Summary
- Fraud has moved beyond onboarding. Today’s biggest losses occur after accounts are opened, making continuous monitoring essential.
- Criminals are evolving faster than traditional controls. AI, organised fraud networks and sophisticated scams are reshaping the threat landscape.
- The greatest risk now lies in trusted accounts and authorised payments. Strong identity checks remain vital, but they are only one part of the solution.
- Effective fraud prevention is continuous and intelligence-led. Combining identity, behavioural, device and network insights helps stop fraud across the customer lifecycle.
In 2025, criminals stole £1.28 billion from people and businesses in the UK¹. That figure went up, not down, in a year when the industry spent more on stopping fraud than ever before. Most firms will tell you they feel well protected. The losses tell a different story.
That gap, between how safe we feel and how much still walks out the door, is the real subject of this guide. Fraud prevention is not a box you tick at account opening. It is a discipline you run every day, across the whole life of a customer, against an opponent who changes shape faster than most control frameworks can keep up.
Here is what fraud prevention is, what it is up against in 2026, and what separates the firms holding the line from the ones quietly writing losses off as the cost of doing business.
What is fraud prevention?
Fraud prevention is everything an organisation does to stop criminals taking money, data or access they are not entitled to. In practice that means verifying who someone is, watching how they behave, scoring the risk of what they are trying to do, and stepping in when something does not add up.
For years the model was simple. Check the customer hard at the front door, at application or account opening, then let them through. Get the gate right and you were safe.
That model is breaking. Not because the checks are bad, but because the fraud has moved. It has moved past the front door into live payments and account activity. It has moved from lone chancers to organised networks that share what works. And it has moved onto AI, which lets a criminal test, adapt and scale in ways a person never could. Prevention that only guards the entrance now guards the wrong place.
So the better definition, the one that matches the threat, is this. Fraud prevention is the continuous management of trust and risk across the entire customer lifecycle, tuned so that genuine customers barely notice it and criminals keep hitting friction they cannot predict.
Key takeaway
Prevention that only guards the entrance now guards the wrong place.
What counts as fraud?
Fraud is any deception carried out for financial gain. In banking and financial services it usually falls into three buckets, and knowing which one you are dealing with changes how you stop it.
First-party fraud
is when someone uses their own identity but lies to get something they are not entitled to, for example inflating income on an application or never intending to repay. It is often misfiled as credit risk, which is exactly why it is so expensive.
Second-party fraud
is when a real person hands over their identity or account for someone else to commit fraud, knowingly or under pressure. Money mules are the classic case.
Third-party fraud
is when a criminal uses someone else’s identity or data without their knowledge. This is what most people mean by identity theft.
The real scale of the problem in 2026
The numbers are worth sitting with, because they explain why the old model is under strain.
UK fraud in 2025, the headline figures
- £1.28 billion stolen through fraud, up 4% on the year.
- £576.4 million of that was authorised push payment fraud, where the victim is tricked into sending the money themselves. Up 19%.
- £703.4 million was unauthorised fraud, such as stolen card and account misuse. Down 5%.
- £1.68 billion of attempted fraud was stopped. The industry now prevents roughly 70p in every £1 criminals try to take.
- Eight people are defrauded every minute in the UK, losing around £2,500 a minute between them.
Look closely and you see the shift. Unauthorised fraud, the kind a strong front door and good card controls are built to stop, is falling. Authorised fraud, where the customer is manipulated into paying a criminal after the account is open and verified, is rising fast. The defences got better at the thing they were designed for. The criminals moved to the thing they were not.
The bill does not stop at the stolen money. The UK government puts the total cost of fraud to England and Wales at more than £14.4 billion a year once you count the response, the recovery and the harm². And since new rules came in, payment firms now reimburse the large majority of authorised push payment losses, around 88% in the first year according to the Payment Systems Regulator³. The cost of getting prevention wrong now lands squarely on the firm.
What fraud costs, beyond the money
For businesses, the direct loss is only the start. There is the operational drag of investigating and reimbursing, the regulatory exposure, and the reputational damage that follows a breach. Trust is slow to earn and quick to lose.
For customers, the harm is financial and personal. Victims lose money they may not get back, time they will not recover, and confidence in the brand that let it happen. A single bad experience can end a relationship that took years to build.

