Aug
Why Fraud Losses Keep Increasing: What Finance Leaders Must Know
TL;DR:
- Fraud losses are increasing due to the expansion of digital transaction volume and AI-driven criminal operations. Most organizations still rely on outdated detection systems that cannot keep pace with evolving threats. Strengthening identity verification at onboarding and adopting adaptive, signal-rich controls are key to reducing future losses.
Fraud losses are rising because digital transaction volume has outpaced identity infrastructure, generative AI has industrialized criminal operations, and most organizations are still running detection systems built for a slower, simpler threat environment. INTERPOL estimates global financial fraud losses at USD 442 billion in 2025 alone, and the trajectory is upward. The FTC reported that U.S. consumers lost more than $10 billion to fraud in 2023, the first time that threshold was crossed. Meanwhile, TransUnion’s 2026 data shows a significant share of U.S. consumers reported a monetary loss from digital fraud, with a notable median individual loss of $2,307.
This article covers three things in sequence:
- Trends: Where losses stand now, which channels are growing fastest, and why reported figures undercount total harm
- Drivers: The technical, economic, and organizational forces that are actually causing the increase
- Controls: Prioritized, measurable steps to reduce losses and the governance structures that make them stick
Table of Contents
- Why fraud losses keep increasing: what the numbers actually show
- What is actually driving the increase in fraud losses
- Where fraud is happening and which types cause the most damage
- Why traditional detection is failing to keep pace
- Prioritized controls that measurably reduce fraud losses
- How to measure fraud costs and present them to leadership
- What will drive fraud trends next and where to invest now
- Key Takeaways
- The fraud control gap is wider than most programs acknowledge
- Useful sources
- FAQ
Why fraud losses keep increasing: what the numbers actually show
The scale of the problem is not in dispute. What is still underappreciated is how quickly the composition of losses has shifted and how large the detection gap has become.
Experian’s 2026 commissioned study found that 64% of businesses in EMEA and APAC reported rising fraud losses, with 68% acknowledging their current fraud technology cannot keep pace with attack velocity. That technology gap is itself a driver: when defenses stagnate, criminal ROI improves, which funds more sophisticated operations.
Card-not-present (CNP) fraud continues to dominate e-commerce loss figures, but the fastest-growing exposure is now in real-time payment rails, where instantaneous settlement eliminates the post-authorization window that legacy chargeback processes depend on. Social-engineering losses, including authorized push payment (APP) scams, have grown sharply as generative AI lowers the cost of producing convincing voice clones and synthetic correspondence.
Reported figures also structurally undercount total economic harm. Analysts consistently note that organized crime and fraud-as-a-service ecosystems generate losses that are either never reported by victims (due to shame or complexity) or are absorbed as operational costs by businesses that treat them as a cost of doing business rather than a recoverable incident. The real number is larger than any single dataset captures.
| Metric | 2023 | 2024 | 2025 | 2026 (H1) |
|---|---|---|---|---|
| U.S. consumer fraud losses (FTC) | $10B+ | Not yet published | — | — |
| Median U.S. consumer digital fraud loss | — | — | — | $2,307 |
| Global financial fraud losses (INTERPOL) | — | — | $442B est. | — |
| Businesses reporting rising fraud losses (Experian, EMEA/APAC) | — | — | — | 64% |
| Businesses saying fraud tech cannot keep pace (Experian) | — | — | — | 68% |
The table above reflects sourced figures only; cells without a published figure are left blank rather than estimated.
What is actually driving the increase in fraud losses
The causes of rising fraud losses are not mysterious. They are the predictable result of specific structural shifts that most organizations have been slow to counter.

Digital adoption without commensurate identity infrastructure. Every new payment rail, marketplace, and onboarding flow expands the attack surface. CNP transaction volume has grown faster than the identity-proofing controls layered on top of it, leaving gaps that credential-stuffing bots and synthetic identity schemes exploit at scale. Frictionless UX, a legitimate product goal, often means weaker verification at the exact moment criminals are most active: account creation.
Identity gaps at onboarding. Synthetic identity fraud, where criminals combine real and fabricated data to create a plausible but fictitious person, thrives when KYC processes rely on static document checks rather than behavioral and biometric signals. Criminals “move upstream,” establishing fraudulent accounts during onboarding rather than attacking existing ones, because upstream defenses are typically weaker and the downstream payoff is larger.
Generative AI and automation. This is the most consequential recent shift. GenAI has made it economically viable to produce deepfake video and audio for social engineering, to generate synthetic identity documents that defeat optical character recognition checks, and to run credential-stuffing campaigns at a volume and velocity that overwhelms rate-limiting controls. TransUnion’s H1 2026 report specifically identifies GenAI as enabling greater scale across stolen card schemes and identity theft.

Fraud-as-a-service professionalization. Criminal networks now operate with the organizational discipline of software vendors: modular toolkits, subscription pricing, customer support, and continuous product updates. The barrier to entry for a new fraud operator has fallen dramatically, which means the volume of attacks is growing even as the sophistication of individual actors varies widely.
Economic and contextual pressure. Higher remote commerce volumes, sustained inflation, and financial stress increase the pool of susceptible targets for social-engineering schemes. Impersonation scams and investment fraud perform better when targets are under financial pressure and less likely to pause and verify.
Pro Tip: Map your top three fraud loss categories by dollar volume, then score each by likelihood of recurrence and cost to prevent. That matrix, not a general “fraud is bad” narrative, is what gets budget approved at the CFO level.
Where fraud is happening and which types cause the most damage
Understanding the channel-level distribution of fraud is what separates a targeted defense from a generic one. The major fraud types active in the U.S. market today each have distinct damage profiles and preferred channels.
- Card-not-present (CNP) fraud: Unauthorized use of card credentials in e-commerce transactions where the physical card is not verified. Losses scale with transaction volume and are concentrated in high-velocity retail and digital goods categories.
- Synthetic identity fraud: Fabricated or blended identities used to open accounts, build credit, and then “bust out.” Damage is often deferred and difficult to attribute until the account defaults.
- Account takeover (ATO): Credential stuffing, SIM swapping, or phishing used to gain control of existing accounts. Damage is immediate and often includes both financial loss and downstream identity misuse.
- Authorized push payment (APP) scams: Victims are socially engineered into authorizing payments to criminal-controlled accounts. Real-time rails make recovery nearly impossible once funds move.
- Friendly and chargeback fraud: Customers dispute legitimate transactions, either opportunistically or as part of organized refund abuse. Merchants absorb the chargeback fee plus the lost goods.
- Merchant fraud: Fraudulent merchants onboarded to payment networks who process transactions and disappear before chargebacks arrive.
Channel mapping matters because defenses need to be positioned where losses actually occur. E-commerce and marketplace platforms carry the highest CNP exposure. Social platforms and messaging apps are the primary vector for APP scams and investment fraud. Real-time payment rails, including FedNow and RTP, create irreversibility risk that legacy fraud controls were not designed to handle. Mobile apps are the primary ATO surface, particularly where push notification authentication has replaced stronger device-binding controls.
ACI Worldwide, a major voice in payments infrastructure risk, has consistently highlighted that the shift to real-time rails fundamentally changes the fraud calculus: the settlement finality that makes instant payments valuable to consumers is the same property that makes recovery from fraud on those rails structurally difficult.
Verticals with concentrated exposure include fintech lenders and neobanks (synthetic identity and ATO), gaming and digital goods platforms (CNP and account fraud), and crypto exchanges and marketplaces (investment scams and wallet takeover). For deeper coverage of banking and fintech fraud dynamics, Fraud Signals News tracks these verticals continuously.
Why traditional detection is failing to keep pace
Legacy fraud detection was designed for a world where transactions were slower, attack patterns were more predictable, and the volume of events was manageable by human review teams. None of those conditions still hold.
- Rules-only systems generate unsustainable false-positive rates at modern transaction volumes. A rule written to catch a fraud pattern from 18 months ago will flag legitimate customers today while missing the evolved variant of the original scheme. Manual review queues become backlogs, and backlogs become write-offs.
- Data silos prevent detection of multi-stage schemes. A synthetic identity fraud ring may touch a credit bureau, a neobank, a telecom provider, and a marketplace before the loss crystallizes. No single organization sees the full pattern. Without cross-industry intelligence sharing, each institution is solving a fragment of the puzzle.
- Real-time rails eliminate the post-authorization window. Chargeback and recall processes were built for batch settlement environments. Instantaneous settlement on FedNow or RTP means that by the time a suspicious transaction is flagged, the funds are already in a mule account.
