Skip to content
The Cyber Security Place

Money

The fraud that passes every check

Banks have become extremely good at stopping somebody pretending to be you. They have almost no answer to somebody persuading you to pay them yourself.

Last reviewed August 30, 2026

Two figures from one year tell the story. Losses from impersonation fell about 5% to £703.4m, with roughly £1.68bn prevented — near 70 pence in every attempted pound. Losses where the customer was talked into paying rose 19% to £576.4m across 248,070 cases, now 32% of the total. Every identity check passes, because the payer really is the payer. What changed behaviour was not a control but a rule: mandatory reimbursement within five working days, with the receiving institution paying the sender half. Banks repaid £354.3m, some 61% of those losses. That single provision gave the institution receiving stolen money a reason to care about the account it had opened, which decades of guidance had never managed to supply.

How much friction is the right amount?

There is no correct answer, only a chosen one. Move the setting and watch two quantities climb together — crime stopped, and honest customers stopped.

What each level of friction stops, and what it costs
FrictionImpersonation stoppedPersuasion stoppedGood payments blocked
None12%0%1 per 1,000
Light48%2%6 per 1,000
Moderate70%9%24 per 1,000
Heavy86%24%78 per 1,000
Severe93%41%190 per 1,000
None
A password, and nothing else. Nothing at all. Payments leave instantly and so does anybody else's.
Light
A one-time code for unfamiliar payees. A brief pause the first time you pay somebody new. Most people barely register it.
Moderate
Device checks, behavioural signals, and a name check against the account. Occasional declines while travelling, and a warning when the payee name does not match.
Heavy
Delays on first payments, callbacks above a threshold, questions about the purpose. Payments held for hours. Somebody telephones to ask why you are sending money.
Severe
Manual review of anything unusual, plus a cooling-off period. Roughly one payment in five is interrupted. Customers begin moving to another bank.

A model of the shape, not any particular bank. The one anchored figure is the top of the impersonation column: the industry stopped roughly 70 pence of every pound of attempted unauthorised fraud in 2025.

The third column carries the point. At the setting that matches observed industry performance against impersonation, the same machinery is roughly 7.8 times less effective against persuasion. That gap does not close by adding checks, because the checks are asking whether the customer is genuine and the answer keeps coming back yes.

Two curves going opposite ways

A single year of reported payment crime, in millions of pounds.

Impersonation losses, falling£703.4mPersuasion losses, rising£576.4mImpersonation prevented£1680m

The prevented figure dwarfs both loss bars, which is the part rarely reported. An industry that stops seven pounds in ten of what is thrown at it is not failing; it is succeeding at one problem while a second one grows behind it. Reporting that quotes only the losses describes a defeat, and reporting that quotes only the prevention describes a victory. Both are the same year.

Why do the defences stop working at the last step?

Nearly every control in this field answers one question: is the person doing this the person entitled to do it. Passwords, codes, device recognition, behavioural signals and biometrics are all elaborate ways of asking it, and the industry has become very good at asking.

A persuasion scam does not contest that question. The customer is genuine, the device is familiar, the location is normal, the behaviour matches the pattern, and the person typing has full authority over the account. Everything the system knows how to check is exactly as it should be. What is wrong is a belief inside somebody's head about who they are paying and why, and no authentication technology examines beliefs.

This explains a fact the numbers make obvious and the coverage rarely draws out: the two categories moved in opposite directions in the same year, under the same institutions, with the same technology budgets. Criminals did not become more capable at breaking authentication. They stopped trying, because the other route works and costs a telephone call.

The interventions that do help are therefore strange-looking. Confirming the payee name against the account is not authentication; it is contradicting a false belief. Delays exist to create room for doubt. A question about the purpose of the payment is, in effect, an invitation to notice something is wrong. All of these are attempts to interrupt a conversation happening elsewhere, which is an unusual thing for a payment system to be doing and the only category of measure with any traction.

The rule that moved more than any product

For years the position was that a payment the customer authorised was the customer's responsibility. That is legally tidy and it produced an outcome nobody defends: the person least equipped to detect a sophisticated deception carried its entire cost, while the institutions with the data to spot it carried none.

