When customers become the attack surface: Cognitive compromise at scale

Sarah Cassidy examines scams, mules, and the next phase of financial crime as UK Finance confirms criminals stole nearly £1.3bn through payment fraud in 2025

August 07 2026

The most dangerous assumption in financial crime today is that scam risk sits outside the bank. That assumption no longer holds.

The defining change is not that customers initiate scam payments – that has long been the case – but that customer behaviour itself has become the primary attack surface. Ordinary account holders are coached, coerced, or manipulated into initiating payments, receiving funds, opening accounts, and moving money on behalf of criminal networks. In many cases, they believe they are acting legitimately, responsibly, or helpfully, and can be difficult to convince otherwise.

According to UK Finance’s Annual Fraud Report 2026, criminals stole £1.28bn through payment fraud in 2025, representing a 4% increase year-on-year and more than four million reported fraud cases. Fraud now operates on an industrial scale, with authorised scams increasingly driven by manipulation rather than technical compromise.

Behind the numbers is a sobering trend. Every scam that requires technical access to an account is declining. Every scam that requires psychological access to a person is accelerating. This is because fraud prevention systems were designed to detect unauthorised access. Now, they need to identify people who are being tricked in real time.

Scam operations are becoming more professional, more adaptive, and more resilient. They are built to reason their way through established fraud controls and exploit the human layer that sits between digital safeguards and irreversible payments.

We are seeing the systematic exploitation of customer decision-making at scale within fully authorised banking journeys. Once a payment is authorised by the customer, many of the bank’s strongest controls are no longer designed to intervene.

The risks are operational, reputational, and increasingly regulatory. What is needed now is a shift from detecting third-party fraud to designing systems that anticipate human compromise throughout the decision journey and prepare institutions for the next generation of fraud risk.

From incidents to infrastructure

Modern scams behave less like crimes of opportunity and more like distributed systems. Their success depends on orchestration, timing, and scale rather than a single point of failure.

They are not isolated incidents or the work of individual bad actors. They are organised, modular operations designed to scale, adapt, and persist—often mirroring the structure and discipline of legitimate enterprises.

Criminal groups design recruitment funnels to identify persuadable individuals. They refine scripts through testing. They manage mule accounts as inventory, onboarding, monitoring, rotating, and discarding them as needed. Funds are routed through layered pathways designed to frustrate attribution and recovery efforts.

Critically, these operations are designed to interact with bank controls. Rather than simply evading detection, they adapt to it. When warnings appear, scripts change. When transaction limits apply, behaviour adjusts. When one channel becomes harder to exploit, another emerges. Increasingly, criminal networks are leveraging AI tools to test which approaches succeed against particular institutions and to scale those methods rapidly.

The UK’s experience demonstrates how fraudsters continuously evolve their tactics. While losses from invoice scams, mandate scams, CEO fraud, and traditional impersonation scams have declined, purchase scams, investment scams, and romance scams have reached record levels, reflecting the migration of criminal activity toward frauds that rely on human persuasion rather than technical compromise.

These scams are shaped long before any money moves.

Social engineering unfolds across calls, messages, social platforms, dating apps, and investment forums well outside the bank. Financial transactions are often the final execution step rather than the starting point.

Coercion as the primary attack vector

The biggest shift in scams over the past two years is the extent to which psychological coercion now scales through technology.

Generative AI has significantly increased the sophistication of impersonation and deception. Fake investment opportunities, fraudulent job offers, account security scams, and long-running romance frauds are becoming more convincing, more personalised, and more profitable.

According to the UK Finance report, investment fraud alone generated more than £221m in losses during 2025. A 40% increase from the previous year, this makes it one of the fastest-growing categories of authorised fraud. Industry leaders increasingly point to AI-enabled deception as a major factor in this growth. And what makes these cases particularly difficult is not ignorance, but conviction. Victims often understand that scams exist. They simply believe the interaction they are experiencing is legitimate.

This presents a profound challenge for financial institutions. The earliest indicators of scam involvement rarely appear as clear transactional anomalies. Instead, they emerge as behavioural inflection points: hesitation, repeated overrides of warnings, unusual device interactions, inconsistent narratives, escalating urgency, or significant changes in payment behaviour over time.

The challenge is increasingly one of identifying cognitive compromise before financial harm occurs.

The next 12 months: Intervention becomes the measure of competence

The coming year will be a decisive period for fraud and scam leaders. Success will be defined less by how quickly institutions can respond after suspicion emerges and more by how early they are prepared to intervene.

Real-time payments and near-instant settlement leave little room for deliberation. In this environment, waiting for certainty is becoming increasingly incompatible with effective harm prevention, regulatory expectations, and customer protection.

Financial institutions now need to:

  • Detect customer intent before payment authorisation
  • Identify behavioural anomalies in real time
  • Collaborate with risk teams and across the enterprise
  • Use AI with more sophistication than fraudsters, making customer-centric decisions with full explainability
  • Prepare for the next wave of fraud threats, with agentic-led interactions and prevention technology

This challenge is becoming more urgent as fraud increasingly originates beyond traditional banking channels. UK Finance reports that many authorised frauds now begin on online platforms, messaging services, and telecommunications networks, highlighting the need for stronger cross-sector accountability and collaboration.

The mandate for fraud leaders

Increasingly, the customer experience is where the fight against fraud will be won or lost.

As criminals shift from system compromises to human exploitation and from opportunistic or physical fraud to organised fraud ecosystems, the financial services industry needs to move from isolated and point-level solutions to shared ecosystems and platforms that can receive and share insight across multiple use cases and sources. This enterprise approach is vital.

The choices made over the next few years—around early intervention, behavioural intelligence, cross-sector collaboration, and the responsible use of advanced analytics—will determine whether trust in digital financial systems strengthens or erodes in the face of increasingly sophisticated criminal operations.

Sarah Cassidy, senior fraud consultant at FICO

Uncover your next opportunity with expert reports

Steer your business strategy with key data and insights from our latest market research reports and company profiles. Not ready to buy? Start small by downloading a sample report first.

Newsletters by sectors

close

Sign up to the newsletter: In Brief

Visit our Privacy Policy for more information about our services, how we may use, process and share your personal data, including information of your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.

Thank you for subscribing

View all newsletters from across the GlobalData Media network.

close