. 
Del Mastro's point, that a local caller ID was used. If it had 
said international caller on that phone, would that have maybe 
raised some eyebrows, or unknown caller?
 She might have still been, because they are very 
convincing. It is a criminal industrial complex. People that 
make billions of dollars convincing Americans because of 
technology. They are fighting a fight they can't win.
 Senator Gillibrand. Maybe questions at the credit union. I 
have heard of many examples where bank tellers saved the day 
saying, ma'am, can I just ask, this seems like a lot of money, 
where are you sending it? Is this important to you? Is it 
someone you know? That one intervention stopped $10,000 from 
going across.
 Maybe more requirements at all of these transmitter 
locations where they are using and demanding money being 
transferred to have questions so that someone who is being 
rushed, somebody who is clearly on another phone call, somebody 
who is showing all these indicia, would that be helpful?
 Mr. Benda. I think having training programs for anyone that 
is transmitting money makes a lot of sense. ABA has a Safe 
Banking for Seniors Program. We have given it to thousands of 
banks that are out there. I think exactly those indicators you 
said, banks and credit unions and money service business should 
all be aware to try and make them stop, think and pause, and 
educate potentially about the scams that are outside.
 Senator Gillibrand. Mr. Ferraro, you have deep federal 
experience at ODNI, the CIA, Department of Homeland Security. 
In 2025, Government Accountability Office found that there was 
little coordination amongst federal agencies. In response, I 
worked with Chairman Scott to introduce our bill, the National 
Strategy for Combating Scams Act.
 It would put the FBI in charge of a multi-agency effort to 
build national strategies on scams. Based on your federal 
experience, how does the lack of coordination of these agencies 
affect our ability to push back? What would a national strategy 
do to combat AI driven scams?
 Mr. Ferraro. Thank you, Senator. Yes, I think that the lack 
of coordination can be a signal failure in government response 
to major issues. It leads to a number of things. One major 
problem is information gaps.
 There are things that some agencies know, some actors know 
that others don't. Second is, of course, unclear 
accountability. When there is no football coach on the team or 
no quarterback, you don't know whom to hold accountable for 
both success and for failure. Third, I think there are 
discordant or disaligned incentives.
 Without clear direction or strategy, bureaucracies can 
simply not act or not act with alacrity. I do think that your 
strategy bill is a good one, because I think it would solve a 
lot of those issues. It would put the FBI in charge, as you 
said, and they can be responsible. They can be called before 
this Committee to give testimony.
 They can offer reports. It would solve information gaps by 
directing that they share information. Of course, it could help 
align incentives to help address this very hydro-headed 
monster.
 Senator Gillibrand. I am out of time, so I just want to end 
with Dr. Amron and Ms. Del Mastro. What happened to you is 
unacceptable. It is pure criminality. It is undermining to your 
sense of safety what you have accomplished in your life.
 For you, Dr. Amron, for you, Ms. Del Mastro, the safety of 
your family and the well-being. I mean, these are very 
traumatic experiences. What do you want from Congress and from 
law enforcement to do to help others who don't know this could 
happen to them, to give you better recourse when it happens?
 If you could just have a magic wand and solve this problem, 
what advice would you give to the Senators?
 Dr. Amron. Well, it is a very pervasive problem. There are 
many different avenues that the scams are taking place on. You 
know, Mr. Scott apologized to me for what I went through. 
Really, the victims are not really me, it is my patients, and 
that I really care about. I want to make that very clear.
 It is big problem. Mr. Tuberville, you know, had this idea 
of educating, which is, I think, a great thing but that is only 
part of the thing. You can't have this buyer beware type of 
mentality, you know, that that is going to be enough with it. 
The pressure at least, at least with what happened with my 
patients, has to be put on the platforms, I believe. The 
platforms that are supporting this and have to have 
consequences.
 Many of the criminals are outside the United States that 
are perpetuating these crimes with things like that. I think 
that there needs to be a lot more responsibility on the 
platform that has to come from government and Congress.
 Senator Gillibrand. Ms. Del Mastro.
 Ms. Del Mastro. I agree with what Mr. Amron said and Mr. 
Benda about, you know, if I had seen that that was an 
international call, I would have had----
 Senator Gillibrand. You would have had a different view.
 Ms. Del Mastro. A completely different outcome. Also, your 
example of having a human teller ask the questions. The thing 
is that so many jobs are being replaced by AI, where you don't 
know if you are talking to a human.
 If you are face to face with someone, if you have someone--
if you are able to actually speak to a human being, I think 
that would help stop the whole scam from happening to begin 
with. I don't how you can keep AI from replacing everyone, but 
I think it is a noble cause to keep us all--yes.
 Senator Gillibrand. Thank you for sharing your story. It is 
just--it is infuriating. We are up against hundreds of 
thousands of criminals doing this every day, stealing billions 
of dollars from Americans. We are very trusting.
 They use our good nature against us. They use out--
everything. It is a disgrace. We are on notice that we have to 
do a lot more to make it better. Mr. Chairman, I return it to 
you. I know you have more questions.
 The Chairman. Thank you. Mr. Benda, can you please explain 
to the Committee the dangers AI is posing by impersonating 
banks, government officials, doctors, etcetera, and the scale 
of damage can be done by successfully tricking Americans into 
believing these impersonations? What are some of the strategies 
the banking industry is using to combat the fraud?
 Mr. Benda. Thank you, Mr. Chairman. You know, I cannot be 