The United Kingdom regime that replaced it does two things. Victims are reimbursed within five working days in most cases, subject to limits and to an exception for gross negligence. And the cost is divided equally between the institution that sent the payment and the institution that received it — the receiving side pays the sending side half of whatever was repaid.

That second half is the interesting engineering, and it is economic rather than technical. Before it, the bank hosting the account into which stolen money landed had no financial stake at all: the loss sat elsewhere and the account was, from its perspective, an ordinary customer. Splitting the bill gave it a stake overnight, and the visible consequences have been tighter account opening, faster freezing of suspicious receiving accounts, and information sharing between institutions that had previously been discussed for years without happening.

It is worth putting beside a finding from elsewhere on this site. In healthcare, when an attack on one hospital lands harm on its neighbours, no regulation, liability or insurance reaches the neighbour, so the party best placed to reduce the damage has the least reason to spend. Payments had precisely that structure and legislated its way out. The mechanism is not sector-specific; the willingness to build it was.

What happened to card fraud?

This archive carries 121 entries mentioning cards, most of them from the years when a stolen card number was the standard currency of online crime. Retail breaches were reported by the million-record, and the numbers moved through markets with published prices.

That economy was substantially dismantled, and it is one of the field's few unambiguous wins. Chip authentication removed the value of copying a magnetic stripe. Tokenisation meant the number a merchant stores is useless anywhere else. Issuer-side scoring turned an unusual transaction into a declined one within milliseconds. None of it made theft impossible; all of it made stolen numbers cheap, and cheap goods attract less effort.

Criminal attention moved accordingly, and it moved toward transfers. A bank transfer is instant, effectively irreversible, unlimited in a way a card is not, and — most usefully — performed by the victim. The category that grew is precisely the one where the industry's accumulated defensive technology has the least to say, which is not a coincidence but a market finding its way to the softest available surface.

The lesson generalises past finance. Hardening a mechanism does not reduce crime; it relocates it, and where it lands is determined by which adjacent route is now easier. Anyone celebrating a control that worked should be asking what the same criminals are doing instead, because the answer is rarely nothing.

Being harder to break is no longer the whole test

Financial regulation has spent a decade adding a second question alongside prevention. Supervisors now ask whether important services keep running through disruption: institutions identify which services matter, set tolerances for how long they may be unavailable, and demonstrate they can stay inside them.

That reframing changes what counts as a security investment. A control that reduces the chance of an incident and a capability that shortens its duration are equally creditable, and the second has historically been much harder to fund. It also forces an uncomfortable admission into the open: some disruption will occur, and the question is how long, not whether.

Concentration is where the reframing bites hardest. A handful of providers underpin payments, market data, hosting and clearing across most of the industry, so an outage at one is a sector event rather than a firm event. Regulators have started treating those suppliers as systemically important in their own right, which amounts to conceding that no individual institution can manage the exposure by choosing a better contract.

For smaller firms the practical form of all this is unromantic. Know which services you could not be without for a day, know who actually provides them underneath the brand on the invoice, and know what you would do for the day they are gone. Most organisations discover during the outage that two of their suppliers depend on the same third one.

What synthetic voices changed

The deception described above has always depended on a persuasive human. The constraint on volume was therefore the number of persuasive humans available and the hours they could spend on the telephone, which is why these operations historically looked like small businesses with rotas and scripts.

Generated speech removed that ceiling. A cloned voice needs seconds of source material, which a public video or a voicemail greeting supplies, and it can hold a conversation in the accent and cadence the target expects. The same tooling drafts the accompanying messages without the spelling errors that once served as a warning, in whatever language the target reads, at whatever hour suits.

What this changes is not the trick but its economics. An approach that previously justified the effort only for a large target now pays at any size, and the practised advice to look for awkward phrasing has quietly stopped working. Industry reporting for the most recent year attributes part of the rise in deception losses directly to this shift, and it is the one part of the picture where the underlying capability is still improving rapidly.

The countermeasure is unchanged and slightly humbling: verify through a channel the caller did not choose. A voice is no longer evidence of identity, which was true of written words twenty years ago and is now true of speech. Families and finance teams that agree a shared question in advance, to be asked when money is discussed, are using the only defence that survives a perfect imitation.

