Security1 distinct publisher3 min readUpdated
A ThreatMark benchmark reports behavioral intelligence rated effective by 83% of respondents and deployed by 18%. The gap, not the technology, is the story.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Fifty-five percent of institutions in ThreatMark's Fraud Readiness Benchmark 2026 said social engineering is involved in most of their fraud [1]. That is a statement about the detection stack as much as about criminals: when the victim uses their own credentials on their own device and approves the transfer themselves, controls built to spot stolen credentials, suspicious devices or account takeover see a legitimate customer completing a normal transaction [2][3].
The mechanics are mundane. Criminals pose as bank employees or other trusted people and persuade the customer to send the money [4]. Every technical signal a fraud engine was tuned on stays intact, because the account is being operated by the person who owns it [5]. So fraud teams are shifting attention to how the session is conducted rather than who appears to be conducting it, looking for indications that a customer is under pressure or following someone else's instructions before the money leaves [6].
That is what the report means by behavioral intelligence: baselining how a customer normally interacts with the service and flagging in-session changes such as unusual hesitation, repeated steps, or an uncharacteristically large transfer to a new payee [7][8]. Eighty-three percent of respondents called it effective against social engineering; 18% said it was already in use [9][10]. That is a 65 point gap between belief and deployment [11], with roughly four in five institutions not yet running the control they rate most highly [12]. More say they are planning deployments [13], which is what respondents always say.
Worth noting what those signals are. Hesitation, repetition and a large payment to a new payee also describe a customer doing something unfamiliar for the first time, so the control's value depends on false positive tolerance the report does not quantify. The published account also does not state how many institutions were surveyed or how they were selected [14], and the benchmark carries a vendor's name.
The forcing function is money. In authorized push payment fraud the victim is manipulated into authorizing the transfer, so the payment originates from the legitimate account holder, which complicates both detection and recovery [15]. In North America, 69% of respondents expect regulation requiring reimbursement for APP fraud within two years, while 31% say they are prepared for such a requirement now [16][17]: a 38 point readiness deficit [18]. Reimbursement rules move more of the loss onto banks and payment providers and generate claims, investigation, customer communication and recovery work [19]. Stopping the payment is cheaper than paying it back.
On the back end, 91% agreed AI can significantly shorten investigation times, with uses including linking related alerts, assembling account activity into a timeline and ranking cases by risk [20][21]. The operational argument is time-to-freeze: faster investigation leaves more room to hold funds or coordinate recovery [22]. The report also found 81% of fraud professionals surveyed now carry cybersecurity responsibilities [23], which matches the shared threat list of phishing, malware, credential theft and account takeover [24].
What to watch: whether that 18% adoption figure moves in next year's benchmark, and whether any North American regulator actually issues a reimbursement mandate on the two-year timeline 69% of respondents expect [16][10]. Watch also for the first published numbers on behavioral intelligence false positive rates, and for what happens to intelligence-sharing arrangements, where privacy and compliance requirements remain a constraint [25], once reimbursement liability gives banks a direct financial reason to name each other's mule accounts.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
In these cases a customer may use legitimate credentials and approve the transaction themselves.
Controls designed to detect stolen credentials, suspicious devices or account takeover may therefore see what appears to be a legitimate customer completing a normal transaction.
Social engineering can leave familiar technical signals intact because the legitimate customer is operating the account.
In authorized push payment fraud a victim is manipulated into authorizing a transfer to a criminal; the payment originates from the legitimate account holder, which can complicate detection and recovery.
Fifty-five percent of institutions surveyed for ThreatMark's Fraud Readiness Benchmark 2026 said social engineering is involved in most of their fraud.
Criminals may pose as bank employees or other trusted people to persuade customers to send money.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor survey, methodology undisclosed
Every quantitative claim traces to one trade-press summary of one vendor's benchmark. The figures are specific and internally consistent, but the published account gives no sample size, no respondent selection method and no geography breakdown beyond a single North America cut, and no independent source in the cluster corroborates any number. The headline effectiveness figure is a respondent opinion rather than a measured detection outcome.
Deployment self-reported at 18%
The one hard adoption datapoint is that 18% of respondents say behavioral intelligence is already in use, leaving roughly four in five not using it; additional institutions are said to be planning deployments but that cohort is unquantified. Reported dual fraud/cyber staffing at 81% shows the organizational side of the shift is further along than the tooling.
Perception figures outrun measured outcomes
The story is honest about the deployment gap, which limits overstatement, but the load-bearing numbers are attitudinal: 83% think behavioral intelligence works and 91% agree AI shortens investigations, with no measured detection rates, time savings or loss reduction anywhere in the cluster. A forward-looking 69% regulatory expectation is also presented as pressure rather than as enacted rule. Positive but moderate, since the article does not claim more than the survey says.
Vendor-authored benchmark on its own category
The benchmark is published by ThreatMark, whose behavioral-intelligence offering is the technology respondents rate 83% effective and only 18% have deployed, so the survey's central finding maps directly onto a sales case. The relaying outlet does not disclose that commercial interest, and the reported reimbursement-regulation expectation adds urgency that favours the same purchase.
Consistent but unverified and single-sourced
Confidence is limited by one publisher, one vendor dataset and no disclosed methodology, and by the fact that the most consequential elements are self-assessment (preparedness) and expectation (regulation). It is not lower because the source is a recognised security trade outlet, the figures are reported precisely and without embellishment, and the article states the adoption limit rather than concealing it.
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
security
Three-quarters claim a crypto inventory. Nearly half have nobody to hand it to.1 distinct publisher
security
AWS gives email-validated certificates three 2027 deadlines, and the last one is a renewal cliff1 distinct publisher
product
France's tax agency lost 678,000 records through logins it had issued itself1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026