At the Nacha 'Smarter, Faster Payments' conference in Las Vegas last month, a fraud panel discussion near midday sparked heated debate. When the moderator asked Con Edison's Chief Financial Officer Frank D'Amadeo about the 'pain points' businesses face amid rising payment fraud, his answer directly targeted the bankers and payment professionals in the audience.

'The U.S. needs to stop fraud before it reaches us, and there's a lot of data showing that if the banking community shared information, we could prevent a significant portion of fraud before it happens,' D'Amadeo said. He emphasized more clearly in an earlier panel discussion: 'Banks need to do more.'

His remarks immediately sparked a debate in the room about whether banks have sufficiently joined forces to curb criminals moving between banks to find victims. JPMorgan Chase, the largest U.S. bank, did not respond to requests for comment, but its executive Steven Bernstein, who moderated the panel D'Amadeo participated in, opened by saying: 'Fraud is everywhere.'

Fraud has become a major challenge for payment participants, including banks, processors, card networks, and numerous intermediaries and fintech companies. Now, faster digital payments (including the upcoming FedNow real-time payment system) and AI innovations threaten to worsen the situation. Thomas French, senior fraud advisor at software company SAS Institute, described the current state: 'It's a basket of badness—scams, scams, and more scams. When scams meet fast payments, it becomes fast fraud.'

Thomas French, Senior Advisor at SAS Institute
Thomas French
Image courtesy of Danielle Bates
 

French, who worked 27 years at Bank of America, former Wachovia, and First Union, said fraud has worsened significantly over the past year and a half. 'It's the industrialization of fraud—different criminal gangs each playing their part,' he said in an interview this month. 'In my 30-plus years in the industry, I've never seen such sophistication, speed, and a landscape full of scammers.'

Bank customers and financial institutions suffer losses together. Federal Trade Commission data from February shows that consumer-reported fraud losses in the U.S. jumped 30% in 2022 from 2021, reaching $8.8 billion, with most of it flowing through payment systems. These frauds occur in contexts such as business, shopping, investing, and online dating.

Payment fraud rises as bank transfers surge

Annual fraud losses by payment category, 2019-2022

Of the fraud reported by the FTC in 2022, 17% had identifiable payment methods. Among recorded channels, bank transfers and payments saw the largest losses, doubling from $762 million in 2021 to nearly $1.6 billion. This channel has been the largest single area of fraud losses for three consecutive years. Although bank payments had the highest losses, credit card fraud had the most reports.

Businesses also suffer losses

With such huge losses, victims are not only consumers but also businesses of all sizes, like the utility company D'Amadeo serves, covering the New York City area. On the receiving end, the utility receives 500 to 600 fraudulent collections daily from valid debit accounts—account information that scammers may buy on the dark web, sometimes even openly using Con Edison's account numbers. D'Amadeo said that relative to its 3 million customers, such fraud is small in scale.

But he is more concerned about risks on the payment side. The company 'constantly' faces email scams—fraudsters impersonating Con Edison executives or suppliers trying to trick payments, involving hundreds of millions of dollars at risk. For example, a company owing Con Edison might be hacked, with hackers sending invoices with accurate information but altered payment accounts, redirecting funds to scammers.

'Our biggest concern is on the payment side—being tricked into changing payment instructions for counterparties. If we don't notice within 24 hours, the funds are unrecoverable,' he said.

Small businesses are also targeted. Las Vegas detective Jefferson Grace described at the conference how a local business that had operated for 30 years went under after mistakenly sending a $1.1 million payment to scammers posing as a supplier. The fraudsters took over or mimicked email addresses and obtained executive names from social media like LinkedIn to send highly convincing emails.

'We place too much trust in email, which was never designed for this,' Grace said. Several speakers emphasized that executives should follow clear payment processing instructions to prevent fraud.

A major root of the problem is valid accounts being exploited by criminals. In the trend of 'synthetic identity fraud,' some real information is pieced together to create a facade of normalcy. Dustin White, head of risk for Visa U.S., said at the ETA Transact conference in Atlanta in April: 'Synthetic identity is a concerning and growing threat factor. It's quite sophisticated and highly damaging—not the $500, $1,000, or $2,000 small frauds that financial institutions face, but single 'explosive' scams of $80,000, $100,000, or even $150,000.' White noted that the Federal Reserve Bank of Boston estimates synthetic identity fraud caused $20 billion in losses in the U.S. in 2021. 'It's a very prevalent and growing threat vector.'