as eloquent as our two other witnesses in the risks, especially 
to doctors and to seniors and I think they pose in that--the 
threat that is out there. I think the education is a key piece 
to it that is going forward. I also think people need to 
recognize the risks of AI.
 When I talk about the industrialization of this, just as 
companies are using chatbots to engage individuals on a broader 
basis and then link that to a human, the criminals are engaging 
the same thing. They are going to start the conversation with a 
chatbot, then hand it off to a human when they have got someone 
on the phone that they think they are going to be able to scam.
 We are going to continue to see this type of activity. We 
really have to restore trust in our telecommunications and our 
social media ecosystems. We have got to ensure that that caller 
ID that is there, that number that is there, that name that 
there is accurate. We can't allow those to be faked. We have to 
ensure when someone is visage is used on an online platform, 
that that visage is actually accurate. You know, I use Google 
photos. I can find pictures of my daughter sitting right back 
there.
 I can followup every picture of my daughter in an instant. 
You are telling me on an online platform can't tell me when 
someone is impersonating someone else that is out there? 
Different tools that are in place, and then the ability to take 
down those scams when they are on there. It should not take 11 
days when we know people are actively being robbed to take down 
an ad.
 This is a doctor who has got a practice that is 
internationally known. If he is reporting something, it should 
be acted on. I think the Scam Act has some requirements in 
there in terms of timeline that Senators Gallego and Moreno 
have put out there. I think those are the types of activities 
that we need to take.
 The Chairman. Thank you. Mr. Ferraro, AI scams are 
inherently borderless. Can you talk about your experience with 
foreign weaponization of deepfakes and what kind of threat do 
they pose?
 Mr. Ferraro. Certainly, Senator. You are absolutely right 
that it is an international phenomenon, and oftentimes it is a 
conspiracy. That there is like actual warehouses of people who 
are operating to execute these frauds, which I think 
underscores something that we haven't really talked about yet, 
which is the importance of international cooperation because 
the folks who are actually going to go and shut down those scam 
operations are going to be local law enforcement.
 This is in my testimony, I believe, but there was a recent 
example of that in Vietnam, where the Vietnamese police worked 
with the American Government to go and literally arrest people 
who are running these sorts of deepfake scams. They run the 
gamut across all the different kinds of scams that we talked 
about, the romance scams, the impersonation scams.
 There was a report recently in the New York Times about, in 
China, that they are thousands of AI avatar doctors who are 
selling supplements. You know, oftentimes that is in some sense 
legal, but you can probably still work with the Chinese 
Government to seek some redress against them, particularly 
when, as I said in my testimony, when things are illegal 
without AI, they are illegal with AI.
 I think that in some ways this just speaks to the need of 
an all of government response, which would include the State 
Department, the FBI, DHS, and others.
 The Chairman. Thank you. Mr. Winters, you have got a 
background in law enforcement. Would a centralized reporting 
portal encourage more victims to come forward?
 Mr. Winters. Yes, absolutely. It would facilitate those 
people coming forward, right. Right now, you could say, where 
should you report it? You could say you go to the FBI or the 
FTC or State AGs or local police department or the AARP. I 
could name 15 different kinds or do it right on the platform.
 None of those things are talking to each other. The owner 
should not be on the victim to try to figure out what the most 
effective way of doing it is. It would facilitate a more 
accurate picture of what is actually going on because you would 
get more reports.
 It would also help facilitate this better education, right. 
Like the fact that it is so fragmented makes it harder to 
educate people about what to do and how to educate yourself. If 
you had the ReportScams.gov where you could report it and learn 
more about it, that would be massive.
 The Chairman. Do you think it is realistic to get all these 
agencies to work together?
 Mr. Winters. I think so. You know, a lot of what I did was 
interagency stuff. You know, not too bad. I think everyone 
wants to stop this exact thing from happening. It is not that 
hard, but it is hard to coordinate everyone to do it.
 The Chairman. Do you have any more?
 Senator Gillibrand. I literally have hours of questions for 
all of you, so I just want to thank you for testifying and 
bringing your stories here and bringing all your 
recommendations. For our three expert witnesses, you have given 
us a lot of good food for thought in terms of recommendations.
 We are going to follow them, but I just want to thank you 
all because this is such a big problem, and this is just the 
tip of the iceberg. These are just two scams out of millions, 
and I am just so grateful that you are focused on trying to 
solve the problem. I really appreciate you, Mr. Chairman, for 
having this hearing.
 The Chairman. We released today a bipartisan report that 
hopefully--we have had some luck with--we did one, a big one on 
generic drugs and we are very close to getting the bill passed 
on. It would impact that. I think we will be--we will get some 
of this stuff done if we continue to work together.
 Thanks everybody for being here today and participating. I 
look forward to continuing to work with all the members here. I 
also want to remind seniors and families watching that the 
Senate Aging Committee operates a fraud hotline.
 For anyone who believes they may have been targeted or 
victimized, the number is 1-855-303-9470. If any Senators have 
additional questions for the witnesses or statements to be 
added, the hearing record will be open until next Wednesday at 
5:00 p.m. Thank you all for being here.
 [Whereupon, at 5:06 p.m., the hearing was adjourned.] 
=======================================================================

