Digital Crime Transformation
Parasites on Trust: Cross-Border Industrial Coercion and the Misallocation of Liability in British Banking
British bank phone scams are misclassified as a consumer protection problem. This paper argues they constitute cross-border industrial coercion — and that the £173 million annual reimbursement figure is the price of that misclassification.
R. Khimich and A. Turkhanov — Working Paper, May 2026
Keywords: authorised push payment fraud, industrial coercion, trust architecture, hybrid aggression, liability misallocation, infrastructure convertibility, violence-as-a-service, UK banking regulation
Abstract
British bank phone scams are routinely analysed as a consumer protection problem and regulated accordingly. This paper argues that framing is structurally incorrect. The industrialised call-centre infrastructure that targets UK retail banking customers constitutes a form of cross-border coercive operation — in the taxonomy developed by Khimich (2021, 2026a, 2026b), a class of adversarial activity whose structural logic, jurisdictional design, and convertibility to non-financial ends place it categorically outside the reach of administrative remedy.
Applying the trust architecture framework developed by Churilov and Khimich, the paper maps how bank impersonation attacks disable each layer of the legitimate trust relationship between an institution and its customer. It then applies the Mitigation–Deterrence–Suppression typology (Khimich, 2026b) to the UK banking context, demonstrating that current policy operates almost exclusively within the Mitigation tier.
The Payment Systems Regulator’s mandatory authorised push payment reimbursement regime — which returned £173 million to victims in its first year of operation — is not identified as evidence of successful management but rather as a quantification of the minimum annual cost of misclassifying the problem.
The paper examines convertibility — the capacity of financial coercion infrastructure to be redirected to non-financial ends — through two scenarios at different stages of the same structural trajectory. The Sweden scenario demonstrates that commoditised coercive infrastructure operating in developed legal environments is available for opportunistic use by state actors without structural modification. Russia is examined as the escalated case: a jurisdiction in which a hostile state has progressed beyond opportunistic use to active development and protection of coercive infrastructure.
The paper closes by arguing that the state, not the financial sector, must bear the primary institutional responsibility for a threat that is political in origin, cross-jurisdictional in character, and national-security in its implications.
1. Introduction
In its first year of operation under the Payment Systems Regulator’s mandatory reimbursement regime, the United Kingdom’s banking sector returned £173 million to victims of authorised push payment (APP) fraud — a reimbursement rate of 88 per cent. The figure is cited as evidence of a well-functioning consumer protection system. This paper argues that it should be read differently: as a precise, empirically grounded measure of the minimum annual cost of a fundamental misclassification.
The misclassification is this. Industrialised bank impersonation fraud — the call-centre operations that persuade UK retail banking customers to transfer funds to accounts controlled by criminals — is routinely treated as a consumer protection problem, managed through financial regulation and customer education. This paper argues it is a form of cross-border coercive aggression, conducted through industrialised infrastructure operating under jurisdictional and epistemic cover, with structural characteristics that place it categorically beyond the reach of the administrative tools currently deployed against it.
The argument proceeds in five stages. Section 2 establishes the distinction between ordinary financial crime and industrialised coercive operations, and shows that UK phone fraud belongs to the latter category. Section 3 applies the trust architecture framework to map how bank impersonation attacks disable legitimate trust. Section 4 examines Russia as the primary diagnostic and prognostic case. Section 5 analyses the structural misallocation of liability embedded in the current UK regulatory framework. Section 6 applies the Mitigation–Deterrence–Suppression typology to the UK banking context. Section 7 concludes.
2. The Misdescription: From Scam Industry to Industrial Coercion Market
2.1 The Definitional Problem
The standard regulatory vocabulary treats UK phone fraud as an escalating form of financial crime. UK Finance describes a fraud landscape in which criminals stole £1.17 billion in 2024 across authorised and unauthorised channels, with banks preventing a further £1.45 billion. The vocabulary is that of loss prevention, consumer protection, and fraud management. This is appropriate for a category of harm that is criminal, domestic, and bounded. It is not appropriate for what UK bank phone fraud has become.
