The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members.

UK Finance’s Annual Fraud Report 2026 highlights a troubling reality: while financial institutions continue to prevent significant volumes of fraud, criminals are becoming more skilled at avoiding scrutiny. 

In 2025 alone, criminals stole £1.28 billion through payment fraud, representing a 4 per cent year-on-year increase and the second consecutive year of growth. These figures reflect not only the scale of the threat but also the adaptability that new technologies afford organised criminal enterprises.

Advertisement on large screen for Fraud Report

The most important insight from this year’s report is not solely the total loss figure itself, but the continued shift in how fraud is perpetrated. As institutions adopt stronger fraud controls, criminals are focusing on exploiting human elements. Through AI-enabled social engineering techniques, they manipulate vulnerable customers into authorising payments themselves, bypassing key institutional controls.

This evolution is fundamentally reshaping the fraud landscape. It is no longer solely a device -or transaction-monitoring challenge but increasingly a customer protection one too. Financial Institutions must, therefore, rethink how they engage with clients, identify behavioural indicators of manipulation, and detect Authorised Push Payment (APP) scams before funds leave the account.

Success will depend on moving beyond traditional approaches and towards more holistic and dynamic models that incorporate consortium analytics and cross-border, cross-sector collaboration.

Authorised Push Payment scams on the rise

The 2026 report highlights a growing divergence in fraud typologies. While losses from unauthorised fraud have declined by 5 per cent (£703.4M gross), reflecting continued investment in detection and preventive controls, Authorised Push Payment (APP) scams have grown by 19 per cent (£576.4M gross).

Fraudsters create prolonged, trust-building interactions to convince victims to initiate payments themselves, such as fake romances and investment schemes. They leverage digital channels, compromised credentials, artificial intelligence and real-time manipulation to bypass traditional safeguards. And they share resources and playbooks with each other to operationalise these scams on a massive, international level.

This presents a structural challenge: Controls designed to detect unauthorised activity are less effective when customers are making an authorised push payment. As a result, the industry has entered a new phase, one where understanding customer behaviour is just as important as identifying criminal anomalies.

Rethinking fraud prevention for a changing threat landscape

The implications for financial institutions are significant. Success can no longer be measured solely by prevention rates. Expectations from regulators, customers and policymakers are expanding to include:

  • Faster and more accurate intervention in scam scenarios.
  • Improved customer outcomes, including reimbursement and resolution.
  • More effective collaboration across institutions, sectors and jurisdictions.

Simultaneously, fraud strategies must evolve to address the changing nature of risk mitigation:

1. Detecting social engineering in real time
Financial Institutions need to identify behavioural indicators of coercion, manipulation and deception before a payment is completed.

2. Strengthening defences against APP fraud
Greater visibility into customer intent, payment context and beneficiary risk can help mitigate losses, especially where traditional rules-based controls often fall short.

3. Enhancing intelligence sharing and collaboration
Fraudsters operate across institutions, channels and borders. Effective prevention increasingly depends on shared intelligence and collaborative action.

4. Balancing prevention with response and recovery
As reimbursement requirements and customer expectations continue to rise, institutions must be equipped to respond at pace, minimise harm, and support victims when fraud does occur.

Combined, these priorities point to a broader shift from siloed controls towards a more integrated, intelligence-driven approach to fraud prevention, detection and response.

From insight to action: building resilience against scams

To keep pace with increasingly sophisticated fraud threats, financial institutions need more than incremental improvements -  they need a step change in capability. This is where modern anti-financial crime platforms play a critical role, enabling organisations to identify risk earlier and intervene before funds are lost forever.

The Nasdaq Verafin platform deploys consortium analytics to detect fraudulent payments at scale. We provide GDPR-compliant visibility across originators, beneficiaries and international borders to see beyond your institution’s barriers, so you can:

  • Identify high-risk accounts and payment recipients before funds are sent.
  • Detect patterns of coordinated fraud activity across networks and borders.
  • Recognise social engineering and suspicious customer behaviour.
  • Enable earlier and more confident intervention in APP fraud scenarios.

These capabilities help bridge the gap between how fraud is perpetrated today and how it is detected, enabling organisations to shift from reactive investigation to proactive prevention.

As the UK Finance report highlights, the fraud landscape will continue to evolve. Institutions that succeed will be those that can adapt just as quickly, combining industry insight and collaborative intelligence with the tools needed to act decisively in near real-time.

Visit us to learn more about how Nasdaq Verafin is helping UK institutions keep pace with the fraud landscape and protect your customers.

Area of expertise: