Full text of the official published hearing record. Extracted from the source document — verify against the official record for citation.
[Senate Hearing 119-513] [From the U.S. Government Publishing Office] S. Hrg. 119-513 THE AI DECEPTION MACHINE: DEEPFAKES, CHATBOTS, AND THE NEW FRONTIER OF SENIOR FRAUD ======================================================================= HEARING BEFORE THE SPECIAL COMMITTEE ON AGING UNITED STATES SENATE ONE HUNDRED NINETEENTH CONGRESS SECOND SESSION __________ WASHINGTON, DC __________ JULY 29, 2026 __________ Serial No. 119-34 Printed for the use of the Special Committee on Aging [GRAPHIC NOT AVAILABLE IN TIFF FORMAT] Available via the World Wide Web: http://www.govinfo.gov __________ U.S. GOVERNMENT PUBLISHING OFFICE 64-451 PDF WASHINGTON : 2026 ======================================================================= SPECIAL COMMITTEE ON AGING RICK SCOTT, Florida, Chairman DAVE McCORMICK, Pennsylvania KIRSTEN E. GILLIBRAND, New York JIM JUSTICE, West Virginia ELIZABETH WARREN, Massachusetts TOMMY TUBERVILLE, Alabama MARK KELLY, Arizona RON JOHNSON, Wisconsin RAPHAEL WARNOCK, Georgia ASHLEY MOODY, Florida ANDY KIM, New Jersey JON HUSTED, Ohio ANGELA ALSOBROOKS, Maryland ---------- McKinley Lewis, Majority Staff Director Claire Descamps, Minority Staff Director C O N T E N T S ---------- Page Opening Statement of Senator Rick Scott, Chairman................ 1 Opening Statement of Senator Kirsten E. Gillibrand, Ranking Member......................................................... 3 PANEL OF WITNESSES David Amron, MD, Founder & Medical Director, The Roxbury Institute, Los Angeles, California............................. 4 Deborah Del Mastro, Victim of AI-Enabled Scam, Martinez, California..................................................... 6 Paul Benda, Executive VP for Risk, Fraud and Cybersecurity, American Bankers Association, Washington, D.C.................. 9 Matthew F. Ferraro, Esq., Partner, Crowell & Moring LLP, Washington, D.C................................................ 11 Ben Winters, Director of AI and Privacy, Consumer Federation of America, Washington, D.C....................................... 12 APPENDIX Prepared Witness Statements David Amron, MD, Founder & Medical Director, The Roxbury Institute, Los Angeles, California............................. 32 Deborah Del Mastro, Victim of AI-Enabled Scam, Martinez, California..................................................... 35 Paul Benda, Executive VP for Risk, Fraud and Cybersecurity, American Bankers Association, Washington, D.C.................. 37 Matthew F. Ferraro, Esq., Partner, Crowell & Moring LLP, Washington, D.C................................................ 49 Ben Winters, Director of AI and Privacy, Consumer Federation of America, Washington, D.C....................................... 58 Questions for the Record Paul Benda, Executive VP for Risk, Fraud and Cybersecurity, American Bankers Association, Washington, D.C.................. 85 Matthew F. Ferraro, Esq., Partner, Crowell & Moring LLP, Washington, D.C................................................ 92 Ben Winters, Director of AI and Privacy, Consumer Federation of America, Washington, D.C....................................... 94 Statements for the Record Alliance for Retired Americans Statement......................... 110 American Psychological Association Statement..................... 113 American Securities Association Statement........................ 118 Benjamin Riley Statement......................................... 121 Center for AI and Digital Policy Statement....................... 122 CFP Board Statement.............................................. 129 Defense Credit Union Council Statement........................... 133 Jill Hollander Statement......................................... 139 Lifespan of Greater Rochester Statement.......................... 141 National Academy of Elder Law Attorneys Statement................ 145 Pindrop Security Statement....................................... 148 THE AI DECEPTION MACHINE: DEEPFAKES, CHATBOTS, AND THE NEW FRONTIER OF SENIOR FRAUD ---------- Wednesday, July 29, 2026 U.S. Senate Special Committee on Aging Washington, DC. The Committee met, pursuant to notice, at 3:43 p.m., Room 562, Hart Senate Office Building, Hon. Rick Scott, Chairman of the Committee, presiding. Present: Senator Scott, Tuberville, Husted, Gillibrand, Kelly, and Alsobrooks. OPENING STATEMENT OF SENATOR RICK SCOTT, CHAIRMAN The Chairman. The U.S. Senate Special Committee on Aging will now come to order. Thank you all for being here today. One of the biggest issues I hear about from Floridians and seniors around the country is the growing threat of scams, fraud, and financial exploitation. Whether it is a phone call from someone posing as a grandchild in trouble, a suspicious investment scheme delivered through the mail, or an email from a government imposter threatening jail time, these criminals are targeting our seniors with increasing sophistication. Our seniors are often especially vulnerable to this kind of fraud. Sadly, for many older Americans, falling victim to a scam doesn't just mean losing money. It could also mean losing peace of mind, trust in others, and confidence in themselves while navigating daily life. As this Committee has heard many times before, this is a multi-billion dollar a year problem. In 2025, Americans over 60 lost a staggering $7.7 billion to scams, and that is just with scams that have been reported. The rise of artificial intelligence has offered scammers new tools to pursue their criminal schemes, and we must adapt and respond to these new threats. AI can be used to make fraudulent videos known as deepfakes, impersonating experts and celebrities to try to defraud our seniors in a variety of devious schemes. AI can also be used to clone someone's voice, a terrifying development that has been used in heartbreaking and evil ways to impersonate a loved one and deceive their family. AI has made existing scams more effective and lowered the barrier to entry for criminals. What once required real coding skill can now be done by anyone with an AI tool. Many of these actions are highlighted within the front section of our new report, Artificial Intelligence and Older Americans, Confronting New Threats, Unlocking New Opportunities. I am grateful to Ranking Member Gillibrand for working with me to put this report together. The report, which is available online at aging.senate.gov, includes helpful information educating on the new threats of AI and efforts you can take to protect yourself. Many seniors live on a fixed incomes and this kind of exploitation can be the difference between a secure, comfortable retirement and years of financial hardship, distress, and isolation. That is why we are focused on combating fraud at every level. We must empower seniors, families, and communities to protect themselves, and then we must act to fight back. That means understanding this new technology, supporting our law enforcement, educating the public, and getting innovative about how we protect vulnerable Americans. Understanding has to come first. That is why I introduced the bipartisan Aging with Artificial Intelligence Act of 2026 with Senators Mark Kelly and Roger Marshall. This bill directs the National Academies to study how older Americans are using AI, and to weigh both its benefits and its risk, including the various scams and fraud we are examining today. Before we can protect seniors from this technology, we need to understand how it is reaching them. I am grateful this effort has the support of groups like AARP, the American Medical Association, and the American Psychological Association but only understanding the threat is not enough. Seniors need an easy way to report it. That is why Senator Maggie Hassan, and I introduced the ReportScams.gov Act, a bipartisan bill that will establish a single federal portal where consumers can report scams, find information about available assistance, and have the report automatically routed to the relevant federal and state agencies. Seniors should not have to navigate a maze of bureaucracy just to be heard. Of course, a report is only useful if law enforcement can act on it. That is why I also joined Senators Katie Britt and Ranking Member Gillibrand to introduce the Guarding Unprotected Aging Retirees from Deception Act, known as the Guard Act, to expand existing federal grant programs. The bill funds specialized law enforcement training on elder fraud and provides tools to trace stolen cryptocurrency. Finally, these efforts must be coordinated. That is why I introduced the National Strategy for Combating Scams Act with Ranking Member Gillibrand to require the FBI to develop a unified national strategy informed by victims, law enforcement, nonprofits, and the private sector. The Federal Government has to coordinate its efforts to effectively combat these complex schemes. Each of these bills attacks the problem from a different angle, but they all share one goal, making sure seniors are never left to face these criminals alone. Today's hearing is part of that effort. We will hear from experts on AI policy, leaders from the financial sector who work to stop these thugs, and victims who have faced these crimes firsthand. Our goal is clear, we want to educate seniors about the rising threat of AI enabled fraud, show them how to defend themselves, and identify the policies the Federal Government can enact to help curb this threat. Seniors deserve to feel safe when answering the phone and opening the mail. They deserve to know that when they report fraud, they will be heard, and action will be taken. Protecting them isn't a partisan issue, and I am grateful for the partnership I have with the members of this Committee. I would now like to recognize Ranking Member Gillibrand for her opening statement. OPENING STATEMENT OF SENATOR KIRSTEN E. GILLIBRAND, RANKING MEMBER Senator Gillibrand. Thank you, Mr. Chairman. I appreciate all the witnesses being here for such an important hearing. The question before us is not whether AI will transform our society. It certainly will. The question is whether we let it be turned against the people we love. Right now, criminals are using AI to steal from families and seniors, cloning voices, faking videos, and tricking honest people. Americans deserve to trust their own eyes and ears. That takes clear rules, honest labels, and real consequences. In just a few years, AI has become part of daily life for nearly every American, older adults included. AARP found that AI use among older adults nearly doubled between 2024 and 2025. That is no surprise. AI holds real promise to improve seniors' lives. In New York, the Office for the Aging is already connecting seniors with AI tools that fight scams, ease loneliness, and support caregivers. We should encourage those uses, but we must also put common sense safeguards in place, so this technology is never used against the people it is intended to serve. I often think about Pope Leo's first encyclical, Magnifica Humanitas, his call to safeguard human dignity in the age of AI. Pope Leo warns that technology is never neutral. The same tools that connect us can also be turned against the most vulnerable among us. Today, we will hear how that is already happening. Scammers use AI to generate deep fake images, clone voices, and launch phishing attacks that drain seniors' savings. In many cases, AI didn't invent these scams. It supercharged them, making old cons more convincing and far easier to pull off. AI deception takes other forms too. Tools that are built without real safeguards can hallucinate and feed older adults dangerously wrong information. Last year, Reuters reported an AI chatbot that repeatedly insisted it was human and invited a 76-year-old man to an address in New York City. He fell on his way to the train station and died of his injuries. This year, the New York Times reported that an AI tool gave a 75-year-old man bad medical advice, and he delayed his cancer treatment because of it. Even one case of AI fueled deception is too many. We can choose differently. We can decide how AI shapes our communities, our families, and the way we care for one another. This morning I sent a letter to leading AI companies, to the AI companion companies, including OpenAI, Meta, and X, asking them to explain how they safeguard their products for older adults and people with disabilities. I was glad to partner with Senator Kelly on this very letter, and I expect these companies to respond promptly and fully. That letter is just one step. It can't be the last. We need a bipartisan framework to govern AI, one that heeds Pope Leo's counsel by putting human dignity first and protecting the most vulnerable, including older adults. We must also confront the scams targeting our seniors head on. I have introduced two bipartisan bills to do exactly that, the National Strategy for Combating Scams Act, and the Guard Act. Both give federal agencies and law enforcement the tools they need to coordinate and to protect consumers from fraud. I look forward to working with Chairman Scott and my colleagues on this Committee to ensure that our older adults are protected from AI's harms and share in their benefits. The Chairman. Thank you, Ranking Member. I would like to welcome our witnesses today. They are here to help the Committee understand the landscape of AI driven fraud and share their experiences dealing with these types of scams. First, I would like to recognize Dr. David Amron, an internationally recognized Surgeon and the Founder and Medical Director of the Roxbury Institute. He joins us today because he saw firsthand how this technology can be turned against us. Scammers used AI to create a deep fake video of him endorsing a fake miracle cream, a product he never made and never endorsed. Thank you for being here. You may begin your testimony. STATEMENT OF DAVID AMRON, MD, FOUNDER & MEDICAL DIRECTOR, THE ROXBURY INSTITUTE, LOS ANGELES, CALIFORNIA Dr. Amron. Chairman Scott, Ranking Member Gillibrand, and distinguished members of the Senate Special Committee on Aging, thank you for the opportunity to testify before you today. My name is Dr. David Amron, and I am the Founder and Medical Director of the Roxbury Institute in Los Angeles, California, and the Founder and Chair of the Lipedema Society. For more than three decades, I have dedicated my career to treating patients with lipedema, a chronic and often misunderstood disease that affects millions of women worldwide. I am widely recognized as a pioneer of lipedema surgery in North America and have devoted my career to advancing treatment, educating patients, and advocating on behalf of patients to help them obtain insurance coverage for their care. As physicians, trust is the foundation of everything we do. Patients rely on us during some of the most vulnerable moments of their lives. I have spent more than three decades building that trust, yet scammers used artificial intelligence to exploit it in a matter of moments. Although I know AI was rapidly evolving, I never imagined how quickly it could be weaponized to deceive patients until it happened to me. We first became aware of the scam in the summer of 2025, with reports increasing significantly