Why Every Scam Makes Honest Life More Expensive
You log into your bank account.
Enter your password. Enter a one-time code. Approve the login on your phone. Verify the device. Solve a CAPTCHA. Get a fraud alert for a purchase you actually made. Re-enter your credentials after the session times out.
None of these steps create value. They exist because somewhere, at some point, someone tried to cheat the system, and now everyone pays for it.
Economists have a name for the idea underneath this, even if not for the tax itself: trust reduces transaction costs. When two parties trust each other, they spend less time verifying identities, less money enforcing contracts, and less energy guarding against deception. When trust declines, those costs don’t disappear. They spread across the economy, quietly enough that hardly anyone can point to where they went. Call the result the Trust Tax, a hidden levy nobody voted for, showing up in every extra form, every verification step, every markup on every price.
Trust used to be cheaper
It’s easy to forget how recently a handshake was often enough.
Cash changed hands with no questions asked. A signature on a cheque was treated as good faith. Small businesses extended credit to regulars without running a check. Calling customer support meant talking to a person who solved your problem, not one who interrogated your identity first. Renting an apartment could mean a conversation and a deposit, not a credit report and three references. Boarding a flight decades ago meant walking up with a ticket, not surrendering your shoes and your water bottle.
None of this was because people were more honest then. The cost of being wrong was still manageable, and institutions hadn’t yet been forced to defend against fraud at scale.
Fraud became industrialized
That changed as scams stopped being isolated incidents and became scalable businesses: identity theft, fake investment schemes, invoice fraud aimed at finance departments, romance scams unfolding over months, cloned voices impersonating executives, fake job listings built to harvest personal data.
How large this has become depends on who you ask. Cybersecurity Ventures, the source behind the number that gets repeated everywhere, projected the global cost of cybercrime would reach $10.5 trillion by 2025, and now projects it will climb to $12.2 trillion by 2031. Other researchers, using narrower methodology focused on measurable direct losses, put the real number closer to $1.2 to $1.5 trillion, an order of magnitude apart. Either way: this is an industry now, with its own tooling and its own return on investment.
It’s not just digital
The pattern isn’t confined to logins and passwords. Retailers lock up ordinary items and check receipts at the exit, a response to theft that Capital One Shopping’s research puts at roughly $47.8 billion a year in the US in shoplifting alone for 2025. Treat that figure cautiously: Capital One Shopping is a data aggregator rather than a primary research body, its own year-to-year figures for this same statistic have varied dramatically, and the National Retail Federation’s underlying 32-year shrink report, which much of this data traces back to, was discontinued in 2024 over its own methodology concerns. The direction of the trend is probably real. The precision of the number isn’t. Employers run background checks and drug tests that would have seemed excessive a generation ago. Landlords pull credit reports and hire tenant-screening services before handing over a key. Airports run security lines that address both fraud and other threats at once. Even classrooms have picked up the habit, with exam proctoring software and plagiarism detection standing in for the trust a teacher once extended by default.
The three hidden costs
Money is the most visible one: compliance departments, fraud investigation teams, identity verification vendors, insurance premiums, chargeback losses, and audits all add to operating costs that eventually show up in the price of ordinary things. Time is less visible but just as real, the hours people spend recovering hacked accounts, resetting forgotten passwords, waiting on hold, replacing compromised cards. Privacy is the strangest cost of the three, because it runs backward: to prove you’re trustworthy, you now hand over face scans, fingerprints, location data, and government ID numbers. IBM’s annual Cost of a Data Breach research, a named source, though vendor-produced like the AML figures below, put the average cost of a single breach at $4.44 million in 2025, down slightly from $4.88 million the year before, consistent enough over time to suggest the systems built to protect you have also become one of the more expensive ways to expose you.
Retailers, employers, landlords, airports, schools, and now the companies holding your data are all doing versions of the same thing, at the same time, without any of them consulting each other. That raises an obvious question: how did checkpoints this expensive and this widespread end up everywhere at once?