 APPENDIX
 
 
=======================================================================

 Prepared Witness Statements

=======================================================================
[GRAPHICS NOT AVAILABLE IN TIFF FORMAT]
 
=======================================================================

 Questions for the Record

=======================================================================
 
 U.S. Senate Special Committee on Aging

"The AI Deception Machine: Deepfakes, Chatbots, and the New Frontier of 
 Senior Fraud"

 July 29, 2026

 Questions for the Record

 Paul Benda

 Ranking Member Kirsten E. Gillibrand

 Question:

 Modern frauds and scams will often span multiple services, 
so no single organization is aware of the full scheme. Data 
sharing among private sector organizations, as well as law 
enforcement, can help prevent frauds and scams and disrupt the 
criminals who carry them out. Hower, the organizations that 
might share that information sometimes say that there is legal 
uncertainty over whether they are allowed to share.In your 
view, is there legal uncertainty regarding the ability of 
private sector actors to share information on frauds and scams?

 Response:

 Yes. There is meaningful legal uncertainty around fraud and 
scam information sharing, particularly when information needs 
to move across different sectors. The United States does not 
have a single legal framework for fraud intelligence sharing. 
Instead, banks, telecommunications providers, technology 
platforms, payment companies, and other participants operate 
under different statutes, governing areas such as anti-money 
laundering, privacy, telecommunications, consumer reporting, 
and cybersecurity. Those laws provide important protections, 
but they were generally not designed to enable all of these 
sectors to collaborate against the same fraud scheme in real 
time.
 Some existing authorities are quite useful. For example, 
Section 314(b) of the USA PATRIOT Act provides participating 
financial institutions with a liability safe harbor for sharing 
information related to suspected money laundering or terrorist 
activity. In June 2026, FinCEN clarified that this authority 
can include fraud-related information and can support real-time 
sharing. That clarification was important. However, the Section 
314(b) safe harbor generally applies to eligible financial 
institutions and does not provide a comprehensive framework for 
sharing with telecommunications companies, online platforms, or 
other sectors that may possess critical information about the 
same scam.
 There are also important distinctions between a law that 
permits certain information to be shared and one that provides 
an explicit safe harbor from liability for sharing it in good 
faith. Where the law is unclear, or where an exception may 
permit sharing but there is no clear liability protection, 
institutions understandably tend to be cautious. The current 
framework is strongest for financial institution-to-financial 
institution sharing and reporting to government, and weaker for 
real-time sharing between financial institutions, technology 
platforms, telecommunications providers, and other sectors.
 Regulatory guidance can help reduce unnecessary 
uncertainty, and agencies should continue clarifying what 
existing law permits. But guidance alone will not resolve the 
underlying structural problem. Congress should establish a 
fraud-specific framework that clearly defines what information 
may be shared, who may participate, how information may be 
used, and the privacy and security protections that apply. Most 
importantly, it should provide appropriate liability 
protections for organizations that in good faith share, 
receive, and responsibly act on fraud-risk information.
 Criminals move seamlessly across telecommunications 
networks, online platforms, financial institutions, 
cryptocurrency exchanges, and payment systems. The 
organizations trying to stop them should not be constrained by 
legal and operational silos that the criminals themselves do 
not face.

 Question:

 What are potential legal, regulatory, or compliance 
barriers to sharing that information?
 Response:

 The potential barriers fall into several categories, and it 
is important to distinguish between information that is 
actually prohibited from being shared and information that 
institutions may be reluctant to share because the legal 
protections are unclear.
 First, existing information-sharing authorities are 
generally sector-specific and purpose-specific. Section 314(b), 
for example, provides a strong safe harbor for eligible 
financial institutions sharing information related to suspected 
money laundering or terrorist activity, including certain 
fraud-related activity, but it does not provide the same 
protection when a bank needs to exchange fraud intelligence 
with a telecommunications provider or online platform.
 Second, different privacy and communications laws govern 
different types of information. The Gramm-Leach-Bliley Act, 
state privacy laws, the Electronic Communications Privacy Act, 
and FCC rules governing Customer Proprietary Network 
Information (CPNI) can all affect what information may be 
shared and under what circumstances. For example, 
communications content is treated differently from metadata 
such as telephone numbers, IP addresses, routing information, 
and timestamps. Telecom providers also face uncertainty about 
proactively sharing fraud indicators with banks and other non-
carrier entities because the FCC's CPNI rules do not provide a 
clear cross-sector safe harbor.
 Third, organizations must consider potential liability 
associated not only with sharing information, but also with how 
it is subsequently used. If inaccurate information is shared or 
another participant acts on it, institutions may be concerned 
about privacy, defamation, business-tort, antitrust, or other 
liability. The Fair Credit Reporting Act can also become 
relevant if shared consumer information is assembled and used 
to make eligibility decisions, such as whether to open an 
account. These are important consumer protections, but a new 
fraud-sharing framework should clearly explain how they 
interact with real-time fraud prevention rather than leaving 
participants uncertain about their obligations.
 Finally, compliance practices themselves can become a 
barrier. SAR confidentiality requirements, for example, are 
sometimes interpreted broadly, and organizations may choose not 
to share even where sharing is legally permissible because the 
consequences of getting the legal analysis wrong can be 
substantial.
 That is why regulatory clarification is useful, but 
ultimately Congress should provide a clear, fraud-specific 
framework with appropriate privacy protections and a strong 
safe harbor for organizations that share, receive, and 
responsibly act on fraud information in good faith.

 Question:

 In your view, is there anything Congress should do to make 
it easier to share that information, or clarify existing legal 
authorities? If Congress seeks to do so, are there potential 
effects for business and consumers that we should take into 
consideration?

