Right. The quality of feedback information is one of the biggest factors in development cost. The bugs you can't reliably recreate are the biggest problems, sometimes by one or two orders of magnitude.
This should be used as a weapon in the security battle. Seems like not enough people use it.
In all likelihood, the scam initiator is not the same person as the scam implementor, so "making it seem to the bad actors that nothing has changed" is likely to inflate their costs tenfold. This also works when the scam is entirely the work of one person, but it's especially effective when multiple parties are involved.