What changed: three shifts that broke the old model
If you take one thing from this guide, take this. Three things changed at once, and together they explain why spending more on the same controls is not moving the loss numbers.
1. The money leaves after you have let the customer in
Authorised push payment fraud does not break down your door. It walks the customer to the payment screen and has them press send. Every identity check at onboarding can pass, and the fraud still happens, because the deception targets the person, not the system. UK Finance reports that around two-thirds of this fraud starts online and a further one in six starts over the phone. If your prevention stops at account opening, you are not looking at where most of the money now goes.
It is not only scams. Genuine, fully verified accounts are increasingly turned to fraud after opening. Cifas recorded facility misuse up 43% in 2025: payment fraud on those accounts up 239%, more credit taken with no intent to repay, and over 22,000 money mule cases under a new filing category4. The account passed every check. The fraud came later.
2. Fraud is a network, and the criminals share better than you do
Modern fraud is a supply chain. Phishing kits, spoofing services, stolen identities and mule accounts are bought and sold ready to use. When a criminal finds a control that fails, that knowledge spreads across the industry within days. Defences, meanwhile, stay locked inside each institution. In research we ran with Forrester, seven in ten fraud decision-makers admitted they do not have the quality data to prevent fraud on their own. The attacker has a file on you at every bank. Most banks have a file on the attacker at only one.
3. The AI arms race, and defenders are behind
AI has changed the economics of fraud. It writes the convincing message, clones the voice, generates the synthetic face that passes a liveness check, and does it at a scale no human team could match.
In our research, 69% of fraud leaders said criminals are further ahead in using AI to commit fraud than their own teams are in using it to fight it5. Cifas reports criminals using deepfake audio against call centres and AI to automate account takeovers, with unauthorised SIM swaps up 38% in a year.
A new front is opening too: autonomous AI agents that act on a customer’s behalf. Nearly a third of the businesses we surveyed had already seen AI agents acting autonomously as part of a fraud event, and UK Finance calls agentic AI the likely next force multiplier for criminals. The uncomfortable part is not the tooling. It is speed. A criminal using AI can change the attack on every attempt. Most fraud controls change on a release cycle.
The most common types of fraud to watch
Different frauds need different defences. These are the ones doing the most damage in banking and financial services right now, and where each is actually stopped.
Type of fraud and 2025 trend | What is it? | Where you stop it |
Authorised push payment (APP) fraud | The customer is tricked into sending money to a criminal posing as someone they trust: their bank, a builder, an investment or a romantic interest. | Real-time payment monitoring and warnings, not just onboarding checks. |
Facility misuse | A genuine, fully verified account is turned to fraud after opening: credit built up then abandoned with no intent to repay (bust-out), payment fraud, or receiving and moving stolen funds as a mule. | Continuous monitoring of account, credit and payment behaviour, plus network signals, not just onboarding checks. |
Account takeover | A criminal seizes control of a genuine customer’s account through stolen credentials, SIM swaps or social engineering. | Behavioural and device signals that spot when the person behind the login has changed. |
Identity theft and synthetic identity | Stolen real data, or a fabricated identity stitched from real and fake details, used to open or access accounts. | Strong identity verification plus checks that the device and session are genuine. |
First-party fraud | A customer misrepresents themselves for gain, then disputes charges or never repays. Cifas assesses this as rising, driven by payment evasion and growing social acceptance. | Data shared across the industry, and reviewing risk across the lifecycle, not just at application. |
Money mule activity | Accounts, often belonging to coerced or complicit people, used to receive and move stolen funds. | Network intelligence and monitoring of inbound and outbound payment patterns. |
Card fraud | Unauthorised use of card details to buy goods or withdraw cash. | Layered transaction controls and anomaly detection. |
AI- enabled scams | Deepfake voices and faces, and AI-written messages, used to defeat verification or manipulate victims. | Liveness and injection-attack detection, and defensive AI that keeps pace. |
Notice how many of these are stopped after the account is open. That is the whole point.
How fraud prevention actually works
Good prevention is layered and continuous. No single control catches everything, so you stack them, and you keep them running for the life of the relationship. Five things separate a strategy that holds from one that leaks.
