Big tech signs pact to swap fraud intel—no cops, no teeth, no penalty
Google, Meta and Microsoft promised on Thursday to trade tips on scammers who hop from one platform to the next—voluntarily, quietly and with zero legal consequence.
The so-called Online Services Agreement, unveiled at a UN anti-fraud summit in Vienna, binds eleven household brands—Amazon, Adobe, LinkedIn, OpenAI, Match, Pinterest, Levi’s, Target and TikTok’s Chinese cousin CapCut joined the club—to circulate red flags about dodgy ads, fake shops and romance swindles within 24 hours of detection. No subpoena required.
Why the hurry? because fraud is now a relay race
A scammer buys Google keywords, lures victims on WhatsApp, harvests photos on Instagram and cashes out through Amazon gift cards. Each company saw only one leg of the race; now they get the full split-screen replay. The pact asks them to share hashes of malicious URLs, ad-account IDs and behavioural fingerprints—think typing cadence, mouse jitter, crypto-wallet addresses—so the same crook can’t simply reopen shop under a new brand tomorrow.
Google will feed the pipe through its SafeBrowsing API; Meta contributes data from 150 million sham accounts it already deletes each quarter; Microsoft throws in the botnet telemetry its Defender crew scoops from 1.2 billion Windows endpoints. Amazon, for its part, will flag merchant accounts that pivot from selling yoga mats to laundering invoice payments.

No fines, no judge, no stick—only carrots
The document is a gentlemen’s agreement, not a regulation. Break it and the only fallout is a mildly awkward phone call. Sources at two signatory firms told TechBloom the clause was intentional: Antitrust lawyers warned us that mandatory data sharing could trigger collusion charges,
one admitted. Translation: the same competition rules that stop price-fixing also hamstring collective security.
Consumer groups rolled their eyes. We’ve seen this rodeo before—2019’s Christchurch Call, 2021’s Tech Accord against ransomware,
said Alice Stollmeyer of Defend Democracy. Without enforcement it’s a PR umbrella, not a safety net.
Still, the timing is shrewd. Washington and Brussels are both cooking legally binding duties on platform risk assessment. By showing up in Vienna with a self-regulatory bouquet, the industry buys narrative leverage: Look, we’re policing ourselves—no need for new red tape.
Whether the move dents the $1 trillion annual fraud haul remains an open experiment. The first joint report is due in twelve months. Expect glossy PDFs, cherry-picked metrics—and, if history is a guide, a fresh round of breaches before the ink dries.
