Acoru Blog & Fraud Insights

Fraud prevention trends: lessons from two decades on the front line

Written by Acoru | Mar 31, 2026, 9:45:00 AM

Twenty years of fighting financial fraud leaves you with a particular kind of pattern recognition. That is where we started a recent conversation on our Fraud Signals podcast, when Richard, our Chief Revenue Officer, sat down with Pablo, our co-founder and CEO, to trace fraud prevention from the first phishing campaigns of 2002 through to what generative AI means for the threat landscape ahead.

 

 

The timing turned out to be apt. In its most recent annual report, the FBI's Internet Crime Complaint Center, now in its 25th year of tracking online fraud, crossed a threshold for the first time: more than one million complaints in a single year, with losses reaching $20.9 billion, up 26% on 2024. Two milestones, one conclusion. Fraud prevention has been running for a generation, and the pace has never been faster than it is right now.

This is a rare conversation, with someone who has been in the room for nearly every major shift in the industry and who now believes the sector is overdue for a genuine technological reset.

Key Takeaways

  • Phishing caught everyone off guard. When it emerged in 2002, no vendor had a solution and no playbook existed. Teams had to build their own responses to a threat that lived entirely outside the bank's perimeter.

  • Malware dominated for nearly a decade. Zeus arrived in 2006 and for the better part of eight years, sophisticated malware ran directly on legitimate banking sites, making two-factor authentication far easier to bypass than anyone had anticipated.

  • The best fraudsters operate like businesses. They test techniques in the most complex markets first, then sell the method to others. A proven exploit in one country becomes a template everywhere else.

  • Scams have staying power. Other threat types burned out. Scams have not, and generative AI is about to make them considerably harder to spot and easier to personalize at scale.

  • GenAI is a weapon on both sides of the fight. Faster detection, better adaptability, improved accuracy on the defense. AI-generated video for extortion and self-adapting malware on the offense.

  • Fraud signals appear long before the transaction. Catching scam campaigns requires looking at signals before authorization happens, and following up after. Monitoring the transaction itself is no longer sufficient.

  • By the time fraud hits hard, it is already too late to react. Deploying new technology in financial institutions takes time. Teams that wait for a significant impact before acting could spend years playing catch-up.

Two decades of fraud, in three phases

Phishing caught everyone off guard when it emerged in 2002. No vendor had a solution, and no playbook existed. Fraud teams had to build their own responses to a threat that lived entirely outside the bank's perimeter, often figuring out detection logic from scratch as the emails landed.

Malware dominated for nearly a decade after that. The Zeus banking trojan arrived and, for the better part of eight years, ran directly on legitimate banking sites, making two-factor authentication far easier to bypass than most institutions had anticipated. The threat had moved from the inbox to the session itself.

Scams are different, and they have proven to have more staying power than either of the threats that came before them. Phishing waves and malware epidemics eventually burned out as defences matured. Scams have not, largely because they exploit trust and manipulation rather than a technical vulnerability, and there is no patch for human trust. Generative AI is now making scams considerably harder to spot and easier to personalise at scale, which is why we think this is the moment the industry needs a genuine reset rather than another incremental fix.

The fraud prevention trends defining 2026

Pulling together what we are hearing from fraud leaders and what the latest research shows, six trends stand out for the year ahead.

Trend

What is driving it

What it means for fraud teams

Deepfake and voice-clone social engineering

Generative AI has made convincing audio and video cheap and accessible

Identity verification alone cannot catch a manipulated but authenticated human

Agentic AI as an attack surrogate

Autonomous agents can plan and execute multi-step fraud with little human input

Static rules cannot keep pace with attacks that adapt in real time

Synthetic and first-party identity fraud

Fraudsters blend real and fabricated data to pass onboarding checks

Account risk has to be tracked continuously, not scored once at onboarding

Real-time payments outpacing real-time detection

Faster Payments, FedNow, and instant credit transfers shrink the intervention window to seconds

Detection has to move earlier, into the pre-transaction window

Fraud and AML convergence

Mule networks and laundering infrastructure sit at the intersection of both problems

Siloed fraud and AML teams miss the same underlying account behaviour

Regulation arriving faster than budgets

The UK's APP reimbursement regime, the EU's PSD3, and the US's NACHA rules are landing in close succession

Institutions cannot wait for the next mandate to start building detection maturity

 

Three of those six, deepfake-driven impersonation, synthetic identity creation, and AI agents acting as attack surrogates, were named as the primary attack vectors in a joint paper published in March 2026 by the American Bankers Association, the Better Identity Coalition, and the Financial Services Sector Coordinating Council, built with input from more than 130 experts across financial institutions, regulators, and government agencies. When the industry's own trade bodies converge on the same taxonomy fraud teams are seeing in their own queues, that is a signal worth taking seriously.