Know who you are dealing with, and keep checking
Verify identity properly at the start, using document, data and biometric checks. Then keep watching, because a customer who was genuine at onboarding can be taken over, coerced or turn bad later. Device intelligence and behavioural signals, how someone types, holds a phone or moves through a page, tell you when the person has changed even when the credentials have not.
Watch the whole lifecycle, not just the front door
The single most useful change most firms can make is to extend monitoring past account opening into live payments and account activity. That is where authorised fraud happens, and it is invisible to controls that only fire at application.
Match the friction to the risk
This is the balance that decides whether prevention helps or hurts the business. Turn every dial to maximum and you stop fraud, but you also block good customers, and that costs more than the fraud does. In our own research, 70% of firms said false positives cost them more than fraud losses, and more than three-quarters of consumers said reducing friction matters to them. Risk scoring lets you apply heavy checks only where the risk is real, and stay light everywhere else.
Use the network
You cannot see the whole picture alone, and you do not have to. Fraud data-sharing consortia let firms pool intelligence, so one member’s confirmed fraud becomes a warning to the rest. Organisations that join a consortium see, on average, a 20% uplift in fraud detection accuracy. The criminals collaborate. Defenders can too.
Put AI to work on defence, honestly
AI is genuinely useful on the defending side. It reads huge volumes of transactions in real time, spots patterns no rules engine would catch, and frees investigators from clearing false alarms. But it is not magic, and buying a model is not a strategy. The firms pulling ahead are the ones closing the speed gap, iterating their defences as fast as the attacker iterates the attack.
Key takeaway
You measure the fraud you caught. Who measures the good customers you turned away?
The honest challenges
Fraud prevention is not free and it is not perfect. Three tensions are worth naming.
- Customer experience. Every extra check adds friction. Too much and you lose the customers you were trying to protect. The answer is not less security, it is security that only shows up when the risk does.
- Cost. Good tools, data and people cost money, and the spend is ongoing. The way to justify it is to measure the whole picture: fraud stopped, yes, but also good customers retained and losses you now carry under reimbursement rules.
- False positives. Oversensitive systems flag genuine customers as fraudsters, creating work for staff and frustration for customers. A system that blocks everything is not a good system. Precision matters as much as reach.
None of these is a reason to do less. They are reasons to do it well, with the trade-offs made on purpose rather than by accident.

Building a fraud prevention strategy
Pulling this together, a strategy that holds up in 2026 does five things.
- Assesses risk honestly. Know your real vulnerabilities and where the current controls leak, especially past the point of onboarding.
- Covers the whole lifecycle. Verify at the start, then monitor account activity and payments continuously.
- Balances friction and risk on purpose. Decide where you will add friction and where you will not, and measure both fraud and the cost of false positives.
- Draws on shared intelligence. Use industry data and networks so you learn from frauds that hit other firms before they hit you.
- Keeps pace. Treat prevention as something you tune constantly, because the threat changes constantly.
If you can only do one thing first, extend your view past the front door. That is where the losses moved, and it is where most defences still are not looking.
Where to start
The threat is not going to slow down, and the cost of getting it wrong now sits with the firm, not just the customer. The firms that will be in a stronger position next year are the ones auditing their controls today: not just whether they stop fraud at the door, but whether they can see it once the door is open.
If you want a clearer picture of where fraud is heading and how UK financial services are responding, our UK Fraud, Financial and Identity Crime Report 2026 sets out the data, the threats and what leading firms are doing about them. It is the best place to pressure-test your own strategy against the reality of the market.
How we can help
If it helps to talk it through, that is what our fraud team is here for. We work with banks, lenders and payment firms to find where the defences are leaking and close the gaps without adding friction customers will feel.
Speak to an expert
If you would like a second opinion on your own approach, speak to one of our fraud experts.
Get in touchSources
[1] Annual Fraud Report 2026, UK Finance
[2] UK Fraud Strategy 2026-2029, UK Government
[3] APP scams reimbursement dashboard for Q4 2025, Payment Systems Regulator
[4] Fraudscape 2026, Cifas
[5] Fraud, Financial and Identity Crime Report 2026, Experian UK

