How Anti-Fraud Is Evolving and Why the Market Must Act Together
Fraud is evolving faster than the procedures designed to combat it. While banks, regulators and law-enforcement agencies continue to operate within their respective remits, fraudsters already work as an interconnected and highly adaptable network. Effective defence therefore depends not only on technology, but also on the speed of the collective response.
At the Eurasian Anti-Fraud Summit 2026, panellists examined global trends and the transformation of anti-fraud from several professional perspectives: banking practice, technology and analytics, regulation, and industry-wide collaboration. This article brings together the main conclusions, using the Georgian market as an example — from the evolution of fraud schemes and defensive tools to cooperation among banks, regulators, technology companies and industry associations.
The Banking Perspective: Protecting the Perimeter Is No Longer Enough
From a banking perspective, one of the most important shifts is that conventional security measures remain effective against traditional forms of fraud but are less successful when customers themselves are persuaded or pressured into taking action. Controls designed to protect accounts and users from established fraud schemes do not fully address cases in which human behaviour is the primary point of vulnerability.
The practical conclusion is clear: anti-fraud can no longer be treated solely as a matter of strengthening a bank’s internal defences. Even a sophisticated control environment cannot provide complete protection if a fraudster establishes trust with a victim, guides them towards a particular action and exploits a human vulnerability rather than a weakness in the banking system.
A further concern for banks is the limited capacity of law enforcement. Meaningful investigative support is not always available: large numbers of relatively small cases place considerable pressure on the system, while police and prosecutors often lack the resources to investigate the full volume of incidents. In practice, this pushes banks to handle part of the response through their own processes and systems. Yet cooperation with law enforcement cannot be dispensed with altogether, particularly when a scheme becomes large-scale or crosses national borders.
Banking experience also points to a more encouraging development: specialist units within the police or wider law-enforcement system can make cooperation substantially more effective. When investigations are handled by teams specialising in cybercrime and financial crime rather than by generalist units, banks do not have to explain the context from the beginning each time. The underlying constraint, however, remains unchanged: the number of specialists is limited, while the caseload is considerable.

The Technology Partner’s Perspective: Trust- and Data-Driven Schemes Are Growing Fastest
From a technology perspective, the fastest-growing schemes are those in which fraudsters target people directly. Call-centre operations, investment scams, telephone fraud and impersonation all exploit trust, fear and emotional engagement. Such attacks are becoming increasingly prevalent across Europe, the Caucasus, Central Asia and other regions.
The same technologies used to strengthen defences are accelerating this trend. Artificial intelligence and large language models enable fraudsters to communicate with people in their own language, target emotional triggers more precisely and imitate familiar forms of communication more convincingly. This poses a particular challenge for smaller countries and less widely spoken languages. Until recently, phishing messages could often be identified by poor translations and unnatural phrasing. That barrier is steadily disappearing: AI can now generate credible messages in virtually any language.
At the same time, fraud is increasingly being offered as a ready-made service. Fraudsters no longer need to build their own infrastructure, source data, develop scripts and configure their tools. Much of what they need can be obtained through illicit marketplaces. This lowers the barrier to entry and allows new schemes to be launched and scaled much more rapidly.
The technological response, however, cannot be reduced to deploying AI. Identifying a suspicious scenario requires more than a customer’s name or the basic parameters of a transaction. Device characteristics, indicators of remote access, the context of a phone call taking place during a transfer, changes in user behaviour and other weak signals all matter. Each may appear harmless in isolation, but together they can reveal a very different picture.
This is precisely why no single machine-learning model can detect every form of fraud equally well. Different schemes require different models, and training those models requires data from multiple market participants. The broader the context, the greater the chance of identifying an emerging scheme before it becomes widespread.