by early September. Patients began contacting the Roxbury Institute after seeing a video that appeared to show me endorsing a so- called miracle cream, miracle lipedema cream. Many forwarded us the video, but by then, some had already purchased the product before realizing it was fraudulent, including several of my own patients. The video was disturbingly realistic. Scammers used actual footage from my YouTube channel and combined it with fully integrated, AI generated likenesses of my voice and my colleague, Dr. Karen Herbst, the head of research and director of diagnostic and preventive medicine at the Rocksbury Institute. As well as AI generated celebrity images and stolen media logos to create a polished advertisement that appeared entirely legitimate. As soon as we recognized it as a coordinated deepfake, my team immediately issued public advisories across social media platforms to warn patients, clarify that neither Dr. Herbst nor I had any involvement, and help our community recognize and report AI generated medical impersonations. Our web developer and digital marketing strategist immediately began investigating the scam as soon as patients alerted us. Before taking action, he investigated the company behind the product, Svelta Venastra, and quickly confirmed it was not a legitimate medical entity. He reported every version of the advertisement to Meta, the fraudulent accounts responsible for publishing it, the domain registrars hosting websites, and the major search engines directing consumers to the scam. Yet each time one version was removed, another quickly appeared. This continued over the course of 11 days. Despite these persistent efforts, the scam kept on recurring. It became quickly clear that existing reporting scams--reporting them was not simply enough to stop a coordinated AI enabled fraud campaign. After exhausting every avenue available to us, we realized we needed to bring national attention to what was happening. We then reached out to major television networks because we believed public awareness might accomplish what traditional reporting mechanisms could not. The Today Show responded, conducted its own investigation, and ultimately brought the scam to a national audience. The Today Show attempted to identify and contact the individuals behind Svelta Venastra, just as we had. Like us, they found no legitimate company, no accountable representative, and no one willing to respond. Although the fraudulent video was eventually removed, versions of the scam have since resurfaced, underscoring how persistent and difficult these AI enabled fraud schemes are to eliminate. What disturbed me most was not that somebody had misused my image. It was knowing that scammers had used my name and my reputation to deceive the very people I have dedicated my career to helping and protecting. The consequences extend far beyond financial loss. Patients may delay legitimate medical care for a progressive disease like lipedema, place their trust in unproven products and services, and allow the condition to worsen. Perhaps most damaging, these scams erode the trust patients place in their physicians. Once that trust is broken, patients no longer know whom they can trust. Artificial intelligence has fundamentally changed the landscape of fraud, giving scammers the ability to convincingly impersonate trusted physicians, fabricate endorsements, and deceive patients on an unprecedented scale. What happened to me is not an isolated incident. Physicians across our country are discovering their images, voices, and professional reputations are being used without their knowledge or consent to promote products they have never evaluated, recommended, or many times even heard of. The danger is clear, these scams put at risk and undermine the credibility of the medical profession. Older Americans are especially vulnerable because they often place tremendous trust in their physicians. Many also rely on the internet, including social media and online search results to learn about medical conditions, making them especially susceptible when fraudulent content appears to come from trusted medical professionals. When they see a realistic online video of a trusted physician recommending a treatment, they have little reason to question its authenticity. That is precisely what makes today's AI generated deepfakes such a powerful tool for deception. This problem is no longer theoretical. It is happening right now, and the consequences for patient safety, medical ethics, and the integrity of health care information are profound. If we do not act, more older Americans and other vulnerable patients will become victims of increasingly sophisticated AI enabled fraud. I respectfully urge Congress to strengthen protections against AI generated impersonation scams, improve accountability for those who create and distribute them, and ensure our laws keep pace with technology that and so easily be used to exploit trust for financial gain. Thank you for the opportunity to testify today. I look forward to answering your questions. The Chairman. Thank you very much. Very sorry that happened to you. Next, I would like to introduce Deborah Del Mastro. She is a Bay Area mother from Martinez, California, who became a public face of the growing AI voice cloning scam after criminals used artificial intelligence to mimic her daughter's voice. She is also a San Francisco Bay Area singer, voice coach, actress, and musician who has taught in voice, drama, and trumpet for over three decades, sharing her voice and her love of music with her community. Thank you for being here. Please begin your testimony. STATEMENT OF DEBORAH DEL MASTRO, VICTIM OF AI-ENABLED SCAM, MARTINEZ, CALIFORNIA Ms. Del Mastro. Thank you. I am very honored to be able to come and share my story with you also. I think my main goal is to let people know that these criminals have, you know, technology that we don't know about. I call this the worst day of my life. It was Thursday, May 14th. The day started with a phone call in the morning. My husband and I were at the breakfast table, and I answered a phone from a local number. I get a lot of my work that way, you know, and I didn't think anything of it. I answered and said, "hello," and a male voice said, "hello, who is this?" I said, "who is this?" He said, "someone you need to talk to. I have your daughter. Is your daughter prone to panic attacks?" Again, I am sitting in my pajamas at the breakfast table, and I said, "my daughter? Yes." Then he put on--I could hear commotion in the background. He put on her voice--now I know her voice and not her--saying, I am so sorry, I am sorry, mom. I am so scared. I am so sorry, and crying, sobbing. It was her voice. It was absolutely her voice. Then he got back on and said that he had 10 pounds of cocaine in his trunk, and my daughter saw a deal go down that she shouldn't have seen, and that his boss was Mexican drug cartel, and his boss told him to take her. He says, his boss doesn't care who he kills, and that he wants $20,000 for the return of my daughter, or he will sell her for what is between her legs. He will kill me, my family, and my daughter if I don't do this, if I come up with the money. Now, we don't have that money. We just don't. I am incredulous with my jaw dropped. I couldn't speak to my husband. I quickly got dressed. I had him on the phone the entire time. As I left the house, I mouthed to my husband that she had been kidnapped. He didn't know where I was going or what was going on at all, but he could just tell it was serious. This man was barking orders to me about having to have the money right away or the boss will do something with her. He told me to bring a phone charger and not to let my phone die or else I would never see my daughter again. He made demands for the next five and a half hours. First to send $2,000 by Western Union to Mexico. He wanted $2,500. I told him I didn't have it, which was really true--just $2,000. He had me go to a local Walmart and that is where I used MoneyGram to send $2,000 to Mexico. I took a picture of it and texted him the receipt as he asked. Then he told me there was a problem with it and that there was an error, and I needed to send the money again. I told him I did not have the money. He said that I would be reimbursed. It would be fine. Just send it again. I said I did not have it. He wanted another $500. I said, all right. I went to my car and found that in my panic, I had locked my keys in the car. Then I had to call my husband to come pick me up, which also brought his bank accounts into play. My husband drove us around with his phone on GPS and my phone on with this person, listening to every moment of it. He ran us around to a bunch of different places, 20 miles away to another Walmart and to Martinez. Twice we were on the phone with this awful man the entire time, listening for every sound, asking where I was, what was going on if I was silent, threatening my family's lives, and telling me that he could sell my daughter right now. I tried our local Safeway to send it. It wouldn't work. Went to Walgreens. He told me not to speak during the entire time I was in any store doing these payments, and to leave the phone on so he could hear everything that happened. Again, I took pictures of the receipts and texted him, now a different number. All the time he was threatening, if I didn't hurry, there was going to be problems. Now he said he was going to drop my daughter off at the first place, then he was going to drop her in another place, then he was going to drop her off in another space. As we were driving to different places and sending money. We sent $5,400 altogether in four different transactions. When it was over, it was about five and a half hours. By the time they probably figured that we didn't have any more money to give them, he ended it. He said, it is over. We were now back 20 miles away at another Walmart, and he said that he had released my daughter at the front of the Walmart, and we were there. He said, go get her, go pick her up or call her, and hung up. I jumped out of the car. She was not there. I was in a total panic. Then I called her. She answered the phone and said, hi, mom. What is going on? I was never so happy in my life to be scammed, so relieved, and furious that we had fallen for this. I heard her twice. I had to be silent with--even in the car driving. There was one time I actually muted the phone so I could speak to my husband, and he started screaming not to do any--no funny business or I would never see her again. He threatened to harm us and my daughter saying that he had kids, and he would kill anyone that got in the way if his kids were at risk. His boss didn't care about anyone. He talked many times how he would sell Sarah for $20,000 or she could pay her way in other ways, hinting that she would be sex trafficked. That he was doing us a favor because we were respectful of him. He had me talk with Sarah again. I asked many times if I could speak to my daughter to make sure she was okay. He had me speak to her again after we had sent, I think, the third amount. He told me exactly what I was to say to her. He said, tell her that this nightmare is almost over. You are going to pick her up as soon as possible. I did that. I said exactly that. My daughter's voice said, I am so sorry, mom. I love you. After that, another man's voice came on, who was much more harsh--the enforcer--who threatened harm to us and Sarah if we didn't come up with more money. That is when we sent another $1,200. It was the last of our available, accessible money. It was a worst day of my life--and my husband, too. Yes, some people are just so broken. I am a Navy veteran. I am usually very, very calm and collected in the face of crisis. I always say I am the person that runs to the fire, not away from it. I was totally, totally convinced that this was my daughter's voice. Yes, you know, it is the perfect scam. It is the perfect scam to talk to family and tell them that you are going to kill them, sell them. You know, it is the perfect scam because you are willing to do anything to get your kids, get your daughter back. I spent most of that time in silence with my husband driving back and forth just trying to figure out how he is going to help her get through her life after an event like this and thank God it was a scam. Thank God it a scam. I had no idea that this was a possibility, that AI could clone the voice. Now, when I called my daughter, both my kids work in IT, my daughter said, mom, that was an AI clone of my voice. She knew it immediately. I said, I didn't know. There needs to be awareness about this, and there needs to guardrails. We need to find out how to protect those of us who don't know about this. Thank you. Thank you for letting me testify. I appreciate it. The Chairman. We are sorry. First--[technical problems]---- Ms. Del Mastro. Yes. The Chairman. We are sorry this has ever happened to you. Ms. Del Mastro. Thank you. The Chairman. Next, I would like to introduce Paul Benda. He is the Executive Vice President for Risk, Fraud, and Cybersecurity at the American Bankers Association where he leads the association's initiatives in fraud, cybersecurity, fiscal security, and information security practices, and chairs the ABA fraud coordination group. Thank you for being here. Please begin your testimony STATEMENT OF PAUL BENDA, EXECUTIVE VP FOR RISK, FRAUD AND CYBERSECURITY, AMERICAN BANKERS ASSOCIATION, WASHINGTON, D.C. Mr. Benda. Chairman Scott, Ranking Member Gillibrand, and members of the Committee, thank you for the opportunity to testify. I am so sorry what you went through. I think it proves the point why we are here today. We are all here to protect Americans from these, as you said, Senator, thugs--these despicable people doing these things. The central point in my testimony is straightforward, generative AI is not replacing traditional scams. It is industrializing them. Generative AI is making impersonation dramatically easier and more convincing. With very little technical skill, a criminal can mimic someone a victim trusts and use personal information gathered online to make the scam feel authentic. What once required significant time, skill, and resources can now be done quickly, cheaply, and at scale. These crimes do not succeed because older Americans are unsophisticated. They succeed because professional criminals are very good at exploiting trust, fear, urgency, and authority. AI simply gives them more powerful tools to do that. A recent FBI warning shows how this threat is evolving. The FBI reported that criminals are using AI generated videos of senior FBI officials, fake social media profiles, and spoofed government websites to impersonate the Internet Crime Complaint Center and target prior victims. In other words, the promise to recover stolen money becomes the mechanism for stealing even more. Bank impersonation scams are another serious example. Just last week, the FCC warned they produced the highest losses of any impersonation scam category and stressed one rule, banks will never ask you to move money to protect it. Additionally, a survey of 14 large banks found identified bank impersonation scams rose 150 percent from 2024 to 2025. The threat is growing rapidly, and much of the deception occurs