 Response:

 Yes. Congress should make it easier for private-sector 
organizations and law enforcement to share fraud and scam 
intelligence by creating a clear, fraud-specific statutory 
framework. Existing authorities provide useful tools, but they 
are fragmented across different sectors and statutes. 
Regulatory guidance can clarify what is already permissible, 
and agencies should continue doing that, but guidance is not a 
substitute for durable legal authority and can leave 
participants uncertain about liability.
 Congress should build on the principles that have worked in 
other information-sharing regimes: voluntary participation, 
clear definitions of what information may be shared and for 
what purposes, strong protections for privacy and security, and 
an explicit safe harbor for organizations that in good faith 
share, receive, and responsibly act on fraud-risk information. 
The framework should allow financial institutions, 
telecommunications providers, technology platforms, payment 
companies, cryptocurrency firms, and appropriate government 
entities to participate under common rules rather than 
operating in separate legal silos.
 Congress should also consider the effects on both 
businesses and consumers. For businesses, the framework should 
avoid creating conflicting or duplicative requirements and 
should recognize the implementation costs of new systems, 
particularly for smaller institutions. Common data standards, 
clear operating rules, and shared infrastructure can help 
reduce that burden.
 For consumers, stronger information sharing must preserve 
protections for privacy, accuracy, transparency, and redress. A 
fraud signal can be extremely valuable, but it can also be 
wrong. If shared information affects an important decision, 
such as whether an account is opened or a transaction proceeds, 
consumers should have appropriate opportunities to correct 
inaccurate information.
 The objective should be to allow legitimate organizations 
to exchange actionable intelligence at the speed of scam, while 
ensuring that the system is accurate, secure, and accountable.

 Question:

 Congress passed the Cybersecurity Information Sharing Act 
of 2015 (CISA) to encourage the voluntary sharing of cyber 
threat information.
 In your view, is the CISA framework a model Congress should 
consider for a framework for sharing data and intelligence 
related to frauds and scams? Why or why not?

 Response:

 The Cybersecurity Information Sharing Act of 2015 passed 
with bipartisan support and has been helpful in protecting the 
privacy of, and reducing the liability for, organizations 
(including banks) that voluntarily share information about 
cyber threats and attacks with other organizations and the U.S. 
government as a means of alerting and allowing others to defend 
against similar attacks. The law expired on September 30, 2025, 
and was temporarily extended through September 30, 2026.
 Last year, ABA partnered with other associations on two 
letters to congressional leadership advocating for 
reauthorization:

 https://www.aba.com/advocacy/policy-analysis/letter-to-
congress-on-cisa
 https://www.aba.com/advocacy/policy-analysis/letter-to-
congress-on-cisa-september

 We believe CISA has encouraged information sharing between 
the U.S. government and the private sector while establishing 
clear expectations for privacy and confidentiality and has 
provided antitrust exemptions and associated protections for 
cyber information sharing between private companies. We 
strongly encourage reauthorization so that information sharing 
among private sector firms and information sharing with U.S. 
government agencies continue.
 We also believe the CISA Act of 2015 provides an important 
model for how Congress should approach fraud and scam 
information sharing, but a new fraud-specific statutory 
framework is needed.
 CISA approached several fundamental challenges correctly. 
It created meaningful liability protections for entities that 
voluntarily share or receive covered cyber threat information, 
permits sharing across sectors rather than limiting 
participation to a particular regulated industry, incorporates 
privacy protections, and establishes a framework for automated, 
real-time exchange. Those are important principles for 
combating scams because financial institutions, 
telecommunications providers, technology platforms, payment 
companies, and law enforcement often possess different pieces 
of intelligence about the same criminal network. However, CISA 
was designed around cyber threat indicators and defensive 
measures for cybersecurity purposes. It is extremely useful for 
cyber-enabled fraud, but its application is less clear when a 
scam is based primarily on social engineering or impersonation 
rather than compromise of an information system.
 Another authority many look to is Section 314(b) of the USA 
PATRIOT Act, but it presents a similar issue. FinCEN recently 
clarified that participating financial institutions may share 
fraud-related information, including in real time. That 
clarification is helpful, but Section 314(b) remains a 
voluntary anti-money-laundering framework whose safe harbor is 
generally limited to eligible financial institutions and 
sharing related to suspected money laundering or terrorist 
activity. It was not designed to connect the full ecosystem 
involved in modern scams or to support automated information 
sharing and intervention at the speed of scam.
 Congress therefore should build on CISA with a new law 
specifically designed for fraud and scams. A new statute should 
clearly address how fraud-information sharing interacts with 
existing consumer protection laws, including the Fair Credit 
Reporting Act. The FCRA provides important safeguards designed 
to promote accuracy and give consumers transparency and an 
opportunity to correct erroneous information when data is used 
in eligibility decisions. Those protections should be 
preserved. At the same time, Congress should provide clear 
rules for how real-time fraud intelligence may be shared and 
acted upon, particularly when information indicating possible 
fraud or mule activity affects decisions such as opening a new 
account. A well-designed framework should allow institutions to 
act quickly on credible fraud signals while ensuring that 
consumers retain appropriate rights to accuracy, notice, and 
redress. The framework should provide an explicit federal and 
state liability safe harbor for entities that in good faith 
send, receive, and act on fraud-risk information, while 
preserving appropriate privacy, accuracy, security, governance, 
and consumer redress protections.
 Finally, legal authority alone will not create an effective 
system. Congress should address who will build, operate, 
secure, fund, and oversee the infrastructure; establish common 
data standards and operating rules; and enable interoperability 
across sectors and, where appropriate, across borders. Those 
elements are essential if banks, telecommunications providers, 
digital platforms, payment systems, and law enforcement are 
going to combine the fragments of information each possesses 
quickly enough to prevent a payment, interrupt a scam, or 
recover stolen funds. That is consistent with ABA's written 
testimony calling for a fraud-specific framework capable of 
operating at the speed of scam.
 In short, CISA is a valuable model because it demonstrates 
that Congress can create strong liability protections and 
enable rapid, voluntary information sharing across sectors. For 
fraud and scams, however, Congress should build on that model 
with a new statute that addresses not only the sharing of 
information, but also the infrastructure for sharing it and the 
legal protections necessary for responsible action based on 
that information.