The analytical shift required was introduced by Khimich (2021) in an early formulation that identified the structural transition from opportunistic fraud to industrialised operation. The key observation was not simply that fraud had grown in scale. It was that it had undergone a qualitative transformation: it was now produced by infrastructure.
Khimich (2026a) extended this analysis to identify what he termed the architecture of remote violence — the structural features that distinguish industrialised coercive operations from conventional crime: purpose-built operational facilities, modular organisational design, specialist division of labour, financial management disciplines, and jurisdictional engineering — the deliberate placement of operational capacity in territories where enforcement cooperation is unavailable, unreliable, or actively obstructed.
2.2 The British Case as Industrial Coercion
These structural characteristics are fully present in the operations that target UK retail banking customers through voice channels. The operations exhibit industrial-scale output: bank and police impersonation scams accounted for £27.1 million in losses in the first half of 2025 alone, representing 11 per cent of all APP scam losses. They exhibit operational modularity: targeting, social engineering, authentication extraction, and money movement are organisationally separated. They exhibit jurisdictional engineering: the operational centres are not located in the United Kingdom, and the principal protection of their operators is not technical but territorial.
The critical point for regulatory analysis: industrialised coercive infrastructure is characterised by rapid adaptability and jurisdictional mobility. Enforcement pressure at one node reliably displaces operations rather than eliminating them. The infrastructure survives because its design anticipates exactly the category of response that the current UK regulatory framework provides — Mitigation at the receiving end, Deterrence against individual operators who are replaced as fast as they are removed.
2.3 The Statutory Mismatch
The Payment Systems Regulator’s mandatory APP reimbursement framework (PSR PS25/5, effective October 2024) requires participating payment service providers to reimburse victims of qualifying APP fraud up to a cap of £85,000 per claim, with liability split equally between the sending and receiving PSP. The regime is designed on the assumption that financial institutions are the most efficient loss-bearers because they are best placed to prevent the harm.
That assumption is sound for unauthorised fraud, where the bank controls authentication and payment execution. For APP fraud driven by industrial coercion operations, it is not. The bank does not control the attack surface. It controls only the payment interface — the final step in a multi-stage operation conducted largely beyond its visibility or jurisdiction.
3. Trust Architecture as the Attack Surface
3.1 The Framework
Trust, in the Churilov–Khimich framework, is an assumption about another agent’s expected behaviour incorporated into the trustor’s plan for a dependent activity. A trust architecture is the ensemble of elements that make a particular trust relationship warranted: identity signals, authority signals, evidence mechanisms, guarantee structures, and dispute resolution. Each of these elements can be degraded, spoofed, or disabled. When they are systematically disabled, the trust architecture fails — not because the trustor acted irrationally, but because the rational basis for their reliance is removed.
3.2 The Anatomy of the Voice-Channel Attack
A British bank impersonation phone scam is not a trick played on a credulous victim. It is an adversarial operation that systematically disables, layer by layer, the institutional signals that would otherwise allow a customer to identify the approach as fraudulent.
| Layer | Legitimate function | Adversarial mechanism | Partial repair |
|---|---|---|---|
| Caller identity | Phone number indicates likely caller | Number spoofing replaces the originating number | Ofcom call-blocking (2025) |
| Institutional authority | The bank or the police have protective power | Impersonator claims that power | None structural |
| Authentication | OTP or security questions verify the customer | Attacker extracts authentication signals | None structural |
| Payment warnings | Friction flags anomalous transactions | Trusted interlocutor interprets warnings as routine | Confirmation of Payee (partial) |
| Receiving account | Payment reaches the intended beneficiary | Mule account intercepts funds | CoP name-matching (partial) |
| Evidentiary record | Post-hoc review establishes facts | Call-origin data not preserved or available | None |
Table 1. Trust architecture layers and adversarial mechanisms in UK bank impersonation fraud.