before a bank ever sees the transaction. Banks are responding aggressively. They are using AI and advanced analytics to recognize behavior that may indicate fraud and to intervene before money leaves an account. Technology is only part of the defense. A trained banker may notice that a longtime customer is suddenly trying to send a large payment while appearing frightened, secretive, or coached by someone on the phone. In those moments, human judgment and the relationship between banker and customer can be just as important as any algorithm. Education is equally critical. More than 2,500 banks have participated in the ABA Foundation's Safe Banking for Seniors Program. The ABA and FBI have developed materials specifically addressing deepfake scams. We are also expanding training to help bankers intervene when a customer has been drawn deeply into a scammer's story. For consumers, the answer is not to become experts at spotting deepfakes. The better approach is to change how we react to unexpected requests for money. Seniors should pause before acting, verify the story through a separate, trusted channel. Families should consider establishing a private password for real emergencies. Remember, if it is a secret, it is scam. Criminals depend on urgency in isolation. They do not want the victim talking to a family member, a banker, or law enforcement. We also need to recognize where the scam lifecycle--where in the scam lifecycle banks enter the picture. We train consumers not to send money to someone they do not know and trust. The problem is that by the time they are ready to send the money, they often believe they know and trust the person on the other end. Generative AI is making it much easier for criminals to manufacture that trust. Increasingly accessible tools can alter a scammer's appearance in real-time video conversation to match the persona they are impersonating. AI can clone voices and translate conversations in real time allowing criminals halfway around the world to communicate convincingly with an American victim. By the time the bank sees the payment, that relationship may have been developing for days, weeks, or even months through telecommunication networks, social media, online advertising, or messaging platforms. The victim is no longer sending money to a stranger. In their mind, they are sending money to someone they know and trust. Banks will continue to intervene where we can, but responsibility has to extend upstream to the telecommunications and online platforms where the impersonation begins, and trust is manufactured. The best fraud prevention is to stop the criminal from reaching and deceiving the victim in the first place. My written testimony lays out a broad policy agenda. We need clear national leadership, which is why ABA is proposing a national office for scam and fraud prevention. We urge Congress to enact the Scam Act, led by Senators Gallego and Murillo, so online platforms have meaningful obligations to verify advertisers and rapidly respond to fraudulent ads. Stronger telecom safeguards are needed to keep criminals off calling networks and restore trust in caller ID. Federal support can help state and local authorities build specialized financial crime capacity. Older Americans should not be expected to distinguish on their own and in real-time between a loved one and a cloned voice, or between their bank and a criminal using their bank's name and telephone number. Banks will continue investing, educating, intervening, and helping victims recover, but durable progress requires every part of the scam ecosystem to help prevent the exception before the victims send money. Thank you, and I look forward to your questions. The Chairman. Thank you, Mr. Benda. Next, I would like to introduce Matthew Ferraro. He is a partner in Crowell & Moring's Privacy and Cybersecurity Group, where he helps clients address complex regulatory matters at the intersection of advanced technology, national security, and crisis management. Thank you for being here and please begin your testimony. STATEMENT OF MATTHEW F. FERRARO, ESQ., PARTNER, CROWELL & MORING LLP, WASHINGTON, D.C. Mr. Ferraro. Chairman Scott, Ranking Member Gillibrand, and members of the Committee, thank you for the opportunity to appear before you today on this critical issue. My name is Matthew F. Ferraro. I am a partner at the law firm Crowell & Moring, where I counsel on artificial intelligence, cybersecurity, and regulation. I also previously served in government, most recently as Senior Counselor for Cybersecurity and Emerging Technology to the Secretary of Homeland Security, and previously as a U.S. Intelligence Officer. I have been working on the policy and legal issues related to AI generated media or deepfakes since 2019. I should say I appear today in my personal capacity. My views do not represent those of my firm or any of my clients. Let me begin with a rhetorical question. How often today have you relied upon the voice of a loved one or the image of a trusted figure before sharing something of value? Perhaps your daughter called from college this morning to ask for a few hundred dollars and you sent it. Maybe you had a video call with a tech support worker and shared your account information. Tonight, you may scroll through social media and see a video of a doctor endorsing an herbal supplement and decide to purchase it. Now consider, what if those representations were all fake? Not your daughter, not the technician, not a doctor, but voices and images forged by AI. Welcome to the world of deepfakes. It is a world we have been living in for several years where AI can create realistic audio, images, and videos that appear true to life but are forgeries. Nearly anyone can access this technology, often for free, and their creations can be sent around the world instantly. While AI generated media has legitimate creative uses, deepfakes can supercharge scams and cyber frauds, especially those targeting senior citizens. In the first quarter of 2025 alone, financial losses from deepfake enabled fraud exceeded $200 million, according to an industry report. Deloitte projects that generative AI could enable fraud losses to reach $40 billion in the United States alone by 2027. Older adults bear a disproportionate burden. They are five times more likely to lose money in a scam than younger people, and according to the AARP, the top digital risk for seniors is scams and frauds. The forms these scams take are varied. For example, fraudsters use AI to generate fake ads featuring the likenesses of celebrities and trusted professionals to sell a range of goods from cryptocurrency to medical cures, as we have heard. Scammers have also cloned the voices of family members telling their victims their loved ones have been kidnapped and demanding ransom, as Ms. Del Mastro testified so powerfully to a few minutes ago. Romance scammers can use AI generated imagery to build ersatz, emotional relationships with victims, before stealing their money and their personal information. What can we do about it? I offer three recommendations. First, we must prioritize education and awareness for all digital media consumers, especially seniors. We should deliver that education through trusted community channels, like senior centers, physicians, community groups, and houses of worship. We must cultivate the appropriate level of skepticism and of discernment. Given the deluge of AI generated media that has and will come, the surest defender against deepfake dupes lies between our ears. Second, we should seek greater coordination across federal and state agencies and with industry. Existing laws already give regulators meaningful tools. The principle applies, if it is illegal without AI, it is illegal with AI. Better knowledge sharing among policymakers, law enforcement, and industry can promote efficiency, improve threat mitigation, and bolster effective enforcement. Third, we should invest in technology. We should promote the use of both AI detection tools and provenance technology that tags media as human created or AI generated. Integrating those tools into our daily lives, much as we do with email spam filters, can help all Americans, and especially seniors tell facts from fakes. I want to close on this note. We should not succumb to cynicism. New technologies, married to ancient vices require responses, but they should neither slake our appetite for innovation and creativity, nor extinguish our faith that we can, with the right steps, navigate the digital world with confidence. Thank you. I look forward to your questions. The Chairman. Thank you. Now, I would like to recognize Ranking Member Gillibrand to introduce the next witness. Senator Gillibrand. Thank you, Chairman Scott. I want to introduce Ben Winters. Mr. Winters is the Director of AI and Privacy at the Consumer Federation of America, where he leads CFA's advocacy efforts regarding data privacy and AI to advocate for consumers. Previously, Mr. Winters worked as an Attorney Advisor for the Civil Rights Division of the Department of Justice and Senior Counsel at the Electronic Privacy Information Center. You may begin. STATEMENT OF BEN WINTERS, DIRECTOR OF AI AND PRIVACY, CONSUMER FEDERATION OF AMERICA, WASHINGTON, D.C. Mr. Winters. Thanks. Good afternoon, Chair Scott, Ranking Member Gillibrand, and members of the Committee. Thanks for the opportunity to talk to you today. I am Ben Winters, Director of AI and Privacy at the Consumer Federation of America, a nonprofit membership organization serving consumers since 1968. Online scam losses have been an unacceptable rate for years but have exploded since generative AI became commercially available and aggressively marketed in 2023. Losses reported to the FBI have ballooned from $3.5 billion dollars in 2019 to $12.5 billion in 2023, to $21 billion last year in 2025. Again, that is just to the FBI, that is just reported, and that is just online scams. CFA estimates in our true cost of scams report that the real number is closer to $150 billion lost just last year, with Americans over 60 losing $55 billion. Given this prevalence and scale, it is not surprising that older Americans describe scams as unavoidable, in that it takes just one minute of distraction to fall victim. Generative AI is not the sole cause of rising scam losses, but it is right now a scammer's dream. It makes scams easier, more effective, and harder to trace. This is just one part of multiple trend lines converging to this record losses. AI companies that aggressively push tools with no regard for harm, an executive branch that refuses to hold tech companies accountable, and confusion and uncertainty around health care eligibility, benefits, and economic security that scammers are exploiting in real time. Scammed content generated by AI systems are just one part of the puzzle. Unregulated and underregulated technology is pervasive across the entire flow of how a scam is created, targeted, delivered, and carried out. CFA calls this the scam stack. This is everything from data brokers that sell detailed personal data, enabling hyper targeted scams based on sensitive characteristics like--and this is a real example--lists of people battling Alzheimer's. This goes to mass communication methods like robotexters, robocallers, and social media companies like Facebook through ads and feeds that allow obvious scam content to remain despite having the technology to detect it. This goes the payment platforms, banks, and crypto wallet providers that let the money go and allow obfuscation of the chain of custody. Last, reporting mechanisms on phones and social platforms that are ineffective, inconsistent, buggy, and disconnected from other reporting mechanisms, like at the government agencies who can do enforcement. My written testimony goes into further detail about how generative AI enables elder fraud at each level of that scam stack and the harm caused by its unchecked growth but it is not just scams. AI systems like chatbots mislead by pretending to be real, sounding authoritative, trying to get you hooked, or giving dangerous medical or financial advice, and are also used by third parties to flood the information ecosystem with convincing falsehoods. That matters especially for older adults, isolated people, and those under health or financial stress. At scale, AI generated misinformation erodes trust in everything people see and hear. It is hard to avoid using these online platforms and scammy content, scams, and falsehood fueled by AI are hurting us all. I want to be clear that the devastating deception we are seeing is not a result of technological ineptitude for older users, the exclusive domain of the dark web, or overseas scam compounds, but rather a crisis emboldened by the biggest tech companies we know, paired with a failure to rein them in. This is not an issue of personal responsibility, but something Congress is uniquely positioned to address. My written testimony details more than a dozen legislative and oversight recommendations with specific bills that have already been introduced, but I want to spend a few minutes talking about that today--a few of them, sorry. One, Congress should hold platforms accountable for spreading, delivering, and targeting scams by passing a bill like the Scam Act, introduced by Senators Moreno and Gallego. We should pass comprehensive data privacy laws, data minimization, and bans on the sale of sensitive data, so it is no longer allowed to be able to sell lists of people battling Alzheimer's for targeting. Pass bills improving the reporting and statistics status quo with a bill like ReportScams.gov Act by Chair Scott and Senator Hassan but would recommend improving that to require platform participation. It is outrageous how complicated the answer is to what do I do when I have been scammed. Reject any provisions that prohibit states from regulating technology or ones being pushed by tech companies right now to limit their liability. Legislation must be paired with sustained oversight of enforcement agencies like the FTC, CFPB, and FBI to ensure key authorities are focused on collaboration, investigation, and choking out the scam upstream, not just chasing individual scammers after the fact. There is no silver bullet for fixing this crisis, but continued inaction only hurts Americans. Thank you again for the opportunity to testify, and I am happy to answer any questions. The Chairman. Thanks for being here. I bet your last job was interesting too. Fascinating what they do. Okay, Senator Tuberville, would you like to start? Senator Tuberville. Thank you, Mr. Chairman. We have got a mess. We know it. You know, technology is bringing us more and more every day. We have heard the problems. My solution is education at a young age. Baby boomers are in trouble because we are all going to get scammed one way or another, and not just domestically, but internationally. I mean, we are going to--it is big time. I hear a lot of problems with that. Mr. Ferraro, how do we fix this? We got the problem. Give us a solution. I am going to ask everybody this, so get your solution ready. Mr. Ferraro. Senator, there is no silver bullet, as Mr. Winters said, but I do think that education is very powerful. If you are looking for an example, I would point the Committee to the