cyberIdaho's Financial Innovation Lab (FIL)
The cyberIdaho Financial Innovation Lab (FIL) seeks to facilitate engagement between government leaders, industry, entrepreneurs/innovators, policymakers, academia, and the public to share key information, concepts, and research on how digital technology innovations are changing financial services for businesses, government entities, and consumers. The goal of the FIL is to bring together the finest minds in the financial technology space to collaborate and strategize on potential best practices and solutions for harnessing innovations, addressing issues, and educating interested parties/stakeholders.
The outcomes of the FIL are published as Principle or Guidance documents and are intended to facilitate collaboration and conversation amongst our community.
Cryptographic Decentralized Identity Solutions are Vital for Protecting Sensitive Information, Reducing Identity Fraud, & Safeguarding Privacy
The rapid digitization of financial products and services is driving the aggregation of sensitive personally identifying information (PII) into large centralized databases that cybercriminals increasingly target, fueling a surge in identity theft and underscoring the need for cryptographic decentralized identity solutions to better protect American businesses, consumers, and financial stakeholders. Cryptographic decentralized identity solutions use advanced cryptographic techniques and mathematical algorithms/proofs (e.g., zero-knowledge proofs) to verify identity attributes without revealing underlying personal data, while decentralized infrastructure such as distributed ledger technologies (e.g., blockchains) provide secure credential verification without relying on centralized databases to enhance privacy, security, and data minimization.
The development and implementation of cryptographic decentralized identity solutions in the financial services space is critical considering the financial sector is currently the most breached industry and identity fraud and scams cost Americans over $47 billion this past year alone.
However, despite the continued digitization of financial services the sector remains heavily reliant on legacy “Know Your Customer” (KYC) identity verification systems that store vast amounts of sensitive PII in centralized databases. These systems create attractive “data honeypots” for global cybercriminals who are seeking to exploit stolen credentials for identity theft and financial fraud. Without modernization, the financial industry will continue to face rising breach incidents, escalating compliance costs, mounting consumer privacy risks, and significant identity theft losses.
As the financial system becomes increasingly digital, policymakers must prioritize the advancement of cryptographic decentralized identity solutions to maintain trust, enhance security, and combat rising cybercrime. Achieving this objective will require coordinated policy action, including designating cryptographic decentralized identity as a national priority and directing relevant federal agencies to develop clear technical standards and regulatory frameworks to foster responsible innovation. Policymakers should further accelerate adoption by supporting pilot programs and establishing safe harbor protections that encourage financial institutions and technology providers to test, develop, and deploy cryptographic decentralized identity solutions at scale.
Digital Forensic Tools & Evidence Locker Audits are Necessary to Identify & Account for Illicit Crypto Assets in Seizure/Forfeiture Programs
A massive increase in illicit activity leveraging crypto assets (e.g., cryptocurrencies such as Bitcoin, Ethereum, Monero etc.) is leading to a surge in criminal/national security cases involving crypto seizures/forfeitures that makes it vital for federal, state, and local stakeholders to adopt an effective audit function to properly identify and account for these assets to ensure victim restitution, protect against misconduct, and stop bad actors from maintaining access to their illicit assets. Known illicit crypto activity reached an all-time high in 2025 totaling $154 billion, while crypto cybercrime losses grew approximately 3677% since 2020 in the United States. Various factors including the digitization of society, pseudonymous nature of crypto assets, short transaction settlement cycles, and rising adoption/value of crypto assets is causing more illicit actors to use crypto in their operations. Concurrently, limited government crypto expertise and outdated asset seizure/forfeiture processes are highlighting the need for government stakeholders to adopt new crypto auditing policies, solutions, and tools. Additionally, since numerous seizures/forfeitures of electronically stored information (e.g., digital storage devices, electronic records, and digital evidence etc.) have not been properly searched for crypto assets in the past many evidence lockers contain unidentified illicit crypto assets that would be uncovered with a proper audit.
Artificial Intelligence Principles:
A Technology Positive Approach
Artificial Intelligence (AI) is here to stay in the financial services space, and a rational technology positive approach should be adopted that enables innovation to thrive for the benefit of society. AI presents many benefits and opportunities making it important to have a cautiously optimistic mindset to maximize its potential, while concurrently addressing issues as they arise.
The flexible, non-prescriptive framework based on the principles found in this report is vital to responsibly maximizing the positive impacts of AI on society for the benefit of the public and financial industry.
Business Email Compromise:
A Growing Cybercrime in Need of an AI Policy Solution
Over the past decade, business email compromise (BEC) attacks were the costliest form of cybercrime in the United States and the vast majority of BEC attacks can be stopped by simply requiring fund transfer beneficiary names match recipient account holder names through the use of basic artificial intelligence (AI) name matching tools. In 2023, BEC victims reported approximately $3 billion in verified losses that led to a significant amount of small business closures. These facts make it vital for policymakers to craft a solution that protects financial institutions from civil litigation if they adopt a risk-based AI name matching program.
In addition to an AI name matching program, increased information sharing between financial institutions and enhancements to the Financial Crimes Enforcement Network’s (FinCEN) Rapid Response Program (RRP) and the Federal Bureau of Investigation’s (FBI) Financial Fraud Kill Chain (FFKC) can help significantly decrease the success of BEC attacks and better protect the public.
Protecting Innovation for Retail Investors:
Analyzing the Impact of Harmful Predictive Data Analytics Regulation on Financial Inclusion and Technological Advancement
Technology has empowered millions of previously underserved Americans to engage in capital markets by minimizing costs and democratizing financial access, but the Securities and Exchange Commission’s (SEC) Predicative Data Analytics’ Rule (PDA) would create a barrier to this progress by placing extreme limitations on the use of technological innovations that have the potential to benefit both investors and the financial industry.
