MerchantGo Intelligence Platform

Industry Update IU-001

Bank Impersonation Is Becoming a Payment-Control Problem.

Reported fraud losses reached new highs in 2025, with bank impersonation and irrevocable payment methods producing some of the most damaging outcomes.

TopicsBanking Fraud · Payment Fraud
Reading Time6 Min Read
PublishedAugust 2026

What changed

On June 15, 2026, the Federal Trade Commission published its consolidated view of consumer fraud reports for 2025. The headline figure — approximately $16 billion in reported losses — represents an increase of roughly 25 percent over the reported 2024 total. Within that total, the FTC reported that consumers lost nearly $1 billion to business impersonators, and that the highest reported losses in that category involved criminals impersonating the consumer's bank.

Two payment-method observations matter more than the headline. First, bank payments produced the highest aggregate reported losses. Second, credit cards were the payment method most frequently identified in fraud reports. Those two facts describe different problems, and conflating them leads institutions to invest in the wrong controls.

The FTC's accompanying testimony on the rising scam economy frames the shift in operational terms: fraud is increasingly delivered as a sustained social-engineering campaign rather than as a single unauthorized transaction.

Why it matters

Most bank and payment controls were designed to answer one question: is this really the customer? Impersonation fraud renders that question insufficient. The customer is genuinely present, genuinely authenticated, and genuinely instructing the payment. What has been compromised is not the credential — it is the decision.

This distinction has direct financial consequences. Unauthorized card fraud is largely absorbed through chargeback and liability frameworks that were built for it. Authorized push payments through bank rails generally are not. When the customer initiates the transfer, recovery depends on speed, beneficiary cooperation and, increasingly, regulatory expectation — not on a dispute right.

It also matters for how institutions read their own numbers. Consumer-reported credit-card fraud is not the same thing as confirmed issuer loss. Reports capture what consumers experienced and chose to report; they do not confirm liability, net loss after recovery, or whether the transaction was ultimately reversed. Treating report frequency as a loss ranking will overweight cards and underweight the rails where the money actually disappeared.

When the customer authorizes the payment but the criminal controls the decision, authentication alone is not enough.

Who is affected

  • Retail and commercial banks. Impersonation of the institution itself is now a direct brand and liability exposure, not a customer-education footnote.
  • Fintechs and neobanks. Fast onboarding and fast outbound payments are precisely the combination scam operators route funds through.
  • Card issuers. High report volume without corresponding loss concentration requires more careful segmentation before allocating control investment.
  • Merchants and payment facilitators. Scam proceeds frequently transit legitimate merchant accounts, producing downstream dispute, compliance and account-review exposure.

MerchantGo analysis

The useful reframing is that impersonation fraud is a payment-control problem sitting inside a customer-communication problem. Authentication confirms identity. It does not evaluate intent, coercion or manipulation. The controls that actually reduce loss in these cases operate on the payment instruction and its context rather than on the login.

In practice, that means treating a set of signals as jointly decisive rather than individually informative. A first-time beneficiary is unremarkable. A first-time beneficiary receiving an unusually large amount, shortly after an inbound call, from a session with an unusual dwell pattern, while the customer navigates directly to the transfer screen without their normal browsing behaviour, is a different event entirely.

The strongest programs we see combine four capabilities: behavioural anomaly detection at the point of instruction, beneficiary intelligence built from network and internal history, calibrated customer intervention that interrupts without insulting, and a recovery function that begins within minutes rather than after the complaint is logged.

Intervention design is where most programs underperform. A generic warning screen shown to every customer is trained away within weeks. Effective intervention is rare, specific, and describes the scenario the customer is actually in — including the fact that a genuine bank will never ask them to move money to a safe account.

Finally, measurement has to change. If an institution only measures unauthorized fraud rate, an impersonation problem is invisible in the reporting until it appears in complaint volume, regulatory attention or press coverage.

What leaders should do now

  1. 01Separate the two fraud types in reporting. Report unauthorized transaction fraud and authorized-payment scams as distinct lines with distinct owners. Aggregating them hides the trend that is growing fastest.
  2. 02Score the payment instruction, not just the session. Combine new-recipient risk, amount deviation, payment velocity, device and session behaviour, and channel context into a single decision at the point of instruction.
  3. 03Build beneficiary intelligence. Track destination accounts across the portfolio. Repeat mule endpoints are the most reusable signal available and the least dependent on customer behaviour.
  4. 04Redesign customer intervention. Replace generic warnings with targeted, scenario-specific interruption for the small percentage of payments that carry most of the risk, and give frontline staff a script for coached customers.
  5. 05Start recovery on a clock. Define a documented recall workflow with target timeframes measured in minutes. Recovery odds decay faster than most institutions' escalation paths.
  6. 06Interpret reported data carefully. Use consumer-reported figures to understand direction and method mix, not to size your own liability. Validate against confirmed internal loss before reallocating budget.

Key Takeaways

What to carry into your next leadership discussion.

  • 01Reported consumer fraud losses of approximately $16 billion in 2025 were roughly 25 percent above the reported 2024 total (FTC).
  • 02Bank payments produced the highest aggregate reported losses; credit cards were the most frequently reported payment method. These are different problems.
  • 03Impersonation fraud defeats authentication by design — the genuine customer authorizes the payment.
  • 04Controls must evaluate the payment instruction, the beneficiary and the behavioural context, not just the identity of the person instructing it.
  • 05Recovery speed and beneficiary intelligence are now core loss-reduction capabilities, not back-office functions.
MB

Author

Michel Bertrand

Founder & Principal Consultant, MerchantGo

Enterprise Fraud · Payments · Decision Intelligence

Share this Industry Update

About MerchantGo

Want to know what this means for your portfolio?

MerchantGo helps fraud, payment and risk leaders translate industry developments into control decisions, reporting changes and remediation plans that hold up in front of executives, acquirers and regulators.