For our own read on what 2026 has in store, see fraud in 2026: what to expect, and for how AI-native detection changes the picture, our episode on building AI native fraud prevention for financial institutions.

Fraud operates like a business, and it scales like one too

One of the more counterintuitive points from the conversation: the best fraudsters do not operate like opportunists. They operate like businesses. New techniques get tested in the most complex, highest-value markets first. Once a method is proven, it gets packaged and sold to others, and a working exploit in one country becomes a template everywhere else within months.

Deloitte's Center for Financial Services has put a number on where that franchising model is heading: generative AI could push US fraud losses from around $12.3 billion in 2023 to as much as $40 billion by 2027, a compound annual growth rate of roughly 32%. The most-cited case behind that projection is still the Arup incident from February 2024, in which a finance employee at the Hong Kong office of the UK engineering firm was convinced, on a video call populated entirely by deepfaked executives, to transfer $25.6 million across 15 transactions. The tooling required to run that kind of attack has only gotten cheaper and more accessible since.

It is not only headline-grabbing eight-figure cases. Smaller, quieter versions of the same technique are now common enough that banks are building specific guidance around them. US Bank describes a case where a CFO authorized a $243,000 transfer after what turned out to be an AI-cloned voice call, and notes that in 2026 the FBI added a dedicated section on AI fraud to its annual crime report for the first time, a reflection of how mainstream the technique has become.

Why scams outlasted every other fraud type

Fraud signals appear long before the transaction itself. Catching scam campaigns requires looking at signals before authorization happens, and following up after. Monitoring the transaction alone is no longer sufficient, and has not been for some time.

That is the structural reason scams have outlasted phishing and malware as the dominant threat. A phishing email or a malware infection is a discrete, technical event that a control can be built around. A scam is a weeks-long behavioral process that plays out mostly in channels a bank cannot see directly: a phone call, a messaging app, a social media conversation. By the time a payment lands, the manipulation is already complete.

Generative AI compounds the problem in two ways:

  • It makes the manipulation itself more convincing, through cloned voices and fabricated video, and
  • It makes personalization cheap enough to run at a scale that used to require a large team of human scammers.

Where a fraud crew once had to hand-craft each approach, a single operator can now run hundreds of tailored conversations at once.

Generative AI is a weapon on both sides

The same technology accelerating the attack is accelerating the defense, and the conversation was clear that this is not a one-sided arms race.

Where AI helps the offense

Where AI helps the defense

AI-generated video and voice for impersonation and extortion

Faster detection across larger, noisier data sets

Self-adapting malware that evades static signatures

Better adaptability as tactics shift

Automated, personalized scam scripts run at scale

Improved accuracy, fewer false positives, from account-level context rather than isolated rules

 

Gartner predicts that AI agents will cut the time it takes to exploit an account exposure by 50% by 2027, as automation extends further into account takeover, from deepfake-voice social engineering through to end-to-end credential abuse. INTERPOL's 2026 Global Financial Fraud Threat Assessment puts a similar picture at global scale, estimating $442 billion in financial fraud losses worldwide in 2025 and finding AI-enhanced fraud roughly 4.5 times more profitable than traditional methods. There will not be one silver-bullet defense against that. The institutions closing the gap are the ones building detection that adapts as fast as the attacks do, rather than institutions layering one more static rule on top of the last one.

The shift already underway: signals before the transaction

By the time fraud hits hard, it is already too late to react. Deploying new technology inside a financial institution takes time, procurement cycles, integration work, and staff training. Teams that wait for a significant loss event before acting can spend years playing catch-up on a threat that has already moved on to its next iteration.

