Outsourcing Assistant guide

Fraud report triage for a Filipino customer support assistant

A Filipino customer support assistant can capture a fraud report, protect the record, and send it to the right manager without trying to solve the case. This guide gives the assistant a narrow intake lane and keeps account, refund, and legal decisions with approved staff.

Key takeaway: The assistant should collect the customer's own account of what happened, save only the needed facts, and move the case to a named manager. The assistant should not promise recovery, move money, change account ownership, or investigate a person.
$12.5Bconsumer-reported fraud lossFTC total for 2024, released March 10, 2025.38%of fraud reporters said they lost moneyFTC figure for 2024, compared with 27% in 2023.2.6Mconsumer fraud reportsReceived by the FTC in 2024.

Give the assistant one clear job

A Filipino customer support assistant can receive a report, record the customer's words, protect the ticket, and alert a named manager. That is useful work, but it is not an investigation and it does not give the assistant authority to decide whether fraud occurred.

Write the finish line before the first ticket arrives: a complete intake note, the right risk label, and a manager alert through an approved channel. Refunds, account ownership changes, evidence requests, legal notices, and contact with banks or police stay with the owner or another approved specialist.

Define what belongs in the queue

Useful triggers include an order the customer did not place, a login the customer does not know, a message asking for a new payment destination, or a caller pretending to be company staff. A customer who says an invoice is wrong may have a normal billing question, but a customer who says somebody changed bank details needs the fraud path.

Give the Filipino assistant a short list of labels such as suspicious message, unknown account activity, identity claim, and payment-change request. Labels help route the work, but they must not read like a verdict. The ticket should say "customer reports" rather than stating that a named person committed a crime.

Fraud report intake map for a Filipino customer support assistant
Report signalAssistant recordsAssistant avoidsManager receives
Unknown orderOrder reference, time noticed, safe contactRefund promise or card detailsTicket and account timeline
Suspicious messageSender shown, channel, customer statementOpening links or calling numbers in the messageOriginal message in the approved system
Account changeChange noticed, last known safe accessResetting ownership without approvalRestricted ticket and urgent alert
Payment changeRequest text, time, known vendor recordEditing bank details or sending fundsSecond-channel check request
Identity claimClaim in the customer's own wordsRequesting excess identity documentsPrivacy-safe note and named owner

Capture facts without collecting everything

Record the customer's name, safe contact method, account or order reference, time noticed, channel used, and a plain description of the event. Ask what the customer already did, such as changing a password or contacting a card issuer, but do not ask the customer to send a full card number, password, government ID, or secret code in a normal ticket.

Keep the original message or screenshot only in the approved support system, and follow the company's retention rule. The FTC tells businesses to keep only personal information they need and to protect what they keep. That is a practical reason to avoid copying sensitive details into chat, email, and several task boards.

Stop account and money actions

Do not let a new report become a reason to reset every login, change an account owner, send money, approve a refund, or edit bank details. A scammer may use the support queue itself to create urgency. The Filipino assistant should lock the ticket from routine handling and ask the named manager to decide the next action.

The FTC said on March 10, 2025 that consumers reported more than $12.5 billion in fraud loss during 2024. The same release said 38% of people who reported fraud said they lost money, up from 27% in 2023. Those figures describe reports received by the FTC, not the expected result for one company or customer.

Share of FTC fraud reporters who said they lost moneyHorizontal bars compare the percentage of FTC fraud reporters who said they lost money in 2023 and 2024.Reported loss share rose in 2024202327% of reporters202438% of reportersUnit: percent of people who reported fraud to the FTC
Share of FTC fraud reporters who said they lost money. Units are percentages of people who reported fraud to the FTC. The FTC published both figures on March 10, 2025; the bars describe submitted reports and do not predict one customer outcome.

The FTC is monitoring those trends closely and working hard to protect the American people from fraud.

Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection. Read the source.

Verify the channel, not the customer story

Use a contact method already stored on the account when the manager asks for a second check. Do not use a phone number, link, or email address supplied inside the suspicious message. If no safe contact method exists, the assistant should mark that gap and wait for the manager rather than inventing a workaround.