example of Finland, which has been very aggressive in teaching both young and old, this is in my written testimony, about disinformation more broadly, but synthetic media particularly. They have found that it works, that you can actually instruct people to be on lookout for false media too, as Mr. Benda said, pause before you send any money, double check, and do all the things that we should do before we make any rash decisions. I do think education is quite important. As I said, I think from a government perspective, interagency cooperation is key here. This is an area where there isn't now a quarterback, to use a metaphor, in the government on these issues, and I think that is something that the Committee might want to consider. I know that there are some bills pending for the Committee on those issues. Third, as I mentioned in my testimony, I think the technology piece is important as well. I mean, just draw the analysis or the analogy rather to email spam. You receive thousands of pieces of spam every day. You just don't happen to see them because they are filtered out by spam filters. One could imagine a situation where similar technology operates in the background on your browser or on your phone to either tag or remove AI generated media. The technology largely exists now. It is just a matter of integrating it. I would offer those. Senator Tuberville. Well, if you do anything in life, you know, the big thing is when you get a manual, you get ethics with it first. The same thing with AI. We have to teach our kids ethics. Again, a lot of us are lost and gone, but our young kids can learn it. Mr. Benda, you have worked for DHS and DOW. Give us your solution. Mr. Benda. Absolutely. I think you are right, education is the key pillar. I think you start out young. I think having a national campaign on how to fight AI deepfakes, how to fight scams and fraud is important. ABA runs financial literacy programs for children. Integrating the AI threat into that and scam threat into that is something that we are looking at doing. I think the national campaign could address people of all ages. I have hope for boomers, sir. I have some boomers that I love, my mother-in-law in one particular. I think the focus needs to also be on safe banking for seniors. How do we get the message to them in channels that they respect, and they use? Whether it is directly from a banker or from people they trust. The other piece I would point to is we have to enable and stop the tech companies from allowing the impersonation that happens out there. You should be able to trust what is on your caller ID. If you put a name and number on there, the telecom should be held accountable if it is not the right person calling. The social media platforms need to stop the impersonations and scams that are out there. They shouldn't be allowed to post the videos that the good doctor talked about. Those types of things, I think, we need more controls and I think there is some legislative solutions that are out there. Senator Tuberville. Yes. Ms. Mastro, I feel your pain. My mother-in-law got scammed. This is internationally. She got a call from my granddaughter. She was in Europe. Please send $10,000. I need it bad. I am broke. I have got to get out of this situation. She sent it. She wasn't in trouble, other than the fact she just needed the money. It sounded just like her. What kind of legislation do you think we need to do for something like this? Have you talked to anybody since your debacle? Ms. Del Mastro. I have not spoken to any legislators until right now. I have spoken to a few experts in the field though, and I believe that--I mean, there are plenty of courses and education out there on how to use AI. That is something you see on social media all the time, those ads, how to learn--take this class, learn how to use it. There is nothing out there on how to protect yourself from AI. There is nothing out there, so that needs to happen. We need to know how to recognize it and how to protect ourselves from it, besides having a safe word, not answering the phone, you know, all the things that everybody immediately goes to. There has got to be an awareness that for senior citizens, certainly, you know, all of us don't know how to hand the remote to the kids to change things. I mean, we need to be aware--if I had been aware that my daughter's voice could possibly be an AI clone, I would have responded differently, but I did not know. I think we need-- education is key, is key, and awareness is key. Senator Tuberville. Just think about, we are just now beginning AI. Just think of how much more they are going to be able to fool people and it is going to get worse and worse. Thank you very much. Thank you, Mr. Chairman. The Chairman. Senator Kelly. Senator Kelly. Thank you, Mr. Chairman. Thank you for having this hearing. As I think all of us know, AI has a very real potential of changing everything about our lives. It is changing how we work, how we make decisions, how entire industries are operating, reshaping our economy, energy systems, and national security. It is affecting people's daily lives. While it brings enormous opportunity, it also introduces risk that demands some serious oversight. That is why we are here today. Over the past year, I have been thinking a lot about how we make AI work for all Americans, not just a few big companies. That is what led me last year to put out a roadmap called AI for America. The ideas behind the roadmap are pretty simple. That is, if AI is going to transform our economy, we need to have a real plan to make sure Americans aren't left behind and that the technology is developed and used responsibly. Here is the thing, these systems are evolving very quickly, even just quickly in the last few weeks. There is a lot that we don't know, and there is a lot that the developers themselves don't know about what some of these products are capable of. Older Americans need to be included in this conversation and not treated as just some afterthought as these products are developed and deployed. About one in five Arizonans in my state are over the age of 65, and when I hear from seniors in my state, they tell me they are concerned about what is real and what isn't real. Ms. Del Mastro, you certainly have experienced that, and I am so sorry for what happened to you and your family. Seniors are seeing more convincing phishing scams and AI generated scams and other forms of online fraud. Sometimes people don't know if they are talking to a bot or a real person. Just yesterday, I was on the phone with my cable company. I called, and I was convinced that this was an artificial person. I still think it may have been. It may have been augmented by a real personal. When I started questioning whether or not the person was real, it became the real person. I think there are systems where one person, where you can have the AI overlaid and there is somebody monitoring. Anyway, we sorted it out. I got the real personally eventually. These are real fair concerns, and it affects everybody. I share them and I do spend--in my former career as somebody who used a lot of technology. Last week, I introduced legislation with Senator Justice called the Senior Chatbot Protection Act. This bill will require companies to clearly disclose when consumers are interacting with AI and safeguard sensitive conversations and address deceptive design practices in their products that put people at risk. We want to help people make informed decisions while supporting not replacing human judgment and trusted relationships. Today, Ranking Member Gillibrand and I are asking the leading AI companies directly, how are you making sure your products are safe for older adults? Are you designing products with them in mind? Do you even know how many older adults are using your products? If we want to make sure AI will help rather than harm, we need to know about, you know, who is using it, how they are using it, and how it reacts in the real world. That is the purpose of my bipartisan aging with AI act which the chairman mentioned, which we introduced, Chairman Scott and I, in June. It will help us build the evidence we need by supporting research into how seniors use AI and its risks and benefits. We have a lot of work ahead of us. AI companies have a responsibility to make their products safe, to be honest about their limitations, and protect our constituents who use them. Congress has a responsibility to set clear rules, demand accountability from tech companies, and make decisions based on science, data, and facts. We have an opportunity to get ahead of these problems. We often do not here in Congress, but we should, and we have to in this case because the window is not going to stay open forever on this. We have got to get this right now. In my remaining time, which I have none--maybe the chairman can give me another 45 seconds--Mr. Winters, based on the harms you have seen and talked about during your testimony, how would the protections in the Senior Chatbot Protection Act make AI chat bots and voice assistance safer for older Americans? And is it important for Congress to do this? Mr. Winters. Yes, thank you, Senator, for the question. I think that some of the provisions in that bill are extraordinarily useful, right. As you mentioned, it is nonsense to not be able to feel confident that you are actually talking to a person or not, right, so that feels like an absolute baseline thing we can do. We can also sort of, you know, integrate significant restrictions on the way the chatbots are actually sort of looking to the user, right, to make it more obvious that it is a chatbot, to make it clear what the choices from those companies are. I think one thing, not to take up too much time, that I want to underline is that the chatbot products especially are products. Their tech companies have choices about what gets spit out by those chatbots, how they are built, and sort of how you interact with them. I think that there are a number of pieces of legislation, including the Senior Chatbot Protection Act, that would be absolutely a positive step forward in making sure those tech companies are pulling their weight and helping here. Senator Kelly. Thank you. The Chairman. Thank you, Senator Kelly. Dr. Amron, you discovered a deepfake video using your face and voice to sell a product you never made and never endorsed. Can you walk through what you had to do to report it and what the process of trying to get it down was like? Dr. Amron. Yes. It was not easy, and it continued to go on. I am going to have to refer back to some notes I have by my team that got involved with this. There was a lot of effort that went in to try to get this down, putting pressure on Meta to respond. It took eleven days to get a response back from them. The team never got transparency in terms of answers, and any timeline, and things like that. It was a very non-transparent process with it. There was no meaningful followup to get the Facebook ads down. The responses we got back were very generic. You never actually knew that you were actually communicating with a real human being with this. We eventually got, at least the Meta ads, down in eleven days. The websites continued to be up there. Then it reappeared weeks and months later again, so it is just a perpetuating process. The Chairman. All right, thank you. Ms. Del Mastro, what did you do immediately after realizing that you had been scammed? Were you able to recover any of the funds that were lost? How did losing those funds affect you and your husband's financial situation? Ms. Del Mastro. Well, thank you. We are senior citizens living on Social Security and our gigs that we do. It affected us greatly. It was all of our available, accessible money. It was all of it. What happened immediately--as I said, my daughter works in AI. When I called her, she told me that is what probably had happened, that it was an AI clone of her voice. After that, we went to the police, the local police. The next morning, when I was a little calmer, I posted on social media. I posted our experience on Facebook and said, let this be, you know, a warning to all of my friends and fans and everyone that these criminals have high-tech capability now. Forgive me, I am still completely traumatized by this. It has been a couple of months. The Chairman. Take your time. Ms. Del Mastro. It just, yes---- The Chairman. What happened is, you talked to your daughter. Then the next step is you are probably--you are happy she is fine. Ms. Del Mastro. Yes. The Chairman. You are furious that you lost all your life savings, because you basically lost all your life savings. Ms. Del Mastro. Yes. The Chairman. Did you go--you called the police department, or you went down there? Ms. Del Mastro. We went to the police department. When my husband and I went home, my daughter got off work and came over. You know, I hugged her and sobbed for a while. Then we went to the local police office and reported it right away. The Chairman. Did they act like they would even be able to help you? Ms. Del Mastro. You know, the officer, the detective in charge that we spoke to said that they see this by the hundreds. They see these kind of things all the time. That probably it was out of the country, you know, a call center out of country and that the money was definitely gone. The money was gone. The Chairman. How did you send the money? Ms. Del Mastro. MoneyGram and Western Union, both. The Chairman. There was no--even though you had a record of it? Ms. Del Mastro. Cash pickup within ten minutes anywhere in Mexico. That is what these all were, so that money was gone by the time we got off the phone. The Chairman. No ability--and they take no responsibility? Ms. Del Mastro. Absolutely. Absolutely. When you go to do these transactions, there are signs everywhere that tell you, you know, don't--you know, if you think this is a fraud, don't do it. However, you have someone on the phone with you right here saying, you know, don't speak to them, be discreet. You know, you got it right there. It is a scare tactic. It is absolutely terrifying. You know, because again, when you hear--I mean, how we understand--when you answer the phone and you hear someone's voice, you know that person by their voice. The Chairman. Right. You get your guard down. Ms. Del Mastro. Right. If you have an AI clone of a loved one's voice, you don't know. You don't know anymore. Yes, like I said, it is terrifying. The Chairman. During the whole process, you were just out trying to solve the problem. Ms. Del Mastro. Yes. The Chairman. They had gotten you. Ms. Del Mastro. Absolutely. The Chairman. Hook, line and sinker. Ms. Del Mastro. Five and a half hours, yes. Yes, I was bound and determined to get my daughter back, one way or another. I was bounded and determined. The Chairman. I think we all would, right. Ms. Del Mastro. Yes. Yes, absolutely. Like I said, it is a perfect scam. It is an old scam with new technology, you know. We just need to know that this is out here. After it happened, and I posted it, I had many people that are friends and fans and family that sent me money to help replace the money. They said, do a GoFundMe. I did a GoFundMe. I set it up a couple of days later, just for the amount of what we lost. The people at GoFundMe