The institutions ahead of this curve are the ones that stopped treating the transaction as the moment of truth. Fraud signals, whether it is a behavioral shift in a victim, the setup of a receiving mule account, or the reconnaissance phase of an AI agent probing for exposures, show up well before authorization. We have written before about what that looks like in practice, from payment fraud red flags to how account-level context strengthens existing transaction monitoring rather than replacing it. The regulatory backdrop is reinforcing the same lesson from a different direction.

Money mule infrastructure sits at the center of nearly all of this, since almost every scam eventually needs somewhere for the money to land. We go deeper on that side of the picture in how to detect mule accounts and the different roles of money mules in fraud operations.

What this means for fraud teams right now

Translating two decades of pattern recognition into a working checklist, a few things stand out for teams building their 2026 roadmap:

  • Stop scoring the transaction in isolation. Behavioral drift and mule account setup both leave traces well before a payment is authorized.
  • Treat fraud and AML as one connected picture. The same mule accounts that launder scam proceeds are the accounts AML teams are already trying to classify.
  • Build for adaptability, not just accuracy. A rules engine tuned to last year's scam script will miss this year's AI-personalised version of it.
  • Plan around regulation that is already in motion rather than waiting for the next mandate. The UK, EU, and US are all moving toward some version of shared accountability for authorized fraud, on different timelines but in the same direction.
  • Do not treat collaboration as optional. Generative AI poses a systemic risk. A threat proven against one institution becomes a template against the next one within weeks, which is exactly the dynamic Pablo described from the fraudster's side of the equation.

The future of fraud prevention, according to two decades in the trenches

Twenty years of phishing, malware, and now AI-personalised scams point to one consistent lesson: every major shift in fraud has punished institutions that waited for proof before they acted, and rewarded the ones that built detection ahead of the threat becoming mainstream. Generative AI is not a future problem to plan for eventually. It is already the present one.

That is the thinking behind our Continuous Account Intelligence Platform, built to read accounts as continuous behavioral sequences rather than isolated transactions, so the signals that used to surface only after a loss can be acted on while there is still time to intervene. If fraud is going to keep operating like a business, testing, scaling, and templating its way across every institution it touches, then detection has to move at the same speed, before a transaction is initiated, not after.

Get your demo here.

Frequently asked questions

What are the biggest fraud prevention trends for 2026?

The six we see having the most impact are deepfake and voice-clone social engineering, agentic AI used as an attack surrogate, synthetic and first-party identity fraud, real-time payments outpacing real-time detection, the convergence of fraud and anti-money laundering functions, and a wave of regulation arriving faster than most institutions' budgets can absorb it.

How has fraud changed over the past two decades?

It has moved from discrete technical events to sustained behavioral manipulation. Phishing in 2002 and the Zeus-era malware that followed were built around exploiting a system or a session. Scams, the dominant threat today, exploit trust over days or weeks, largely in channels outside a bank's direct view, which is why transaction-level monitoring alone can no longer catch them.

Is generative AI making fraud worse, or helping fight it?

Both. Deloitte projects generative AI could push US fraud losses to around $40 billion by 2027, and INTERPOL's 2026 assessment found AI-enhanced fraud is roughly 4.5 times more profitable than traditional methods. At the same time, the same technology is improving detection speed, adaptability, and accuracy on the defensive side. The institutions pulling ahead are the ones investing in AI-native detection rather than treating it purely as a threat to defend against.

What is agentic AI's role in fraud, and should fraud teams worry about it?

Agentic AI refers to autonomous systems that can plan and execute multi-step tasks with limited human input. In fraud, that means agents capable of running reconnaissance, personalizing a scam script, and adapting mid-attack without a human operator at every step. Gartner predicts AI agents will cut the time needed to exploit an account exposure by half by 2027, which is a strong argument for detection systems that can adapt in real time rather than relying on static rules.

Why do fraud and anti-money laundering teams need to work more closely together?

Because they are increasingly looking at the same accounts from two different angles. A mule account moving scam proceeds is simultaneously a fraud problem, in that it is the destination for a manipulated payment, and an AML problem, in that it is a step in laundering the proceeds. Siloed teams working from separate systems miss the connections between the two.

How can financial institutions prepare for fraud trends before they hit?

By shifting detection earlier, from scoring individual transactions to continuously classifying account behavior across the weeks that precede a payment. That means connecting signals across channels, tracking behavioral drift and mule account setup as they happen, and building systems flexible enough to adapt as attack techniques change, rather than waiting for a significant loss event to justify the investment.