Fraud targets human psychology; panel urges ecosystem reform

Panelists at an Ecommpay webinar warned fraud now targets human psychology and called for industry-wide regulatory reform and secure data sharing; Interpol says AI-enhanced fraud is 4.5x more profitable.

At an online webinar hosted in association with Ecommpay, industry experts warned that fraud has shifted from technical exploits to tactics that target human decision-making. Panelists referenced Interpol’s finding that AI-enhanced fraud is 4.5 times more profitable than traditional schemes. The session included Willem Wellinghoff, Ecommpay’s UK chair and chief compliance officer, with Teresa Connors as moderator.

Panel members argued that fraudsters now combine psychological manipulation, automation and synthetic media to make scams harder for both consumers and institutions to spot. The presenters said individual organisations can no longer rely only on internal controls, customer education or single-company measures to prevent social engineering and AI-driven attacks.

Speakers identified two structural problems that limit prevention. Responsibility for fraud oversight is split across multiple regulatory and oversight bodies, leaving no single entity with end-to-end authority. At the same time, firms build their own prevention tools and share limited data, producing fragmented detection and response across the financial ecosystem.

The panel discussed regulatory reforms to reduce fragmentation. Proposals included a clearer, unified regulatory framework that sets baseline requirements for fraud reporting and information sharing while allowing flexibility for firms of different sizes and risk profiles. They also outlined legal and technical mechanisms to enable secure, privacy-compliant sharing of fraud data and suggested regulatory support or carve-outs to limit compliance burdens on smaller firms.

Speakers reviewed the potential benefits and drawbacks of standardised fraud processes. Standardisation could aggregate indicators of compromise, speed coordinated responses and reduce duplicated effort. Drawbacks cited were high implementation costs for small businesses, competition and data-ownership concerns, and conflicts with national privacy and financial laws. The panel noted any common approach would need governance that balances interoperability with legal and commercial limits.

The discussion listed roadblocks to creating a single non-profit industry solution: regulatory conflicts across jurisdictions, unclear liability rules for data sharing, uneven technology adoption, and insufficient incentives for firms to contribute sensitive intelligence about attacks. Panelists recommended clarifying legal protections for shared data, harmonising reporting requirements where feasible, and providing funding or technical help to bring smaller players into shared systems.

Panel members urged regulators and industry stakeholders to prioritise cross-sector collaboration, interoperable reporting standards and legal frameworks that enable secure data exchange without exposing consumers or firms to undue risk. They said those changes would require policy action, investment in shared technical infrastructure and governance models that reflect differing resources and risk levels across the financial sector.

Articles by this author