Regulators, Firms Urged to Treat Fraud as an Ecosystem
Officials and industry executives pushed for shared data standards, legal safe harbors and faster signal sharing to detect coordinated fraud across banks, payments and identity services.
At meetings in London and Washington this year, regulators and financial firms urged treating fraud as an ecosystem and changing rules, data sharing and detection practices so criminal networks that move across banks, payment providers and identity services can be detected earlier.
Participants noted organized fraud now spans multiple firms and platforms and that current rules and siloed data make it hard to follow actors and the flow of stolen funds. They called for faster, standardized ways to share threat signals, clearer legal protections for information exchange and requirements that key transaction and identity data be retained in formats useful for cross-firm analysis.
Recommendations presented included privacy-preserving channels for sharing suspicious activity indicators, mandated minimum data fields for high-risk transactions and timelines for retaining digital evidence such as device fingerprints and session logs. Regulators proposed standards for how companies label and exchange alerts so automated systems can correlate events across institutions in near real time.
Technology proposals focused on giving fraud teams access to cross-sector signal-sharing platforms and tools such as graph analytics and identity resolution that link phone numbers, device IDs, email addresses and bank accounts. Firms recommended pilot programs that let approved participants test shared detection models on anonymized datasets to measure whether coordinated alerts reduce false positives and speed detection.
Privacy and legal limits on data exchange were raised repeatedly. A senior European regulator cautioned any framework must protect consumer privacy and comply with data protection laws while permitting targeted, proportionate sharing for fraud prevention. A chief fraud officer at a large payments firm warned: “We can see much more when we combine signals, but we also need confidence that sharing those signals won’t expose us to regulatory penalties or litigation.”
Operational proposals included creating industry-wide taxonomies for fraud types, a centralized repository of confirmed bad actors and mule networks accessible to vetted partners, and requirements that firms preserve and export forensic artifacts in a standardized format. Banks and card networks recommended wider use of tokens and stronger identity verification at onboarding to reduce creation of synthetic identities used in coordinated schemes.
Several institutions proposed regulatory changes such as mandating rapid reporting of certain types of multi-jurisdictional fraud and establishing a safe-harbor for firms that share information in good faith with regulated entities and law enforcement. Participants discussed the need for cross-border cooperation among regulators to address fraud rings that exploit gaps between national frameworks.
Meeting briefings noted common attack patterns: identity compromise, fintech onboarding, movement through payment rails, and cash-out via money-service businesses or mule accounts. Investigators described cases where separate firms each saw only a fragment of a scheme and funds had been dispersed by the time patterns became clear.
Next steps include formal pilot projects among banks, card schemes and identity providers, legislative proposals to clarify permissible signal sharing, and joint exercises to test end-to-end detection and disruption. Regulators plan to publish guidance on acceptable practices for data sharing and retention and to consult privacy authorities; industry groups plan to map legal barriers and propose targeted changes aimed at enabling coordinated detection while maintaining consumer protections.