 Question:

 Disrupting online frauds and scams requires taking that 
content off the internet. However, that requires cooperation 
with platforms, law enforcement, and registrars or other third 
parties.
 In your view, what are the most significant barriers to 
disrupting the actions of criminals who engage in online frauds 
and scams?
 Should Congress consider policy changes to enhance the 
ability to disrupt online fraudsters and scammers? If so, what 
should those policy changes look like, and how can they 
minimize unintended consequences for lawful content, consumers, 
and legitimate businesses?

 Response:

 The most significant barrier to disrupting online fraud and 
scams is that too much of our current approach is reactive. We 
identify a fraudulent advertisement, report it, and seek to 
have it removed. Takedown is important, but if the criminal can 
immediately create another account or purchase another 
advertisement, we are simply playing whack-a-mole.
 Congress should therefore focus on who is purchasing paid 
advertisements and require platforms to conduct meaningful 
know-your-customer (KYC) verification before allowing an 
advertiser to reach consumers. At a minimum, platforms should 
verify that the advertiser is a real person or legitimate 
business and, where the advertiser claims to represent a 
regulated financial institution or other trusted entity, that 
the advertiser is actually affiliated with that organization. 
Platforms should also have safeguards to prevent criminals from 
evading verification through shell companies, advertising 
intermediaries, stolen credentials, or synthetic identities. 
This is one reason ABA strongly supports the approach embodied 
in S. 3774, the SCAM Act, which would require advertiser 
verification, impersonation detection, accessible reporting, 
prompt investigation, removal of confirmed fraudulent 
advertisements, and measures to prevent circumvention through 
false, stolen, or synthetic identities.
 The FCC's recent work on illegal calls provides a useful 
model. The Commission has proposed stronger KYC requirements 
for originating voice providers so they conduct meaningful 
diligence before giving a customer access to the calling 
network. ABA supports that approach because stopping a bad 
actor at the point of entry is more effective than trying to 
identify and block fraudulent activity after it has been 
launched. Our FCC comments cited an originating provider that 
went from no calls to more than 136 million calls in a single 
month just two months later, with analysis indicating that most 
of the traffic was illegal. That example illustrates the risk 
of providing powerful communications infrastructure without 
adequate diligence on the customer using it.
 The same principle should apply to online advertising. A 
platform that accepts payment to distribute and target an 
advertisement should take reasonable steps to know who is 
buying that access before the advertisement runs. Once an 
advertiser is confirmed to be fraudulent, the platform should 
also prevent that actor from simply returning under another 
account or business name.
 The goal should be to move from repeatedly taking down 
individual scam advertisements to creating sufficient friction 
at the point of entry that criminals cannot easily buy their 
way back onto the platform.

 Senator Raphael Warnock

 Question:

 The proliferation of artificial intelligence (AI) has led 
to an increase in AI-driven scams and fraud, creating serious 
risks for seniors and their financial institutions. Banks are 
often the main or only touchpoint for victims of fraud; 
according to a Gallup poll from the Stop Scams Alliance, 
Americans are more likely to report scams and fraud to their 
financial institution than state or local law enforcement, 
federal law enforcement, or other federal government agencies.
 How are banks increasing their efforts to protect older 
customers from financial fraud, including AI-generated 
deepfakes?

 Response:

