Fraud Has Industrialised. Is Your Bank Ready?
There is a number that should stop every payments professional in their tracks: $442 billion. That is the estimated global loss to scams in a single year — and behind every one of those transactions is an uncomfortable truth. A bank approved it.
Not because the fraud slipped through undetected. But because the customer authorised it.
This is the defining challenge of our moment, and it is the subject of a piece published this week on SecurityBrief UK by Sandy Lavorel, Vyntra’s Head of Fraud Intelligence. The article, Fraud Has Industrialised and Banking Defences Must Do the Same, is essential reading for anyone in financial crime, payments risk, or compliance. Here is why it matters — and what it means for the institutions we work with every day.
Why Traditional Controls Are Failing
The article puts its finger on the precise reason most fraud frameworks are struggling: they are built around the wrong threat model.
Traditional fraud controls are designed to detect unauthorised access — compromised credentials, account takeovers, suspicious login patterns. That remains relevant. But the dominant fraud vector today follows a completely different logic.
In an Authorised Push Payment (APP) scam, the victim is manipulated — through urgency, fear, or manufactured trust — into authorising the payment themselves. From the system’s perspective, everything looks legitimate. The authentication passes. The payment is confirmed. No breach is flagged. And yet the fraud has already taken place.
This is why APP fraud prevention cannot rely on the same tools used to detect unauthorised transactions. The payment is authorised. The safeguard has been bypassed not by technical exploit, but by human manipulation. Effective APP fraud prevention requires understanding intent and context — not just credentials and thresholds.
From a Volume Problem to a Structural One
For years, fraud was framed as a volume problem. More attacks meant more controls, and banks responded by tightening authentication rules and layering on transaction monitoring. That logic still holds — but it is no longer enough.
What Lavorel describes is a structural shift. Fraud today does not look like opportunistic crime. It looks like an industry. Fraudsters test and refine their methods, reuse successful tactics across campaigns, and share intelligence across networks. They measure conversion rates. They optimise for performance. The sophistication gap between attacker and defender has never been wider.
Artificial intelligence is accelerating this shift — but it is not the root cause. AI simply gives fraud operations the ability to scale personalisation, eliminate obvious red flags, and compress the time between targeting and execution. What took hours now takes minutes.
The Speed Trap
Lavorel identifies timing as one of the most critical and underappreciated dimensions of modern fraud. But it operates in two distinct phases.
The manipulation phase can be slow — romance baiting and investment scams can unfold over weeks or months, building trust deliberately before asking for money. But once a payment is initiated, execution is near-instant. Funds are transferred within minutes, moved through mule networks, converted or withdrawn before any investigation can begin.
At the same time, payment infrastructure is getting faster. Instant payment rails are expanding globally. The window for detection is shrinking — and fraudsters know it. They create urgency. They compress decision-making. They exploit the very speed that modern payment systems are designed to deliver.
For financial institutions, this makes real-time APP fraud prevention non-negotiable. Delayed intervention is no longer an option when the money is already gone.
Regulation Is Shifting the Accountability Map
The regulatory environment is catching up — and the consequences for institutions that are not ready are significant.
In the UK, mandatory reimbursement for APP fraud took effect on 7 October 2024, placing liability on both sending and receiving institutions for scams executed via Faster Payments and CHAPS. Across Europe, PSD3 and the Payment Services Regulation (PSR) will extend similar obligations, requiring payment service providers to reimburse victims of impersonation scams where prevention standards have not been met.
These rules do not prevent fraud. But they fundamentally change who bears the cost. And they create a clear commercial incentive to invest in APP fraud prevention before an incident occurs, rather than managing reimbursements after the fact.
The Case for Network Intelligence
One of the most important arguments in Lavorel’s piece is the case for collaboration. Fraudsters operate as networks — sharing infrastructure, data and tactics. When one institution hardens its defences, the same campaign is quickly redirected elsewhere. Banks, by contrast, have historically operated in isolation, each institution working with only its own data.
The result is a structural disadvantage. The most valuable fraud signals — suspicious beneficiary accounts, mule network activity, emerging scam patterns — do not exist within a single institution’s view. They exist across the ecosystem.
Addressing this requires a shift from isolated APP fraud prevention systems to interoperable, network-level solutions — ones capable of ingesting external intelligence and applying risk scoring in real time, across all payment rails. This is precisely the model behind community-based fraud intelligence frameworks, including Vyntra’s own Community Scoring & Intelligence — a solution referenced in the article as part of the new baseline for financial crime prevention.
What This Means for Your Institution
The article’s conclusion is clear: static rules and post-event analysis are no longer sufficient. The new baseline for APP fraud prevention requires dynamic risk assessment, real-time decision-making, and visibility that extends beyond internal systems to the wider payment ecosystem.
At Vyntra, this is exactly what we build. Our AI-powered platform gives financial institutions real-time mastery over transaction risk — across every payment rail, at every stage of the payment lifecycle. Whether the threat is an APP scam, a mule account, or an emerging fraud pattern spreading across the network, our solutions are designed to detect and intervene before funds leave the system.



