Article

The Fraud That Passes Every Test

Article 8 min read Originally on LinkedIn ↗

The Fraud That Passes Every Test

Authorized fraud is growing twice as fast as everything else — because our defenses were built to answer the wrong question. Ahead of Febraban Tech, here is why Brazil may be where the missing layer gets built first.

Picture the transaction our industry has spent thirty years learning to stop. Stolen credentials. An unfamiliar device. A login from the wrong continent at the wrong hour. Every control we built — device binding, biometrics, behavioral analytics, transaction-graph risk — exists to catch that transaction.

Now picture the transaction actually draining accounts in 2026. The real customer. Their real phone. Their real face, their real fingerprint, their real password. A payment initiated by the legitimate account holder, inside a genuine session, to a recipient they typed themselves — while someone on the other end of a phone call or a WhatsApp thread walks them through it.

The device check passes. The biometric passes. The anomaly model shrugs. Approved.

Authorized push payment (APP) fraud is not a failure of our controls. It is their graduation ceremony. The criminal no longer needs to defeat the device binding, the biometric, or the risk model — the genuine customer defeats them on the criminal's behalf.

The numbers are no longer arguable

The industry's most authoritative sources have converged on the same picture, from different methods and different data:

  • Nasdaq Verafin's 2026 Global Financial Crime Report estimates $579 billion in global fraud losses for 2025 — and inside that number, consumer scam losses reached $62 billion, growing at a 19.3% compound annual rate: more than double the 8.2% growth of unauthorized fraud. [1] The fraud we built our stacks to stop is the slow-growing kind.
  • ACI Worldwide's Scamscope projects APP scam losses climbing to $7.6 billion by 2028 across six leading real-time payment markets — with losses over real-time rails specifically growing at 17% a year. [2] The faster money moves, the faster deception scales.
  • GASA's Global State of Scams 2025 — 46,000 adults, 42 markets — found that 57% encountered a scam in the past year and 23% lost money. Here is the detail that should end an entire category of strategy: 73% of people feel confident they can spot a scam. Nearly a quarter lost money anyway. [3] Awareness campaigns are necessary. They are not a control.

Three institutions, three methodologies, one conclusion: the growth in fraud is concentrated precisely where identity checks are useless — transactions the right person authorizes for the wrong reason.

Regulators have already decided who pays

While the industry debates detection, regulators worldwide have quietly settled the other question: when a customer is scammed, the institution pays.

The UK made reimbursement of APP scam victims mandatory in October 2024 — up to £85,000 per claim, with liability split between sending and receiving institutions. Singapore's Shared Responsibility Framework took effect the same year. Australia's Scams Prevention Framework followed. In the US, the CFPB sued three of the largest banks over scam losses on Zelle. [4]

And here is the result every bank CFO should sit with. In the first full year of the UK's mandatory reimbursement regime — the most aggressive liability shift in the world — APP fraud losses did not fall. They rose 19%, to £576 million. [5] UK Finance's own head of economic crime put it plainly: "it is clear we are not tackling the underlying problem effectively enough."

Reimbursement moves the loss onto the bank's balance sheet. It does not stop the loss from happening. Those are different problems — and only one of them has been regulated.

Brazil: the fastest-growing market for the fraud, and the best-positioned to end it

I will be at Febraban Tech in São Paulo this August, and I want to say something about Brazil that is not said often enough: Brazil is not behind on this problem. Brazil is early — on both sides of it.

Pix is the most successful instant-payment rail ever launched. It is also where authorized fraud found its perfect conditions. ACI projects Brazil as the fastest-growing APP scam market of any it analyzes — roughly 38% compound annual growth, from ~$380 million in 2023 toward ~$1.9 billion by 2028, with 94% of losses moving over Pix. [2] Febraban's own figures show scam losses of R$ 10.1 billion to the banking sector across two years, with Pix scams up 43%. [6] Independent research puts the social cost far higher: an estimated 56 million Brazilians — one in three adults — victimized by digital scams in a single year, 107 people per minute, with AI-assisted scams up 456%. [7]

But look at what Brazil did next, because no other market has moved this decisively. In February 2026, the Central Bank made MED 2.0 mandatory for every Pix participant: self-service refund requests inside every banking app, tracing of stolen funds through intermediary accounts, automatic blocking of suspect values for up to eleven days. [8] Recovery, standardized at the level of the rail itself — not bank by bank, but ecosystem-wide, all at once.

That is exactly the right instinct. It is aimed at the wrong end of the timeline.

MED operates on money that is already gone — and recovery after the fact remains brutally hard: acceptance rates on refund requests have been falling, not rising, as fraudsters route proceeds through layers of mule accounts. [7] Meanwhile, everything upstream of the loss — the moment a deceived, pressured, or terrified human presses confirmar — remains unexamined by every system in the flow.