 Banks are increasing their efforts on several fronts 
because protecting older customers from scams requires both 
technology and human intervention. Banks are using AI, machine 
learning, and advanced analytics to identify unusual 
transactions and behavior that may indicate fraud, while 
strengthening identity verification and authentication as 
criminals increasingly use generative AI, deepfakes, and 
synthetic identities.
 Technology alone, however, cannot determine whether every 
customer has been deceived. Banks therefore continue to train 
front-line employees to recognize when a customer may be under 
a scammer's influence, such as when a longtime customer 
suddenly changes behavior, appears frightened or secretive, or 
is being coached during a transaction. That human intervention 
is especially important with AI-enabled scams because the 
criminal may sound or even appear to be someone the customer 
knows and trusts.
 Consumer education is equally important. Through the ABA's 
non-profit foundation, banks can access the Safe Banking for 
Seniors program, which provides free resources to help older 
Americans, their families, and caregivers recognize and avoid 
fraud and financial exploitation. Over the past decade, more 
than 2,100 banks have participated in the program to reach 
millions of older people.
 The ABA Foundation has also collaborated with a broad 
network of government, law enforcement, regulatory, and 
industry partners, including the Commodity Futures Trading 
Commission (CFTC), the Federal Bureau of Investigation (FBI), 
the Federal Trade Commission (FTC), the Financial Crimes 
Enforcement Network (FinCEN), FINRA, IRS Criminal Investigation 
(IRS-CI), the Securities and Exchange Commission (SEC), 
Homeland Security Investigations (HSI), the U.S. Postal 
Inspection Service (USPIS), and the U.S. Secret Service (USSS), 
to educate consumers about emerging fraud threats.
 Together, these efforts have addressed a wide range of 
scams, including check washing, cryptocurrency, imposter, money 
mule, romance, and tech support scams.
 Building on this collaborative approach, the Foundation and 
the FBI have also developed educational resources to help 
consumers recognize and respond to the growing threat of 
deepfake media scams. These materials encourage individuals to 
pause and think critically before acting, independently verify 
identities through trusted channels, and establish family code 
words rather than relying solely on the apparent authenticity 
of a voice or video.
 ABA is also updating #BanksNeverAskThat, our national 
consumer scam-prevention campaign, to address evolving 
impersonation tactics, including deepfake-enabled scams. The 
campaign already helps consumers recognize bank-impersonation 
scams and the psychological techniques criminals use to create 
urgency and manipulate victims, and the 2026 campaign is being 
refreshed with new materials for banks and consumers. The 
underlying message across these efforts is simple: older 
Americans should not have to become deepfake experts. Banks can 
provide technology, trained employees, and practical education 
that help customers pause, verify, and avoid sending money to 
criminals in the first place.

 Question:

 What policies or regulatory gaps are limiting how banks can 
investigate consumers' reports of fraud or exploitation?

 Response:

 Several gaps are particularly important.
 Banks often do not have access to the information held by 
the other sectors through which a scam occurred. A bank may see 
the payment, while a telecommunications provider has 
information about the phone number used to contact the victim 
and an online platform has information about the account or 
advertisement that initiated the scam. Existing law provides 
several avenues for information sharing, but there is no 
comprehensive, cross-sector safe harbor that clearly allows 
these entities to share and act on fraud intelligence in good 
faith. As discussed in my response above, Congress should 
establish a fraud-specific framework that allows this 
information to be exchanged quickly and securely across 
sectors. The current patchwork creates legal uncertainty and 
can leave each participant investigating only the portion of 
the scam visible to it.
 Additionally, we should improve the ability of banks and 
Adult Protective Services to work together when an older 
customer may be experiencing financial exploitation.Existing 
law has made important progress. The Senior Safe Act provides 
liability protection for certain trained financial institution 
employees who report suspected exploitation in good faith to 
APS, law enforcement, and other covered agencies, and federal 
regulators have clarified that the Gramm-Leach-Bliley Act 
generally permits banks to report suspected elder financial 
abuse to appropriate authorities.
 The challenge is that an effective investigation often 
requires more than making an initial report. Banks can remain 
uncertain about what customer information they may provide 
during follow-up discussions, how much information may be 
shared, and what information APS can share back with the bank. 
The CFPB itself identifies restrictions on when, with whom, and 
how much customer information may be shared as a potential 
challenge in elder-protection networks. That uncertainty can 
make it harder for the bank, APS, and law enforcement to 
develop a complete picture and determine how best to protect 
the victim.
 Congress and regulators should therefore provide clearer 
authority and appropriate safe-harbor protections for good-
faith, two-way information sharing between financial 
institutions, APS, law enforcement, and other appropriate 
partners when investigating suspected fraud or elder financial 
exploitation. Those protections should preserve appropriate 
privacy and confidentiality safeguards while allowing the 
parties trying to protect the victim to share the information 
necessary to investigate and intervene effectively.
 Finally, another significant policy gap is the lack of a 
consistent federal framework that allows financial institutions 
to delay disbursements or place temporary holds on transactions 
when they reasonably suspect elder financial exploitation or 
fraud. Without this authority, banks may identify red flags but 
have limited ability to pause a transaction long enough to 
investigate before funds are lost.
 Congress should consider legislative solutions that provide 
financial institutions with the authority, along with 
appropriate safe harbor protections, to temporarily delay 
disbursements or hold transactions when there is reasonable 
cause to believe a transaction may be fraudulent. This would 
give banks a critical opportunity to investigate suspicious 
activity and help prevent losses before they occur.
 A uniform national framework would eliminate 
inconsistencies among state laws. The ABA supports legislation 
such as H.R. 9668, the Safeguarding Transactions to Outpace 
Predatory (STOP) Senior Fraud Act, which would help address 
this gap by giving banks additional tools to investigate 
suspected exploitation and protect older adults from financial 
harm.

 Question:

 What policies can banks adopt to streamline reporting 
processes and encourage consumers to report instances of fraud 
or scams to law enforcement agencies?

