Most Banks Still Fight Fraud Alone
7 min read
Somewhere right now, a fraudster is on the phone with a bank's contact center, asking for a wire transfer out of an account that isn't theirs. They have the account number, the name on file, and probably even a text message with a one-time code, forwarded from a phone they took over days earlier. Every piece of information they're offering checks out, because it's real. It just doesn't belong to them.
This is the moment where most fraud either gets caught or gets away, and what decides it usually isn't a clever fraudster or a careless bank rep. It's whether anyone on that call is looking at more than the three facts sitting in front of them.
Ask any fraud team what tools they use and you'll get an impressive list: identity verification, device fingerprinting, behavioral analytics, transaction monitoring, real-time risk scoring. Ask how often those tools actually talk to each other mid-investigation, and the answer gets a lot quieter.
That gap, more than any single piece of technology, is why fraud keeps winning, not because banks lack good tools, but because a fraud attack today rarely stays inside one tool's jurisdiction.
The scale backs this up: the most recent identity fraud data available puts U.S. consumer losses at just over $27 billion for 2024, up 19 percent from the year before, with account takeover, fraud where someone hijacks an account that already exists rather than opening a new one, responsible for more than half of it. That's not a one-year spike, but part of a climb that's continued for several years running.
| Year | Account Takeover Fraud | All Identity Fraud |
|---|---|---|
| 2022 | $11.0B | $20.3B |
| 2023 | $12.7B | $22.8B |
| 2024 | $15.6B | $27.2B |
- Account takeover
- All identity fraud
The honest explanation isn't that fraud got smarter overnight. It's that fraud has always moved in stages, across accounts, channels, and institutions, while most detection systems were built to watch exactly one of those things at a time.
One Category at a Time Isn't Enough Anymore
That pattern is easiest to see by picturing how a modern fraud case actually unfolds: it rarely starts and ends in the same place. A data breach leaks someone's login details, and weeks later those same details resurface in a phishing Scam disguised as a bank notice. The person clicks, and that's enough for a fraudster to gain just enough access to start testing the account.
None of that looks alarming on its own: a breach is background noise by now, a phishing attempt gets reported and forgotten, and a login from an unfamiliar device might just be someone's new phone.
Treated as three separate, minor events, nothing here trips an alarm, but treated as one unfolding story, the pattern is obvious. Most fraud-detection systems are still built around the first read rather than the second, because they were designed to flag individual transactions or accounts rather than the chain connecting them.
Fraud rings understand this better than most banks do. They already operate like a coordinated network, comparing which tactics work, passing stolen data between accounts and institutions, and layering several techniques into a single attack. Fraud-prevention teams, for the most part, still don't coordinate the same way across their own organizations, let alone with other banks. That asymmetry is the whole game, and right now, it favors whoever's better organized. That's rarely the bank.
It also doesn't help that the tools available to fraudsters have gotten dramatically easier to use. Deepfakes, synthetic identities, and convincing phishing kits used to take real skill to pull off, but now they're closer to off-the-shelf software, which means the gap between a sophisticated fraud ring and a lone Scammer with a laptop has never been narrower.
What Actually Closes the Gap
None of that, though, means banks need an entirely new toolkit. Nearly everything required already exists: identity verification strong enough to catch a forged document or a reused face, device signals that flag automation or an unfamiliar browser fingerprint, behavioral patterns like typing speed and navigation habits that shift when someone new is behind the keyboard, and risk scores that pull all of it together into one real-time read on whether to trust an interaction or slow it down.
What's usually missing isn't any one of these, but the wiring between them. A fraud team with five excellent, disconnected tools is still working from five different half-pictures. A fraud team with three good tools that share one view of the customer, by contrast, is working from an accurate one.
Go back to that phone call from the opening. A representative working from a name, an account number, and a one-time code alone has no way to know the person on the line isn't who they claim to be, because every one of those details is real and already stolen. A representative whose system is quietly checking geolocation, IP consistency, and whether this caller's typing and navigation habits match the real customer's is looking at an entirely different call, even though nothing about the fraudster's story changed.