read my story and asked if the local media could contact me. That is why I am here today because local media--I was interviewed by a station where the actual broadcaster who interviewed me had an AI fraud like a month and a half before that with a video of her daughter asking for money. Now, her daughter was next door, so she knew it was a fraud, but they had a video of her daughter. Yes, it is frightening. It is really frightening. The Chairman. Were you able to raise the money on GoFundMe? Ms. Del Mastro. Yes. The Chairman. Isn't that nice? There are a lot of wonderful people in the world, right? Ms. Del Mastro. Yes, they are--I mean, I have a very, very wonderful, supportive community of friends and fans and families. It is--I am very blessed in that way. The Chairman. There are a lot of good people out there. There is evil people out there, but there are some good people. Ms. Del Mastro. Yes, there certainly are. We need to protect all of them, yes. The Chairman. I agree. Senator Gillibrand. Senator Gillibrand. Senator Alsobrooks, I am going to give you my time, but I will give you a minute to get set up. Okay, you can go ahead then. Senator Alsobrooks. Thank you so much to Chair Scott and Ranking Member Gillibrand for hosting today's hearing. I want to thank you as well to all of our witnesses for being present. There is an old warning that many of us learn from our parents. It goes like this. If it sounds too good to be true, then it probably is. That warning assumes that we recognize when something is not real. Artificial intelligence is making that much harder. For older Americans, the harm from a senior scam does not end with stolen money or identity. It ends with stolen dignity. These scams can make our elders afraid to answer the phone. They cause distrust and paranoia that cuts off real communications from our family. I know this firsthand. I am a part of the sandwich generation, and I have been horrified watching my mother, who is at home during the day--the predatory calls are absolutely unbelievable that she receives all day long. They take away not only from those individuals a sense of safety and independence, but they also frighten the families, and it is not easily restored. AI has the potential to help older adults remain independent, we understand that supports caregivers, and even improve health care but left unchecked, those tools have been bold and bad actors and made our seniors especially vulnerable to scams. Congress, I believe, has a responsibility to set clear rules, require meaningful safeguards, and hold companies accountable when they ignore known risks. We know this harm is already happening, and we should not wait for more families to suffer. Ms. Del Mastro, my first question is for you. I was able to watch your testimony, and I want to thank you so much for being here and for being willing to share what happened to you. I am also the mother of a daughter, so I can only imagine the true trauma that you experienced that day. I know it is not easy to relive those five hours, and I am so sorry for what you and your family had to endure. Now, I want to be clear. I want to just ask you a few questions. I know you believed your daughter was in danger, and you did what any parent would do, which is everything you could to protect her. The people who targeted you counted on your motherly reaction. If you are comfortable sharing, what has stayed with you most since that day, if you can say, and how did you feel upon learning that these seasoned criminals manipulated your emotions to create a sense of false urgency and emergency? Ms. Del Mastro. Yes, well, I was absolutely furious when it was over. Absolutely furious. I am quite certain I screamed in the parking lot of that Walmart. I am certain I did. However, and again, and I was so incredibly relieved that it was a scam, so relieved it was the scam. Senator Alsobrooks. What would you say the part that has stuck with you the most has been? Ms. Del Mastro. Is how--I think what stuck with me the most is how real it was, absolutely how real it was. It was her voice. It was--it was her voice, even though they never spoke to her. I mean, they more than likely got that off of--got her voice off of social media would be my guess but yes, it is frightening how precise it is. Senator Alsobrooks. Yes. Now, once you realize what happened, would you say that the institutions that you turned to for help were able to provide appropriate resources? Or were you left to navigate the aftermath largely on your own? With the way that the system is set up now, what should victims be able to expect in those first critical hours? Ms. Del Mastro. Yes, well, like I said, I went to the police immediately afterwards. Actually, my daughter and I went to see that same detective a couple of times. It was pretty clear there was nothing he could do. It was clear that they were not going to find these people. There was no way to get the money back from it. It was clear. Senator Alsobrooks. Nothing to do---- Ms. Del Mastro. Yes. Senator Alsobrooks. Well, let me just quickly go to Mr. Benda. My time is going quickly. In 2025, over 4,500 Marylanders aged 60 and older filed complaints of internet crime and reported more than $176 million in losses. When an older customer tells a bank that they were deceived into sending money, the question is what happens next, and how quickly can the bank act, and where does its ability to trace or recover the money depend on. Does it depend on another institution or law enforcement? Mr. Benda. Thank you, Senator. That is a great question. I think it is--one of the challenges that we have is following that money. A lot of it depends on where they report. I know a lot of folks are focused on reporting law enforcement, but the best chance to get that money back is to report directly to your bank. The stopping the flow of funds happens in financial institutions, not through law enforcement. We highly recommend the first place to report to is your bank. Your bank can potentially reach out if it is another financial institution, such as a bank, or even a credit union. We can reach out to them and there are wire recall procedures, ACH return procedures that can be done. ABA itself is investing in resources to allow banks to freeze funds faster in those instances. If it goes to a crypto firm or some other fintech firm, it becomes a lot more challenging. The structures aren't there. If it goes to a money service business like Western Union or other places, the rules are different as well and it becomes an instant transfer and becomes even more difficult. It varies depending on what institution is handling the transfer. Senator Alsobrooks. Thank you. The Chairman. Senator Gillibrand. Senator Gillibrand. Thank you all for your testimony. Ms. Del Mastro and Dr. Amron, I am furious on your behalf. I am stunned with how much injustice there is around these types of scams. I have personal friends who got targeted and winds up sending money in a crypto machine to some unaware unknown place. My aunt was scammed into paying $5,000 because somebody told her she didn't pay her taxes right and that they were going to send the FBI to arrest her. I have taken--I have traveled all across New York and listened to our seniors about what has happened to them. I have heard about the boyfriend scam, the girlfriend scam. I have hurt about the child scam, the grandchild. Every--I mean, it is endless. These are seasoned, sophisticated, criminal networks from all over the globe, targeting our family members, targeting our loved ones, to just separate them from their hard earned money, and it is a disgrace. I think it is incumbent on Congress and this Administration to do a hell of a lot more than we are doing today to protect Americans. It is not acceptable that this has metastasized into a cancer that is harming New Yorkers, harming Americans every day. I am furious with the President for deleting so many of the organizations and personnel that are supposed to protect you, to actually stand between you and the scammer. Okay, so since taking office, President Trump has taken a hacksaw to the very agencies that protect Americans from scammers and bad actors, barring the CFPB from bringing enforcement actions, moving to shut down the CFPB entirely. Slashing CISA funding and workforce. Dismantling the organized crime drug enforcement task forces. These are all terrible outcomes. I don't know who is supposed to protect who at this point. Let me just start with you, Mr. Winters, and I am going to talk to you all about this situation that is just unacceptable. How have these policy changes affected our ability to stop scammers? Mr. Winters. Thank you, Senator. Everything that we all talked about today was the problem and already in place before this Administration did all of those things you talked about. Before that, there were people at the CFPB helping chase down the money they lost. There were people with the Federal Trade Commission that were getting that upstream actor, like Riter, that had their case sort of reversed after this AI generated thing. All of these actions have devastated and sort of failed Americans, right. This is only going to get worse because of the lack of those cops on the beat, so to speak. We need more, not less. Senator Gillibrand. Mr. Benda, from your perspective, what investments and what protections should we put in place so that we have more safeguards for people who are being scammed? Mr. Benda. Thank you for the question, Senator. I share your rage at this instance. I think a great example is, as Ms. Del Mastro's point, that a local caller ID was used. If it had said international caller on that phone, would that have maybe raised some eyebrows, or unknown caller? She might have still been, because they are very convincing. It is a criminal industrial complex. People that make billions of dollars convincing Americans because of technology. They are fighting a fight they can't win. Senator Gillibrand. Maybe questions at the credit union. I have heard of many examples where bank tellers saved the day saying, ma'am, can I just ask, this seems like a lot of money, where are you sending it? Is this important to you? Is it someone you know? That one intervention stopped $10,000 from going across. Maybe more requirements at all of these transmitter locations where they are using and demanding money being transferred to have questions so that someone who is being rushed, somebody who is clearly on another phone call, somebody who is showing all these indicia, would that be helpful? Mr. Benda. I think having training programs for anyone that is transmitting money makes a lot of sense. ABA has a Safe Banking for Seniors Program. We have given it to thousands of banks that are out there. I think exactly those indicators you said, banks and credit unions and money service business should all be aware to try and make them stop, think and pause, and educate potentially about the scams that are outside. Senator Gillibrand. Mr. Ferraro, you have deep federal experience at ODNI, the CIA, Department of Homeland Security. In 2025, Government Accountability Office found that there was little coordination amongst federal agencies. In response, I worked with Chairman Scott to introduce our bill, the National Strategy for Combating Scams Act. It would put the FBI in charge of a multi-agency effort to build national strategies on scams. Based on your federal experience, how does the lack of coordination of these agencies affect our ability to push back? What would a national strategy do to combat AI driven scams? Mr. Ferraro. Thank you, Senator. Yes, I think that the lack of coordination can be a signal failure in government response to major issues. It leads to a number of things. One major problem is information gaps. There are things that some agencies know, some actors know that others don't. Second is, of course, unclear accountability. When there is no football coach on the team or no quarterback, you don't know whom to hold accountable for both success and for failure. Third, I think there are discordant or disaligned incentives. Without clear direction or strategy, bureaucracies can simply not act or not act with alacrity. I do think that your strategy bill is a good one, because I think it would solve a lot of those issues. It would put the FBI in charge, as you said, and they can be responsible. They can be called before this Committee to give testimony. They can offer reports. It would solve information gaps by directing that they share information. Of course, it could help align incentives to help address this very hydro-headed monster. Senator Gillibrand. I am out of time, so I just want to end with Dr. Amron and Ms. Del Mastro. What happened to you is unacceptable. It is pure criminality. It is undermining to your sense of safety what you have accomplished in your life. For you, Dr. Amron, for you, Ms. Del Mastro, the safety of your family and the well-being. I mean, these are very traumatic experiences. What do you want from Congress and from law enforcement to do to help others who don't know this could happen to them, to give you better recourse when it happens? If you could just have a magic wand and solve this problem, what advice would you give to the Senators? Dr. Amron. Well, it is a very pervasive problem. There are many different avenues that the scams are taking place on. You know, Mr. Scott apologized to me for what I went through. Really, the victims are not really me, it is my patients, and that I really care about. I want to make that very clear. It is big problem. Mr. Tuberville, you know, had this idea of educating, which is, I think, a great thing but that is only part of the thing. You can't have this buyer beware type of mentality, you know, that that is going to be enough with it. The pressure at least, at least with what happened with my patients, has to be put on the platforms, I believe. The platforms that are supporting this and have to have consequences. Many of the criminals are outside the United States that are perpetuating these crimes with things like that. I think that there needs to be a lot more responsibility on the platform that has to come from government and Congress. Senator Gillibrand. Ms. Del Mastro. Ms. Del Mastro. I agree with what Mr. Amron said and Mr. Benda about, you know, if I had seen that that was an international call, I would have had---- Senator Gillibrand. You would have had a different view. Ms. Del Mastro. A completely different outcome. Also, your example of having a human teller ask the questions. The thing is that so many jobs are being replaced by AI, where you don't know if you are talking to a human. If you are face to face with someone, if you have someone-- if you are able to actually speak to a human being, I think that would help stop the whole scam from happening to begin with. I don't how you can keep AI from replacing everyone, but I think it is a noble cause to keep us all--yes. Senator Gillibrand. Thank you for sharing your story. It is just--it is infuriating. We are up against hundreds of thousands of criminals doing this every day, stealing billions of dollars from Americans. We are very trusting. They use our good nature against us. They use out-- everything. It is a disgrace. We are