 Response:

 Banks should make it as easy as possible for customers to 
report a suspected scam, and the first call should be to the 
customer's financial institution. In a payment scam, speed is 
critical. Banks can help customers take immediate steps to 
protect their finances, such as securing accounts, changing 
credentials, monitoring for unauthorized activity, opening new 
accounts when appropriate, and implementing safeguards to 
prevent additional losses or exploitation.
 ABA encourages banks to direct victims to report cyber-
enabled fraud to the FBI's Internet Crime Complaint Center 
(IC3). IC3 provides an important national reporting and 
intelligence function, and its Recovery Asset Team operates the 
Financial Fraud Kill Chain, which can work with financial 
institutions and law enforcement to freeze stolen funds. In 
2025, the FBI initiated 3,900 Financial Fraud Kill Chain 
incidents involving approximately $1.16 billion in attempted 
theft and froze more than $679 million. The FBI itself 
emphasizes that victims should contact their financial 
institution immediately and report quickly to IC3 because 
timely transaction information can help freeze funds.
 The larger challenge, however, is ensuring that a report 
leads to action. IC3 received more than one million complaints 
in 2025, while the Financial Fraud Kill Chain was initiated in 
3,900 incidents. Not every IC3 complaint involves a financial 
transaction appropriate for that process, but the disparity 
illustrates the scale of the challenge facing law enforcement. 
We should not measure success simply by how many victims we 
persuade to file another report. Law enforcement, particularly 
at the state and local levels, needs the specialized personnel, 
training, technology, and legal authorities necessary to act 
quickly when a victim reports a scam.
 That is why ABA has proposed the National Payment Fraud 
Crime Control Act, which would establish a Bureau of Justice 
Assistance grant program to help states create or strengthen 
Financial Crimes Intelligence Centers. These centers would 
serve as specialized hubs for investigating payment fraud, 
training state and local law enforcement, coordinating with 
financial institutions, and supporting recovery efforts.
 Texas provides a useful model for strengthening law 
enforcement's response to scams and fraud. In 2025, Texas 
expanded the mission of its Financial Crimes Intelligence 
Center from primarily card fraud to broader payment fraud and 
strengthened its ability to assist financial institutions and 
law enforcement. Texas also updated its asset-forfeiture laws 
to address digital currency, including allowing certain 
cryptocurrency forfeiture proceedings to occur where the law 
enforcement agency initiating the seizure is located and 
providing procedures for law enforcement to secure seized 
digital assets.
 Ultimately, the objective should not simply be to increase 
the number of reports. It should be to create a system in which 
the victim, the financial institutions involved, and law 
enforcement can act together at the speed of scam to stop the 
movement of funds, recover money when possible, and disrupt the 
criminal network behind the fraud.

 Question:

 What are some challenges that community banks or other 
financial institutions are facing due to the rising rate of 
senior financial exploitation?

 Response:

 Community banks face many of the same challenges as larger 
financial institutions as senior financial exploitation becomes 
more sophisticated and more prevalent. Banks must continually 
invest in fraud-detection technology, employee training, 
customer education, investigation, reporting, and funds 
recovery. For smaller institutions, those demands may fall on 
fewer specialized personnel, which makes free industry 
resources, shared services, and partnerships especially 
important. ABA and the ABA Foundation work to ensure that banks 
of all sizes have access to training and resources for 
recognizing and responding to elder financial exploitation.
 One of the most difficult challenges is intervention. In 
many scams, the customer is authorizing the transaction because 
the criminal has convinced the victim that the story is real. 
The customer may have been coached to conceal the purpose of 
the payment or to distrust the banker trying to help. A 
community banker may know that customer personally and 
recognize that something is wrong, which can be an important 
advantage. But even a trusted banker may have difficulty 
breaking the "scam spell" after a criminal has spent weeks or 
months establishing trust. ABA is expanding training 
specifically to help bankers intervene in these situations and 
support victims without shaming them.
 A related concern is the erosion of trust in the financial 
and online ecosystem. Criminals increasingly impersonate banks 
through spoofed telephone numbers, fraudulent websites, social 
media accounts, and other communications that appear 
legitimate. When a customer is deceived by someone convincingly 
posing as their bank, the harm extends beyond immediate 
financial loss. It can undermine confidence in legitimate bank 
communications, including the fraud alerts and outreach that 
banks use to protect customers. Over time, widespread 
impersonation threatens the trust that is particularly 
important to the relationship between community banks and the 
customers they serve.
 That is why banks cannot address rising senior exploitation 
alone. Banks will continue investing in technology, training 
employees, educating customers, and intervening when they 
identify warning signs. But reducing the burden on institutions 
of every size ultimately requires stopping more scams upstream, 
strengthening collaboration with and capacity among Adult 
Protective Services and law enforcement, improving information 
sharing, and ensuring that telecommunications providers, online 
platforms, and other parts of the ecosystem help prevent 
criminals from impersonating trusted institutions in the first 
place.

 U.S. Senate Special Committee on Aging

"The AI Deception Machine: Deepfakes, Chatbots, and the New Frontier of 
 Senior Fraud"

 July 29, 2026

 Questions for the Record

 Matthew F. Ferraro

 Ranking Member Kirsten E. Gillibrand

 Question:

 The Trump Administration has accelerated federal adoption 
of AI. The Social Security Administration is one example - 
using AI for everything from customer-service chatbots to 
processing medical claims. The public can benefit when agencies 
modernize. But the government has to manage the risks that come 
with it, especially for vulnerable people like seniors.
 What should agencies like SSA do to make sure government AI 
helps Americans rather than putting them at risk? And, in your 
opinion, how do we draw oversight and governance lines between 
using AI to perform routine office tasks and deliver 
administrative efficiencies versus deploying non-humans to make 
benefit entitlement and appeal decisions?

