top of page

The Second Approach Is the Expensive One: The Rise of Recovery Room Scams

Writer: TrustSphere Network
TrustSphere Network
2 hours ago
8 min read

Every completed scam produces a second asset that the criminal can sell. Not the money, which is dispersed within hours, but the knowledge: a name, a telephone number, an amount, a date and the precise shape of how somebody was persuaded. Recovery room fraud is the monetisation of that knowledge. It is the approach made weeks or months after the original loss, by a person who offers to get the money back and who knows more about the fraud than the victim's own bank does.


The mechanics are unglamorous and highly repeatable. Victim lists, assembled by the original operation or lifted from a compromised platform, are traded between groups. A caller works the list presenting as a solicitor, an asset recovery specialist, a blockchain investigator, or an official of the very regulator the victim has already complained to. The proposition is always the same: your money has been traced, and a payment is required before it can be released. That payment is styled as a court fee, a retainer, a bond, a tax liability, an escrow deposit or, in the cryptoasset variant, an unlock fee for a wallet the victim can see on screen and cannot move.


What makes the typology worth separate treatment is that it is the only one in which the institution already holds the decisive piece of information before the second fraud begins. The bank knows the customer reported a loss. It knows roughly when, how much, and what kind of scam it was. An outbound payment from that customer in the weeks that follow is, on any honest reading of the base rates, the most suspicious payment on the book. Our argument here is that most firms do not use that fact, because the claim and the payment decision live in different systems owned by different teams, and that the point of maximum leverage is not the second payment at all. It is the first claim conversation.


Regulatory and Market Context


The perimeter is unusually messy, because the bodies being impersonated are real and mostly sit outside financial services. Claims management activity is a regulated activity supervised by the Financial Conduct Authority, and carrying it on without permission is an offence. Legal services are regulated separately by the Solicitors Regulation Authority and its equivalents, insolvency practitioners by their recognised professional bodies, and the Financial Ombudsman Service is free to consumers at every stage. Each of those facts is a detection rule in disguise: the FCA does not telephone consumers to offer restitution, the Ombudsman does not levy a fee, and a genuine solicitor does not ask a client to send money to a personal account. The FCA's warning list and its long running work on clone firms exist precisely because criminals have found impersonating a regulator easier than impersonating a bank.


Mandatory reimbursement has changed the economics of the second approach in a way the industry has not fully absorbed. The Payment Systems Regulator's requirement covers a defined perimeter: faster payments and CHAPS, up to a maximum level, subject to a consumer standard of caution. A great deal of scam loss sits outside it. Transfers into a victim's own cryptoasset wallet before onward dispersal, international payments, business losses and any excess above the maximum level all leave a residue of money that is never coming back. That residue is the recovery room's addressable market.


What the Data Is Showing


Across the recovery room casework TrustSphere reviewed for United Kingdom retail banking and payments clients during 2025, what stood out was not the sophistication of the approach but the speed with which it followed the first loss. In the files we examined, the interval between a customer reporting a scam and the first documented recovery approach usually fell inside three months, with a visible cluster in the weeks immediately after the customer had been told in writing that their claim would not be reimbursed. That timing is not accidental. The approach is calibrated to arrive at the moment the legitimate route has been exhausted.


The second loss was smaller than the first in almost every file, and considerably more likely to be repeated. A recovery room does not ask for one large payment; it asks for a sequence of modest ones, each justified by a fresh obstacle. In our sample the second fraud typically ran to three or more separate payments, and a meaningful minority of victims paid more in aggregate to the recovery operation than they had lost originally. The source of the money also changed. The first loss usually came from savings or an investment pot; the second came from credit, from pension drawdown, from family or from the sale of an asset, which is why the harm is frequently more severe even where the amount is lower.


The victim profile is narrow and should surprise nobody. Customers approached again were disproportionately older, more likely to be already flagged as vulnerable on the firm's own records, more likely to live alone and much more likely to have discussed the original fraud somewhere public, with several files showing the approach arriving shortly after such a post. Repeat victimisation is not random selection; it is targeted marketing against a list refreshed by victims themselves as well as by criminal trade.


The detection finding is the part of this work that most directly changes what a firm should do. Applying a deliberately crude rule retrospectively to client data, flagging any outbound payment to a new beneficiary from a customer who had logged a fraud claim in the preceding ninety days, the rule fired on a very small share of total payment volume and captured a materially higher proportion of subsequently confirmed recovery losses than the firms' production scam models did. In most of the institutions we worked with it could not be implemented, because the claim sat in a case management system with no real time feed into payment decisioning.