The version that empties company accounts

Consumer scams draw the coverage because there are millions of them. The larger individual sums leave businesses, through a technique so plain it barely deserves a name: somebody changes the bank details on an invoice.

The setup varies and the ending does not. An attacker reads a mailbox for weeks, learns which supplier invoices monthly and for how much, waits for a genuine invoice to appear, and sends a follow-up from a lookalike domain apologising for a change of account. Or they skip the intrusion entirely and simply write to accounts payable with a plausible letterhead. Either way the payment is made by an employee with authority, from a genuine device, to a supplier the company really uses.

Nothing in the payment stack objects. The transfer looks exactly like the twelve previous ones except for the destination, and the destination is a field the company itself just changed. The discovery usually comes weeks later, when the real supplier asks about a missing settlement, by which time the money has moved through several accounts and out.

The defence is a phone call to a number the company already held, never the one on the letter requesting the change. It costs thirty seconds, it defeats the entire technique, and it fails only where the finance team has been trained to treat supplier requests as routine administration. Firms that write that rule down, and make it acceptable to enforce it against a senior person in a hurry, stop losing money this way. The ones that rely on staff being careful keep paying.

Where does the money actually go?

Stolen funds have to land somewhere, and that somewhere is an account at a regulated institution held by a person with a name. Understanding what happens next explains why the receiving leg became the focus of both the rules and the enforcement.

Most receiving accounts belong to a real individual who agreed to let their account be used. Some are recruited with an advertisement promising easy money; some are students, or people in debt, or newly arrived and short of options; and a proportion are themselves victims of a separate deception. Once money arrives it is moved rapidly through several such accounts and across borders, which is why recovery falls away sharply after the first hours.

This is why speed matters more than sophistication in the response. An account frozen within the hour frequently still holds the funds; the same account examined the next morning does not. It also explains the pressure on account opening: a receiving account has to be opened before it can be used, and the checks at that moment are the cheapest place in the whole chain to intervene.

The human dimension deserves stating plainly, because the industry language does not. People who let their accounts be used commit an offence and frequently lose banking access for years, which is a serious consequence for someone who answered an advertisement at nineteen. The institutions that handle this well distinguish the organiser from the recruited, and the ones that do not simply exclude a population that was already on the edge of the financial system.

What an individual can usefully do

Most advice given to consumers about this is either unhelpfully vague or quietly blames them. Three habits genuinely reduce exposure, and none of them requires vigilance sustained over years.

Treat any unexpected contact about money as false until proven otherwise, and verify by contacting the organisation yourself using a number you already had — from a card, a statement, the back of a letter. Deception in this category depends entirely on the target using the channel the criminal supplied. Hanging up and dialling independently ends almost every version of it, and no legitimate institution is harmed by being called back.

Slow down for anything urgent. Urgency is not incidental to these approaches; it is the mechanism, because the deception cannot survive an hour of ordinary reflection. A bank will wait. A tax authority will wait. An investment that cannot wait until tomorrow is telling you something useful about itself.

And know the reimbursement position before needing it. In the United Kingdom most victims are repaid within five working days, which is a genuine protection and not an unconditional one — there are caps, an exception for gross negligence, and different treatment for payments to accounts you control yourself, which is how many cryptocurrency deceptions are structured. Somebody who knows this in advance reports faster and argues better, and speed is the variable that determines whether the funds are still there.

Can these numbers be trusted?

They are among the better statistics in this field, because they come from institutions counting money that actually left accounts rather than from a survey asking people how worried they feel. That does not make them complete, and the gaps run in one direction.

Only reported cases appear. Somebody who loses a modest sum and decides the embarrassment outweighs the recovery odds is invisible, and shame is a documented feature of this crime rather than an incidental one. The figures also cover regulated payment channels, so a transfer made in order to buy cryptocurrency is counted at the moment it leaves the bank while everything that happens afterwards falls outside entirely — which is how a substantial category of loss becomes a single small entry.

There is a definitional edge too. Whether an approach is recorded as a scam or as a commercial dispute can turn on how the victim describes it, and the boundary between a fraudulent investment and a very poor one is drawn by people applying judgement under time pressure. Reasonable institutions classify the same event differently.