The challenge for payment and banking professionals is fixing fraud vulnerabilities without introducing too much 'friction.' The industry has made significant progress in making digital payments convenient for consumers, and banks and businesses are reluctant to remove features that facilitate commerce, especially online commerce.

Nacha turns to anti-fraud

Nevertheless, a consensus is forming: action must be taken. Industry organizations that can unite the banking and payment communities are brewing new initiatives. A Citi executive at the Nacha conference said during a debate: 'It's coming.'

A key player in any new effort will be Nacha (formerly the National Automated Clearing House Association). It is cautiously pushing for change within its community, including large bank operators, to make financial institutions take on more anti-fraud responsibility. Earlier this month, Nacha sought public comment on a new 'risk management framework' it is developing, designed to address the new era of fraud where funds are mistakenly 'pushed' by users to inappropriate accounts. Nacha said the update would address the growing fraud threat from ACH credits, wire transfers, cards, and other instant and digital payments.

'As a new risk management strategy, the framework aims to unite the ACH network and the broader payment community to address emerging and important areas of need and provide overall direction for new initiatives, guidance, rules, and industry tools,' said the May 2 Nacha executive summary. Nacha said the new framework aims to increase awareness of illegal push scams, reduce the success rate of such fraud, and improve opportunities for fund recovery after fraud occurs. Nacha spokesperson Dan Roth did not respond to multiple requests for comment.

Barriers to cooperation

Mark Dixon, vice president of education at the New England Automated Clearing House Association in Burlington, Massachusetts, said part of the problem is banks' reluctance to share customer data that could help fight fraud. Banks have long been sensitive about sharing information that might undermine their proprietary interests, but this attitude may now be shifting, at least slightly.

'The industry is looking at how to communicate more proactively,' Dixon said, mentioning Nacha's new framework concept and the Nacha Contact Registry designed to help institutions connect. 'The challenge is ensuring all institutions participate.'

The difficulty also lies in the fact that there are nearly 10,000 banks in the U.S., making it a daunting task to get them to communicate with each other. To that end, Nacha developed the Contact Registry in 2020 and took on the labor-intensive work of inviting bank personnel to register. The registry now has 45,000 contacts. Nacha's operating rules require financial institutions to provide contacts so other institutions can reach them when needed, and all institutions should be willing to share in the spirit of reciprocity.

'The registry is designed to provide financial institutions with consistent, accurate information so they can contact other institutions in fraud scenarios such as business email compromise and supplier impersonation,' said Jeanette Fox, senior director of risk investigations and ACH network risk management at Nacha, in an email statement.

Early Warning Services, the bank-owned operator of the payment tool Zelle, also runs a national shared database where large U.S. banks contribute account information, but professionals note that because small banks hold more than a quarter of accounts, the database has significant coverage gaps.

Banks launch another initiative

Other banking organizations are also brainstorming. According to an industry source who spoke on condition of anonymity, the American Bankers Association is working with Early Warning Services on a new anti-fraud prevention project. The project currently has only a few banks involved and is about to enter a pilot phase; the source declined to provide more details. American Bankers Association spokesperson Sarah Grano and Early Warning Services spokesperson Meghan Fintland both declined to comment.

Professionals from these organizations meet regularly to discuss fraud and risk, but French remains concerned that banks are not capturing and sharing information sufficiently. He noted that bankers are heavily constrained by policy and reluctant to share information with third parties. Additionally, some professionals prefer not to publicize new technologies to avoid tipping off criminals. 'There is some sharing, but I think there is a need and a desire for more sharing of different information,' said French, whose company sells fraud analytics software.

Nevertheless, in recent months, companies including SAS Institute, card network Mastercard, credit bureau Experian, and numerous fintech firms have increased public promotion of new anti-fraud tools.

Europe explores new paths

Across the Atlantic in Europe, collective industry response has made more progress. The new concept of 'authorized push payment' has taken root, with banks bearing joint liability for erroneous payments, said Donna Turner, former chief operating officer of Early Warning Services and now an advisor at audit firm EY. Sending financial institutions in Europe now bear equal anti-fraud responsibility as receiving institutions. With the open banking trend following the EU's Second Payment Services Directive (PSD2) in 2016, data sharing among European banks has expanded.

'Banks and payment participants on both sides of a transaction have stronger incentives to change behavior to combat fraud,' Turner said in an interview this month. 'It's about protecting the ecosystem.' Participants in the U.S. payment ecosystem may be starting to adopt the same mindset to build a stronger industry-wide anti-fraud defense.

Caitlin Mullen contributed to this article.