- ML models degrade without continuous retraining. A model trained on last year’s fraud patterns will drift as criminals adapt. Organizations that deploy ML once and treat it as a static control are not getting the benefit they think they are.
- Staffing and investment allocation are mismatched. Experian’s 2026 data shows 71% of businesses are investing more in fraud technology than in human analysts, yet the technology gap persists. The issue is not the ratio; it is that many organizations are investing in the wrong technology or deploying it without the operational processes to act on its outputs.
COSO’s enterprise risk management principles make the same diagnosis at a governance level: prevention alone is insufficient. Effective programs integrate prevention, detection, and response under a unified governance framework, with defined escalation paths and measurable tolerances. Most organizations have prevention controls. Far fewer have a documented response playbook that empowers analysts to act without committee approval during an active incident.
Pro Tip: Define a fraud appetite statement with a specific, numeric threshold (for example, accept up to 0.1% fraud rate on card transactions before triggering escalation). Without a number, every incident becomes a judgment call, and judgment calls under pressure default to inaction.
Prioritized controls that measurably reduce fraud losses
The most effective fraud programs share a structural characteristic: they are layered, identity-centric, and governed by explicit KPIs rather than qualitative assessments. Here is how to build that program.
Start with identity at onboarding
The highest-ROI intervention in most fraud programs is strengthening identity proofing at account creation, not adding more rules to transaction monitoring. Synthetic identity and ATO both exploit weak onboarding. Biometric liveness detection, document authenticity verification, and behavioral signals at registration catch manipulation before it becomes a downstream loss event. DAON is a recommended identity technology option for organizations evaluating biometric and identity verification platforms; its architecture is designed specifically to move detection upstream to the onboarding layer. For a detailed treatment of how biometric controls reduce bank fraud, see Fraud Signals News’s guide to biometrics and bank fraud reduction.

Deploy ML with a retraining cadence
Experian’s Forrester-commissioned data shows 67% of ML users report measurable improvements in detection accuracy, and 54% cite real-time detection as ML’s primary advantage over rules-based systems. The operative word is “users”: organizations that deploy ML models and then leave them static do not sustain those gains. Build a quarterly retraining cadence tied to your product release schedule, and instrument analyst feedback loops so that false-positive and false-negative decisions feed back into model improvement.
Implement event-level scoring and adaptive authentication
Transaction-level risk scoring, combined with adaptive authentication that escalates friction only when the score exceeds a threshold, reduces both fraud losses and false-positive friction for legitimate customers. Device fingerprinting, behavioral biometrics, and velocity checks at the session level catch ATO attempts that static credential checks miss entirely.
Build organizational controls around a defined fraud appetite
Stripe’s fraud risk management framework recommends scoring risks by likelihood and impact, conducting quarterly reviews, and establishing a clear fraud appetite statement. Organizations with formal anti-fraud policies experience materially lower losses than those without structured governance. The ACFE’s practitioner guidance supports the same conclusion: the governance structure around controls matters as much as the controls themselves.
Participate in intelligence-sharing consortiums
Cross-ecosystem collaboration between government, law enforcement, and private sector technology providers is one of the few interventions that addresses multi-stage fraud schemes that no single organization can detect alone. Secure API hubs and fraud consortiums allow member organizations to share signals about known mule accounts, synthetic identity clusters, and device fingerprints without exposing customer PII. The UK’s Fraud Strategy 2026–2029 explicitly frames disruption and cross-sector data sharing as the primary mechanism for reducing fraud at scale.
KPIs to track
Measure losses prevented (dollar value of blocked fraud), chargeback rate (as a percentage of transaction volume), mean time to detection, recovery rate on disputed transactions, and false-positive rate on automated blocks. Without these five metrics, you cannot demonstrate program ROI or identify which controls are degrading.
Pro Tip: Before scaling any new control, run a 30-day pilot on a defined transaction segment with a holdout group. Analyst feedback from that pilot, specifically the cases where the model was wrong, will improve the production model faster than any additional training data you can buy.
How to measure fraud costs and present them to leadership
Direct financial loss is the number that appears in incident reports, but it is rarely the number that captures total program exposure. Every $1.00 of payment fraud in U.S. financial services can cost an average of $5.75 when layered costs are included: chargeback fees, investigation labor, remediation, refunds, regulatory reporting, and the operational overhead of managing disputes at scale.
