
GASA San Francisco: 20 Months of the Global Signal Exchange
Earlier this month, the GSE team went to San Francisco for the Global Anti Scam Summit America 2026. We ran two sessions: a Plenary panel and a follow-on workshop on scam geographies. Between the two, we heard from 20 speakers across government, law enforcement, big tech, telecoms, domains and philanthropy. The conversations were honest, and the momentum in the room was unlike anything we have seen before.
The Plenary brought us 20 months back.
Jorij Abraham, founder of GASA, took the room back to where GSE actually started, an anti scam summit barely three years ago, where a working group landed on the usual conclusion that the industry should share more data. Except this time the chair turned to him directly and told him to go and fix it. Within weeks, more than 60 organisations gathered at Meta's offices in March to work out how real data sharing could function in practice. The Global Signal Exchange was born, with GASA as one of its founding partners.
Emily Taylor, speaking for GSE, described sitting beside Abraham in that original working group. She remembers it well. Three separate threads were converging at once. There was the technical platform she and Lucien Taylor's team at OXIL had spent two decades building. There was the legal groundwork for lawful cross border data movement, which she had developed as a data protection lawyer. Coincidentally, unknown to either of them at the time, Google had spent two years searching for exactly this kind of independent, non profit home for signal sharing.
Nathaniel Gleicher of Meta gave the platform's first hard numbers. Under a pilot with the Belgian Cyber Security Center, over a three month period roughly 25 percent of the ads Belgium flagged as suspected scams had already been removed by Meta. But the Belgian evidence let Meta confirm a further 50 percent that it could not previously have determined were scams on its own, sharply increasing Meta's recall. Signal flows back to Belgium too, so its own detection improves in turn.
Will Blay of Microsoft framed GSE's value as scale. Even with Microsoft's resources, a bespoke integration with every organisation wanting to share data is not realistic. So GSE gives Microsoft a common data taxonomy and a single interface now wired directly into its core detection models. This simplifies both what comes in and what goes out to governments, law enforcement and other tech companies.
Abigail Bishop of Amazon offered the metaphor that stuck with the room longest, every organisation looking at the scam problem through its own straw, seeing only a slice of an enormous shared threat. GSE's job, she said, is to string those straws together. And the community's real task now is shifting its focus from counting inputs, the signals shared, to measuring outputs, the harm actually prevented.
Andre Ng of GovTech Singapore reported that scam tainted URLs sent through GSE contributed to more than 30,000 malicious entities being removed from Facebook and Instagram. He also pointed to closer working relationships with Microsoft, Google, Meta and Amazon. And to lower integration costs, since Singapore only has to build one connection to GSE, rather than separate integrations with every partner.
Jayde Richmond of Australia's National Anti Scam Centre, joining by video, announced a cross border intelligence pilot running jointly with Australia's Financial Crimes Exchange. It may go on to shape the settings for actionable scam intelligence sharing under Australia's new Scam Prevention Framework. She also confirmed that the Centre's Fusion Cell task force is sharing intelligence on gambling scams with GSE, and calling on global partners to help address the harm those scams are doing to vulnerable Australians.
Justen Davies of Somos brought the telecoms view, explaining that numbering intelligence closes a gap alongside the tech and banking signals already on the platform. He compared the shift to moving from a defence that only covers certain zones of the field to one with full coverage across the line.
Carole House of ACAMS spoke to the point where cyber crime and financial crime meet, drawing on years as a regulator and her time working on this issue from inside the White House.
Akssenya Beedassy of TikTok said the platform's existing fraud safeguards are already strong. But the additional layer of signal and intelligence sharing is what will let TikTok move from responding to individual scams one at a time toward identifying patterns early and acting proactively.
Mike Haley of Cifas took the room back 38 years, to when fraud data sharing in the UK started as a national response to what was then a local problem. With fraud now global, he described Cifas, whose members include the UK's retail banks and mobile network operators, as the bridge between that mature national data sharing community and the global exchange the moment now demands.
Jean Jacques Sahel of Google, arriving after being delayed in traffic, argued plainly that if GSE did not exist the industry would have had to build it. He said the platform's real measure of success is not the volume of signals moving through it but the scam networks that have already been dismantled as a result. He closed with an open invitation for more governments, banks and telecoms to join.
