External Attack, Internal Gaps: Rethinking Anti-Fraud for a New Fraud Ecosystem
Digital fraud is no longer simply an external attack on a bank, platform or application. A scheme may begin on a marketplace or messaging app, move through a remote identification process, rely on perfectly normal customer behaviour and exploit weaknesses within the organisation itself. The outcome is often an argument over who should bear the loss instead of a concerted effort to protect the customer.
This is why anti-fraud teams need to see the entire chain of risk rather than isolated incidents. Speakers at the Eurasian Anti-Fraud Summit 2026 examined the issue from different professional perspectives, but kept returning to the same underlying problem. This article brings together the main conclusions from that discussion and the practical implications for business.
Fraud Increasingly Looks Like Normal Customer Behaviour
Modern fraud often involves behaviour that appears entirely legitimate. The customer logs in from their own device, uses their own account, authorises the transaction and discloses the information themselves. As far as the system is concerned, everything looks normal.
This creates a different challenge for anti-fraud teams. Traditionally, much of their work involved separating normal activity from transactions that showed clear signs of suspicion. Today, the transaction itself may trigger none of the familiar technical warnings. The fraudster persuades the customer to take the required action, exploiting human behaviour rather than a weakness in the system. Social engineering has become one of the main mechanisms of fraud. The bank must now protect not only the account or application, but also the customer at the point of decision, when that customer is still acting voluntarily but has already been drawn into a script written by someone else.
A Single Point of Defence Is No Longer Enough
Digital fraud now tends to unfold across several different environments. A typical example from the Georgian market begins when a fraudster contacts a seller through an online marketplace and moves the conversation to a messaging app. The fraudster explains that they cannot collect the item in person, promises to send a courier or representative, and asks for information supposedly needed to make the payment. The seller then provides details that are used to withdraw funds. Significantly, victims do not always realise straight away that they have been defrauded. From their perspective, every step looked like part of an ordinary sale.
The weakness therefore lies not in one place, but at the points where several systems and organisations meet. The bank sees only part of the journey. The marketplace sees another part. The identity provider sees its own segment. The customer experiences it all as one routine process. Anti-fraud teams must find ways to piece together the context from signals that sit across different systems.

The Legal Problem Begins When Fraud Looks Legitimate
If a transaction appears legitimate, where does the financial institution’s responsibility begin and where does it end? This emerged as one of the most difficult questions in the discussion.
An institution may spot the risk and try to stop the transaction. Yet blocking a payment, freezing funds or restricting an account creates legal and operational consequences of its own.
Once funds have been stopped on suspicion of fraud, the legal questions are only beginning. How long can they remain frozen? What is the legal basis for keeping them frozen? What happens if the investigation makes no progress and the institution cannot conclusively prove that the transaction was fraudulent? The funds are caught in a form of legal limbo. The risk is apparent, but there is not enough procedural certainty to determine what should happen next.
The allocation of responsibility adds another layer of tension. In some jurisdictions, the debate is gradually moving away from finding one party to blame. Instead, regulators and market participants are looking at the combination of failed controls that allowed the fraud to succeed. But the opposite extreme is also dangerous. If financial institutions reject any responsibility for customer losses simply because the correct formal procedures were followed, trust in the system will suffer. Anti-fraud is therefore about more than limiting financial losses. It also affects the relationship between the customer, the bank and the wider regulatory system.