The attack begins at the identity layer. The caller displays a number matching the bank’s official contact number. At the authority level, the attacker claims to be acting in the victim’s best interests — positioning the bank or police as having detected fraud. This weaponises institutional authority: the victim is not being asked to defy a trusted institution but to comply with one.
3.3 The Evidentiary Deficit
The current UK voice-channel trust architecture generates almost no useful evidence at the layer where attribution matters most — the telecoms layer. Call records establishing the true origin of the attacking call are not routinely preserved, are not accessible to victims, and are not incorporated into reimbursement adjudications. The result is that the evidentiary asymmetry between the attacker and the victim persists into the dispute-resolution process.
This is not an accidental gap. It is a structural feature of a system in which telecoms and financial infrastructure were designed for different purposes by different regulatory bodies, with no requirement to produce a jointly adequate evidentiary record for the category of harm that now most commonly occurs at their intersection.
4. The Sweden Scenario: Convertibility in Developed Legal Environments
4.1 Structural Characteristics
The convertibility of coercive infrastructure is not confined to jurisdictions with a weak rule of law or active interstate conflict. A structurally analogous pattern has emerged across Scandinavian and Northern European states — most extensively documented in Sweden and Denmark. The infrastructure consists of decentralised criminal gang networks that have undergone a specific technological transition: the digitisation of recruitment, task assignment, and payment. Assignments ranging from surveillance and drug transport to arson and contract killing are posted as standardised offers on digital platforms, including open social media and encrypted messaging applications.
4.2 The Commoditisation of Minor Executors
Judicial and investigative materials document that minors in Sweden have been recruited for violent assignments — including attempted and completed killings — at sums comparable to low-skilled gig-economy labour. In at least one documented instance, the sum paid to the executor fell at or below the black-market acquisition cost of the weapon deployed. On the floor of this market, the executor costs less than the instrument.
This is the pricing signature of commoditisation: a standardised service, available at a discoverable price, with elastic supply that accommodates new demand without structural modification. A resource-endowed actor seeking coercive capacity in this environment faces no meaningful procurement barrier.
One qualification is analytically necessary. The term “market” applies to the product — standardised violent assignments at posted prices — not to the labour relation between recruiter and executor. The minor executor is not a contracting party with exit rights; the market logic operates entirely on the demand side. The executor is a consumable, not a counterparty.
4.3 Documented Convertibility: The Iran–Foxtrot Case
The transition from criminal-commercial to politically motivated violence within this infrastructure has been documented in at least one case meeting prosecutor-level evidentiary standards. In September 2025, five minors participated in an attempted assassination of an Iranian dissident in Malmö; judicial proceedings against them commenced in April 2026. The Swedish Security Service (SÄPO) confirmed that foreign states, including Iran, have used Swedish criminal gang networks and recruited children for attacks against Israeli and Iranian opposition targets in Europe; the UK government imposed sanctions on the Foxtrot network and its leadership in April 2025 for violence against Jewish and Israeli targets “on behalf of the Iranian regime.”
The case is cited here as documented behavioural convertibility, not as closed attribution.
4.4 Distinguishing Features
The Sweden scenario differs from the escalated Russian case in two respects material to policy analysis.
First, the state actors making opportunistic use of this infrastructure are customers, not developers. The infrastructure was not built for their purposes, is not sustained by their resources, and does not depend on their political protection.
Second, the Sweden scenario operates within functioning legal environments. This creates both a constraint and an opportunity: the same legal environment provides the doctrinal basis for reclassification and the Suppression-tier responses that are structurally unavailable in conflict-zone operational geographies.
