External Attack, Internal Gaps: Rethinking Anti-Fraud for a New Fraud Ecosystem
Article
16.07.2026
9 minutes

External Attack, Internal Gaps: Rethinking Anti-Fraud for a New Fraud Ecosystem

Digital fraud is no longer simply an external attack on a bank, platform or application. A scheme may begin on a marketplace or messaging app, move through a remote identification process, rely on perfectly normal customer behaviour and exploit weaknesses within the organisation itself. The outcome is often an argument over who should bear the loss instead of a concerted effort to protect the customer.

This is why anti-fraud teams need to see the entire chain of risk rather than isolated incidents. Speakers at the Eurasian Anti-Fraud Summit 2026 examined the issue from different professional perspectives, but kept returning to the same underlying problem. This article brings together the main conclusions from that discussion and the practical implications for business.

Fraud Increasingly Looks Like Normal Customer Behaviour

Modern fraud often involves behaviour that appears entirely legitimate. The customer logs in from their own device, uses their own account, authorises the transaction and discloses the information themselves. As far as the system is concerned, everything looks normal.

This creates a different challenge for anti-fraud teams. Traditionally, much of their work involved separating normal activity from transactions that showed clear signs of suspicion. Today, the transaction itself may trigger none of the familiar technical warnings. The fraudster persuades the customer to take the required action, exploiting human behaviour rather than a weakness in the system. Social engineering has become one of the main mechanisms of fraud. The bank must now protect not only the account or application, but also the customer at the point of decision, when that customer is still acting voluntarily but has already been drawn into a script written by someone else.

A Single Point of Defence Is No Longer Enough

Digital fraud now tends to unfold across several different environments. A typical example from the Georgian market begins when a fraudster contacts a seller through an online marketplace and moves the conversation to a messaging app. The fraudster explains that they cannot collect the item in person, promises to send a courier or representative, and asks for information supposedly needed to make the payment. The seller then provides details that are used to withdraw funds. Significantly, victims do not always realise straight away that they have been defrauded. From their perspective, every step looked like part of an ordinary sale.

The weakness therefore lies not in one place, but at the points where several systems and organisations meet. The bank sees only part of the journey. The marketplace sees another part. The identity provider sees its own segment. The customer experiences it all as one routine process. Anti-fraud teams must find ways to piece together the context from signals that sit across different systems.

The Legal Problem Begins When Fraud Looks Legitimate

If a transaction appears legitimate, where does the financial institution’s responsibility begin and where does it end? This emerged as one of the most difficult questions in the discussion.

An institution may spot the risk and try to stop the transaction. Yet blocking a payment, freezing funds or restricting an account creates legal and operational consequences of its own.

Once funds have been stopped on suspicion of fraud, the legal questions are only beginning. How long can they remain frozen? What is the legal basis for keeping them frozen? What happens if the investigation makes no progress and the institution cannot conclusively prove that the transaction was fraudulent? The funds are caught in a form of legal limbo. The risk is apparent, but there is not enough procedural certainty to determine what should happen next.

The allocation of responsibility adds another layer of tension. In some jurisdictions, the debate is gradually moving away from finding one party to blame. Instead, regulators and market participants are looking at the combination of failed controls that allowed the fraud to succeed. But the opposite extreme is also dangerous. If financial institutions reject any responsibility for customer losses simply because the correct formal procedures were followed, trust in the system will suffer. Anti-fraud is therefore about more than limiting financial losses. It also affects the relationship between the customer, the bank and the wider regulatory system.

Internal Vulnerabilities Extend Beyond Malicious Insiders

The internal control environment is another area of concern. The problem is not limited to employees who deliberately help fraudsters. Support from inside an organisation does not always involve conscious collusion.

It may be enough for someone to know about an important IT release or understand when a system will be particularly vulnerable to disruption. Employees may discuss operational details in personal chats, use private devices for work or rely on weaker controls outside normal working hours. In one case, information about an upcoming change to a customer-facing account gave fraudsters time to prepare. They waited for the right moment and exploited an unresolved vulnerability over the weekend, when the organisation had fewer people monitoring its systems.

Insider risk therefore needs a broader definition. It covers the deliberate disclosure of data, but also the informal circulation of sensitive information, poor coordination between software releases, security and operations, and blurred boundaries between corporate and personal digital environments. At the same time, employee monitoring creates a difficult trade-off between oversight and privacy.

Remote Identification Remains One of the Weakest Links

Biometrics and remote verification present a separate set of risks. Even when a company uses a robust identity verification service, the weakness may lie in a related process. The problem may not be the original registration, for example, but the procedure for recovering access to an account.

This distinction matters. Businesses often strengthen the main point of entry while leaving supposedly secondary service journeys less protected. Yet fraudsters may use precisely these routes. Armed with personal information obtained elsewhere, they can attempt to regain access to an account or take advantage of a simplified identity verification procedure.

More sophisticated impersonation tools are making the problem worse. AI can already make fraudulent approaches far more convincing. Language, voice, appearance and even the style of communication are becoming harder to distinguish from the real thing. The change is particularly significant in markets where language once offered an additional line of defence. Until recently, poor translations and unnatural phrasing often exposed phishing messages. That protection is rapidly disappearing.

