Security1 publisher2 min readPublished
Banks expand behavioural checks before mobile payments are authorised
Banking scams targeting mobile users rose 35% in 12 months, according to research cited by Tech Radar. Because victims send the money themselves, banks are looking for signs of manipulation before a payment is authorised.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Scammers use the ease of mobile banking apps to persuade customers to move money themselves, without breaking into their accounts.
- Research cited by Tech Radar finds that 90% of all scams now reach victims through mobile phones.
- UK reimbursement policies already cover victims after a scam, but the priority there is moving toward stopping payments before they reach criminals.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Password, device and login controls cannot block a payment the real customer authorises, so detection has to judge the customer's behaviour inside the session.
- exposure Under these figures, controls built around email or landline cover about one scam in ten. Detection effort has to sit in the banking app.
- decision Acting on a behavioural signal means a bank holding a transfer its own customer started, on evidence of manipulation alone.
The attacker in these cases does not need the victim's password. The account holder opens the app, logs in and sends the money on the scammer's instruction [9]. Every authentication check passes because the person passing it is the real customer [2]. Account-takeover defences pass this fraud straight through [2].
That leaves one point of control: the gap between the customer pressing send and the bank authorising the payment. According to the SC World brief, which summarises Tech Radar reporting, banks are expanding their use of behavioural intelligence to spot signs of manipulation before a transaction is authorised [8]. Acting on that signal means a bank holding a transfer its own customer started [2].
The research puts 90% of all scams on mobile phones [3]. That leaves one scam in ten for email, landline and every other channel combined [1]. Banking scams in particular are now aimed almost wholly at mobile devices, where victims can move money easily [2].
By type, purchase scams are the most common, at 33% of all scam attempts [4]. Romance scams rose 23% over the year [5]. Investment scams cost the most, with an average case value of $6,600 [6].
The brief says scammers are using AI to make their schemes more convincing and to run them at greater scale [7]. It describes this across scam types, as a change in how fraudsters in general operate [7]. The brief does not name the study behind its figures, its sample, the baseline for the 35% rise, or any group running the scams [1] [3].
Everything here is public, and all of it is secondhand: SC World citing Tech Radar citing research described only as new [3]. The precise figures should be treated as single-sourced until the underlying study is published.
In the UK, reimbursement policies already exist to protect victims financially after a scam [10]. Reimbursement acts once the money has left the account. The behavioural check runs before the bank authorises the transfer [8]. The brief says the UK priority is moving toward preventing payments from reaching criminals in the first place [10].
What to watch
- Publication of the underlying study, with its sample and period, to test whether the 35% and 90% figures hold.
- UK banks or regulators reporting whether pre-authorisation interventions cut the number of reimbursement claims.
- Banks disclosing which behavioural signals they act on and how often they hold customer-initiated payments.