Internal Vulnerabilities Extend Beyond Malicious Insiders
The internal control environment is another area of concern. The problem is not limited to employees who deliberately help fraudsters. Support from inside an organisation does not always involve conscious collusion.
It may be enough for someone to know about an important IT release or understand when a system will be particularly vulnerable to disruption. Employees may discuss operational details in personal chats, use private devices for work or rely on weaker controls outside normal working hours. In one case, information about an upcoming change to a customer-facing account gave fraudsters time to prepare. They waited for the right moment and exploited an unresolved vulnerability over the weekend, when the organisation had fewer people monitoring its systems.
Insider risk therefore needs a broader definition. It covers the deliberate disclosure of data, but also the informal circulation of sensitive information, poor coordination between software releases, security and operations, and blurred boundaries between corporate and personal digital environments. At the same time, employee monitoring creates a difficult trade-off between oversight and privacy.
Remote Identification Remains One of the Weakest Links
Biometrics and remote verification present a separate set of risks. Even when a company uses a robust identity verification service, the weakness may lie in a related process. The problem may not be the original registration, for example, but the procedure for recovering access to an account.
This distinction matters. Businesses often strengthen the main point of entry while leaving supposedly secondary service journeys less protected. Yet fraudsters may use precisely these routes. Armed with personal information obtained elsewhere, they can attempt to regain access to an account or take advantage of a simplified identity verification procedure.
More sophisticated impersonation tools are making the problem worse. AI can already make fraudulent approaches far more convincing. Language, voice, appearance and even the style of communication are becoming harder to distinguish from the real thing. The change is particularly significant in markets where language once offered an additional line of defence. Until recently, poor translations and unnatural phrasing often exposed phishing messages. That protection is rapidly disappearing.

Anti-Fraud Is Shifting from Fixed Models to Anomaly Detection
Traditional anti-fraud models often struggle with new forms of attack because they are trained on known cases. The faster fraud changes, the less effective an approach based only on past experience becomes.
This has increased interest in using AI to detect anomalous behaviour. Its value lies in spotting deviations and assessing several weak signals at the same time. These may include a sudden surge in applications from a location where activity is normally low, unusual device characteristics, atypical employee behaviour or actions performed outside normal working hours. None of these signals may prove fraud on its own. Taken together, however, they may justify closer scrutiny.
The important change is not the technology itself, but the way it is used. The aim is no longer to find one universal set of rules. It is to recognise what looks unusual in a particular context. Fraud now operates across an ecosystem, so detection must focus on the connections between actions rather than treating each event in isolation.
What This Means for Business

Several practical conclusions emerge from the discussion.
First, anti-fraud can no longer focus only on protecting a particular channel. Companies need to consider customer behaviour across the entire journey, from the initial contact on an external platform to the transaction itself, account recovery and the investigation that follows an incident.
Second, businesses should reassess service journeys that have traditionally been treated as secondary. Strong controls at onboarding offer limited protection if account recovery or remote servicing remains vulnerable.
Third, the internal control environment involves much more than conventional insider risk. Release schedules, the exchange of operational information, employee behaviour outside normal working arrangements, the use of personal devices and controls during weekends and out-of-hours periods all require attention.
Fourth, the tension between convenience and security is becoming harder to manage. Stricter onboarding and verification checks can frustrate customers and reduce conversion. A simpler customer journey, however, may leave the system exposed. Finding the right balance requires regular management attention. It cannot be left entirely to either the product team or the security function.
Fifth, anti-fraud increasingly shapes customer trust. A company that can protect customers from schemes in which they themselves become part of the attack does more than limit its own losses. It strengthens the service and creates a genuine competitive advantage.
Anti-fraud is moving beyond the narrow task of catching fraudsters. The wider challenge is to preserve the integrity of the system. For businesses, this is perhaps the most important point. Effective protection now depends on recognising an attack as a chain of connected events while, to the customer, it still looks like an ordinary part of everyday life.
Three Pillars of Manufacturing Efficiency: What Companies Need for Sustainable Growth
How do companies achieve tangible efficiency gains without new equipment or large-scale capital investments? What helps them move from individual initiatives to systemic change? These questions are addressed by Oleg Zakharov, Director of Operational Excellence at ERG, who shares hands-on experience of which elements of a production system actually work — and how these approaches […]
How Anti-Fraud Is Evolving and Why the Market Must Act Together
Why modern fraud can no longer be treated as a problem for individual banks to solve. Fraud schemes increasingly exploit human behaviour, scale rapidly across borders and harness new technologies as effectively as financial institutions themselves. What this means for anti-fraud, why the market needs faster ways to share intelligence, and how the challenge is viewed by banks, regulators, industry associations and technology partners.