Skip to main content

Fraud vs. friction: Banks must walk a fine line

Share

While third-party fraud continues to wreak havoc on financial institutions, first-party fraud is also on the rise, according to the BAI Banking Outlook: 2024 Trends.

Third-party fraud—fraudsters using the identity of others to take over their accounts—remains the most common type committed by swindlers. Nearly a third (32%) of financial institutions reported they experienced third-party fraud in the past year, according to BAI’s survey of 102 financial institutions.

However, an increasing percentage of institutions are now seeing incidents of first-party fraud, in which fraudsters open accounts themselves. Forty-two percent of institutions said they experienced first-party and third-party fraud equally. It’s not just hardened criminals committing first-party fraud. Customers sometimes dispute purchases they made, even though they knew they didn’t have enough money in their account to afford the purchase.

Some consumers misrepresent their income on digital applications, as well as wash their credit report—disputing a negative item to get it removed. They then fraudulently obtain new credit before the negative item is reinserted into their credit report.

Institutions walk a fine line on fraud. They must put controls in place to mitigate fraud. But if they go too far, they create false positives. Then well-intended customers express their dissatisfaction through social media, which damages the bank’s overall brand.

Banks and credit unions know they can never eliminate fraud. All they can do is work diligently to contain it. The challenge is determining how much fraud they are willing to accept.

Phishing and check fraud remain the most common type of third-party fraud reported by customers of the institutions surveyed (73% and 72%, respectively). That’s followed by debit card fraud (69%), electronic banking fraud (52%), account takeover (47%), impersonation of official scams such as Social Security and other government programs (37%), malware (25%), provider scams (19%), charity scams (13%) and economic relief scams (13%).

Also on the rise: synthetic fraud. Fraudsters make up a name based on fictitious information to create enough of a backstory so they can open an account. Then they funnel fraudulent or nefarious transactions through the account. BAI’s fraud subcommittee members tell us there’s been a big surge in “drop-fraud” accounts, typically opened digitally with zero or low balances. Fraudsters then wait awhile to make other deposits, such as funds they’ve stolen from tax refunds or other government subsidies. Or they transfer funds from other accounts that were generated from nefarious acts. Fraudsters then close the account and move on to opening new drop-fraud accounts.

Most institutions surveyed have stepped up their fraud reduction efforts in the last year. The vast majority (79%) are protecting their customers using a multifaceted approach. Three-fourths (76%) are educating their customers about how to protect themselves, particularly from third-party fraud. Roughly the same percentage (75%) are providing additional training for their employees. Sixty percent of the financial institutions surveyed are investing in new technology to address fraud. Nearly half (45%) have revised their employee policies and procedures to address fraud, and 7% have had to hire a crisis management company.

In cases of synthetic fraud, where there is no real customer, institutions need to train their employees on what to look for, such as inconsistencies with a customer’s normal behavior. Then they need to establish policies and procedures to reduce those types of accounts. For example, we just talked to an institution that recently reduced the time they close accounts with little or no funding from 60 days to 30 days. That’s because the small number of accounts that were funded from Day 31 to Day 60 were mostly fraudsters dropping money into those accounts. Closing accounts with little or no funding after 30 days or having customers go through some re-authentication process allows banks to contain synthetic fraud.

Institutions are also leveraging more technology on the back end, as well as on front end, to determine if there’s been an account takeover by a fraudster. But again, institutions need to balance fraud prevention and the customer experience so they’re not making their processes so difficult that customers get frustrated and walk away.

Most financial institutions are using artificial intelligence (AI) to address fraud, or they plan to within the next year, according to BAI Banking Outlook: 2024 Trends survey. AI is helping institutions detect patterns in customer behavior—and anomalies to those patterns—to help determine when to contact customers to validate a transaction outside the range of their normal behavior.

In a separate BAI survey of 1,000 consumers divided equally between all four generations, we found the No. 1 concern about the digital banking experience for every generation—except Generation Z—is security and/or becoming a victim of fraud. It was the No. 2 concern for Gen Z.

In addition to educating customers about how to better protect themselves against fraudsters, institutions can also offer account alerts via their apps or online banking portals.

Some institutions are offering customers monitoring services of their outside accounts to enhance the overall customer experience.

As the fight against fraud continues into the year ahead, the industry should consider some type of formal network to help communicate among the members the rapidly evolving forms of fraud they are seeing.

Fraud undermines the trust that customers have in their financial institution. And by working together as an industry, there’s an opportunity to create a more solid foundation of trust.

Isio Nelson is Managing Director, Research at BAI.

A version of this article first appeared in the BAI December Executive Report: “2024 Banking Outlook.”

Related Articles

Login to View This Content

 

Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.