Top Banks Deploy AI, Data Sharing to Curb Consumer Scams

JPMorgan, HSBC, Barclays and others are using machine learning, shared data, stronger authentication and operational changes to cut consumer scam losses on real-time payments.

Over the past two to three years, major banks including JPMorgan Chase, HSBC, Barclays, Citigroup, Santander and Bank of America have increased investment in fraud technology and cross-industry programs to reduce consumer scam losses and protect retail customers on real-time payment systems.

Banks are deploying machine learning alongside behavior and network analytics to detect patterns that traditional rule sets miss. Models score transactions using device fingerprints, historical payment relationships, transfer velocity and unusual routing. Graph analysis links accounts that repeatedly appear in scam chains, allowing institutions to freeze or quarantine high-risk payments for manual review. Several banks have set up specialized units to handle authorized push payment complaints and to accelerate customer contact when a transfer looks irregular.

Regulatory and infrastructure changes have affected how banks act in different markets. In Europe, PSD2 requirements for strong customer authentication led banks to update authentication flows for e-commerce and some bank-initiated payments. In the U.K., Confirmation of Payee checks whether a payee name matches the account number and an industry reimbursement code for authorized push payments was revised to require clearer detection standards and faster remediation. In the U.S., as real-time rails expand, clearinghouses and banks have discussed standardized fraud controls and more formal information sharing to track suspect accounts across institutions.

Banks are increasing collaboration with fintechs and third-party identity providers. Some institutions use biometric checks during onboarding and for high-value transfers. Others route suspicious transactions through out-of-band confirmation, asking customers to approve a transaction through a separate channel. Several banks are piloting call-center safeguards such as voice verification and one-time verification codes to counter impostor schemes executed by phone.

Data sharing has become a focus for fraud teams. Consortiums and secure data platforms let banks exchange indicators of compromise and lists of accounts linked to scams while protecting customer privacy. Industry databases that catalogue scam account numbers and names are used to block repeat offenders and identify networks of mule accounts. Banks continue to file reports with law enforcement and national fraud registries to help disrupt operations.

Operational changes supplement technology. Some banks have lengthened investigation windows for certain instant payments to allow human review, raised the prominence of on-screen warnings for unfamiliar payees and simplified the process for customers to report suspected fraud. Customer education campaigns outline common social-engineering tactics and recommend pausing before large transfers and using two-factor authentication. Where possible, banks have reduced friction for routine users while adding more checks for higher-risk transfers.

Several banks now act faster to reclaim funds when transfers move through domestic payment systems and coordinate with recipient banks to freeze funds during investigations. Those recovery practices vary by jurisdiction and by the legal framework governing different payment rails.

Bank officials point to a rise in social-engineering scams and the spread of instant payments during the pandemic as drivers of the intensified controls. Financial institutions say combining automated detection with human review and clearer customer remediation pathways is part of their plan to limit consumer losses while keeping retail payments fast.

Articles by this author