5. Russia as Escalated Case
5.1 The Logic of Escalation
Russia represents the advanced form of the convertibility trajectory whose early stages the Sweden scenario makes visible. In the Sweden scenario, state actors are opportunistic customers of a pre-existing criminal market. The Russian case presents a qualitatively different configuration: coercive infrastructure operating under conditions of active interstate conflict in which the host jurisdiction had both the political interest and the operational incentive to develop, protect, and direct the infrastructure.
Two features define the escalated case analytically. First, the hostile state functions not as a customer but as a developer and protector: providing territorial sanctuary, absorbing enforcement pressure, and directing operational priorities. Second, the conflict context removes the residual constraint that limits Sweden-scenario convertibility — namely, that the criminal infrastructure has its own commercial logic that state actors must accommodate.
5.2 The Financial Phase
Available evidence consistently identified Ukraine as the primary operational geography for the coercive infrastructure targeting Russian citizens: by 2022, Sberbank estimated that up to 90 per cent of fraudulent calls reaching Russian citizens originated from Ukrainian territory. The infrastructure — call centres conducting bank impersonation, investment fraud, and extortion — operated from Ukrainian territory, exploiting the regulatory and enforcement gap created by the conflict between the two states.
The Russian response was Mitigation through domestic financial and telecoms regulation: mandatory payment-return mechanisms, call-blocking by network operators, and public awareness campaigns. It was directed at the consumer-bank interface and at individual operators. It was not directed at the infrastructure itself, which was beyond its jurisdictional reach.
5.3 The Convertibility Threshold
The analytically critical development is the emergence of three independent evidentiary layers, each establishing a distinct dimension of infrastructure convertibility.
The technical layer. In December 2024, the Investigative Committee of the Russian Federation published materials on a prevented attack against the director of a defence enterprise, in which detained individuals were identified as operators of SIM-box networks used simultaneously for mass fraud calls, false terrorist alerts, and sabotage communications logistics. The same physical infrastructure served all three functions without structural modification.
The operational-chain layer. From mid-2023 onwards, documented cases established the complete manipulation sequence: standard bank-impersonation call → funds transferred to “safe account” → threat of criminal prosecution → assignment of a physical task — damaging power infrastructure, railway relay cabinets, restricted facilities. An independent investigation by Mediazona documented 187 arson attacks on military enlistment offices and other targets organised through telephone fraud channels since the start of the full-scale invasion.
The infrastructure-origin layer. Investigative reporting from Dnipro city found that by 2021, work in criminal call centres was one of the most common forms of employment for local youth, with hundreds of operations employing several thousand operators. Subsequent analysis documented job advertisements openly soliciting recruits on the grounds that targeting Russian citizens constituted a form of economic warfare. The same city and, in several documented instances, overlapping organisational networks subsequently became the operational base for intelligence-directed recruitment of Russian citizens for sabotage operations. The transition required no new infrastructure. It required new instructions delivered through an existing apparatus.
What the three layers establish in combination is not that the financial coercion infrastructure was converted at a specific moment. It is that such infrastructure does not require conversion — it operates across financial extraction, psychological manipulation, and kinetic task assignment interchangeably. This is the concept of infrastructure convertibility, made empirically concrete across three independent source traditions.
5.4 Implications for the United Kingdom
The United Kingdom is not Russia. The geopolitical context, the bilateral relationship with the primary source jurisdictions, and the current state of development of the relevant infrastructure differ. The UK is at the financial coercion phase. The convertibility threshold has not been crossed.
But three observations from the Russian experience carry directly:
First, Mitigation measures that raise costs at the consumer-bank interface are absorbed by the industrial supply chain as a cost-of-goods increase, not through reduced capacity.
Second, the convertibility of the infrastructure means that the state’s interest in disrupting it is not merely a consumer protection interest. The infrastructure represents a latent capability available to hostile states.
Third, the temporal window for effective policy intervention narrows as the infrastructure matures. The policy window is open. It will not remain so indefinitely.