Anti-Fraud Is Shifting from Fixed Models to Anomaly Detection

Traditional anti-fraud models often struggle with new forms of attack because they are trained on known cases. The faster fraud changes, the less effective an approach based only on past experience becomes.

This has increased interest in using AI to detect anomalous behaviour. Its value lies in spotting deviations and assessing several weak signals at the same time. These may include a sudden surge in applications from a location where activity is normally low, unusual device characteristics, atypical employee behaviour or actions performed outside normal working hours. None of these signals may prove fraud on its own. Taken together, however, they may justify closer scrutiny.

The important change is not the technology itself, but the way it is used. The aim is no longer to find one universal set of rules. It is to recognise what looks unusual in a particular context. Fraud now operates across an ecosystem, so detection must focus on the connections between actions rather than treating each event in isolation.

What This Means for Business

Several practical conclusions emerge from the discussion.

First, anti-fraud can no longer focus only on protecting a particular channel. Companies need to consider customer behaviour across the entire journey, from the initial contact on an external platform to the transaction itself, account recovery and the investigation that follows an incident.

Second, businesses should reassess service journeys that have traditionally been treated as secondary. Strong controls at onboarding offer limited protection if account recovery or remote servicing remains vulnerable.

Third, the internal control environment involves much more than conventional insider risk. Release schedules, the exchange of operational information, employee behaviour outside normal working arrangements, the use of personal devices and controls during weekends and out-of-hours periods all require attention.

Fourth, the tension between convenience and security is becoming harder to manage. Stricter onboarding and verification checks can frustrate customers and reduce conversion. A simpler customer journey, however, may leave the system exposed. Finding the right balance requires regular management attention. It cannot be left entirely to either the product team or the security function.

Fifth, anti-fraud increasingly shapes customer trust. A company that can protect customers from schemes in which they themselves become part of the attack does more than limit its own losses. It strengthens the service and creates a genuine competitive advantage.

Anti-fraud is moving beyond the narrow task of catching fraudsters. The wider challenge is to preserve the integrity of the system. For businesses, this is perhaps the most important point. Effective protection now depends on recognising an attack as a chain of connected events while, to the customer, it still looks like an ordinary part of everyday life.

Three Pillars of Manufacturing Efficiency: What Companies Need for Sustainable Growth
Three Pillars of Manufacturing Efficiency: What Companies Need for Sustainable Growth
#Employee Engagement, #Lean Manufacturing

How do companies achieve tangible efficiency gains without new equipment or large-scale capital investments? What helps them move from individual initiatives to systemic change? These questions are addressed by Oleg Zakharov, Director of Operational Excellence at ERG, who shares hands-on experience of which elements of a production system actually work — and how these approaches […]

How Anti-Fraud Is Evolving and Why the Market Must Act Together
How Anti-Fraud Is Evolving and Why the Market Must Act Together
#Anti-Fraud, #Banking, #Digital Transformation, #Financial Fraud, #Risk Management

Why modern fraud can no longer be treated as a problem for individual banks to solve. Fraud schemes increasingly exploit human behaviour, scale rapidly across borders and harness new technologies as effectively as financial institutions themselves. What this means for anti-fraud, why the market needs faster ways to share intelligence, and how the challenge is viewed by banks, regulators, industry associations and technology partners.

Similar articles

How to Build a Mature Anti-Fraud Function
#AML #Anti-Fraud #Banking Risk #Compliance #Financial Crime #Fraud Analytics #fraud prevention #Fraud Risk Management #Operational Risk
How to Build a Mature Anti-Fraud Function

Fraud schemes often evolve faster than internal controls. A mature anti-fraud function does more than investigate losses. It identifies weaknesses early, informs product design, connects signals across accounts and measures whether controls are reducing risk without creating unnecessary friction.

How attackers enter corporate networks through employee accounts
#Anti-Fraud #Cybersecurity #Data Protection #Hybrid Work #Risk Management
How attackers enter corporate networks through employee accounts

Why the most dangerous threat to businesses is no longer external hacking, but access gained through legitimate employee accounts. How security logic is evolving in hybrid environments, how attackers penetrate internal systems, and which signals can reveal an attack before it results in data leakage or infrastructure takeover.

Risk Management as Part of Decision-Making
#Board of Directors #Corporate Governance #Enterprise Risk Management #Operational Efficiency #Risk Management #Strategy
Risk Management as Part of Decision-Making

Policies, risk registers and risk committees do not necessarily mean that a company is managing risk. The system begins to add value when it helps to take better decision before a mistake becomes irreversible. This article looks at how to connect risk with business objectives, involve the risk function earlier and turn indicators into management action.

Fraud in fintech: the price of convenience
#Antifraud #Artificial Intelligence #Digital Services #Fintech #Operational Efficiency #Risk Management
Fraud in fintech: the price of convenience

Fraud in fintech is no longer just a security concern. It shapes growth, trust and regulatory scrutiny. This article explores the trade-offs between convenience and control, what works in practice, and how risk strategy evolves as companies mature.