Harden Stance Briefing: Anti-Scam Learnings from GASS London 2025

Harden Stance Briefing: Anti-Scam Learnings from GASS London 2025
HardenStance’s April 2025 briefing from GASS London highlights a coordinated shift in anti-scam efforts, with governments, banks, telcos, and platforms taking greater responsibility for disrupting fraud and improving consumer protection. The report emphasizes stronger intelligence sharing, better regulation, more effective victim recovery, and a move away from blaming users as scammers adapt quickly to new defenses. #GASSLondon #GlobalSignalsExchange #FIRE #ScamSignalAPI #NCA #Meta #GSMA #FSISAC #NatWest #Lloyds #CIFAS #ACCC #InternationalBankingFederation

Keypoints

  • Annual cybersecurity and anti-scam reports typically begin with an executive summary or event overview, followed by key themes, major threats, notable trends, stakeholder perspectives, and practical takeaways for industry and government.
  • They often include a section on the current threat landscape, where authors summarize scam methods, fraud patterns, attacker behavior, and the scale of consumer and economic harm.
  • A dedicated findings section usually highlights the most important statistics, emerging operational models, regulatory developments, and examples of collaboration across sectors.
  • Many reports conclude with recommendations, future priorities, and references to related research, white papers, briefings, or upcoming events.
  • This briefing reports more than 700 in-person attendees and more than 750 online registrants, which the organizers described as the largest ever meeting of the global counter fraud community.
  • The central theme is that online fraud has reached a scale where politicians and regulators can no longer leave protection to industry alone and are increasingly assuming direct responsibility.
  • A recurring finding is that scam disruption depends on better intelligence sharing, with progress noted among the International Banking Federation, the Global Signals Exchange, Meta, GSMA, the UK National Crime Agency, and financial institutions.
  • The Global Signals Exchange was formally launched on January 1, 2025, as a cross-sector intelligence clearing house designed to aggregate threat data while respecting organizational sharing constraints.
  • Meta’s Fraud Intelligence Reciprocal Exchange pilot with UK banks was extended to FS-ISAC, showing growing adoption of structured fraud-intelligence collaboration.
  • The UK National Crime Agency’s partnership with NatWest, Lloyds, and other banks was described as the largest project of its kind worldwide for tackling criminal gangs and dirty money.
  • UK telcos and banks are collaborating through the Scam Signal API, enabling banks to use telecom customer information tied to fraud to improve transaction decisions.
  • The report argues that calls for “less” or “more” regulation miss the point; what is needed is better regulation that is effective, practical, and able to remove rules that hinder protection.
  • Stakeholders stressed that scam alerts alone are insufficient, especially if users are overloaded, and that anti-scam messaging should be simpler, better timed, and more targeted.
  • Several speakers emphasized that the burden should not be placed on victims, and that messaging should focus on criminals, not on what victims did or failed to do.
  • Another important trend is the need to move from awareness to real-time intervention, including device-level guidance at vulnerable moments and faster deployment of defenses against deepfakes and impersonation.
  • The report highlights instant payments as a fraud risk area, with the view that speed without friction can enable instant fraud and that banks and regulators must collaborate to introduce preventive controls.
  • Victim recovery is becoming a more prominent focus, with better data sharing proposed so victims only need to report an incident once rather than repeating their story across multiple organizations.
  • Across the briefing, the dominant takeaway is that effective anti-scam strategy now depends on collaboration, intelligence exchange, smarter regulation, quicker defensive deployment, and improved recovery for consumers.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github