6. The Liability Misallocation
6.1 The Structural Argument
The PSR’s mandatory APP reimbursement regime rests on a defensible premise: that financial institutions bear responsibility for ensuring payment is made to the intended beneficiary. This premise is sound for unauthorised fraud. It is not sound for APP fraud driven by industrialised cross-border coercive operations. The bank did not fail. The fraud warnings were displayed. The problem lies not in any failure of the bank’s systems but in the destruction of the epistemic conditions under which a rational customer could have recognised the instruction as fraudulent — a destruction carried out by an adversarial infrastructure operating beyond the bank’s visibility and jurisdiction.
6.2 The Terrorist Attack Analogy
Requiring financial institutions to reimburse victims of phone fraud losses caused by state-organised or state-tolerated coercive infrastructure is structurally equivalent to requiring property developers or building owners to compensate victims of a terrorist attack on the grounds that better physical security might have reduced harm.
In the case of a terrorist attack, we do not say that building security is irrelevant. We say that the building owner is not the responsible agent — the attacker is — and that the correct institutional response identifies the attacker and applies state power against them. We do not redesign building codes as the primary counter-terrorism measure.
6.3 The Incentive Consequence
The liability misallocation has a direct incentive consequence. Financial institutions facing mandatory reimbursement liability invest in measures to reduce their liability exposure — all legitimate Mitigation measures. They generate no reduction in adversarial capacity.
Suppression — the active disruption of coercive infrastructure operating in foreign jurisdictions — is not an investment decision that any private or regulatory actor can make. It requires the exercise of sovereign authority: intelligence mandates, cross-border operational capacity, and the political will to act against infrastructure that hostile states tolerate or protect. No financial institution holds that mandate. No financial regulator can confer it.
7. A Restructured Policy Framework
7.1 The Typology Applied
Khimich (2026b) proposes a three-tier typology for state responses to industrialised cross-border coercive infrastructure:
| Strategy | Current UK manifestation | Structural limit |
|---|---|---|
| Mitigation | PSR reimbursement regime; Ofcom call-blocking; 159 infrastructure; CoP; payment warnings | Does not address source infrastructure; absorbed as cost-of-goods |
| Deterrence | NCA operations against mule networks; some bilateral law enforcement cooperation | Infrastructure is modular and jurisdictionally mobile; individual operator removal does not reduce capacity |
| Suppression | No current framework or mandate | Absent: requires doctrinal reclassification of the problem as national security |
Table 2. Mitigation–Deterrence–Suppression typology applied to the UK banking context.
The current UK policy framework is almost entirely Mitigation, with a weak and poorly coordinated Deterrence element and no Suppression capability targeting cross-border coercive infrastructure.
7.2 What a Restructured Framework Requires
At the Mitigation tier: The PSR’s reimbursement requirement should be retained as a consumer protection measure. Its liability structure, however, should be revised to distinguish between losses attributable to institutional failure — where bank liability is appropriate — and losses attributable to cross-border coercive operations — where state co-liability is appropriate. The evidentiary gap at the telecoms layer should be addressed as a regulatory priority: network operators should be required to preserve the metadata necessary to establish call origin, transit infrastructure, and pattern signatures consistent with known coercive operations.
At the Deterrence tier: The primary barrier is institutional fragmentation among financial regulation, telecoms regulation, and law enforcement. A joint operational centre — analogous to the Joint Money Laundering Intelligence Taskforce but with a broader cross-sector mandate — would partially address this fragmentation. The political attribution of coercive operations to state actors is an underused Deterrence instrument: where it can be established, it should be communicated publicly and used as the basis for diplomatic, economic, and legal countermeasures.