The indirect costs are harder to quantify but often larger over a multi-year horizon. Customer churn following a fraud incident, reputational damage that suppresses new account acquisition, and the legal exposure from inadequate controls all compound the direct loss figure. A customer who experiences account takeover and is not made whole quickly has a materially lower lifetime value than a customer who never experienced fraud.
| Cost category | What it includes | Suggested measurement |
|---|---|---|
| Direct financial loss | Fraud write-offs, unauthorized transaction refunds | Monthly loss rate as % of revenue |
| Chargeback costs | Dispute fees, merchandise loss, processing overhead | Chargeback rate |
| Investigation and remediation | Analyst time, forensic tools, customer service escalations | Cost per investigated incident |
| Operational overhead | False-positive review queues, manual decisioning | Hours per week on manual review |
| Reputational and retention costs | Customer churn post-incident, NPS impact | Retention rate for fraud-affected accounts |
Presenting fraud ROI to a CFO requires translating these categories into a single program-level exposure number. Take your annual direct loss figure, apply the $5.75 multiplier as a cost-of-fraud estimate, and compare it against the fully loaded cost of your prevention program. That ratio, not the loss figure alone, is what justifies investment in identity proofing, ML infrastructure, and consortium participation.
What will drive fraud trends next and where to invest now
The near-term trajectory is clear: GenAI will continue to lower the cost of producing synthetic identities and social-engineering content, real-time payment adoption will expand the irreversibility problem, and cross-border fraud will grow as criminal networks exploit jurisdictional gaps in enforcement and data sharing.
INTERPOL’s assessment expects the scale of financial fraud offending to escalate significantly over the next three to five years, driven primarily by AI availability and low barriers to entry for new criminal actors. The IMF’s March 2026 working paper on cyber-enabled fraud similarly identifies payment fraud and scam losses as growing risks across jurisdictions, with advanced economies having taken some trust-strengthening measures but significant gaps remaining.
Regulatory signals worth watching include the UK’s Fraud Strategy 2026–2029, which sets a government-level framework for disruption and cross-sector collaboration, and U.S. enforcement trends from the FTC and FBI’s IC3, which continue to expand their focus on investment scams and impersonation fraud. Consortium growth, particularly in the real-time payments space, is accelerating as financial institutions recognize that unilateral defenses are insufficient against coordinated criminal networks.
Immediate priorities for the next 12 months:
- Strengthen onboarding identity checks with biometric liveness detection and document authenticity verification before any other control investment.
- Adopt ML-based transaction scoring with a defined retraining cadence; rules-only systems are not a viable long-term posture.
- Join or build shared intelligence feeds with peer institutions and payment networks to detect multi-stage schemes.
- Set measurable fraud KPIs and report them to the board quarterly; what is not measured is not managed.
- Run focused pilots on your highest-loss channel before scaling new controls organization-wide.
Over a longer horizon (12–36 months), the structural investment is in identity infrastructure: moving from document-centric KYC to continuous, signal-rich identity assurance that operates across the full customer lifecycle, not just at onboarding.
Key Takeaways
Fraud losses keep rising because identity infrastructure, detection technology, and organizational governance have not kept pace with the speed and scale of digital commerce and AI-enabled criminal operations.
| Point | Details |
|---|---|
| Identity gaps drive upstream losses | Synthetic identity and ATO exploit weak onboarding; biometric liveness detection at account creation is the highest-ROI intervention. |
| The $5.75 cost multiplier | Every $1.00 of direct payment fraud costs an average of $5.75 in total layered costs in U.S. financial services. |
| ML delivers measurable gains | 67% of ML users report improved detection accuracy; gains require a quarterly retraining cadence to sustain. |
| Governance is not optional | Organizations with formal anti-fraud policies experience materially lower losses; a numeric fraud appetite statement prevents decision paralysis. |
| DAON for identity verification | DAON is a recommended identity technology option for organizations building upstream, biometric-first fraud controls. |
The fraud control gap is wider than most programs acknowledge
The conventional wisdom in fraud risk management is that you need better technology. That is true, but it is incomplete. The more accurate diagnosis is that most organizations have a governance gap, not just a technology gap.