on notice that we have to do a lot more to make it better. Mr. Chairman, I return it to you. I know you have more questions. The Chairman. Thank you. Mr. Benda, can you please explain to the Committee the dangers AI is posing by impersonating banks, government officials, doctors, etcetera, and the scale of damage can be done by successfully tricking Americans into believing these impersonations? What are some of the strategies the banking industry is using to combat the fraud? Mr. Benda. Thank you, Mr. Chairman. You know, I cannot be as eloquent as our two other witnesses in the risks, especially to doctors and to seniors and I think they pose in that--the threat that is out there. I think the education is a key piece to it that is going forward. I also think people need to recognize the risks of AI. When I talk about the industrialization of this, just as companies are using chatbots to engage individuals on a broader basis and then link that to a human, the criminals are engaging the same thing. They are going to start the conversation with a chatbot, then hand it off to a human when they have got someone on the phone that they think they are going to be able to scam. We are going to continue to see this type of activity. We really have to restore trust in our telecommunications and our social media ecosystems. We have got to ensure that that caller ID that is there, that number that is there, that name that there is accurate. We can't allow those to be faked. We have to ensure when someone is visage is used on an online platform, that that visage is actually accurate. You know, I use Google photos. I can find pictures of my daughter sitting right back there. I can followup every picture of my daughter in an instant. You are telling me on an online platform can't tell me when someone is impersonating someone else that is out there? Different tools that are in place, and then the ability to take down those scams when they are on there. It should not take 11 days when we know people are actively being robbed to take down an ad. This is a doctor who has got a practice that is internationally known. If he is reporting something, it should be acted on. I think the Scam Act has some requirements in there in terms of timeline that Senators Gallego and Moreno have put out there. I think those are the types of activities that we need to take. The Chairman. Thank you. Mr. Ferraro, AI scams are inherently borderless. Can you talk about your experience with foreign weaponization of deepfakes and what kind of threat do they pose? Mr. Ferraro. Certainly, Senator. You are absolutely right that it is an international phenomenon, and oftentimes it is a conspiracy. That there is like actual warehouses of people who are operating to execute these frauds, which I think underscores something that we haven't really talked about yet, which is the importance of international cooperation because the folks who are actually going to go and shut down those scam operations are going to be local law enforcement. This is in my testimony, I believe, but there was a recent example of that in Vietnam, where the Vietnamese police worked with the American Government to go and literally arrest people who are running these sorts of deepfake scams. They run the gamut across all the different kinds of scams that we talked about, the romance scams, the impersonation scams. There was a report recently in the New York Times about, in China, that they are thousands of AI avatar doctors who are selling supplements. You know, oftentimes that is in some sense legal, but you can probably still work with the Chinese Government to seek some redress against them, particularly when, as I said in my testimony, when things are illegal without AI, they are illegal with AI. I think that in some ways this just speaks to the need of an all of government response, which would include the State Department, the FBI, DHS, and others. The Chairman. Thank you. Mr. Winters, you have got a background in law enforcement. Would a centralized reporting portal encourage more victims to come forward? Mr. Winters. Yes, absolutely. It would facilitate those people coming forward, right. Right now, you could say, where should you report it? You could say you go to the FBI or the FTC or State AGs or local police department or the AARP. I could name 15 different kinds or do it right on the platform. None of those things are talking to each other. The owner should not be on the victim to try to figure out what the most effective way of doing it is. It would facilitate a more accurate picture of what is actually going on because you would get more reports. It would also help facilitate this better education, right. Like the fact that it is so fragmented makes it harder to educate people about what to do and how to educate yourself. If you had the ReportScams.gov where you could report it and learn more about it, that would be massive. The Chairman. Do you think it is realistic to get all these agencies to work together? Mr. Winters. I think so. You know, a lot of what I did was interagency stuff. You know, not too bad. I think everyone wants to stop this exact thing from happening. It is not that hard, but it is hard to coordinate everyone to do it. The Chairman. Do you have any more? Senator Gillibrand. I literally have hours of questions for all of you, so I just want to thank you for testifying and bringing your stories here and bringing all your recommendations. For our three expert witnesses, you have given us a lot of good food for thought in terms of recommendations. We are going to follow them, but I just want to thank you all because this is such a big problem, and this is just the tip of the iceberg. These are just two scams out of millions, and I am just so grateful that you are focused on trying to solve the problem. I really appreciate you, Mr. Chairman, for having this hearing. The Chairman. We released today a bipartisan report that hopefully--we have had some luck with--we did one, a big one on generic drugs and we are very close to getting the bill passed on. It would impact that. I think we will be--we will get some of this stuff done if we continue to work together. Thanks everybody for being here today and participating. I look forward to continuing to work with all the members here. I also want to remind seniors and families watching that the Senate Aging Committee operates a fraud hotline. For anyone who believes they may have been targeted or victimized, the number is 1-855-303-9470. If any Senators have additional questions for the witnesses or statements to be added, the hearing record will be open until next Wednesday at 5:00 p.m. Thank you all for being here. [Whereupon, at 5:06 p.m., the hearing was adjourned.] ======================================================================= APPENDIX ======================================================================= Prepared Witness Statements ======================================================================= [GRAPHICS NOT AVAILABLE IN TIFF FORMAT] ======================================================================= Questions for the Record ======================================================================= U.S. Senate Special Committee on Aging "The AI Deception Machine: Deepfakes, Chatbots, and the New Frontier of Senior Fraud" July 29, 2026 Questions for the Record Paul Benda Ranking Member Kirsten E. Gillibrand Question: Modern frauds and scams will often span multiple services, so no single organization is aware of the full scheme. Data sharing among private sector organizations, as well as law enforcement, can help prevent frauds and scams and disrupt the criminals who carry them out. Hower, the organizations that might share that information sometimes say that there is legal uncertainty over whether they are allowed to share.In your view, is there legal uncertainty regarding the ability of private sector actors to share information on frauds and scams? Response: Yes. There is meaningful legal uncertainty around fraud and scam information sharing, particularly when information needs to move across different sectors. The United States does not have a single legal framework for fraud intelligence sharing. Instead, banks, telecommunications providers, technology platforms, payment companies, and other participants operate under different statutes, governing areas such as anti-money laundering, privacy, telecommunications, consumer reporting, and cybersecurity. Those laws provide important protections, but they were generally not designed to enable all of these sectors to collaborate against the same fraud scheme in real time. Some existing authorities are quite useful. For example, Section 314(b) of the USA PATRIOT Act provides participating financial institutions with a liability safe harbor for sharing information related to suspected money laundering or terrorist activity. In June 2026, FinCEN clarified that this authority can include fraud-related information and can support real-time sharing. That clarification was important. However, the Section 314(b) safe harbor generally applies to eligible financial institutions and does not provide a comprehensive framework for sharing with telecommunications companies, online platforms, or other sectors that may possess critical information about the same scam. There are also important distinctions between a law that permits certain information to be shared and one that provides an explicit safe harbor from liability for sharing it in good faith. Where the law is unclear, or where an exception may permit sharing but there is no clear liability protection, institutions understandably tend to be cautious. The current framework is strongest for financial institution-to-financial institution sharing and reporting to government, and weaker for real-time sharing between financial institutions, technology platforms, telecommunications providers, and other sectors. Regulatory guidance can help reduce unnecessary uncertainty, and agencies should continue clarifying what existing law permits. But guidance alone will not resolve the underlying structural problem. Congress should establish a fraud-specific framework that clearly defines what information may be shared, who may participate, how information may be used, and the privacy and security protections that apply. Most importantly, it should provide appropriate liability protections for organizations that in good faith share, receive, and responsibly act on fraud-risk information. Criminals move seamlessly across telecommunications networks, online platforms, financial institutions, cryptocurrency exchanges, and payment systems. The organizations trying to stop them should not be constrained by legal and operational silos that the criminals themselves do not face. Question: What are potential legal, regulatory, or compliance barriers to sharing that information? Response: The potential barriers fall into several categories, and it is important to distinguish between information that is actually prohibited from being shared and information that institutions may be reluctant to share because the legal protections are unclear. First, existing information-sharing authorities are generally sector-specific and purpose-specific. Section 314(b), for example, provides a strong safe harbor for eligible financial institutions sharing information related to suspected money laundering or terrorist activity, including certain fraud-related activity, but it does not provide the same protection when a bank needs to exchange fraud intelligence with a telecommunications provider or online platform. Second, different privacy and communications laws govern different types of information. The Gramm-Leach-Bliley Act, state privacy laws, the Electronic Communications Privacy Act, and FCC rules governing Customer Proprietary Network Information (CPNI) can all affect what information may be shared and under what circumstances. For example, communications content is treated differently from metadata such as telephone numbers, IP addresses, routing information, and timestamps. Telecom providers also face uncertainty about proactively sharing fraud indicators with banks and other non- carrier entities because the FCC's CPNI rules do not provide a clear cross-sector safe harbor. Third, organizations must consider potential liability associated not only with sharing information, but also with how it is subsequently used. If inaccurate information is shared or another participant acts on it, institutions may be concerned about privacy, defamation, business-tort, antitrust, or other liability. The Fair Credit Reporting Act can also become relevant if shared consumer information is assembled and used to make eligibility decisions, such as whether to open an account. These are important consumer protections, but a new fraud-sharing framework should clearly explain how they interact with real-time fraud prevention rather than leaving participants uncertain about their obligations. Finally, compliance practices themselves can become a barrier. SAR confidentiality requirements, for example, are sometimes interpreted broadly, and organizations may choose not to share even where sharing is legally permissible because the consequences of getting the legal analysis wrong can be substantial. That is why regulatory clarification is useful, but ultimately Congress should provide a clear, fraud-specific framework with appropriate privacy protections and a strong safe harbor for organizations that share, receive, and responsibly act on fraud information in good faith. Question: In your view, is there anything Congress should do to make it easier to share that information, or clarify existing legal authorities? If Congress seeks to do so, are there potential effects for business and consumers that we should take into consideration? Response: Yes. Congress should make it easier for private-sector organizations and law enforcement to share fraud and scam intelligence by creating a clear, fraud-specific statutory framework. Existing authorities provide useful tools, but they are fragmented across different sectors and statutes. Regulatory guidance can clarify what is already permissible, and agencies should continue doing that, but guidance is not a substitute for durable legal authority and can leave participants uncertain about liability. Congress should build on the principles that have worked in other information-sharing regimes: voluntary participation, clear definitions of what information may be shared and for what purposes, strong protections for privacy and security, and an explicit safe harbor for organizations that in good faith share, receive, and responsibly act on fraud-risk information. The framework should allow financial institutions, telecommunications providers, technology platforms, payment companies, cryptocurrency firms, and appropriate government entities to participate under common rules rather than operating in separate legal silos. Congress should also consider the effects on both businesses and consumers. For businesses, the framework should avoid creating conflicting or duplicative requirements and should recognize the implementation costs of new systems, particularly for smaller institutions. Common data standards, clear operating rules, and