Craig Newmark, the philanthropist whose support has helped underwrite GSE, reaffirmed his long standing commitment to sharing threat intelligence. He also floated an idea he is personally excited about, sharing open weight small language models that could eventually run scam detection directly on people's phones.
Following on from the Plenary, the workshop on scam geographies, chaired by Emily Taylor, went deeper into the operational detail behind those headline numbers. It worked through four questions in turn: where are the victims, where are the scammers, where is the kit, and what are we going to do about it.
Andrei Skorobogatov of GASA opened the victims' question with the uncomfortable answer that they are everywhere, across every country and every social group. He challenged two common assumptions directly. Younger people, not older people, are statistically more likely to be victimised. And people in developing countries tend to lose a higher share of their income to fraud than people in wealthier countries. He drew a distinction worth holding onto, that being vulnerable to fraud and being vulnerable from fraud are not the same thing, since some groups are targeted less often but suffer far greater and longer lasting harm when they are hit.
On where the scammers are, Lucien Taylor of OXIL presented fresh analysis drawn from GSE's full signal base of 1.5 billion data points, narrowed for this study to nearly 8 million unique URL signals collected over the first six months of the year, and scored by a proprietary large language model methodology for how specifically each one references a place. The pattern is consistent. Scammers tailor their infrastructure to local language and culture, referencing local pharmacies, banks or sports teams to build trust with a specific audience, as seen clearly in a word map of signals targeting California. By raw volume, China is the most targeted country, followed by the US, Japan and Brazil. Once the data is filtered down to the highest confidence signals, the US moves into first place, followed by China, the UK and Brazil.
Scott Swatner of Meta presented the company's mapping of physical scam compounds, concentrated across three areas on the borders of Thailand, Cambodia, Laos and Myanmar, home to sites including K99 and Tai Cheng that he compared in scale to a city the size of Reno. He described the compounds as strikingly resilient. Disrupted operations frequently reappear nearby within months, visible even in satellite imagery of land that was empty a year earlier, with Sihanoukville a recurring hotspot. Meta's response has centred on joint disruption weeks run with law enforcement, including sprints in Bangkok with the Royal Thai Police in December and again in March, and a first US sprint in May and June with the DOJ's scam center strike force.
A recorded message from Abdus Salam, who was trafficked into a scam compound in Southeast Asia, brought a personal dimension to the panel. He described being handed a list of 3,000 numbers with a five day target to text all of them, using VPNs and foreign SIM cards, including American, Canadian and UK numbers, to appear local. Operations were run by Chinese speaking bosses, with victims identified across more than 60 countries. The technical infrastructure, including websites and back end systems, was built by an entirely separate team from the people making first contact with victims.
Turning to where the kit itself comes from, Lucien Taylor walked through GSE's supply chain analysis of the domain registries, registrars and hosting providers implicated in scam signals. By raw volume, Verisign dominates simply because it produces the most domain names in the world. But GSE's league tables, ranking providers by the share of their stock appearing in threat reports, tell a sharper story. Seychelles tops the list with a 21.68 percent bad report rate. The US sits nineteenth overall, but a California based registrar for the .coupon domain ranks fourth worst globally with a 9.26 percent report rate, and shares back end services with CentralNic in the UK, the same provider behind a Seychelles based shell registry for .help domains tied to a Hong Kong operation. In Sweden, a single low ranked registrar accounts for 9.5 percent of the country's flagged stock. In California, Global Domain Group accounts for 38 percent of its own country's reports, over a third of its total stock. Both offer reseller automation kits and white label APIs that allow rapid domain provisioning with no identity verification at all, and their stock includes domains under .xyz, .top, .shop and .cfd that scammers use for convincingly branded storefronts. On the registrant side, the US, China and Iceland lead, highlighting proxy services, including one Icelandic provider that registers scam domains under the name of the Icelandic Phallological Museum as a deliberately conspicuous proxy.
Iain Young of Mastercard closed out the kit discussion by describing Mastercard's position at what he called the final mile of the scam journey, drawing on a payments network spanning around 210 countries and territories and a zero liability guarantee for consumers hit by fraud. He confirmed Mastercard is currently running a pilot with GSE to understand how identity and cyber signals can be folded into its existing fraud models alongside payment data alone.
