Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Scam Victims Are Being Targeted Again. Here Is How the Repeat Cycle Works.

If You Got Scammed Once, Someone May Already Be Planning Round Two
The Federal Trade Commission has been warning fraud victims about a specific follow-up play: callers and texters posing as FTC agents, claiming they can recover stolen money, and sending photos of fake agency badges to look credible. The targets share one thing in common. Each had already lost money to a prior scam.
This is a business model.
How the Lists Work
According to the FTC, criminal networks maintain what are called "sucker lists." These documents record a victim's name, address, phone number, the type of scam they fell for, and how much they paid. The lists are bought and sold between fraud operations because past victims are considered higher-probability targets. Someone who paid once may pay again, especially if the new pitch references the original loss.
A caller who already knows you lost $4,200 to a fake tech support scheme three months ago sounds a lot more credible than a cold-contact scammer working from nothing.
The Recovery Scam Structure
The FTC describes the follow-up scheme in straightforward terms. The fraudster contacts the victim, demonstrates knowledge of the original incident, and offers to recover the lost funds. Then comes the ask: a retainer fee, a processing charge, or bank account details needed to "facilitate the transfer."
The FBI's Internet Crime Complaint Center flagged a parallel version targeting cryptocurrency scam victims. According to the FBI, fictitious law firms have been approaching people who lost money in crypto fraud, offering legal recovery services in exchange for upfront fees. The FBI notes these schemes exploit the financial and emotional strain that follows a real loss.
Neither agency has recovered funds for victims through unsolicited outreach. If someone contacts you claiming to be the FTC and asks for money or personal information, that is the scam.
The Social Security Number Problem
One reason the repeat-targeting cycle is so durable: some stolen information cannot be canceled.
A bank can issue a new card number within days. A Social Security number is a different problem. The Social Security Administration assigns replacement numbers only in limited circumstances and generally requires an in-person appointment. That means a thief who obtained your SSN, birth date, and address in the first incident still holds usable credentials long after the original fraudulent account gets closed.
The Identity Theft Resource Center's 2026 Trends in Identity Report found that 25.6% of identity crime victims were managing two or more incidents simultaneously. The same report found that 62.1% of attempted identity misuse cases involved new account applications, meaning stolen identity data is most commonly being used to open credit lines, not just drain existing ones.
The Fair Counterargument
Some consumer advocates push back on the way this problem is framed, arguing that focusing on victim behavior, why people fall for recovery scams, why they were on a list in the first place, places disproportionate responsibility on individuals rather than on the institutions that stored and then lost their data. Data breaches at companies, healthcare providers, and government agencies regularly expose Social Security numbers and personal details that consumers never knowingly handed to anyone. Victims of a hospital data breach, for instance, had no choice in the matter. Blaming repeat victimization entirely on individual behavior ignores structural exposure.
The FTC's own data supports both points: people who are targeted repeatedly often face compounding vulnerability from multiple sources, not just their own prior scam interactions.
What Actually Limits the Risk
Freezing your credit with all three major bureaus, Equifax, Experian, and TransUnion, prevents new account applications using your SSN without a lift. It does not cost anything under federal law. The FTC recommends it as the single most effective step after an identity theft incident.
The FTC also maintains IdentityTheft.gov, which walks victims through a personalized recovery plan and, critically, does NOT solicit fees or personal financial information as part of that process. Any outreach claiming to be from the FTC that asks for payment is fraudulent.
For people who have already been targeted once, the Identity Theft Resource Center raises an unresolved question in its 2026 report: as long as SSNs remain the primary verification mechanism for financial accounts in the United States, the repeat-victimization window stays open indefinitely after a single breach. Whether Congress addresses that through a national digital identity framework or some other mechanism remains an open policy question with no scheduled answer.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.