The Scam Classification & Mapping System (SC&MS) has been public since March 2026, when I released version 0.3 of the taxonomy on GitHub. This post is the introduction it never got at the time. After nearly two decades in cybersecurity research, I built a tool to address a gap I kept running into. Now the project has a proper home: a place to explore the taxonomy and receive updates on new developments.
The problem
Americans reported losing $15.9 billion to fraud in 2025 according to the FTC, a 27% increase over the prior year. Investment scams alone accounted for $7.9 billion, followed by $3.5 billion in imposter scams. And those are only the reported losses.
In September 2025, the Aspen Institute's National Task Force on Fraud and Scam Prevention called for coordinated action, noting that defenders work in silos while scammers share tactics freely. As Kathy Stokes, AARP's Senior Director of Fraud Prevention Programs, told Axios: "We coordinate much worse than the criminals do." That momentum has continued: in June 2026, Aspen launched a standing Scam Prevention Initiative with a cross-sector leadership group spanning finance, technology, and retail, putting the theft rate at more than $3 billion every week.
Defenders of networks have long had a shared vocabulary for adversary behavior. Defenders of people never did.
The framework
SC&MS is a framework built around a structured, lifecycle-based taxonomy that works across sectors and scam types. At its core is the ABCDEF lifecycle:
- Access: vectors used to initiate first contact with a potential victim
- Bait: lures, offers, and alerts used to entice a victim's engagement
- Coercion: pressure and control tactics used to compel action or maintain compliance
- Deception: fabricated or manipulated artifacts used to mislead victims and make the scam believable
- Exploiting Trust: borrowed or cultivated trust used to lower a victim's skepticism
- Financial Gain: methods used to extract money, assets, or other value from victims
Version 0.3 includes 156 techniques and subtechniques, each documented with descriptions and tags for filtering.
What comes next
The focus now is refining the taxonomy and validating its usefulness across research, fraud operations, and trust and safety work.
Future releases may add mappings to other frameworks and case studies.
Availability
SC&MS is licensed under CC BY-ND 4.0 and the source is available on GitHub. You can explore the framework in the Explorer and follow the project for future updates.
I maintain the taxonomy, and I welcome feedback from anyone using it in the field.