LIVE · cybersecurity feed
Live wire
finance

Banks look for fraud signals in customer behavior

Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fraud operations. Social engineering moves the risk into the customer interaction Fifty-five percent of institutions survey

zeroday.news ·

Financial institutions are increasingly confronting a surge in fraud cases where customers are coerced into authorizing payments by criminals, prompting a shift in fraud detection strategies. A recent industry benchmark report, the Fraud Readiness Benchmark 2026, highlights that social engineering, evolving reimbursement regulations, and a growing volume of cases are significantly reshaping fraud operations within the banking sector.

Social engineering, where criminals manipulate customers into initiating transactions themselves, is a predominant concern. Fifty-five percent of surveyed institutions reported that social engineering is a factor in the majority of their fraud incidents. In these scenarios, attackers often impersonate trusted entities, such as bank employees, to persuade customers to transfer funds. Because customers use their legitimate credentials and approve transactions, traditional fraud controls designed to detect stolen credentials or account takeovers may fail to flag these activities, as they appear to be legitimate customer actions.

In response, fraud teams are intensifying their focus on customer behavior during banking sessions. They are actively seeking indicators that a customer might be under duress or following external instructions before a payment is finalized. Behavioral intelligence is emerging as a key technology in this effort, capable of establishing baseline patterns of customer interaction with banking services and identifying deviations during a session. Such anomalies might include unusual hesitation, repetitive actions, or an uncharacteristically large transfer to a new payee.

Eighty-three percent of respondents affirmed the effectiveness of behavioral intelligence in detecting social engineering. Despite this high rating, adoption remains limited, with only eighteen percent of institutions currently utilizing the technology, though more are planning deployments. Behavioral intelligence can augment existing fraud controls by providing contextual insights into unusual interaction patterns, allowing for further scrutiny even when a transaction passes standard technical checks.

The rise of authorized push payment (APP) fraud, where victims are manipulated into initiating transfers to criminals, is also driving regulatory changes. This type of fraud is particularly challenging to detect and recover from because the payment originates from the legitimate account holder. In North America, sixty-nine percent of institutions anticipate regulations mandating reimbursement for APP fraud within the next two years, yet only thirty-one percent currently feel prepared for such requirements. These reimbursement mandates are expected to shift more of the financial burden of scams onto banks and payment providers, necessitating earlier fraud detection to prevent transactions before claims and recovery processes become necessary.

Artificial intelligence (AI) is increasingly being leveraged to streamline post-alert investigations. Fraud investigations often involve analysts gathering information from disparate systems, tracing transactions, reviewing communications, and constructing event timelines. A significant ninety-one percent of institutions believe AI can substantially reduce investigation times. AI applications include connecting related alerts, compiling account activity timelines, and prioritizing cases based on risk. This allows AI to help manage case volumes, direct human analysts to cases requiring complex judgment, and potentially provide more time to freeze funds or coordinate recovery efforts after fraud is detected, while also reducing routine investigative tasks.

There is also a growing convergence between fraud and cybersecurity operations, as both teams contend with common threats like phishing, malware, credential theft, and account takeover. Eighty-one percent of surveyed fraud professionals now report having cybersecurity responsibilities, leading to more integrated workflows for managing fraud and cyber threats. Banks are also collaborating with external providers and participating in fraud intelligence-sharing networks to identify widespread scam campaigns, suspicious accounts, and attack patterns across multiple organizations, all while adhering to data privacy and compliance standards.

A primary challenge remains the early detection of fraud within the payment process. Social engineering often leaves technical signals undisturbed because the legitimate customer is operating their own account. Behavioral signals offer an alternative method to identify potential manipulation during an interaction, shifting focus to customer actions during a session, deviations from established patterns, and the need for bank intervention before a payment is completed.

finance
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates 154 issues (16.3% of all patches) were assigned a critical severity rating Oracle Fusion Middleware received the highest number of patches at 262,

ai

ChatGPT’s new feature could give infostealers a map of your Mac activity

OpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer History does Computer History builds a timeline out of everyday computer use, grouping activity into summaries and noting which apps and websites contributed to each one

breach

Australian hotel chain leaks guests’ PII after breach at third-party database operator

Unknown parties know where you stayed last summer, down under, across 120 Quest properties

security

ISC Stormcast For Wednesday, August 19th, 2026 (Wed, Aug 19th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

nation-state

China-Linked Hacker Shows AI Capabilities in APAC Attack

In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.

ai

OpenAI's overhead will rise 20 percent for some workloads as it hardens security

Expanded multistage chain of thought monitoring makes frontier model work more expensive