Same fraudster, same script, same three stolen facts. The only variable that changes the outcome is whether anyone was looking past them.
The Piece Everyone Skips
There's one more layer to this same problem, and it's the one the industry is most reluctant to admit: banks are just as siloed from each other as their internal tools are from one another.
A legal, formal channel for U.S. financial institutions to share fraud intelligence with each other already exists, yet fewer than 3 percent of eligible institutions actually use it, and that number has been shrinking rather than growing. The reasons given are consistent across the industry: fear of losing customers to added friction, privacy concerns, reluctance to admit fraud losses publicly, and an instinct to treat fraud data as competitive advantage rather than shared defense.
| Status | Share of Eligible Institutions |
|---|---|
| Enrolled in information sharing | ~3% |
| Not enrolled | ~97% |
- Not enrolled286,210
- Enrolled7,790
That instinct is understandable, and completely counterproductive. Fraud rings already operate as a network that spans banks, digital wallets, and cryptocurrency exchanges without a second thought. Tools built specifically to test stolen credentials across hundreds of sites at once, or slip past weak multi-factor authentication, exist and are actively used, precisely because institutions aren't comparing notes in real time. Every bank defending alone is, functionally, choosing to fight a networked opponent one-on-one.
Customers feel the effects of this long before they understand the cause. Most people quietly assume their bank is already watching for anything unusual and will catch it before real damage happens. Recent consumer research suggests otherwise: a majority say they'd want to be proactively alerted if their information turned up in a data breach or on the dark web, or if it were used to open an account elsewhere, and most feel their bank isn't doing enough of this today.
Tellingly, the people most likely to already have fraud alerts turned on are the ones who've already lived through an account takeover once. Trust, in other words, tends to arrive after the damage, not before it. That's backwards, and it's fixable, but only through the same kind of connected visibility that's missing everywhere else in this picture.
None of this requires a bank to rebuild its entire fraud stack or choose between security and a smooth customer experience. The version of verification that actually catches fraud, built on shared signals and real behavior rather than static facts, is also the version that creates the least friction for a legitimate customer. Security and convenience were never really in tension. Disconnection was always the real cost.
Common Questions
A few questions come up naturally after reading this. Here are direct answers.
What exactly is account takeover fraud?
It's when a fraudster gains control of an account that already exists, usually through stolen credentials or personal information, rather than opening a new fraudulent one. It's currently responsible for more than half of all identity fraud losses.
If the technology to stop this already exists, why doesn't every bank use it?
Most already own pieces of it. What's usually missing is the connection between those pieces, not the pieces themselves. A bank can have excellent identity verification, device intelligence, and behavioral analytics and still miss fraud that moves across all three, because none of those tools were built to compare notes with each other in real time.
Why won't banks just share fraud data with each other?
Mainly out of fear: of losing customers to added friction, of privacy exposure, of publicly admitting fraud losses, and of treating fraud intelligence as a competitive edge instead of a shared defense. A legal channel for this kind of sharing already exists, and fewer than 3 percent of eligible institutions actually use it.
Does stronger, more connected verification mean more friction for real customers?
Not necessarily. Checks based on behavior and device signals tend to run quietly in the background, so a legitimate customer often notices less friction than they would with repeated manual verification, not more.
Where does Avert Intelligence fit into all of this?
Avert Intelligence turns the fraud reports and evidence victims already generate into intelligence that banks and financial institutions can act on in real time, closing the exact information gap described above before the next transfer goes through, not after.
Figures referenced throughout are drawn from recent, publicly available U.S. identity fraud research and consumer survey data.

Sahil Pruthi — CEO
Sahil has spent a decade on the front lines of fraud and cybersecurity. Previously as Head of Product for Innovation at Norton Lifelock, he built Norton Genie - the world's first AI model to detect scams in calls, texts and emails, and scaled other product lines to over $60M in ARR. Now, he's channeling that experience into Avert Intelligence, driven by a single mission: a scam-free world, where every organization has the intelligence it needs to keep its customers safe before a scam ever reaches them.