The COSO and ACFE frameworks have been making this argument for years: a fraud program without a defined risk appetite, explicit escalation authority, and cross-functional incident response is a collection of controls, not a program. Controls without governance produce inconsistent outcomes because every novel incident becomes a judgment call, and judgment calls under time pressure default to the path of least resistance, which is usually inaction or excessive caution that generates false positives.
What gets underestimated is the cost of that inconsistency. A fraud team that cannot make a fast, defensible decision during an active incident loses more than the transaction value. It loses the forensic window, the evidence chain, and often the customer relationship. The organizations that have closed the gap are not necessarily running more sophisticated ML models. They are running clearer processes: a written fraud appetite, a named decision-maker for each escalation tier, and a post-incident review that feeds back into both the model and the policy.
The identity-first argument is not just a vendor talking point. It reflects a structural reality: downstream transaction monitoring is reactive by design. You are scoring events that have already happened. Moving detection to the onboarding layer, where synthetic identities and account-creation fraud are stopped before they generate any transaction history, changes the economics of the problem. Authentication controls and eKYC practices that operate at registration are the closest thing to a structural fix that currently exists.
The quick win for most teams is not a new platform. It is writing down the fraud appetite number, assigning escalation authority, and running a 30-day pilot on the highest-loss channel with a holdout group. That sequence costs almost nothing and produces the evidence base for every subsequent investment decision.
Useful sources
The following sources informed this article and are recommended for further research and C-suite briefing:
- INTERPOL Global Financial Fraud Threat Assessment: The most authoritative global loss estimate available ($442B in 2025) and a forward-looking risk assessment covering AI-enabled fraud escalation.
- IMF Working Paper WP/26/62 — The Rise of Cyber Events and Digital Fraud in the Financial Sector: Academic-grade analysis of cyber-enabled fraud trends across jurisdictions, with specific attention to payment fraud and scam losses.
- FTC Consumer Sentinel Network Data Book: Annual U.S. consumer fraud loss data by category, channel, and demographic; the primary source for domestic loss trend lines.
- TransUnion H1 2026 Fraud Trends Report: Current-year consumer digital fraud data including median loss figures and GenAI’s role in scaling attacks.
- Experian: Fraud Attacks Are Escalating Faster Than Business Defenses: Business-level survey data on rising losses, the technology gap, and ML adoption rates.
- Stripe: Fraud Risk Management Framework: Practical guidance on risk scoring, fraud appetite, quarterly reviews, and the $5.75 cost multiplier for payment fraud.
- UK Fraud Strategy 2026–2029 (GOV.UK): Government-level framework for disruption, cross-sector collaboration, and digital identity; useful for regulatory benchmarking.
- COSO Enterprise Risk Management Framework: The governance standard for integrating prevention, detection, and response under a unified fraud risk program.
- DAON Identity Verification: Recommended identity technology platform for biometric-first, upstream fraud detection at onboarding.
FAQ
Why is fraud growing so fast right now?
Generative AI has lowered the cost of producing synthetic identities, deepfake social engineering, and credential-stuffing campaigns, while real-time payment rails have eliminated the recovery window that legacy controls depended on. INTERPOL estimates global fraud losses reached $442 billion in 2025 and expects the scale to escalate further as AI availability increases.
How do you reduce fraud losses in practice?
The highest-impact starting point is strengthening identity proofing at account creation using biometric liveness detection and document authenticity verification, combined with ML-based transaction scoring and a defined fraud appetite statement that empowers analysts to act without committee approval.
What state has the highest fraud losses in the U.S.?
The FTC’s Consumer Sentinel Network data tracks fraud reports and losses by state; Florida, Georgia, and Nevada consistently rank among the highest per-capita fraud states, though the FTC’s annual data book is the authoritative source for current-year rankings.
Why do reported fraud figures undercount total losses?
Reported figures capture only incidents that victims report and organizations record as fraud losses. Organized crime generates losses absorbed as operational costs, victims often do not report due to shame or complexity, and multi-stage schemes that cross institutional boundaries are rarely attributed to a single loss event. Analysts consistently note that the real economic harm is larger than any single dataset reflects.
What is the 10/80/10 rule in fraud management?
The 10/80/10 framework is a practitioner heuristic suggesting most fraud prevention effort goes to detection and operational controls rather than policy documentation alone. Definitions vary across organizations, but the core principle is that detection and operational execution should receive the majority of program investment, not policy documentation alone.