The one question no control asks

Every layer of the modern fraud stack answers one of two questions: Is this the right person? and Does this transaction look statistically normal? APP fraud is engineered to answer yes to both.

The question none of them ask is the only one that matters at that moment: is this person authorizing freely?

That question has an observable answer. Deception, pressure, and coercion leave traces in the human — in facial affect, in vocal prosody, in the microexpressions that leak around a scripted confirmation — and those traces can be measured at the moment of authorization and compared against that same person's own baseline. This is what we build at RTScale: the State of Mind Signature™ — a cryptographically signed, on-device capture, a few seconds long, that produces tamper-evident evidence not of who approved a payment, but of how they were when they approved it.

To be precise about what that is and is not: it is not a lie detector, and it renders no verdict. It reads observable affect against a baseline and surfaces one signal — among several — so that a bank can route a suspect moment to a human, a callback, a cooling-off period, an out-of-band check. In a reimbursement era, that signal does double duty: it is the intervention point before an irrevocable payment, and it is audit-grade consent evidence after — exactly what the new liability regimes will demand when institutions dispute who should have caught what.

A scammer can coach a victim through every screen a bank puts in front of them. What the scammer cannot do is coach the victim's own involuntary state back to normal. The one surface the criminal cannot harden is the human they are exploiting.

Brazil leapfrogged the world on payments. It can do it again on consent.

Pix succeeded because Brazil built it as shared infrastructure — one standard, every institution, all at once. MED 2.0 followed the same playbook for recovery. The missing layer is the same playbook applied to prevention: consent verification at the authorization moment, standardized at the level of the ecosystem rather than rebuilt bank by bank.

The president of Febraban, Isaac Sidney, said it better than I can: "Ou nos unimos, ou vamos sucumbir diante desses marginais cada vez mais sofisticados." Either we unite, or we succumb. [6]

The uniting has started — on recovery. The next act is proving, at the moment of authorization, that consent was real. The country that taught the world how fast money can move is the natural place to teach it how to be sure the human behind the money meant it.

I'll be at Febraban Tech, August 24–26. If you are working on fraud, payments, or trust infrastructure at a financial institution — in Brazil, LATAM, or anywhere the regulators are rewriting who pays — I would welcome the conversation.

Vejo vocês em São Paulo.

Peter Walker is Co-founder & CEO of RTScale, building affective compute infrastructure for high-stakes authorization. The State of Mind Signature™ produces audit-grade, tamper-evident consent evidence at the moments that matter most.

Sources

  1. Nasdaq Verafin, 2026 Global Financial Crime Report (Mar 2026): https://ir.nasdaq.com/news-releases/news-release-details/nasdaqr-verafin-report-finds-financial-crime-epidemic-reaching
  2. ACI Worldwide Scamscope, with GlobalData (Nov 2024): https://investor.aciworldwide.com/news-releases/news-release-details/aci-worldwide-scamscope-projects-app-scam-losses-hit-76-billion
  3. GASA / Feedzai, Global State of Scams 2025 (Oct 2025): https://gasa.org/knowledge-base/blog/global-scams-on-the-rise-over-half-of-adults-worldwide-report-scam-encounters
  4. UK PSR reimbursement policy (PS25/5, May 2025): https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf ; MAS/IMDA Shared Responsibility Framework (Dec 2024): https://www.mas.gov.sg/news/media-releases/2024/mas-and-imda-announce-implementation-of-shared-responsibility-framework-from-16-december-2024 ; CFPB v. Zelle banks (Dec 2024): https://www.consumerfinance.gov/archive/newsroom/cfpb-sues-jpmorgan-chase-bank-of-america-and-wells-fargo-for-allowing-fraud-to-fester-on-zelle/
  5. UK Finance, Annual Fraud Report 2026 (Jun 2026): https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2026-press-release
  6. Febraban / Isaac Sidney (Mar 2025), via Finsiders Brasil: https://finsidersbrasil.com.br/eventos/golpes-com-pix-dao-prejuizos-de-quase-r-3-bi-em-dois-anos-diz-febraban/
  7. Silverguard, Estudo Golpes com Pix 2025 (with Datafolha / Fórum Brasileiro de Segurança Pública): https://uploads.finsidersbrasil.com.br/2025/10/Silverguard-Estudo_Golpes_com_Pix_2025.pdf
  8. Agência Brasil, "Novas regras de segurança do Pix entram em vigor" (Feb 2026): https://agenciabrasil.ebc.com.br/economia/noticia/2026-02/novas-regras-de-seguranca-do-pix-entram-em-vigor-veja-mudancas