The most difficult banking transaction to stop may no longer be the one initiated by a criminal using stolen credentials. It may be the payment made by the genuine customer, from their own device, after passing every security check the bank has put in place. They recognise the beneficiary, approve the transfer and authenticate themselves correctly. The problem is that someone on a phone call, messaging app or video screen has convinced them that sending the money is exactly what they should do. As banking security becomes harder to penetrate technically, fraudsters are increasingly attacking something banks cannot patch with a software update: customer trust.
Fraud Is Moving Around the Security Perimeter
For years, much of banking security has concentrated on preventing unauthorised access. Banks strengthened passwords, introduced one-time passwords, added device binding, deployed biometrics and built increasingly sophisticated transaction-monitoring systems.
Those controls remain essential, but the economics of fraud are changing. Visa’s Spring 2026 threat assessment describes scams as a rapidly growing source of consumer harm as criminals increasingly use AI and social engineering to manipulate people into authorising payments themselves.
That creates a fundamentally different problem for banks. Traditional fraud detection asks whether the person initiating a transaction is really the account holder. Scam detection increasingly needs to determine whether a legitimate account holder is making a decision under manipulation.
The distinction is enormous. A criminal does not necessarily need to steal the customer’s password, intercept an OTP or compromise the banking application if the customer can simply be persuaded to authorise the payment.
The Customer Can Pass Every Security Check
Consider how sophisticated a modern impersonation scam can become. A customer receives a call apparently from their bank. The caller already knows their name and perhaps other personal information obtained through previous data leaks, social media or publicly available sources. They create urgency by claiming that suspicious activity has been detected.
The customer is told that money needs to be transferred, a new beneficiary approved or a security request confirmed. Every action may then take place through the customer’s legitimate banking application.
The customer unlocks their own phone. They authenticate themselves. They approve the beneficiary. They confirm the payment.
From the bank’s perspective, many of the traditional indicators of account takeover may be absent. The device is familiar, the biometric authentication is genuine, the account credentials are correct and the customer themselves is pressing the button.
This is why the industry’s move towards stronger authentication solves only part of the problem. As Finnoex recently explored in The OTP Isn’t Dead Yet. But Banks Are Already Building What Comes Next, financial institutions are moving towards stronger in-app authentication, biometrics and device-based verification. Better authentication can make impersonating the customer more difficult. It cannot necessarily prevent someone from manipulating the real customer.
AI Is Making Trust Easier to Exploit
Social engineering itself is not new. What is changing is the quality, scale and personalisation available to criminals.
Generative AI can produce convincing emails and messages, while synthetic voices and deepfake video can make impersonation significantly more believable. Criminals can potentially personalise communications using information gathered from social media, leaked data and other digital sources.
The result is an important change in the economics of social engineering. A scam that previously required a skilled criminal capable of maintaining a convincing conversation can increasingly be supported by technology. Language can be localised, messages personalised, voices replicated and large numbers of potential victims targeted simultaneously.
The threat is also evolving quickly enough that fraud prevention systems may increasingly need to operate at machine speed. As discussed in The Next Cybersecurity Arms Race Will Move at Machine Speed, the growing use of AI by attackers is putting pressure on financial institutions to detect and respond to threats faster than traditional human-led processes can manage.
The attack surface is no longer simply the banking system. It is human judgement.
Banks Need to Understand Intent, Not Just Identity
This creates one of the hardest challenges in modern fraud prevention.
Banks have become increasingly sophisticated at answering one question: Who is making this transaction?
The next question is much harder: Why are they making it?
A customer who normally transfers AED 2,000 may suddenly attempt to send AED 75,000 to a newly created beneficiary. Technically, everything may be legitimate. Behaviourally, however, the transaction could be highly unusual.
That means fraud detection increasingly needs context. How quickly was the beneficiary added before the payment? Has the customer ever transferred money to this recipient? Is the amount unusual relative to their normal behaviour? Is the customer navigating the application differently? Does the transaction resemble known scam patterns?
Behavioural intelligence can potentially identify signals that authentication alone cannot. Instead of treating identity verification as the final security checkpoint, banks can combine identity, device, transaction and behavioural information to build a more complete picture of risk.
The direction of travel is clear: proving identity is becoming only one layer of fraud prevention.
