
Call for Collaboration
This month’s stories highlight a growing challenge in fraud prevention: the information needed to stop scams is often spread across banks, online platforms, regulators, and customers. From liability debates to intelligence-sharing initiatives, the industry is grappling with the same question: how can organizations prevent fraud they cannot fully see?
1. ThreatMark Named a Leader in QKS Group’s 2026 SPARK Matrix
QKS Group has named ThreatMark a Leader in its 2026 SPARK Matrix for Behavioral Biometrics and Device Intelligence. The assessment evaluates vendors on technology excellence and customer impact, recognizing platforms that help financial institutions detect and disrupt fraud with greater precision.
For fraud teams evaluating their defenses, the placement signals which behavioral biometrics and device intelligence approaches independent analysts consider most effective. The full report includes vendor comparisons and selection criteria to inform that decision.
2. Outcomes of UK Reimbursement Rules
An independent review commissioned by the UK’s Payment Systems Regulator (PSR) found that APP fraud losses through Faster Payments fell by around 21%, equivalent to a reduction of approximately £73 million per year, following the introduction of mandatory reimbursement rules for scam victims. Reimbursement rates increased from 54% before the policy to 65% after implementation.
The review suggests that greater liability has encouraged payment providers to invest more heavily in fraud prevention. However, protections remain uneven, as some APP scam losses still fall outside the reimbursement scheme or are excluded under its rules.
3. ABA Urges Court to Dismiss Zelle Fraud Lawsuit
The American Bankers Association (ABA) has urged a New York court to dismiss a lawsuit against Zelle operator Early Warning Services (EWS), filed by New York Attorney General Letitia James. Yet the case has taken a significant step forward after a judge allowed New York’s fraud claims against EWS to proceed.
Reigniting the debate over who should bear responsibility for scam losses, the lawsuit alleges that EWS failed to adequately protect users from fraud. In its defense, the ABA argues that payment providers cannot reasonably detect or prevent scams that originate through communications they cannot see, such as phone calls, text messages, or social media, reiterating that “technology alone cannot stop scams that develop over time through sustained manipulation.”
The outcome could have broader implications for how liability is assigned in scams where legitimate customers authorize payments under false pretenses. Recent developments in the UK suggest that shifting more liability toward payment providers and incentivizing stronger fraud prevention measures may help reduce losses. After all, the technology to prevent scams already exists.
4. Do US Banks Have the Best View of Scam Activity?
Most Americans report scams to their bank or payment provider—not to government agencies, American Banker reports. Citing the first joint study by Stop Scams Alliance and Gallup, the publication notes that while consumers reported $15.9 billion in scam losses to the FTC, actual losses could reach $68 billion.
The findings suggest banks collectively hold a far more complete picture of scam activity than official datasets, adding fresh momentum to the debate over fraud intelligence sharing and the role banks play in preventing scam losses.
5. ESRB Raises Alarm Over AI-Powered Cyber Threats
The European Systemic Risk Board (ESRB) has warned that frontier AI models are reshaping the cyber threat landscape for financial institutions by enabling cyberattacks that are faster, more scalable, and more sophisticated. The warning comes after the ESRB raised its assessment of systemic cyber risk from “elevated” to “severe” in just three months.
The ESRB argues that addressing these risks will require a coordinated response across the ecosystem, bringing together AI providers, software vendors, security firms, financial institutions, and public authorities.
6. Fraud Victims Increasingly Targeted by Recovery Scams
The US Federal Trade Commission is warning about a growing wave of recovery scams targeting people who have already fallen victim to fraud. Criminals pose as government officials, law firms, or recovery specialists and promise to help victims recover lost funds, usually in exchange for upfront fees or additional personal information.
The approach is enabled by so-called “sucker lists,” which contain information about previous scam victims and can be shared or sold among criminal groups. According to the Identity Theft Resource Center, more than one in four identity crime victims now manage multiple incidents simultaneously.
7. NPCI Pilots AI to Track Stolen Funds Across Banks
India’s National Payments Corporation (NPCI) has launched a pilot using AI to track stolen funds in real time as they move through multiple bank accounts. Rather than focusing solely on detecting suspicious transactions, the system aims to follow illicit funds across institutions, helping banks intervene before the money disappears.
The initiative reflects a broader shift from institution-centric fraud detection toward network-level fraud intelligence, enabling banks to see criminal activity that would otherwise remain fragmented across institutions.
8. Big Tech Platforms Could Be Required to Ban Scam Advertisers in the UK
Facebook, Instagram, Snapchat, X, and YouTube could be required to block bad actors who post fraudulent ads and prevent them from creating new accounts under proposed measures announced by the UK’s communications regulator, Ofcom.
The proposals include reducing the risk of accounts being hijacked and used to host scams, ensuring that ads promoting banking or financial services have the necessary legal authorization, and providing law enforcement with channels for identifying fraudulent advertisements.
The move follows growing criticism that major technology platforms are not doing enough to protect users from scams. The scrutiny intensified after reports that Meta may have generated as much as $7 billion in annual revenue from so-called “high-risk” scam ads displaying clear signs of fraud.
9. Operation First Light Exposes Industrial-Scale FraudAI Becomes the Customer
A realistic replica of a Brazilian police station, complete with fake uniforms, signage, and equipment, was seized in Eswatini during Operation First Light 2026. Used by scammers posing as Brazil’s Federal Police via video call, the elaborate setup helped convince victims they had become targets of a crime and persuaded them to transfer funds to a “safe” account—only for the money to be stolen.
This was just one example uncovered during the global INTERPOL-coordinated operation, which involved 97 countries and territories and led to the arrest of 5,811 individuals and the seizure of $293 million in illicit assets.
The staggering figures highlight the extent to which social engineering fraud has escalated into sophisticated, business-like operations for criminals—and a major transnational threat to everyone else.
10. Fraudsters Shift Focus to What Customers See
ThreatMark has observed an emerging fraud technique: UI manipulation fraud, in which attackers alter or replace information displayed during a legitimate banking session. The goal is to mislead customers into authorizing transactions based on false information presented on their screen, such as fake incoming payments or altered account balances.
The tactic creates a significant challenge for fraud prevention teams because the transaction originates from the legitimate account holder. In that sense, UI manipulation fraud resembles modern APP scams, while also highlighting a familiar pattern in fraud prevention: as one attack path becomes harder to exploit, fraudsters simply start looking for the next blind spot.
Banking Threat Bulletin highlights the stories shaping global fraud prevention and customer protection. Stay informed. Strengthen trust. Protect your customers.