Institutions respond, and it compounds
Every time a scam succeeds, an institution somewhere adds a checkpoint so it can’t happen the same way twice. Banks add one-time passwords, device verification, biometric logins, transaction limits. Governments add know-your-customer rules and digital ID systems. Businesses add email verification, document uploads, account reviews.
Anti-money-laundering compliance shows how large and how murky these costs get. A recurring survey by LexisNexis Risk Solutions and Forrester Consulting found U.S. and Canadian financial institutions alone spent $61 billion on financial crime compliance in 2024. Vendor-produced global estimates run considerably higher, toward $275 billion, though those come from companies selling compliance software and should be read as an upper bound rather than a consensus figure.
Nobody is coordinating any of it. A bank doesn’t consult an airline before adding a new verification step. But once fraud losses become large enough, institutions tend to independently reach the same conclusion, that prevention is cheaper than continuing to absorb the losses. Because they’re all solving roughly the same cost equation, they move in the same direction at once, without anyone planning it that way. What looks like a coordinated tightening of the world is really thousands of separate, uncoordinated decisions that happen to point the same way.
Looked at individually, each step is trivial. A CAPTCHA costs five seconds. An OTP costs ten. But nobody experiences just one, and multiplied across every login, every year, across an entire population, the hours add up fast.
The loop that never runs backward
Run the sequence forward: scams succeed, institutions lose money, they add verification, transactions slow down, costs rise for everyone including honest customers, companies pass those costs on in higher prices, scammers adapt to the new defenses within weeks, and the cycle repeats.
The more interesting question is why it never runs in reverse. Removing a verification layer creates visible risk, a fraud wave, a headline, a regulator’s question. Keeping it creates only invisible inconvenience, spread thin across millions of people who will each individually shrug and comply anyway. Given that asymmetry, institutions have every reason to keep adding steps and almost none to remove one.
There’s also a simpler reason the honest majority ends up carrying most of this cost: scammers move faster than institutions do. A verification step that costs a legitimate customer ten minutes might cost a determined fraud operation only a minor adjustment to a script. The people the checkpoint was built to catch adapt to it almost immediately. The people it wasn’t built for are stuck with it indefinitely.
Trust debt
That distinction points to something worth separating out on its own. Everything above describes a flow, a cost paid per transaction, per login, per checkpoint. But because so few of these checkpoints are ever retired, a second thing accumulates alongside it: a stock rather than a flow, the total backlog of verification steps added for a reason nobody remembers and nobody has re-checked.
Call that backlog trust debt. A company can carry technical debt in its codebase or financial debt on its balance sheet. Society, in the same way, carries an unaudited balance of rules that were once justified and have never been revisited. The Tax is what you pay today. The Debt is what’s still owed from every year before this one, and there is no accounting department whose job is to write any of it off.
Why we tolerate it
None of this works unless the other side of the transaction goes along with it, and mostly, we do. Some of that is simple arithmetic: ten seconds of your life isn’t worth an argument with your bank. Some of it is that there’s rarely anyone to argue with in the first place; a CAPTCHA has no name attached to it, so there’s no one to blame and nothing to negotiate. The deeper reason is asymmetric information: an institution can see its own fraud losses against its own prevention costs, while a customer sees only the checkpoint, with no way of knowing whether the ten minutes they just spent uploading a passport photo stopped anything at all, or was simply inherited from a decision made years ago for reasons no longer written down anywhere.
Not every checkpoint is about fraud
Some verification exists for reasons that have nothing to do with catching thieves. Healthcare identity checks also reduce medical errors and mixed-up records. Airport screening addresses terrorism as much as fraud. Financial KYC rules serve anti-money-laundering goals that matter on their own terms, whatever you think of their cost-effectiveness.
Still, a large share of what people encounter daily, the extra login step, the repeated identity checks, the interrogation before a simple customer service question gets answered, does trace back specifically to fraud prevention rather than these other goals. The two get blended together in practice, which is part of why the Trust Tax is hard to see clearly.
The Trust Premium
An entire industry has grown up around the fact that trust is now harder to come by: identity verification companies, fraud-detection vendors, background-check services, credit-monitoring firms, compliance consultants, cybersecurity insurers. As fraud risk rises, demand for all of these rises with it.