Banking May Need More Friction, Not Less
For more than a decade, digital banking has pursued friction reduction. Fewer screens, faster payments, instant onboarding, one-touch authentication and real-time transfers have become measures of a good digital experience.
Most of those developments have improved banking enormously. But security may require banks to reconsider the assumption that every additional second in a customer journey is undesirable.
A suspicious transfer to a new beneficiary may justify an additional confirmation. An unusually large payment could trigger further verification or, in particularly high-risk circumstances, a temporary delay. A customer exhibiting abnormal behaviour might receive a warning explaining the specific scam pattern associated with the transaction.
The challenge is applying that friction intelligently.
Banks cannot interrupt every transfer with generic fraud warnings. Customers quickly learn to dismiss warnings they encounter repeatedly. The intervention needs to appear when risk signals justify it and ideally explain why the bank is concerned.
Instead of simply asking whether a customer is sure they want to make a payment, a bank could ask whether someone claiming to represent the bank, police, government or another organisation has instructed them to transfer the money.
The difference is important. One asks the customer to confirm a transaction they already intend to make. The other interrupts the social engineering process itself.
Real-Time Payments Make the Decision Window Smaller
There is another reason this problem is becoming more urgent: money increasingly moves instantly.
Real-time payment infrastructure provides enormous benefits to customers and businesses, but it also compresses the period available to identify and stop fraud. Once a manipulated customer authorises an instant transfer and the funds move through multiple accounts, recovery can become substantially more difficult.
This creates a difficult balance for banks. Customers increasingly expect payments to happen immediately, while fraud teams may sometimes need additional time to establish whether an unusual transaction is genuinely intended.
The answer is unlikely to be slowing every payment. Instead, banks will need increasingly sophisticated risk models capable of identifying the small proportion of transactions where additional intervention is justified.
Fraud prevention therefore needs to move earlier in the transaction journey. Stopping a scam before the customer presses confirm is considerably more valuable than attempting to recover funds after the payment has moved.
The Responsibility Question Will Become Harder
There is also an uncomfortable policy question behind all of this.
If a bank’s systems function correctly, the customer’s identity is verified and the customer deliberately authorises the transaction, who is responsible when that customer has been deceived?
The answer is becoming less straightforward as scams become more sophisticated. Banks cannot reasonably know the circumstances surrounding every legitimate payment. At the same time, financial institutions possess behavioural, transactional and network-level information that customers do not.
That creates pressure for fraud prevention to move beyond simply securing access to an account.
The consequences also extend beyond the immediate financial loss. As Finnoex examined in The Cost of a Banking Data Breach Isn’t the Fine. It’s Everything That Comes After, security incidents can create much wider consequences around remediation, regulatory scrutiny, reputation and customer confidence.
For banks, preventing scams is therefore becoming part of a broader challenge around maintaining trust in digital financial services. Customers may technically be responsible for protecting their credentials and approving transactions carefully, but they will increasingly expect their bank to recognise when something does not look right.
Security Is Becoming a Behavioural Problem
The next generation of banking security will still require stronger authentication, better cybersecurity and more sophisticated fraud models. But those technologies will increasingly operate alongside systems designed to understand behaviour and context.
Fraudsters are adapting because the banking perimeter is becoming harder to breach. Instead of breaking through the front door, they are convincing the person inside to open it.
That changes what banks need to protect.
The question is no longer simply whether the person using the banking application is genuinely the customer. Increasingly, banks will also need to understand whether the action that customer is taking genuinely reflects their intent.
What it means for the industry
- Authentication alone cannot solve scam fraud. A transaction can be fully authenticated and still result from manipulation.
- Behavioural intelligence will become a more important security layer. Banks will increasingly need to identify unusual customer behaviour alongside suspicious transactions.
- AI is strengthening both sides of the fraud battle. Criminals can create more convincing impersonation scams, while banks can use AI to identify anomalies and intervene earlier.
- Some friction may need to return to digital banking. High-risk transactions may justify targeted warnings, additional verification or temporary delays rather than unconditional speed.
- Real-time payments increase the importance of prevention. As money moves faster, banks have less opportunity to recover funds after a scam succeeds.
- The industry’s security question is changing. Knowing that the customer is genuine may no longer be enough. Banks increasingly need to determine whether the customer’s decision is genuine too.