shared infrastructure can help reduce that burden. For consumers, stronger information sharing must preserve protections for privacy, accuracy, transparency, and redress. A fraud signal can be extremely valuable, but it can also be wrong. If shared information affects an important decision, such as whether an account is opened or a transaction proceeds, consumers should have appropriate opportunities to correct inaccurate information. The objective should be to allow legitimate organizations to exchange actionable intelligence at the speed of scam, while ensuring that the system is accurate, secure, and accountable. Question: Congress passed the Cybersecurity Information Sharing Act of 2015 (CISA) to encourage the voluntary sharing of cyber threat information. In your view, is the CISA framework a model Congress should consider for a framework for sharing data and intelligence related to frauds and scams? Why or why not? Response: The Cybersecurity Information Sharing Act of 2015 passed with bipartisan support and has been helpful in protecting the privacy of, and reducing the liability for, organizations (including banks) that voluntarily share information about cyber threats and attacks with other organizations and the U.S. government as a means of alerting and allowing others to defend against similar attacks. The law expired on September 30, 2025, and was temporarily extended through September 30, 2026. Last year, ABA partnered with other associations on two letters to congressional leadership advocating for reauthorization: https://www.aba.com/advocacy/policy-analysis/letter-to- congress-on-cisa https://www.aba.com/advocacy/policy-analysis/letter-to- congress-on-cisa-september We believe CISA has encouraged information sharing between the U.S. government and the private sector while establishing clear expectations for privacy and confidentiality and has provided antitrust exemptions and associated protections for cyber information sharing between private companies. We strongly encourage reauthorization so that information sharing among private sector firms and information sharing with U.S. government agencies continue. We also believe the CISA Act of 2015 provides an important model for how Congress should approach fraud and scam information sharing, but a new fraud-specific statutory framework is needed. CISA approached several fundamental challenges correctly. It created meaningful liability protections for entities that voluntarily share or receive covered cyber threat information, permits sharing across sectors rather than limiting participation to a particular regulated industry, incorporates privacy protections, and establishes a framework for automated, real-time exchange. Those are important principles for combating scams because financial institutions, telecommunications providers, technology platforms, payment companies, and law enforcement often possess different pieces of intelligence about the same criminal network. However, CISA was designed around cyber threat indicators and defensive measures for cybersecurity purposes. It is extremely useful for cyber-enabled fraud, but its application is less clear when a scam is based primarily on social engineering or impersonation rather than compromise of an information system. Another authority many look to is Section 314(b) of the USA PATRIOT Act, but it presents a similar issue. FinCEN recently clarified that participating financial institutions may share fraud-related information, including in real time. That clarification is helpful, but Section 314(b) remains a voluntary anti-money-laundering framework whose safe harbor is generally limited to eligible financial institutions and sharing related to suspected money laundering or terrorist activity. It was not designed to connect the full ecosystem involved in modern scams or to support automated information sharing and intervention at the speed of scam. Congress therefore should build on CISA with a new law specifically designed for fraud and scams. A new statute should clearly address how fraud-information sharing interacts with existing consumer protection laws, including the Fair Credit Reporting Act. The FCRA provides important safeguards designed to promote accuracy and give consumers transparency and an opportunity to correct erroneous information when data is used in eligibility decisions. Those protections should be preserved. At the same time, Congress should provide clear rules for how real-time fraud intelligence may be shared and acted upon, particularly when information indicating possible fraud or mule activity affects decisions such as opening a new account. A well-designed framework should allow institutions to act quickly on credible fraud signals while ensuring that consumers retain appropriate rights to accuracy, notice, and redress. The framework should provide an explicit federal and state liability safe harbor for entities that in good faith send, receive, and act on fraud-risk information, while preserving appropriate privacy, accuracy, security, governance, and consumer redress protections. Finally, legal authority alone will not create an effective system. Congress should address who will build, operate, secure, fund, and oversee the infrastructure; establish common data standards and operating rules; and enable interoperability across sectors and, where appropriate, across borders. Those elements are essential if banks, telecommunications providers, digital platforms, payment systems, and law enforcement are going to combine the fragments of information each possesses quickly enough to prevent a payment, interrupt a scam, or recover stolen funds. That is consistent with ABA's written testimony calling for a fraud-specific framework capable of operating at the speed of scam. In short, CISA is a valuable model because it demonstrates that Congress can create strong liability protections and enable rapid, voluntary information sharing across sectors. For fraud and scams, however, Congress should build on that model with a new statute that addresses not only the sharing of information, but also the infrastructure for sharing it and the legal protections necessary for responsible action based on that information. Question: Disrupting online frauds and scams requires taking that content off the internet. However, that requires cooperation with platforms, law enforcement, and registrars or other third parties. In your view, what are the most significant barriers to disrupting the actions of criminals who engage in online frauds and scams? Should Congress consider policy changes to enhance the ability to disrupt online fraudsters and scammers? If so, what should those policy changes look like, and how can they minimize unintended consequences for lawful content, consumers, and legitimate businesses? Response: The most significant barrier to disrupting online fraud and scams is that too much of our current approach is reactive. We identify a fraudulent advertisement, report it, and seek to have it removed. Takedown is important, but if the criminal can immediately create another account or purchase another advertisement, we are simply playing whack-a-mole. Congress should therefore focus on who is purchasing paid advertisements and require platforms to conduct meaningful know-your-customer (KYC) verification before allowing an advertiser to reach consumers. At a minimum, platforms should verify that the advertiser is a real person or legitimate business and, where the advertiser claims to represent a regulated financial institution or other trusted entity, that the advertiser is actually affiliated with that organization. Platforms should also have safeguards to prevent criminals from evading verification through shell companies, advertising intermediaries, stolen credentials, or synthetic identities. This is one reason ABA strongly supports the approach embodied in S. 3774, the SCAM Act, which would require advertiser verification, impersonation detection, accessible reporting, prompt investigation, removal of confirmed fraudulent advertisements, and measures to prevent circumvention through false, stolen, or synthetic identities. The FCC's recent work on illegal calls provides a useful model. The Commission has proposed stronger KYC requirements for originating voice providers so they conduct meaningful diligence before giving a customer access to the calling network. ABA supports that approach because stopping a bad actor at the point of entry is more effective than trying to identify and block fraudulent activity after it has been launched. Our FCC comments cited an originating provider that went from no calls to more than 136 million calls in a single month just two months later, with analysis indicating that most of the traffic was illegal. That example illustrates the risk of providing powerful communications infrastructure without adequate diligence on the customer using it. The same principle should apply to online advertising. A platform that accepts payment to distribute and target an advertisement should take reasonable steps to know who is buying that access before the advertisement runs. Once an advertiser is confirmed to be fraudulent, the platform should also prevent that actor from simply returning under another account or business name. The goal should be to move from repeatedly taking down individual scam advertisements to creating sufficient friction at the point of entry that criminals cannot easily buy their way back onto the platform. Senator Raphael Warnock Question: The proliferation of artificial intelligence (AI) has led to an increase in AI-driven scams and fraud, creating serious risks for seniors and their financial institutions. Banks are often the main or only touchpoint for victims of fraud; according to a Gallup poll from the Stop Scams Alliance, Americans are more likely to report scams and fraud to their financial institution than state or local law enforcement, federal law enforcement, or other federal government agencies. How are banks increasing their efforts to protect older customers from financial fraud, including AI-generated deepfakes? Response: Banks are increasing their efforts on several fronts because protecting older customers from scams requires both technology and human intervention. Banks are using AI, machine learning, and advanced analytics to identify unusual transactions and behavior that may indicate fraud, while strengthening identity verification and authentication as criminals increasingly use generative AI, deepfakes, and synthetic identities. Technology alone, however, cannot determine whether every customer has been deceived. Banks therefore continue to train front-line employees to recognize when a customer may be under a scammer's influence, such as when a longtime customer suddenly changes behavior, appears frightened or secretive, or is being coached during a transaction. That human intervention is especially important with AI-enabled scams because the criminal may sound or even appear to be someone the customer knows and trusts. Consumer education is equally important. Through the ABA's non-profit foundation, banks can access the Safe Banking for Seniors program, which provides free resources to help older Americans, their families, and caregivers recognize and avoid fraud and financial exploitation. Over the past decade, more than 2,100 banks have participated in the program to reach millions of older people. The ABA Foundation has also collaborated with a broad network of government, law enforcement, regulatory, and industry partners, including the Commodity Futures Trading Commission (CFTC), the Federal Bureau of Investigation (FBI), the Federal Trade Commission (FTC), the Financial Crimes Enforcement Network (FinCEN), FINRA, IRS Criminal Investigation (IRS-CI), the Securities and Exchange Commission (SEC), Homeland Security Investigations (HSI), the U.S. Postal Inspection Service (USPIS), and the U.S. Secret Service (USSS), to educate consumers about emerging fraud threats. Together, these efforts have addressed a wide range of scams, including check washing, cryptocurrency, imposter, money mule, romance, and tech support scams. Building on this collaborative approach, the Foundation and the FBI have also developed educational resources to help consumers recognize and respond to the growing threat of deepfake media scams. These materials encourage individuals to pause and think critically before acting, independently verify identities through trusted channels, and establish family code words rather than relying solely on the apparent authenticity of a voice or video. ABA is also updating #BanksNeverAskThat, our national consumer scam-prevention campaign, to address evolving impersonation tactics, including deepfake-enabled scams. The campaign already helps consumers recognize bank-impersonation scams and the psychological techniques criminals use to create urgency and manipulate victims, and the 2026 campaign is being refreshed with new materials for banks and consumers. The underlying message across these efforts is simple: older Americans should not have to become deepfake experts. Banks can provide technology, trained employees, and practical education that help customers pause, verify, and avoid sending money to criminals in the first place. Question: What policies or regulatory gaps are limiting how banks can investigate consumers' reports of fraud or exploitation? Response: Several gaps are particularly important. Banks often do not have access to the information held by the other sectors through which a scam occurred. A bank may see the payment, while a telecommunications provider has information about the phone number used to contact the victim and an online platform has information about the account or advertisement that initiated the scam. Existing law provides several avenues for information sharing, but there is no comprehensive, cross-sector safe harbor that clearly allows these entities to share and act on fraud intelligence in good faith. As discussed in my response above, Congress should establish a fraud-specific framework that allows this information to be exchanged quickly and securely across sectors. The current patchwork creates legal uncertainty and can leave each participant investigating only the portion of the scam visible to it. Additionally, we should improve the ability of banks and Adult Protective Services to work together when an older customer may be experiencing financial exploitation.Existing law has made important progress. The Senior Safe Act provides liability protection for certain trained financial institution employees who report suspected exploitation in good faith to APS, law enforcement, and other covered agencies, and federal regulators have clarified that the Gramm-Leach-Bliley Act generally permits banks to report suspected elder financial abuse to appropriate authorities. The challenge is that an effective investigation often requires more than making an initial report. Banks can remain uncertain about what customer information they may provide during follow-up discussions, how much information may be shared, and what information APS can share back with the bank. The CFPB itself identifies restrictions on when, with whom, and how much customer information may be shared