The closing segment turned from diagnosis to response.
Fran Dowling of the UK Home Office opened with the scale of the problem at home. Fraud now accounts for 47 percent of all crime in the UK, and once cyber crime and ransomware are added that climbs past 50 percent, with over 70 percent of it originating overseas. She pointed to the UNODC and Interpol Global Fraud Summit in March, which drew 115 countries, 40 of them at ministerial level, and around 500 industry representatives. There was also a Five Country Ministerial with Australia, New Zealand, Canada and the US where fraud featured as a major agenda item. The UK also runs bilateral law enforcement partnerships, including with Nigeria and Vietnam, and Dowling highlighted the UK's new Online Crime Centre, currently moving from tech alpha into beta in January, which shares law enforcement data out to industry partners including through GSE for enrichment. That work has already led directly to arrests, including one banking sector sprint that eliminated an estimated 85 to 95 percent of a specific type of fraud.
Andre Ng returned to share a case study of a problematic Singapore based domain registrar, which had been responsible for nearly 40 percent of the roughly 400 to 1,000 domains Singapore blocks each day out of the 500,000 websites it scans daily, and which also sat in the bottom ten of GSE's global leaderboard. Rather than reach for regulatory penalties, Singapore issued a formal warning, handed over more than 10,000 records of hard evidence, and gave the registrar access to a GSE rescue package combining community data feeds with the public leaderboard. The registrar responded by disrupting around 51 percent of the domains flagged to it, tightening its verification process so throwaway email addresses could no longer be used to register an account, and adopting a zero tolerance policy for repeat offenders. Within about four to five weeks its share of Singapore's blocked domains fell from 40 percent to 2 percent, a 95 percent drop. It became one of the first organisations on the platform to give GSE structured feedback.
Jean Jacques Sahel of Google described two tracks going forward. One is using shared signals to understand and structurally disrupt the legitimate infrastructure, DNS, hosting, payments, that scammers exploit at scale, an effort Google is taking into GASA's enforcement working group. The other is straightforward enforcement, passing forensic detail on to law enforcement for full legal referral. He argued that awareness campaigns and legislation matter but only go so far, and that the priority now has to be going after the organised crime groups behind the scams.
Will Blay of Microsoft pointed to a live example, the disruption of a fraud marketplace called RedVDS by Microsoft's Digital Crimes Unit earlier this year, with indicators of compromise shared onward through GSE to Google for further action. He described a two way commitment Microsoft has made to itself: giving feedback on the value of signal it receives, and tracking how valuable the signal it shares is to others. He also flagged that legal and privacy sign off, not technology, has often been the real bottleneck to data sharing. Microsoft has recently made progress unblocking that internally, and Blay argued the industry as a whole still needs a shared taxonomy or framework for what can be shared and how.
Mary Odisho of Amazon said the scattered geography of scams makes it harder to connect a customer report to the true scale of harm behind it, since the customer reporting a scam is not always the customer suffering the financial damage. She noted that scammers now shift channels within hours rather than weeks. And she described Amazon's parallel push to give customers direct tools to verify communications and report concerns, including a newly launched feature within Alexa for shopping, alongside continued support for customers after harm has occurred.
Akssenya Beedassy of TikTok closed the session by naming the platform's biggest blind spot: visibility ends the moment a scammer moves a victim off platform. This is compounded by the fact that scammers and the money mules they use often sit in different countries entirely, adding further data privacy and legal complexity to any response. She said being part of GSE has already resolved much of that legal question for TikTok, since data shared through the platform does not require a separate bilateral agreement with every partner. Her broader point echoed the day: no one is going to catch every scammer outright. But adding friction at every stage, sign up, verification, payment, slows the whole operation down.
The session offered a rich and detailed picture of both the impact GSE has already had and the operational reality behind it, from platform level takedown numbers to individual registrar turnarounds to survivor testimony.
Across every panel, the speakers converged on the same point: that a single scam can touch a dozen jurisdictions at once. And that GSE offers something bilateral agreements and internal tooling alone cannot, speed, scale, and a trusted neutral platform for turning shared signal into coordinated action.




