Banking Scams Shift to Mobile Devices
A new BioCatch report claims 90% of scams now happen on phones, with banking scam attempts up 35% in the past year.
Banking fraud has a new preferred venue, and it fits in your pocket. According to research from fraud intelligence firm BioCatch, scam attempts targeting banking customers have climbed 35% over the past 12 months, and the overwhelming majority of those attempts now unfold on mobile devices rather than landlines or desktop email.
The report, which examines global fraud patterns, claims that 90% of all scams take place via a mobile phone. That figure sits at the center of BioCatch's argument that the convenience of mobile banking apps has become a direct operational advantage for criminals who no longer need to break into anything — they simply persuade victims to move money themselves.
Mobile becomes the default channel
BioCatch's research highlights a range of scam types growing in prevalence, including romance scams and investment scams. But the headline finding is the migration of banking scams to mobile. The report attributes this shift to two factors: the proliferation of mobile phones worldwide and the widespread availability of banking apps that let users transfer funds instantly.
The report does not claim that scammers have abandoned other channels entirely, but it does argue that mobile is now where the overwhelming share of activity occurs. That concentration matters because mobile banking compresses the distance between a victim's decision and the irreversible transfer of funds — a dynamic that traditional fraud controls were not necessarily designed around.
BioCatch also identifies artificial intelligence as a tool used on both sides of the fight. Scammers, according to the report, use AI to lower the barrier to entry and produce more convincing lures at scale, while banks deploy AI-driven techniques in an attempt to detect manipulation before a payment is authorized.
The economics of a scam
Not all scams are equal in cost. BioCatch's data shows that investment scams are the most costly per case, with an average case value of $6,600. Romance scams, meanwhile, increased by 23% over the last year.
Purchase scams remain the most common category overall, accounting for 33% of all scam attempts. That makes purchase fraud the volume leader even as banking, romance, and investment scams dominate the headlines for their financial impact.
The distribution of these figures suggests that fraudsters are not running a single playbook. Instead, they appear to operate across multiple scam categories simultaneously, with different tactics matched to different victim profiles.
Persuasion replaces intrusion
The core mechanic behind banking scams, according to BioCatch, rests on two pillars: manipulative and persuasive strategies that induce an irrational financial panic in the victim, and the ease with which money moves through a mobile banking app.
This is a form of theft that never requires unauthorized access to an account. The victim authorizes the transaction. The fraudster's job is to make that authorization feel like the right decision under pressure.
"Scammers don't need to break into an account if they can persuade the customer to move the money for them. That is the challenge banks face today with investment and romance scams, where customers are manipulated into making payments they believe are legitimate."
— Jonathan Frost, Director of Global Advisory at BioCatch
That framing places the burden on banks to detect coercion in the moment, not just to flag unusual transaction patterns after the fact. A payment that a customer genuinely intends to make looks, at the transaction level, like a legitimate payment — which is precisely what makes these scams difficult to intercept using conventional rules-based fraud detection.
AI on both sides of the transaction
BioCatch's report notes that artificial intelligence techniques are used by both scammers and banks. For the former, AI reduces the cost and skill required to run convincing social engineering campaigns. For the latter, it offers a way to analyze behavioral signals that may indicate a customer is being manipulated.
"Social engineering scams have not suddenly become less prevalent or sophisticated. If anything, artificial intelligence has lowered the barrier to entry for aspiring scammers, allowing more bad actors to create more convincing scams at a scale we've never seen before. In response, many banks have realised behavioural intelligence enables them to recognise signs of manipulation and coercion before an accountholder ever authorises a transaction."
— Thomas Peacock, Director of Global Fraud Intelligence at BioCatch
Peacock's statement points to a specific technical approach: behavioral intelligence, which examines how a user interacts with a device or application rather than solely what transaction they attempt. BioCatch's report frames this as a response to the fact that scam payments are authorized by the legitimate account holder, meaning traditional authentication checks alone will not catch them.
Reimbursement versus prevention
Different territories take different approaches to helping scam victims. In the UK, protection is available in the form of reimbursement. BioCatch's report acknowledges this but argues it addresses only part of the problem.
"Reimbursement in the UK protects victims financially after the event, but it does not stop the scam from succeeding. The priority now has to be preventing the payment from reaching the criminal in the first place."
— Jonathan Frost, Director of Global Advisory at BioCatch
The distinction between compensating victims and stopping transfers is central to the report's argument. Reimbursement shifts the financial loss away from the individual, but it does not interrupt the scam itself — the criminal still receives the funds, and the same infrastructure remains in place for the next victim.
BioCatch's position is that prevention requires banks to intervene during the payment flow, at the point where a customer is being coached or pressured into authorizing a transfer.
The scale of the problem
The report's key figures, taken together, describe a fraud landscape that has consolidated around mobile channels:
- 35% increase in banking scam attempts over the past 12 months
- 90% of all scams take place via a mobile phone
- 33% of all scam attempts are purchase scams, the most common category
- 23% year-over-year increase in romance scams
- $6,600 average case value for investment scams, the most costly type
These numbers come from a single vendor's research and have not been independently verified. BioCatch sells fraud detection technology, which is worth noting when evaluating its conclusions about which defensive approaches work best.
What the report does not resolve
BioCatch's report identifies the problem clearly but stops short of prescribing a specific technical remedy that banks can deploy universally. The emphasis on behavioral intelligence reflects the company's own product focus, and the report does not quantify how widely such systems are already deployed or how effective they have proven in practice.
It also does not break down scam rates by region beyond noting the UK's reimbursement model, nor does it offer a timeline for when the mobile fraud trend began accelerating. The 35% year-over-year increase is presented as a headline figure without a breakdown of which scam categories drove it most.
What the report does establish is a direction of travel: fraud that once required a phone call to a landline or a phishing email is now concentrated in the device most people check dozens of times a day. The barrier for the criminal is persuasion, not penetration, and the transaction that follows is authorized by the victim.
Why it matters
For banks, the report's findings suggest that scam prevention may increasingly hinge on detecting coercion during a transaction rather than authenticating the person initiating it. If the account holder is the one authorizing the payment, then identity verification alone offers limited protection — which could push financial institutions toward behavioral monitoring and real-time intervention as fraud volumes grow.
For consumers, the practical implication is narrower but sharper: the mobile banking app that makes transferring money effortless also makes it effortless for a scammer who has successfully manipulated you. The report's data on investment and romance scams suggests the highest-value targets are those willing to make large, considered transfers under emotional pressure.
For regulators, the UK's reimbursement model offers a case study in the limits of after-the-fact compensation. BioCatch's argument — that prevention must happen before funds reach the criminal — implies that policy focused solely on making victims whole may not reduce the underlying scam economy. Whether banks can build systems that reliably distinguish a coached payment from a legitimate one remains an open question, and one that the report raises without fully answering.
Sources
- TechRadar Original source
Continue Reading
ShinyHunters suspect held in Jordan
A reported detention in Jordan and a week of digital silence are testing the extortion group's resilience.
DTU breach exposes 200k user records
Hackers accessed the Technical University of Denmark's identity system using compromised credentials, potentially exposing data of up to 200,000 people.
Warlock Hits SharePoint, Then Strikes
Symantec says the China-linked group behind Warlock ransomware disabled defenses on dozens of hosts within hours of exploiting SharePoint flaws.