Skip to main content
When 65% Growth Meets $20 Billion in LossesFraud Typologies
4 min readFor Fraud Risk Managers

When 65% Growth Meets $20 Billion in Losses

The Challenge

Between 2024 and 2025, financial institutions saw a 65% year-over-year increase in scam volume. This surge overwhelmed investigation teams, strained customer service, and left fraud departments struggling with limited resources.

The issue wasn't just the volume. Purchase scams rose 14%, while romance and investment scams spiked. Phishing variants like smishing spread across SMS channels. The only decline was a 15% drop in impersonation scams, thanks to targeted awareness campaigns and tighter controls.

Despite this success, scams still affected 22 million victims, causing $20 billion in losses, according to Javelin Strategy & Research. Financial institutions faced a pressing question: how to build a dedicated scam prevention program without regulatory mandates and an ever-expanding attack surface?

The Environment and Constraints

In the U.S., financial institutions operate in a market-driven regulatory environment without federal mandates for scam prevention. Unlike the UK, which has loss-sharing requirements, U.S. institutions must independently decide on investing in scam mitigation.

This decision is complex. Scams result in both authorized losses (customer-approved transactions under manipulation) and unauthorized losses (account takeovers, stolen credentials). Each case requires manual investigation, tracing transactions, contacting receiving institutions, and documenting outcomes for potential reimbursement.

Costs extend beyond direct losses. Customer attrition is significant when victims leave, often taking life savings. Replacing these customers is costly, shrinking deposit portfolios and reducing profitability.

Cybercriminals have adopted generative AI faster than financial institutions can build defenses. Phishing emails are now grammatically correct, and deepfake audio scams are convincing. While institutions deploy AI in customer-facing tools, criminals exploit these systems.

Financial institutions struggle to keep pace with attackers. Compliance, data privacy, and governance slow AI adoption on the defensive side, while criminals face no such constraints.

The Approach Taken

Some institutions looked to international models. Australia implemented proactive scam prevention measures without waiting for regulation. Banks there deployed technology and process controls to protect customers before losses occurred.

The UK enforced loss-sharing between institutions, creating financial incentives to prevent scams at both origination and destination points.

U.S. institutions couldn't directly adopt these models due to a fragmented banking landscape and regulatory structure. Leading banks began building their own frameworks, recognizing scams as more than just a fraud problem.

The shift involved treating scams as an ecosystem threat. Mule accounts, where scam proceeds land, became a focus. Identifying and freezing these accounts quickly disrupts the scam lifecycle. This requires monitoring for patterns like rapid deposits followed by immediate transfers, synthetic identities, and dormant accounts suddenly activated for high-velocity transactions.

Some institutions formed industry task forces to share scam intelligence. Others invested in behavioral analytics platforms to flag unusual customer actions. A few piloted AI-driven detection models trained on known scam patterns.

The most critical step was executive commitment. Banks that made scam prevention a key performance indicator (KPI) at the highest levels allocated budgets, hired specialized staff, and integrated scam detection into existing fraud operations.

Results and Metrics

The 15% decline in impersonation scams showed that targeted intervention works. Increasing customer awareness about government agency impersonation and implementing stricter verification for high-risk transactions reduced this specific scam type.

However, the overall problem remains significant, with $20 billion in losses and 22 million victims. Purchase, romance, and investment scams continue to grow despite efforts.

The gap between effective focused controls and the need for comprehensive coverage defines the current state. Institutions with dedicated scam programs improved investigation efficiency and mule account identification but haven't yet achieved systematic prevention to materially reduce losses.

What They'd Do Differently

Institutions that acted late realized they should have responded when scam volumes first increased, not after losses became significant. Waiting for regulatory mandates meant losing valuable time for learning and control development.

Technology investments should have been made earlier. Behavioral analytics platforms need training data and tuning periods to deliver reliable signals. Starting this process late means always being behind the attack curve.

Cross-institution information sharing needed formal structure from the start. Standardized scam typology databases and real-time mule account registries could have prevented duplicate losses.

Organizational structure matters. Institutions that embedded scam prevention within existing fraud teams faced competing priorities. Those that created dedicated scam operations units moved faster and achieved better outcomes.

Takeaways for Your Team

If you're building a scam prevention program now, start with executive alignment. Make scam mitigation a board-level KPI. Without this commitment, you won't have the budget or authority to implement effective controls.

Focus on mule account detection. Build monitoring rules for rapid deposit-and-transfer patterns, synthetic identity indicators, and dormant account reactivation. Coordinate with other institutions to share mule account intelligence.

Invest in behavioral analytics to flag customer actions inconsistent with normal patterns. Investigate transactions like a customer who’s never used P2P payments suddenly sending $10,000 to a new contact before completion.

Don't wait for AI solutions to mature. Deploy controls you can implement today: transaction velocity limits, mandatory cooling-off periods for high-risk transfers, enhanced verification for new payees, and friction-based interventions to give customers time to reconsider.

Learn from the impersonation scam decline. Targeted awareness campaigns work when paired with specific controls. Identify which typologies affect your customer base most and build focused prevention programs for those threats first.

The 65% growth rate won't reverse on its own, nor will the $20 billion loss figure. Your institution must build dedicated scam prevention capabilities now or continue absorbing losses while customers leave for banks that offer better protection.

You Might Also Like