Proposed regulations such as the PDA at both federal and state levels risk dismantling the significant progress achieved in enabling a diverse range of Americans to enter financial markets and take control of their finances.
To ensure we harness the full potential of emerging technologies while safeguarding investor interests, the U.S. should develop fintech sandboxes for experimentation, research and develop roles and responsibilities for technology users, deployers, and builders, and foster robust dialogue on the opportunities and risks an innovation presents to strike a prudent balanced approach to emerging technology regulation.
Tokenization:
America’s Opportunity to Build the Financial System of the Future
It is vital for the United States to take a leadership role in the development of tokenized assets by creating a responsible technology positive regulatory environment because geopolitical competitors/rivals are attempting to use blockchain technologies to build a new global financial hierarchy and dilute America’s primary role in the global financial system. If America’s rivals build the financial infrastructure of the future, they will have the ability to lessen their dependence on the U.S. dollar, evade potential sanctions, and most importantly increase their geopolitical influence and strength by controlling more financial/economic activity.
The use of shared distributed programmable ledgers (e.g., blockchains) in tokenization enhances operational efficiencies by enabling cheaper and quicker financial transactions and significantly improving liquidity, accessibility, financial inclusion, and transparency throughout the financial ecosystem for the benefit of stakeholders. The benefits tokenization provides make it a likely candidate to become the next generation of financial infrastructure that will replace the current 50-year-old financial rails/systems in use today.
By embracing tokenization, the United States can maintain its primary role in the financial system and use it to promote western democratic values, further U.S. dollar dominance, and build innovative frameworks and businesses that will safeguard American geopolitical and economic strength. To ensure American leadership in tokenization and the global financial system, regulators and policymakers should modernize their registration processes, update settlement/custody guidance, explore alternative trading platforms, and create collaborative vehicles (e.g., sandboxes) to test tokenization infrastructure, business models, and regulatory frameworks. Industry should use this regulatory clarity to build and test tokenization infrastructure, use cases and products, build workforce capacity, and develop risk assessment frameworks.
Fighting Growing Pig Butchering Schemes & Industrialized Cybercrime Operations Targeting Americans
The emergence of large global organized cybercrime operations and compounds conducting pig butchering investment schemes is leading to surging financial losses for American citizens that requires a proactive offensive response from the United States (U.S.) government to dismantle these operations and better protect Americans from cybercrime. Known American cybercrime losses increased to $16.6 billion in 2024 largely due to an over 1800% increase in losses from investment/pig butchering schemes since 2020. A pig butchering cybercrime scheme combines elements of traditional investment schemes, romance/friendship scams, and cryptocurrency to fool innocent victims into sending funds to fake websites for fictitious cryptocurrency investments that are then stolen by illicit actors. Pig butchering schemes are popular with cybercriminals because it enables them to create an emotional relationship with victims that often leads to long-term continuous large deposits into their investment scams making them extremely profitable for bad actors.
The benefits cybercrime presents illicit actors in the form of profitability, scalable attacks, and global targeting combined with Americans becoming increasingly reliant on digital tools and services is motivating cybercriminals to organize and build dedicated physical industrialized cybercrime compounds to steal the wealth of Americans at scale. Since many cybercriminals conducting pig butchering schemes operate outside the reach of U.S. law enforcement in Asia, often with the help of complicit local governments, they are free to organize and develop large-scale cybercrime operations and compounds to target Americans with relative impunity. This means that U.S. cybercrime losses will continue to proliferate unless the U.S. adopts an offensive posture and strategy to attack these industrialized cybercrime compounds and pig butchering operations.
Increasing cybercrime and pig butchering losses highlight that organized cybercrime operations/compounds are currently overwhelming American defensive measures, which makes it essential for the U.S. to adopt a strategy that enables offensive cyber actions, provides necessary proactive authorities to government and private sector entities, and delivers key protections to potential American victims. A successful offensive cybercrime response strategy should include clear authorization from Congress and the White House for targeted cyber operations against industrialized cybercrime compounds and pig butchering operations, diplomatic pressure tools, primary and secondary sanctions, Department of Defense (DoD)/ Department of War (DoW) led offensive cyber operations, a letters of marque program, new proactive cybercrime prevention authorities and liability protections for financial entities, and tax liability protections for cyber and financial crime victims.
Rapidly Growing Cybercrime in Idaho Makes the Creation of a Specialized Cyber and Financial Crime Response Structure Necessary
Increasing access and reliance on the internet/digital services is leading to a proliferation in cybercrime against Idahoans that requires the development of a specialized Idaho cyber and financial crime response structure that can better protect the financial health of Idaho’s citizens and business community. Known cybercrime losses increased to over $16.6 billion in 2025 with known Idaho cybercrime losses growing over 440% since 2020, which is 145% above the national average. Various factors ranging from the digitization of society and the borderless nature of the internet to finite federal government capabilities, limited cyber/financial crime expertise, lack of access to key investigative tools, and outdated investigative/legal structures makes the creation of a specialized Idaho cyber and financial crime response structure essential to protecting Idahoans from surging cybercrime threats.
Since Idaho currently lacks the organizational structure and capacity to address rising cybercrime it should look to build a specialized structure that accounts for the investigative and prosecutorial gaps cybercriminals take advantage of to harm Idaho businesses and steal the hard-earned money of Idahoans, especially seniors. To accomplish this goal Idaho should develop a strategy that designates a lead state investigative agency and prosecutor’s office for cyber and financial crimes, helps acquire necessary technological tools for addressing cybercrime, identifies key investigator/prosecutor trainings to improve essential skills and expertise, and establishes a cybercrime prevention workforce/recruitment pipeline to assist in the fight against cybercriminals for the benefit of all Idahoans.