The Regulator’s Perspective: Fraud Cannot Be Separated from AML or the Cross-Border Context
From a regulatory perspective, anti-fraud is becoming increasingly intertwined with anti-money laundering. Fraud rarely ends when funds leave a victim’s account: the money subsequently moves through chains of accounts, intermediaries and jurisdictions. Banks and public authorities must therefore treat the initial attack and the subsequent movement of funds as parts of the same process.
This is particularly relevant for Georgia, where a significant proportion of fraud is cross-border in nature. Call-centre operations, investment fraud, phishing and social-engineering schemes may be organised in one country and target victims in another, while the money flows and digital trails pass through several additional jurisdictions.
The second essential element is therefore international information sharing. When suspicious activity is detected, the relevant intelligence must be shared not only within the domestic system but also with organisations abroad that may be able to identify the next stage of the scheme or halt the movement of funds.
Reporting alone, however, is not enough. The value of information depends directly on how quickly it reaches those in a position to act. In practice, information sharing is complicated by differences in legislation, data-protection requirements and varying levels of institutional readiness to cooperate at speed.
The key question, then, is not simply whether suspicious activity is reported, but whether the market can act on that information before the money disappears and the same scheme is deployed against new victims.

The Industry Association’s Perspective: Without a Framework for Coordination, the Market Will Remain Slower Than the Fraudsters
An industry association should serve as more than a forum for meetings. Its role is to turn discussion into sustained cooperation among banks, regulators and other market participants.
In Georgia, this cooperation takes place through specialist committees and working groups covering legal matters, cybersecurity, Open Banking and other areas. Importantly, the process involves not only the largest institutions but also smaller banks, while the regulator participates in discussions on issues affecting the sector as a whole.
The practical value of this model becomes particularly clear during a crisis. When a new fraud scheme emerges, the association can quickly bring participants together, compare what they are seeing and establish a coordinated working response. It also maintains relationships with banking associations in neighbouring countries — a particularly important function given the cross-border nature of fraud.
Fraudsters have long operated as organised networks, sharing tools, data and proven methods. Banks, by contrast, often see only the part of an attack that affects their own customers. The market therefore needs forms of cooperation in which information is used not to gain a competitive advantage, but to strengthen the collective security of the sector.
Consortium-based initiatives, shared repositories of fraud signals, early-warning systems and near-real-time data exchange can turn fragmented observations into a coherent picture. Without this organisational framework, even highly capable banks will respond more slowly than an interconnected network of criminals.

Anti-Fraud Priorities for Practical Action
Taken together, the panellists’ perspectives point to four practical priorities for businesses.
The first is to shift the focus from protecting the channel alone to protecting customers at the point of decision. Fraudsters increasingly succeed by defeating the individual rather than the system. Anti-fraud controls must therefore account for manipulation, coercion and manufactured trust.
The second is to reduce the time between detecting a signal and passing it to those able to act on it. Cross-border schemes, call-centre operations and distributed infrastructure are making slow procedures increasingly ineffective. Wherever possible, the market needs shorter and faster routes for sharing intelligence.
The third is to improve the quality of the signal layer. Basic transaction attributes are no longer sufficient to combat modern fraud. Behavioural, device-level and contextual indicators are becoming more valuable because they make it easier to distinguish ordinary activity from an action induced by a fraudster.
The fourth is to treat anti-fraud as a cross-functional operating model rather than an isolated function. Outcomes depend not only on anti-fraud tools, but also on the legal framework, compliance, customer communication, market-wide cooperation and the quality of engagement with law enforcement.
Modern fraud advances fastest when organisations respond to it in fragments: technology in one silo, compliance in another, customer communication elsewhere, and market and law-enforcement engagement through separate channels. Fraud schemes, by contrast, operate as an integrated system.
The central question for any business is therefore whether it can rapidly bring together all the internal functions and external relationships required to respond to an incident, without losing critical time at organisational fault lines. Where that connectivity is absent, even sophisticated tools will have only a limited impact.
External Attack, Internal Gaps: Rethinking Anti-Fraud for a New Fraud Ecosystem
Modern fraud rarely looks like a conventional cyberattack. It is often disguised as routine customer activity and moves through marketplaces, messaging apps, remote identity checks and gaps in a company’s own processes. What does this mean for anti-fraud, the allocation of responsibility and the way businesses manage risk?
Anti-fraud under resource constraints: how to identify risk convergence points
How banks can build effective anti-fraud systems when resources are insufficient for total control. Why, in such conditions, the number of checks matters less than precise prioritization, the ability to separate noise from real risk, and the discipline to identify where fraudulent activity converges. What measures strengthen protection without heavy infrastructure: monitoring dormant accounts, limiting remote onboarding, analyzing links between transactions, and involving employees beyond the anti-fraud function.