There’s a mirror image worth naming, because it explains something the rest of this piece doesn’t: why some companies invest so heavily in being trusted at all. People increasingly pay more, often without noticing, to buy from sellers and platforms they already trust, established retailers, large banks, official app stores, verified marketplace sellers. Call this the Trust Premium, the other half of the same transaction-cost equation that produces the Tax. If trust lowers transaction costs, then whoever can credibly sell trust gets to keep some of that saved cost as profit. Large technology platforms, payment networks, and identity providers have ended up functioning as trusted intermediaries for exactly this reason, whatever their original intentions were.
A company will invest in reducing fraud right up to the point where it stops paying that company back, not up to the point where the Tax disappears for everyone else. The fixes get built where they’re profitable, not where they’re needed most.
Winners, losers, and the unequal burden
The gains and the costs land on different people. Cybersecurity firms, identity platforms, and large incumbent banks and retailers benefit, partly because compliance is a cost they can absorb more easily than a smaller rival can. Large technology platforms that have become trusted intermediaries by default do too. Governments often get framed as beneficiaries as well, since KYC and AML rules give them more visibility into citizens’ financial lives, though that’s a more contested claim than it first appears: whether that visibility is a reasonable cost of fraud and terrorism prevention or a form of financial surveillance overreach is a live policy argument, not a settled one, and this piece isn’t the place to resolve it.
On the other side of the ledger sit people without an established credit history, who face more documentation rather than less; immigrants working through longer verification processes; families sending remittances, who face scrutiny meant to catch a tiny fraction of bad actors; small businesses and startups that can’t spread compliance costs across a large customer base; and anyone who simply values a level of anonymity that’s steadily getting harder to obtain in ordinary commercial life. As trust becomes something proven through digital records, people without a substantial digital footprint risk being locked out of basic financial services altogether.
A barrier to building things
A startup in 2005 could build a product, launch it, and iterate. A startup today has to work through privacy policy, security infrastructure, compliance workflows, fraud prevention, and age verification before it even launches. None of this is unreasonable in isolation, but together it raises the cost of starting something new, and larger, well-capitalized companies absorb that cost more easily than small teams can.
Where this is headed
The unaudited backlog described earlier, trust debt nobody is assigned to review, is the problem the next wave of identity technology is aimed at. Digital identity wallets that bundle verified credentials into a single reusable proof are, in effect, an attempt to pay down years of duplicated verification in one pass rather than adding another layer on top. Continuous authentication, broader age-verification requirements, and reputation scores extending beyond gig work and lending are extensions of the same idea: rather than re-proving trust at every checkpoint, prove it once and carry the proof.
Whether that actually reduces the total debt, or just consolidates it into a smaller number of more powerful gatekeepers, is an open question. It’s also plausible that trust itself becomes something you subscribe to, with consumers paying directly, or through fees folded into other services, for verified identities and lower-friction experiences, buying their way out of a cost everyone else keeps absorbing for free.
Closing
Every scam makes headlines for a few days and fades. The security measures introduced afterward rarely fade at all. They stay for years, until they’re just another step nobody questions.
The harder problem isn’t that this tax exists. It’s that it has no natural stopping point. A government tax gets debated, adjusted, sometimes repealed. The Trust Tax has no legislature, so it has no mechanism for going down, only up, one unremoved checkpoint at a time. Every fix on offer, a wallet, a subscription, a new authentication standard, adds another layer of infrastructure rather than removing an old one. The debt isn’t being paid off. It’s being refinanced.
Sourcing note: the cybercrime cost figures (Cybersecurity Ventures vs. independent researchers), the AML compliance figures (LexisNexis Risk Solutions/Forrester Consulting vs. vendor estimates), the data-breach-cost figure (IBM), and the retail theft figure (Capital One Shopping) all trace to named, checkable sources. Several are vendor- or aggregator-produced and should be read as directional estimates rather than neutral consensus figures; the retail theft figure in particular has shown significant year-to-year volatility from its own source and rests on NRF data whose methodology the NRF itself discontinued reporting on in 2024.