None of which undermines the comparison this page rests on, because the two categories are counted by the same organisations under the same definitions in the same year. The direction of each — one falling, one rising by a fifth — is far more robust than either absolute total, and it is the direction that carries the argument.

Common questions

What is authorised push payment fraud?

A scam where the account holder is persuaded to send the money themselves, usually after a convincing conversation about an invoice, an investment, a romance or a supposed bank security team. Because the payment is genuinely authorised by the genuine customer, every check designed to confirm identity passes.

How large are payment losses now?

Reported United Kingdom losses across all payment crime came to roughly £1.3bn in 2025 across more than four million cases. Of that, £703.4m came from unauthorised transactions and £576.4m from authorised ones, the latter representing about 32% of the total.

Is banking security getting better or worse?

Both, in different places. Unauthorised losses fell about 5% while attempts rose, and the industry prevented some £1.68bn — roughly 70 pence of every pound attempted. Over the same period authorised losses climbed 19%. The defences work where they can test identity and struggle where identity is not the question.

Who pays when somebody is tricked into transferring money?

Under the United Kingdom reimbursement regime the customer is repaid within five working days in most cases, and the cost is split evenly between the two institutions: the receiving provider pays the sending provider half. In 2025 banks reimbursed £354.3m, about 61% of authorised losses.

Why does it matter that the receiving bank pays half?

Because before that rule the institution hosting the account that received stolen money had no financial reason to care. Splitting the bill created one, and the visible consequence has been far more attention paid to how accounts are opened and how quickly a suspicious receiving account is frozen.

Does more security friction reduce fraud?

Against impersonation, substantially. Against persuasion, much less, because the customer passes every check by construction. Friction also has a cost that grows faster than its benefit: at the strictest settings a meaningful share of legitimate payments is interrupted and customers move elsewhere.

Why is card fraud less discussed than it used to be?

Because it was largely engineered down. Chip authentication, tokenised card numbers and issuer-side scoring made mass card compromise far less profitable, which pushed criminal effort toward transfers, where the money moves instantly and irreversibly and the victim performs the action.

Are financial firms actually attacked more than other sectors?

They are targeted more and breached comparatively less. Decades of regulation, examination and spending have made them harder than most industries, which is why criminal attention has shifted from breaking into the institution toward deceiving its customers — the softest remaining surface.

What is operational resilience regulation about?

It asks a different question from security regulation: not whether you can prevent an incident but whether important services keep running through one. Firms are required to identify those services, set tolerances for disruption, and demonstrate they can stay within them, which reframes the conversation from prevention toward continuity.

How does concentration risk apply to finance?

A small number of providers underpin payments, market data, cloud hosting and clearing for a large share of the industry, so an outage at one is a sector event rather than a company one. Regulators have begun treating those suppliers as systemically important, which is an admission that the individual firm cannot manage the exposure alone.

What should a small business do to protect its payments?

Verify changes to bank details by calling a number you already had, never one supplied in the message requesting the change. Invoice redirection is the commonest way businesses lose large sums, it survives every technical control, and a thirty-second phone call defeats it.

Can a cloned voice really fool somebody?

Reliably, and the material required is trivial — seconds of speech from a public video or a voicemail greeting. What changed is the economics rather than the technique: an approach that once justified the effort only against a large target now pays at any size, and the old advice to listen for awkward phrasing has stopped working. Verify through a channel the caller did not choose.

Why do banks freeze accounts so aggressively now?

Because speed determines recovery. An account frozen within the hour often still holds the money; the same account looked at the following morning does not. The reimbursement rules gave receiving institutions a direct financial stake in acting fast, and the visible side effect is more legitimate accounts being interrupted while somebody checks.

Are cryptocurrency losses counted in these figures?

Generally not. Payment fraud statistics cover regulated payment channels, so a transfer made to buy cryptocurrency appears as an authorised payment while anything happening afterwards falls outside the reporting. The published totals therefore understate consumer losses rather than overstating them.

Money and payments in the archive

507 entries, peaking in 2015 with 123. 49 mention fraud and 47 mention mobile.