A family office that has done the work on payment fraud already holds a verification rule, and it is the right one: when an instruction arrives, end the contact and call the person back on a number the office keeps in its own records. That rule works because the office knows the person and holds the number. It has nothing to say about a caller who presents as a police officer, a tax inspector, a consular official or a bank’s fraud desk, because the office holds no number of record for any of them, and the number it reaches for under pressure is the one the caller supplied or the one a search returned.

The remedy is not a better instinct but a short list, written down and kept current, so that the number exists before anyone needs it.

What the advisories establish

The FBI’s Internet Crime Complaint Center published an advisory on 17 September 2026 recording nearly 61,000 complaints of law enforcement and government impersonation between January 2025 and July 2026, with losses above $1.6 billion. Those are United States figures reported through a United States channel, and the mechanism is not confined to one country. Australia’s National Anti-Scam Centre recorded 481,523 scam reports in 2025, of which 274,577 involved a financial loss, for a combined A$2.18 billion, with phishing the most-reported category at 65,361 reports. Scamwatch, the Australian regulator’s consumer service, warns that scammers “claim that you owe money or that you are in trouble with authorities and threaten you with legal action or arrest” and warn that “the police will come to your door and arrest you if you do not pay the fee or fine straight away.”

The FBI states the rule it wants the public to hold: “Law enforcement and government authorities will never contact members of the public by telephone or text message to demand any form of payment or to request personal or sensitive information,” and officials “will never request payment via prepaid cards, cryptocurrency, or courier.”

No legitimate authority needs you to act during the call, so hang up and call back on a number you found yourself. That costs a real official nothing and ends the scam.

What makes an explicit rule necessary is the second finding. The actors “spoof authentic phone numbers, email addresses, employee names, and credentials,” so every surface a person would ordinarily read as confirmation belongs to the caller. The IC3’s page on impersonation of Chinese authorities puts it in one sentence worth reading to household staff verbatim: “Contact from an apparently official phone number is not proof of official action.” In that cross-border version the props go further, with criminals presenting “realistic-looking arrest warrants” and drawing on “basic knowledge of the victim to appear more legitimate.”

The tactic that defeats a family’s informal controls is not technical. The FBI records that these actors isolate victims from family and friends, which removes the one person who would have asked why a police force wants payment in cryptocurrency. An instruction to keep the matter confidential is not a feature of the situation the caller is describing; it is the finding.

Where the money is lost, and who loses it

The distribution inside the FBI’s figures is more useful to a family office than the total. Threats about missed jury duty produced 6,833 complaints and $36 million, an average of roughly $5,300. Threats of extradition made against foreign nationals and international students produced 1,809 complaints and $140 million, an average above $77,000. Volume and loss sit in different places, and the larger losses fall where the target has both means and a plausible reason to believe that a foreign authority has some hold over them. A family whose members hold more than one nationality, study abroad, or own property in a second country is in that second group by construction rather than by bad luck.

The authorities that can plausibly call you are knowable in advance

An advisory from March 2026 is the clearest demonstration of how a target is selected. Criminals impersonated city and county planning and zoning officials and emailed “individuals and businesses with active applications for land-use permits,” requesting fees by wire transfer, peer-to-peer payment or cryptocurrency. The emails carried accurate permit details and arrived from non-governmental domains. Nothing in the targets’ systems failed, and what made them reachable was a live application sitting in a public record, which told a stranger both whom to call and what to call about.

A family office manufactures that condition continuously, because every undertaking of any size creates a record somewhere. A renovation opens a permit file, a new residence a property tax account, a relocating family member a visa and a consular relationship, a foundation a charity registration, a new custodian an account whose fraud desk the family has never spoken to. Each is a public or semi-public fact that hands an impersonator a specific and checkable-sounding reason to make contact, and each is known to the office before it is known to anybody else.

That predictability is what makes a list possible, and the regulators point at the remedy without quite taking the last step. The FBI’s advice in the permit case is to “Call the city or county government, using the phone number listed on the official website, to verify outstanding fees,” and Scamwatch reaches the same place from the other side of the world, telling people to “verify their identity by calling the relevant organization directly.” Both assume someone can find the official number calmly. We recommend finding it in advance instead, because the FBI separately records criminals using search engine optimization poisoning that “promotes fraudulent advertisement links that mimic legitimate ones,” and a number retrieved from search results in the middle of a frightening call is not independent of the person who caused the fear.