Implications for Financial Institutions


The first implication is that a fraud claim must become a customer level risk attribute with a defined life, visible to every outbound payment decision, rather than a case record sitting in an operations platform. The attribute needs three fields: that a loss was reported, the approximate date, and the broad typology. It does not need the amount or the counterparty, which keeps the data protection argument manageable. Ninety days is a defensible starting life and should then be tuned against outcomes. A firm that cannot do this should stop claiming it has a customer level view of risk, because the single most predictive attribute it owns is stranded.


The second implication is that the intervention which works happens at the first claim, not at the second payment. By the time the recovery payment is being made, the victim has been prepared by somebody who has spent hours building trust and who has explicitly told them the bank will try to stop this. The claim conversation is different: the customer is distressed, receptive and has not yet been contacted. That is the moment to say plainly that a second approach is likely, that it will reference details only a criminal could know, that no legitimate body charges a fee to return stolen money, and that the Ombudsman is free. It belongs in the claim acknowledgement letter as well, because the customer will not remember the call.


The third implication concerns warning content, which in most firms is written for the first fraud and is close to useless against the second. A generic message asking whether the customer has been contacted unexpectedly about an investment does not engage somebody who believes they are paying a court fee to a solicitor recovering their own money. Content that works names the scenario: that victim lists are bought and sold, that a caller knowing the details of your loss is evidence of criminality rather than legitimacy, and that no regulator telephones consumers about restitution.


The fourth implication is about how the second claim is assessed, and it is where firms are most likely to go wrong. There is an obvious temptation to treat a customer defrauded twice as having failed the consumer standard of caution, on the reasoning that they of all people should have known. That reasoning is weak. It ignores that the second approach is targeted precisely because the victim is known to be susceptible, that the psychological aftermath of a large loss is well documented as impairing judgement, and that the firm may itself have failed to warn. Vulnerability and Consumer Duty reasoning both point towards a cautious default and towards sampling these outcomes centrally rather than leaving them to individual assessors.


The fifth implication is that firms should take seriously the question of where the victim list came from. Some is criminal trade in data captured during the original fraud, some comes from breaches at platforms and exchanges where victims had registered, and some is volunteered publicly by victims. A proportion, in cases we have seen and in cases enforcement agencies have described, has come from inside institutions and their outsourced providers, where somebody with access to claim records sold them. Any firm holding a concentrated list of confirmed fraud victims is holding an asset with a criminal market price, and its access controls, logging and egress monitoring should reflect that.


Conclusion


Recovery room fraud is unusual in that the industry already holds everything it needs and declines to use it. There is no missing data asset here, no coordination problem with another sector and no gap in the law. The failure is architectural and organisational: the claim sits in one system, the payment decision in another, and the customer is warned at the moment the warning has least chance of landing.


Make the fraud claim a live risk attribute with a defined expiry. Rewrite the first claim conversation so that it inoculates rather than merely records. Write warning content that names the recovery scenario instead of gesturing at fraud in general. Assess the second claim on its facts rather than on an assumption of carelessness. None of that requires a vendor, a budget cycle or a change in regulation, which is exactly why a firm that has not done it will struggle to explain itself.


Suggested Next Steps


  • Create a customer level fraud claim attribute carrying the fact of a reported loss, its approximate date and its broad typology, feed it into outbound payment decisioning in real time, and set an initial ninety day life to be tuned against measured outcomes.


  • Rewrite the first claim conversation and the claim acknowledgement letter to warn explicitly about the recovery approach, naming the fake law firm, fake regulator, asset recovery agent and cryptoasset unlock fee variants, and record that the warning was given.


  • Run a retrospective count of customers who made an outbound payment to a new beneficiary within ninety days of logging a scam claim, confirm how many were recovery losses, and use that number rather than an industry estimate to build the business case.


  • Treat concentrated fraud claim and complaint data as a high value target, review access rights, logging and egress controls across internal teams and outsourced providers, and test whether an unauthorised export of a victim list would be detected.


Sources: Payment Systems Regulator mandatory reimbursement requirement for authorised push payment scams; Financial Conduct Authority financial crime guide, Consumer Duty, guidance on the fair treatment of vulnerable customers, warning list and published material on clone firm impersonation; Financial Ombudsman Service published decisions and guidance on scam complaints; Financial Services and Markets Act 2000 (Regulated Activities) Order provisions on claims management activity; Solicitors Regulation Authority warnings on firm impersonation; UK Finance fraud analysis and authorised push payment reporting; National Crime Agency and Action Fraud reporting on fraud recovery approaches; National Cyber Security Centre guidance on data exposure and social engineering; Global Anti-Scam Alliance research on repeat victimisation; INTERPOL and FBI Internet Crime Complaint Center advisories on advance fee and asset recovery fraud; TrustSphere Risk Index, April 2026.


Companion vendor assessment: today's TrustSphere Risk Index post assesses Arkose Labs against this problem. Read it at www.trustsphere.ai



TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai


 
 
 

Comments


Recommended by TrustSphere

© 2026 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page