CISA tells people to resist pressure to act immediately and to use a known address or number when checking a suspicious message. In a support lane, that means the assistant pauses, preserves the request, and switches to the company's trusted contact record. The assistant does not call a supposed bank, vendor, or family member found through the message.

Plan the Philippine shift handoff

Set one urgent route that works during Philippine Time, such as an on-call manager queue with a backup contact. Give examples of urgent events: active account takeover, a payment-change request due the same day, exposed customer records, or a threat that appears credible. Normal disputes and incomplete reports can wait in the review queue.

The end-of-shift note should list the ticket number, risk label, time received, safe contact status, evidence location, and manager notified. It should not repeat full personal details in a general team chat. The next Filipino assistant can see that the case is already owned without reopening the story or asking the customer to send the same material again.

The four-step fraud report routeA separate process graphic showing how a Filipino customer support assistant can move a report to a manager without taking over the decision.A narrow support-to-manager path1. Receive
Listen, use the customer's words, and open one restricted ticket.
2. Record
Save the needed facts and keep sensitive data in the approved system.
3. Route
Apply the risk label and alert the named manager through a trusted channel.
4. Close the loop
Add the manager's next step and leave a clean note for the next shift.
Manager rule: support records and routes; approved staff decide and act.
The four-step fraud report route. A separate process graphic showing how a Filipino customer support assistant can move a report to a manager without taking over the decision.

Give the manager a usable record

Put each event in order with a time zone: customer report received, account note checked, safe contact attempted, ticket restricted, and manager alerted. Separate the customer's statement from facts visible in company systems. This keeps the note honest and helps the manager see what still needs proof.

NIST published Incident Response Recommendations and Considerations for Cybersecurity Risk Management in April 2025. The guide treats incident response as part of wider risk management, which fits a small support lane: prepare the route, detect a concern, respond through named owners, and learn from the record. A customer support assistant can support those steps without becoming the incident lead.

Train with samples and review the lane

Run three samples with the Filipino assistant: an unknown order, a fake payment-change email, and a normal billing correction. Ask the assistant to label each case, write the intake note, choose the safe contact path, and name the manager. Correct the checklist when the assistant has to guess, because that is a process gap.

Review the lane each month using a small sample of closed tickets. Check whether sensitive data was copied, urgent cases reached the right person, ordinary support work was not over-escalated, and managers left a final note. Keep the rule that the assistant reports and routes the concern while approved staff decide what the business does next.

Keep planning the handoff

Questions people ask

Can a Filipino customer support assistant decide that fraud occurred?

No. The assistant records what the customer reported and routes the case under the company's labels. A named manager or specialist decides how the business classifies and handles it.

What information should the assistant collect first?

Collect a safe contact method, account or order reference, time noticed, channel, and the customer's plain description. Do not request passwords, secret codes, or full card details in an ordinary ticket.

Should the assistant promise a refund or recovery?

No. The assistant can explain that a manager will review the report and give the next approved step. Money decisions and recovery promises stay with approved staff.

How should the assistant handle a suspicious link?

Do not open it from the support message. Preserve the message in the approved system, use a known contact path if instructed, and alert the manager.

What belongs in the shift handoff?

Include the ticket number, risk label, time received, safe contact status, evidence location, and manager notified. Keep full personal details inside the approved support system.

Sources

The figures and guidance above come from the original publishers. Each note says how the source was used.

  1. Federal Trade Commission, 2024 fraud data release, March 10, 2025The three dated figures, year comparison, and exact Christopher Mufarrige quote.
  2. Federal Trade Commission, Protecting Personal Information: A Guide for BusinessPrimary business guidance for collecting only needed information and protecting retained records.
  3. CISA, Recognize and Report PhishingPrimary guidance for resisting urgency, checking through known contact details, and reporting suspicious messages.
  4. NIST SP 800-61 Revision 3, April 2025Primary incident response guidance used for the prepare, detect, respond, and learn structure.
  5. NIST Cybersecurity Framework 2.0, February 26, 2024Primary risk management context for named owners, governance, and documented response work.
OA-FRAUD-TRIAGE-2026