The outside party the office is trained to obey

One authority calls the office routinely and is neither a regulator nor a bank. In most family offices the help desk belongs to a managed service provider, its technicians rotate, and they call from unrecognized numbers to ask people to approve prompts, read out codes or install software, and staff cooperate because cooperating is the job.

The joint advisory on Scattered Spider, published by CISA and the FBI with Canada’s RCMP and CCCS, Australia’s ACSC and AFP, and the United Kingdom’s NCSC, records the technique running in both directions. Actors have “Posed as company IT and/or helpdesk staff using phone calls or SMS messages to obtain credentials from employees and gain access to the network,” and they have “Posed as employees to convince IT and/or helpdesk staff to provide sensitive information, reset the employee’s password, and transfer the employee’s MFA to a device they control.” The second direction is the one that matters most in a family office, because the population the help desk serves includes family members and household staff the provider has never met and cannot recognize.

We recommend settling the identification convention with the provider in the contract rather than leaving it to habit: how the provider will identify itself, what it will never ask for by telephone, and how the office confirms an unexpected technician before anybody approves anything. Establish at the same time what the provider will require before it resets a credential or moves a second factor for someone claiming to be a family member.

What to build

  • Write the authority list. For every authority that could plausibly contact the family, record the organization, the jurisdiction and the number the office will call, taken from the official channel today. That means the tax authority in each country the family files in, the police force covering each residence, the consulate for each nationality held, the published fraud line for each bank and custodian, and the provider’s main switchboard. Refresh it whenever a project, a property or a relocation adds a counterparty.
  • Keep the rule short enough to survive pressure. Nobody in the office or the household acts on authority asserted over an inbound contact. The contact ends and the office calls back on a number from the list.
  • Name one person to call. Household staff and family members should not have to judge whether a caller is genuine. They should have one internal number and standing permission to use it for something that turns out to be nothing.
  • Extend the rule past money. Payment dominates the advisories because payment is measurable, but the same contact is used to obtain personal information, remote access to a device, or confirmation of where the family will be. Treat disclosing anything about the family as the same event as paying.
  • Tell the household that secrecy is the tell. A caller who instructs someone not to discuss the matter with family, staff or an advisor has identified themselves more reliably than any other signal in the call.
  • Cover the people the office does not employ. The rule reaches a principal’s personal phone, an elderly relative’s landline and a family member studying abroad only if somebody has had the conversation with them, and the office is the only party positioned to have it.

What to ask this week

If someone rang the office in an hour claiming to be a police officer, whose number would we call back, and where is it written down? Which of the family’s current activities are visible in a public record, and which authority does each of them make plausible? Has anyone told the household staff and the family members who are not on the payroll what the rule is? What has the IT provider agreed it will never ask for by telephone? And if a family member were told to keep a call confidential, who would they break that instruction to?

Answers are usually thin on a first pass, which is the ordinary result for a control that no contract assigns and no annual review reaches.

Where this sits

The payment half of this problem, meaning how to authorize a transfer so that a convincing impersonation of someone the office knows cannot succeed, is covered in wire transfer authorization controls. What happens once something has gone wrong is in the first 24 hours of a cyber incident. Deciding who holds the authority to set a rule like this and enforce it is one row in the wider accountability problem we work through in family office cybersecurity governance.

Writing the authority list, agreeing the identification convention with the provider and instructing the household is work we handle through cybersecurity program development. Keeping the list current as properties, projects and counterparties change is what ongoing advisory is for.

Sources

FBI Internet Crime Complaint Center, Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes, 17 September 2026

FBI Internet Crime Complaint Center, Chinese Authority Impersonation

FBI Internet Crime Complaint Center, Criminals Impersonating City and County Officials in Phishing Emails for Planning and Zoning Permits, 9 March 2026

FBI Internet Crime Complaint Center, Tech/Customer Support and Government Impersonation

FBI Internet Crime Complaint Center, Cyber Criminals Redirecting Users to Fraudulent Websites with Malicious Traffic Distribution Systems, 18 June 2026

CISA, FBI, RCMP, ASD’s ACSC, AFP, CCCS and NCSC-UK, Scattered Spider, Advisory AA23-320A, revised 29 July 2025

National Anti-Scam Centre, Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025, 30 March 2026

Scamwatch, Australian Competition and Consumer Commission, Threats and extortion scams