Brian Sims
Editor

UK institutions “caught in crosshairs” of sophisticated criminal networks

THE ANNUAL Fraud Report 2026 published by UK Finance highlights a troubling reality: while financial institutions continue to prevent significant volumes of fraud, criminals are becoming more skilled at avoiding scrutiny.

In 2025 alone, criminals stole £1.28 billion through payment fraud, representing a 4% year-on-year increase and the second consecutive year of growth. These figures reflect not only the scale of the threat, but also the adaptability that new technologies afford organised criminal enterprises.

The most important insight from this year’s report is not solely the total loss figure itself, but instead the continued shift in how fraud is perpetrated. As institutions adopt stronger fraud controls, criminals are focusing on exploiting human elements. Through Artificial Intelligence (AI)-enabled social engineering techniques, they manipulate vulnerable customers into authorising payments themselves, thereby bypassing key institutional controls.

This evolution is fundamentally reshaping the fraud landscape. It’s no longer solely a device or transaction monitoring challenge, but increasingly so a customer protection-focused one as well. As such, financial institutions must rethink how they engage with clients, identify behavioural indicators of manipulation and detect Authorised Push Payment (APP) scams before funds leave accounts.

Success will depend on moving beyond traditional approaches and towards more holistic and dynamic models that incorporate consortium analytics and cross-border, cross-sector collaboration.

APP scams on the rise

The 2026 report highlights a growing divergence in fraud typologies. While losses from unauthorised fraud have declined by 5% (totalling £703.4 million gross) and reflecting continued investment in detection and preventive controls, APP scams have grown by 19% (£576.4 million gross).

Fraudsters create prolonged, trust-building interactions to convince victims to initiate payments themselves, such as fake romances and investment schemes. They leverage digital channels, compromised credentials, AI and real-time manipulation to bypass traditional safeguards. They also share resources and playbooks with each other in order to operationalise these scams on a massive and international level.

This presents a structural challenge. Controls designed to detect unauthorised activity are less effective when customers are making an authorised push payment. As a direct result, the industry has entered a new phase: one in which developing an understanding of customer behaviour is just as important as identifying criminal anomalies.

Rethinking fraud prevention

The implications for financial institutions are significant. Success can no longer be measured solely by prevention rates. Expectations from regulators, customers and policymakers are expanding to include faster and more accurate intervention in scam scenarios, improved customer outcomes (including reimbursement and resolution) and more effective collaboration across institutions, sectors and jurisdictions.

Simultaneously, fraud strategies must evolve to address the changing nature of risk mitigation. Financial Institutions need to identify behavioural indicators of coercion, manipulation and deception before a payment is completed. Greater visibility into customer intent, payment context and beneficiary risk can help mitigate losses, notably so where traditional rules-based controls often fall short.

Fraudsters operate across institutions, channels and borders. Effective prevention increasingly depends on shared intelligence and collaborative action.

As reimbursement requirements and customer expectations continue to rise, institutions must be equipped to respond at pace, minimise harm and support victims when fraud does occur. When combined, these priorities point to a broader shift from siloed controls towards a more integrated and intelligence-driven approach to fraud prevention, detection and response.

Building resilience

In order to keep pace with increasingly sophisticated fraud threats, financial institutions need more than incremental improvements: they require a step change in capability. This is where modern anti-financial crime platforms play a critical role, enabling organisations to identify risk earlier and intervene before funds are lost forever.

The Nasdaq Verafin platform deploys consortium analytics to detect fraudulent payments at scale. General Data Protection Regulation-compliant visibility is provided across originators, beneficiaries and international borders to see beyond a given institution’s barriers.

Organisations are able to identify high-risk accounts and payment recipients before funds are sent, detect patterns of co-ordinated fraud activity across networks and borders, recognise social engineering and suspicious customer behaviour and enable earlier and more confident intervention in APP-focused fraud scenarios.

These capabilities help to bridge the gap between how fraud is perpetrated today and how it’s detected, enabling organisations to shift from reactive investigation towards proactive prevention.

As this latest UK Finance report highlights, the fraud landscape will continue to evolve. The institutions that succeed will be those that can adapt just as quickly, combining industry insight and collaborative intelligence with the tools needed to act decisively in near real-time.

*Further information is available online at www.ukfinance.org.uk

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up