At the Suppression tier: The United Kingdom currently lacks both the doctrinal framework and the institutional mandate to suppress cross-border coercive infrastructure. Developing both is the primary long-term policy requirement. Counter-narcotics frameworks established that operations targeting a state’s population from foreign territory constitute a threat to national security, regardless of where those operations occur. The structural parallel to industrialised cross-border coercive infrastructure is direct. Doctrinal reclassification along these lines would not resolve the operational challenges of Suppression — it would establish the legal and political foundation without which those challenges cannot be formally addressed.
7.3 The Specific Role of Financial Institutions
Reclaiming the primary state role does not eliminate the role of financial institutions; it clarifies and constrains it. Banks and payment service providers have three specific contributions:
First, they are best placed to generate and preserve the evidentiary record of the customer-facing attack. Standardising the preservation and availability of this record — for both reimbursement adjudication and law enforcement use — is a natural extension of existing compliance infrastructure.
Second, financial institutions collectively hold pattern data about money movement through mule account chains that, if shared systematically and in near real time, would substantially improve the speed and accuracy of Deterrence operations.
Third, financial institutions with significant market presence have the standing and the interest to advocate for the political reclassification of the problem. The £173 million figure is a compelling opening for that conversation.
8. Conclusion
The argument of this paper can be stated in five propositions.
First, British bank phone scams are a form of industrial coercion conducted through cross-border infrastructure, not an elevated variant of domestic fraud. The distinction is not semantic. It determines which interventions have leverage over the problem.
Second, the trust architecture through which these attacks operate is systematically disabled by the adversarial operation rather than simply exploited. The victim’s rational reliance on institutional signals is the mechanism of the attack.
Third, convertibility — the capacity of financial coercion infrastructure to be redirected to qualitatively different ends without structural modification — is a general property of mature coercive infrastructure. The Sweden scenario demonstrates this in developed legal environments. The commoditisation of minor executors — at price points falling at or below the cost of the weapon deployed — is the signature of infrastructural maturity and the mechanism that makes opportunistic state engagement structurally straightforward.
Fourth, Russia is the prognostic case, not merely a parallel example. It represents the escalated form of the trajectory: a configuration in which a hostile state has moved from opportunistic customer to active developer and protector of coercive infrastructure. The documented conversion of financial coercion capacity to kinetic operations demonstrates where the trajectory leads.
Fifth, the liability misallocation embedded in the current regulatory framework — requiring financial institutions to bear the primary cost of a state-level threat — systematically under-invests in Deterrence and Suppression while over-investing in Mitigation measures that reduce individual harm without engaging the infrastructure responsible for it.
The corrective is not the abolition of consumer protection. It is the recognition that consumer protection is a Mitigation instrument, and that Mitigation, however well-designed, is structurally insufficient against industrialised, cross-border, coercive infrastructure operating under jurisdictional cover. The state must assume the primary institutional role in Deterrence and Suppression. Financial institutions, telecoms operators, and regulators must function as partners in that effort rather than as substitute respondents in the state’s absence.
The £173 million is not the price of a well-functioning system. It is the price of a misclassification.
References
HM Government. (2025). Fraud Sector Charter: Telecommunications. London: DSIT / Home Office.
GI-TOC (2026). Scammers’ Paradise? Assessing Scam Centres in Eurasia. Geneva: GI-TOC.
Khimich, R. (2021). Theses on Personal Safety in the Digital Realm.
Khimich, R. (2026a). The Digital Transit of Coercion: Industrialization, Distribution, and the Emerging Architecture of Remote Violence. Working Paper. https://doi.org/10.5281/zenodo.20023495
Khimich, R. (2026b). Mitigation, Deterrence, Suppression: A Policy Typology for Industrialized Cross-Border Coercion. Working Paper. https://doi.org/10.5281/zenodo.20023938
Mediazona. (2025, January 16). In Russia, phone scammers talk people into setting military enlistment offices on fire.
Payment Systems Regulator. (2025). APP Scams Reimbursement Requirement: Consolidated Policy Statement (PS25/5). London: PSR.
UK Finance. (2025). Fraud Report 2025. London: UK Finance.