
Banks are turning to customer behavior as a new front in the fight against fraud, as criminals manipulate victims into authorizing payments themselves.
Social engineering scams—where fraudsters impersonate bank employees or trusted figures to coerce transfers—now make up the majority of fraud cases at 55% of financial institutions, according to recent findings.
Behavior becomes the new battleground
Traditional fraud controls, designed to flag stolen credentials or suspicious devices, often miss these scams. The customer logs in with valid details, approves the transaction, and the payment appears legitimate. Fraud teams now search for subtler signals like hesitation, repeated steps, or transfers that deviate from a customer’s usual patterns.
Behavioral intelligence tools examine how users interact with banking services, establishing baseline patterns and flagging deviations in real time. An unusually large transfer to a new payee, for instance, might prompt extra scrutiny, even if the transaction passes standard security checks.
While 83% of institutions surveyed rated the technology as effective, adoption remains limited. Only 18% have deployed it so far, though more plan to. These tools don’t replace existing fraud controls but add context, revealing when a customer’s actions suggest they’re under duress or following someone else’s instructions.
Monitoring raises concerns about how much banks should intrude into customer behavior, even with good intentions. The boundary between security and surveillance isn’t always clear, and false positives could frustrate users who simply deviate from their usual habits.
Regulation piles on the pressure
The stakes are rising as authorized push payment fraud—where victims are tricked into sending money—becomes a regulatory flashpoint. In North America, 69% of respondents expect laws requiring reimbursement for these scams within two years. Only 31% say their institutions are prepared for the change.
Related: Tuskira boosts security with new control system
Reimbursement rules shift more of the financial burden to banks and payment providers, creating a direct incentive to prevent fraud before it happens. The alternative—processing claims, investigating cases, and recovering funds—adds operational costs and strains customer relationships. Early detection helps avoid both regulatory and financial complications.
AI is helping ease some of that burden. Fraud teams already use machine learning to speed up investigations, which often involve piecing together data from multiple systems, tracing transactions, and reviewing communications. Most institutions agree AI can significantly reduce investigation times by compiling timelines, connecting related alerts, and prioritizing high-risk cases.
The technology doesn’t replace human analysts but allows them to focus on cases requiring judgment. Faster investigations mean more time to freeze funds or coordinate recoveries, though automation also risks missing details only a person might notice.
Fraud and cybersecurity blur together
The overlap between fraud and cybersecurity is expanding. Both deal with phishing, malware, and account takeovers, and 81% of fraud professionals now also handle cybersecurity responsibilities. This convergence pushes banks to integrate threat intelligence, sharing data on scam campaigns and suspicious accounts across institutions.
Detecting fraud earlier remains a challenge. Social engineering leaves few technical traces because the customer initiates the transaction. Behavioral signals offer a way to spot manipulation in progress, but they aren’t foolproof. A customer acting under pressure might still slip through, especially if their behavior doesn’t trigger the bank’s predefined red flags.
For now, the focus remains on stopping payments before they leave the account. Banks must watch not just what customers do, but how they do it—and determine when to step in.