as a potential challenge in elder-protection networks. That uncertainty can make it harder for the bank, APS, and law enforcement to develop a complete picture and determine how best to protect the victim. Congress and regulators should therefore provide clearer authority and appropriate safe-harbor protections for good- faith, two-way information sharing between financial institutions, APS, law enforcement, and other appropriate partners when investigating suspected fraud or elder financial exploitation. Those protections should preserve appropriate privacy and confidentiality safeguards while allowing the parties trying to protect the victim to share the information necessary to investigate and intervene effectively. Finally, another significant policy gap is the lack of a consistent federal framework that allows financial institutions to delay disbursements or place temporary holds on transactions when they reasonably suspect elder financial exploitation or fraud. Without this authority, banks may identify red flags but have limited ability to pause a transaction long enough to investigate before funds are lost. Congress should consider legislative solutions that provide financial institutions with the authority, along with appropriate safe harbor protections, to temporarily delay disbursements or hold transactions when there is reasonable cause to believe a transaction may be fraudulent. This would give banks a critical opportunity to investigate suspicious activity and help prevent losses before they occur. A uniform national framework would eliminate inconsistencies among state laws. The ABA supports legislation such as H.R. 9668, the Safeguarding Transactions to Outpace Predatory (STOP) Senior Fraud Act, which would help address this gap by giving banks additional tools to investigate suspected exploitation and protect older adults from financial harm. Question: What policies can banks adopt to streamline reporting processes and encourage consumers to report instances of fraud or scams to law enforcement agencies? Response: Banks should make it as easy as possible for customers to report a suspected scam, and the first call should be to the customer's financial institution. In a payment scam, speed is critical. Banks can help customers take immediate steps to protect their finances, such as securing accounts, changing credentials, monitoring for unauthorized activity, opening new accounts when appropriate, and implementing safeguards to prevent additional losses or exploitation. ABA encourages banks to direct victims to report cyber- enabled fraud to the FBI's Internet Crime Complaint Center (IC3). IC3 provides an important national reporting and intelligence function, and its Recovery Asset Team operates the Financial Fraud Kill Chain, which can work with financial institutions and law enforcement to freeze stolen funds. In 2025, the FBI initiated 3,900 Financial Fraud Kill Chain incidents involving approximately $1.16 billion in attempted theft and froze more than $679 million. The FBI itself emphasizes that victims should contact their financial institution immediately and report quickly to IC3 because timely transaction information can help freeze funds. The larger challenge, however, is ensuring that a report leads to action. IC3 received more than one million complaints in 2025, while the Financial Fraud Kill Chain was initiated in 3,900 incidents. Not every IC3 complaint involves a financial transaction appropriate for that process, but the disparity illustrates the scale of the challenge facing law enforcement. We should not measure success simply by how many victims we persuade to file another report. Law enforcement, particularly at the state and local levels, needs the specialized personnel, training, technology, and legal authorities necessary to act quickly when a victim reports a scam. That is why ABA has proposed the National Payment Fraud Crime Control Act, which would establish a Bureau of Justice Assistance grant program to help states create or strengthen Financial Crimes Intelligence Centers. These centers would serve as specialized hubs for investigating payment fraud, training state and local law enforcement, coordinating with financial institutions, and supporting recovery efforts. Texas provides a useful model for strengthening law enforcement's response to scams and fraud. In 2025, Texas expanded the mission of its Financial Crimes Intelligence Center from primarily card fraud to broader payment fraud and strengthened its ability to assist financial institutions and law enforcement. Texas also updated its asset-forfeiture laws to address digital currency, including allowing certain cryptocurrency forfeiture proceedings to occur where the law enforcement agency initiating the seizure is located and providing procedures for law enforcement to secure seized digital assets. Ultimately, the objective should not simply be to increase the number of reports. It should be to create a system in which the victim, the financial institutions involved, and law enforcement can act together at the speed of scam to stop the movement of funds, recover money when possible, and disrupt the criminal network behind the fraud. Question: What are some challenges that community banks or other financial institutions are facing due to the rising rate of senior financial exploitation? Response: Community banks face many of the same challenges as larger financial institutions as senior financial exploitation becomes more sophisticated and more prevalent. Banks must continually invest in fraud-detection technology, employee training, customer education, investigation, reporting, and funds recovery. For smaller institutions, those demands may fall on fewer specialized personnel, which makes free industry resources, shared services, and partnerships especially important. ABA and the ABA Foundation work to ensure that banks of all sizes have access to training and resources for recognizing and responding to elder financial exploitation. One of the most difficult challenges is intervention. In many scams, the customer is authorizing the transaction because the criminal has convinced the victim that the story is real. The customer may have been coached to conceal the purpose of the payment or to distrust the banker trying to help. A community banker may know that customer personally and recognize that something is wrong, which can be an important advantage. But even a trusted banker may have difficulty breaking the "scam spell" after a criminal has spent weeks or months establishing trust. ABA is expanding training specifically to help bankers intervene in these situations and support victims without shaming them. A related concern is the erosion of trust in the financial and online ecosystem. Criminals increasingly impersonate banks through spoofed telephone numbers, fraudulent websites, social media accounts, and other communications that appear legitimate. When a customer is deceived by someone convincingly posing as their bank, the harm extends beyond immediate financial loss. It can undermine confidence in legitimate bank communications, including the fraud alerts and outreach that banks use to protect customers. Over time, widespread impersonation threatens the trust that is particularly important to the relationship between community banks and the customers they serve. That is why banks cannot address rising senior exploitation alone. Banks will continue investing in technology, training employees, educating customers, and intervening when they identify warning signs. But reducing the burden on institutions of every size ultimately requires stopping more scams upstream, strengthening collaboration with and capacity among Adult Protective Services and law enforcement, improving information sharing, and ensuring that telecommunications providers, online platforms, and other parts of the ecosystem help prevent criminals from impersonating trusted institutions in the first place. U.S. Senate Special Committee on Aging "The AI Deception Machine: Deepfakes, Chatbots, and the New Frontier of Senior Fraud" July 29, 2026 Questions for the Record Matthew F. Ferraro Ranking Member Kirsten E. Gillibrand Question: The Trump Administration has accelerated federal adoption of AI. The Social Security Administration is one example - using AI for everything from customer-service chatbots to processing medical claims. The public can benefit when agencies modernize. But the government has to manage the risks that come with it, especially for vulnerable people like seniors. What should agencies like SSA do to make sure government AI helps Americans rather than putting them at risk? And, in your opinion, how do we draw oversight and governance lines between using AI to perform routine office tasks and deliver administrative efficiencies versus deploying non-humans to make benefit entitlement and appeal decisions? Response: I believe that a useful overarching maxim is that agencies should "adopt advisedly and govern aggressively. First, AI deployments should align with public organizations' missions. Deployments should be narrowly scoped to enhancing the agency's specific goals. Second, from the very beginning, organizations should consider how to make sure AI use is responsible and trustworthy and how to address potential risks to privacy, security, and safety. Third, agencies should measure progress with metrics and incorporate feedback from users, because one cannot understand or fix what one does not measure. I also point the Committee to a publication we produced when I served at the U.S. Department of Homeland Security, the "DHS Playbook for Public Sector Gen AI Deployment," (https:// www.dhs.gov/sites/default/files/2025-01/25--0106--ocio--dhs- playbook-for-public-sector-generative-artificial-intelligence- deployment-508-signed.pdf) which discusses these themes at length and provides actionable guidance. With regard to how we draw oversight and governance lines between AI performing routine tasks and making entitlement decisions: I believe that, at this stage in the technology's development, agencies should scope the application of AI tools appropriately given their limitations and the necessity to establish accountability for AI-related actions to a human, through what is known as "human-in-the-loop" governance. In short, AI-generated outputs should not be the sole basis for any agency's critical decisions or entitlement determinations." Question: Modern frauds and scams will often span multiple services, so no single organization is aware of the full scheme. Data sharing among private sector organizations, as well as law enforcement, can help prevent frauds and scams and disrupt the criminals who carry them out. Hower, the organizations that might share that information sometimes say that there is legal uncertainty over whether they are allowed to share. In your view, is there legal uncertainty regarding the ability of private sector actors to share information on frauds and scams? What are potential legal, regulatory, or compliance barriers to sharing that information? In your view, is there anything Congress should do to make it easier to share that information, or clarify existing legal authorities? If Congress seeks to do so, are there potential effects for business and consumers that we should take into consideration? Response: Private-public information sharing is governed by a web of disparate laws, rules, and guidances that vary by sector and information type. These varying laws and regulations include the Gramm-Leach-Bliley Act, the Cybersecurity Information Sharing Act of 2015 for cybersecurity threat information, regulations issued by the Financial Crimes Enforcement Network (FinCEN), and state-level privacy frameworks, among others. Legislation that codified liability protections for cross- institutional and cross-sector information sharing of suspected fraud indicators could help reassure industries that face various legal, regulatory, and compliance barriers. Question: Congress passed the Cybersecurity Information Sharing Act of 2015 (CISA) to encourage the voluntary sharing of cyber threat information. In your view, is the CISA framework a model Congress should consider for a framework for sharing data and intelligence related to frauds and scams? Why or why not? Response: The Cybersecurity Information Sharing Act of 2015 created a system for federal agencies to receive and share anonymized threat indicators from and with companies without concerns of running afoul of antitrust laws. I believe this Act was largely a success and could serve as a baseline for a framework for a national-fraud-and-scam data-sharing network. That law may point to a viable path forward in this circumstance. Its liability and antitrust protections, requirements to remove unrelated personal identifiable information, and clearinghouse system could help inform a framework that focuses on consumers and fraud." Question: Disrupting online frauds and scams requires taking that content off the internet. However, that requires cooperation with platforms, law enforcement, and registrars or other third parties. In your view, what are the most significant barriers to disrupting the actions of criminals who engage in online frauds and scams? Should Congress consider policy changes to enhance the ability to disrupt online fraudsters and scammers? If so, what should those policy changes look like, and how can they minimize unintended consequences for lawful content, consumers, and legitimate businesses? Response: A lack of coordination among government agencies at both the state and federal level-and with international partners-is a significant barrier to disrupting criminals who engage in online frauds and scams. Better coordination would allow these bodies to leverage to better effect existing laws that make these scams and fraud illegal already. These laws include (depending on the underlying activity) the Federal Trade Commission Act, the TAKE IT DOWN Act, the Telephone Consumer Protection Act, and laws prohibiting wire fraud (18 U.S.C. 1343), identity theft (18 U.S.C. 1028), and computer fraud (18 U.S.C. 1030), among others. The adage applies: if it is illegal without AI, it is illegal with AI. Furthermore, using deepfakes of trusted messengers to deceive victims is a broad, international phenomenon. For example, in 2024, a social media platform removed over 400,000 accounts originating in West Africa that fraudsters used to impersonate military personnel or businesspeople in an effort to scam individuals in Australia, Britain, Europe, the United States, and other locations. Also, in October 2024, Hong Kong police arrested over two dozen members of an alleged fraud ring that used deepfakes to trick victims in Taiwan, Singapore, India, and elsewhere in Asia into believing they were engaged in relationships. In light of these circumstances, Congress should consider policies that enhance coordination domestically and internationally to use existing laws to disrupt and degrade criminal fraudsters. [GRAPHICS NOT AVAILABLE IN TIFF FORMAT] ======================================================================= Statements for the Record ======================================================================= [GRAPHICS NOT AVAILABLE IN TIFF FORMAT] [all]