 Response:

 I believe that a useful overarching maxim is that agencies 
should "adopt advisedly and govern aggressively.
 First, AI deployments should align with public 
organizations' missions. Deployments should be narrowly scoped 
to enhancing the agency's specific goals.
 Second, from the very beginning, organizations should 
consider how to make sure AI use is responsible and trustworthy 
and how to address potential risks to privacy, security, and 
safety.
 Third, agencies should measure progress with metrics and 
incorporate feedback from users, because one cannot understand 
or fix what one does not measure.
 I also point the Committee to a publication we produced 
when I served at the U.S. Department of Homeland Security, the 
"DHS Playbook for Public Sector Gen AI Deployment," (https://
www.dhs.gov/sites/default/files/2025-01/25--0106--ocio--dhs-
playbook-for-public-sector-generative-artificial-intelligence-
deployment-508-signed.pdf) which discusses these themes at 
length and provides actionable guidance.
 With regard to how we draw oversight and governance lines 
between AI performing routine tasks and making entitlement 
decisions: I believe that, at this stage in the technology's 
development, agencies should scope the application of AI tools 
appropriately given their limitations and the necessity to 
establish accountability for AI-related actions to a human, 
through what is known as "human-in-the-loop" governance. In 
short, AI-generated outputs should not be the sole basis for 
any agency's critical decisions or entitlement determinations."

 Question:

 Modern frauds and scams will often span multiple services, 
so no single organization is aware of the full scheme. Data 
sharing among private sector organizations, as well as law 
enforcement, can help prevent frauds and scams and disrupt the 
criminals who carry them out. Hower, the organizations that 
might share that information sometimes say that there is legal 
uncertainty over whether they are allowed to share.
 In your view, is there legal uncertainty regarding the 
ability of private sector actors to share information on frauds 
and scams?
 What are potential legal, regulatory, or compliance 
barriers to sharing that information?
 In your view, is there anything Congress should do to make 
it easier to share that information, or clarify existing legal 
authorities? If Congress seeks to do so, are there potential 
effects for business and consumers that we should take into 
consideration?
 Response:

 Private-public information sharing is governed by a web of 
disparate laws, rules, and guidances that vary by sector and 
information type. These varying laws and regulations include 
the Gramm-Leach-Bliley Act, the Cybersecurity Information 
Sharing Act of 2015 for cybersecurity threat information, 
regulations issued by the Financial Crimes Enforcement Network 
(FinCEN), and state-level privacy frameworks, among others.
 Legislation that codified liability protections for cross-
institutional and cross-sector information sharing of suspected 
fraud indicators could help reassure industries that face 
various legal, regulatory, and compliance barriers.

 Question:

 Congress passed the Cybersecurity Information Sharing Act 
of 2015 (CISA) to encourage the voluntary sharing of cyber 
threat information.
 In your view, is the CISA framework a model Congress should 
consider for a framework for sharing data and intelligence 
related to frauds and scams? Why or why not?

 Response:

 The Cybersecurity Information Sharing Act of 2015 created a 
system for federal agencies to receive and share anonymized 
threat indicators from and with companies without concerns of 
running afoul of antitrust laws. I believe this Act was largely 
a success and could serve as a baseline for a framework for a 
national-fraud-and-scam data-sharing network. That law may 
point to a viable path forward in this circumstance. Its 
liability and antitrust protections, requirements to remove 
unrelated personal identifiable information, and clearinghouse 
system could help inform a framework that focuses on consumers 
and fraud."

 Question:

 Disrupting online frauds and scams requires taking that 
content off the internet. However, that requires cooperation 
with platforms, law enforcement, and registrars or other third 
parties.
 In your view, what are the most significant barriers to 
disrupting the actions of criminals who engage in online frauds 
and scams?
 Should Congress consider policy changes to enhance the 
ability to disrupt online fraudsters and scammers? If so, what 
should those policy changes look like, and how can they 
minimize unintended consequences for lawful content, consumers, 
and legitimate businesses?

 Response:

 A lack of coordination among government agencies at both 
the state and federal level-and with international partners-is 
a significant barrier to disrupting criminals who engage in 
online frauds and scams. Better coordination would allow these 
bodies to leverage to better effect existing laws that make 
these scams and fraud illegal already. These laws include 
(depending on the underlying activity) the Federal Trade 
Commission Act, the TAKE IT DOWN Act, the Telephone Consumer 
Protection Act, and laws prohibiting wire fraud (18 U.S.C. 
 1343), identity theft (18 U.S.C. 1028), and 
computer fraud (18 U.S.C. 1030), among others. The 
adage applies: if it is illegal without AI, it is illegal with 
AI.
 Furthermore, using deepfakes of trusted messengers to 
deceive victims is a broad, international phenomenon. For 
example, in 2024, a social media platform removed over 400,000 
accounts originating in West Africa that fraudsters used to 
impersonate military personnel or businesspeople in an effort 
to scam individuals in Australia, Britain, Europe, the United 
States, and other locations. Also, in October 2024, Hong Kong 
police arrested over two dozen members of an alleged fraud ring 
that used deepfakes to trick victims in Taiwan, Singapore, 
India, and elsewhere in Asia into believing they were engaged 
in relationships.
 In light of these circumstances, Congress should consider 
policies that enhance coordination domestically and 
internationally to use existing laws to disrupt and degrade 
criminal fraudsters.
[GRAPHICS NOT AVAILABLE IN TIFF FORMAT] 
 
=======================================================================

 Statements for the Record

=======================================================================
[GRAPHICS NOT AVAILABLE IN TIFF FORMAT]

 [all]