JT International Blog

Breaking Down Fraud Silos: Key Lessons from the UK Finance Fraud Report 2026

Written by Henry Howe | 28-Jul-2026 10:30:08


Key Takeaways

  • APP fraud is increasingly a cross-sector challenge requiring shared intelligence.

  • The earliest fraud signals often appear on telecom and digital channels.

  • Real-time mobile data can add critical context to fraud and identity decisions.

  • Organisations that act earlier have the best chance of stopping scams before payment.


The UK lost £1.28 billion to 4.06 million fraud cases last year — but the bigger story is where those scams now began.
 
According to UK Finance, 83% of authorised push payment (APP) fraud cases either started online or through telecoms channels, where fraudsters isolate and deceive their victims into approving the payment themselves. By the time banks and fintechs assess the payment, the manipulation has already succeeded.

Deception by Consent

Losses from unauthorised fraud — where a third party makes the payment without the account holder’s approval — fell by 5%. Banks also prevented £1.68 billion in attempted unauthorised fraud.
 
But APP fraud in particular, where the customer is manipulated into authorising the payment, rose 19% to £576.4 million and caused the full increase in total fraud losses.
 
APP fraud is difficult to detect because the customer passes every check while acting on a lie. To the bank, the payment looks legitimate: the account is real and the customer has confirmed the transaction. What the payment system cannot always see is the coercion behind that decision.

Telecoms Fraud Causes Larger Losses

Interestingly, online platforms originated 66% of APP fraud cases but accounted for just 32% of losses. In contrast, telecom channels initiated only 17% of cases but drove a disproportionate 28% of losses.
 
That’s because fraudsters usually make first contact through investment advertisements on social media, then continue the conversation by phone or messaging app. Many impersonate banks or government bodies by text. Delivery scams have become quite prevalent as well; scammers send messages directing the recipient to fake payment pages.
 
In all these scenarios, the pretext changes but the tactic is the same: the criminal builds trust or creates urgency and then convinces the victim that the payment is necessary.

Fraudsters are Attacking Human Judgement

This persuasion-based behavioural hijacking has fuelled a record-breaking surge in "malicious-payee" fraud — an umbrella category covering purchase, investment, romance, and advance-fee scams. Losses across these categories spiked 35% year-on-year to £437 million, with every single sub-category reaching an all-time high.
 
Purchase scams spread rapidly through online marketplaces and social platforms to make up 71% of all cases. Fraudsters advertise goods or services that don’t exist and then pressure victims to pay outside the platform’s payment system.
 
Investment fraud claimed fewer victims but accounted for 38% of all APP fraud losses. These high-value scams are a psychological long game. Romance scams, where perpetrators systematically manufacture trust, may develop over several months before the fraudster engineers a fabricated ‘financial emergency’ and requests money. Some app-based investment scams even go undetected for years until the victim discovers that the entire trading platform — and the returns it reports — never existed.

Why Current Defences Fail

When exploiting cognitive blind spots, criminals rarely need to bypass an authentication control: they only need to make the victim believe that the payment request is genuine. Meticulous social engineering can persuade customers to willingly authorise the transfer, essentially making even the strongest bank authentication controls toothless.
 
The problem isn’t that there’s a lack of warning signs — it’s that those signs are scattered across different organizations.
 
It might begin when a fake advertisement slips past content filters and onto the target’s social media, who then clicks through, migrating the conversation to a direct mobile call or messaging app.
 
Bit by bit, the criminal makes the payment appear legitimate to the victim until pressing ‘send’ seems like the only logical choice. They might warn that a bank account is under imminent attack or dangle an exclusive, fast-closing investment that expires in minutes. Panicked customers are swept by this fabricated urgency: they log in and willingly authorise the transfer using their own valid credentials.
 
Clues that something is wrong may register at different stages of the journey, but because these warning signs are trapped in separate organisational silos, the bank at the very end of the line receives what looks like an authenticated request. It assumes that the customer is acting freely, assessing the final transfer on the evidence available and approving it.

Reimbursement is Not Prevention

Banks are carrying an increasing share of the financial damage caused by APP fraud. 89% of in-scope APP fraud losses were returned to victims under the UK Payment Systems Regulator’s mandatory reimbursement rules. The reimbursement bill continues to grow even though the original deception happened elsewhere.
 
Refunding losses goes a long way in protecting consumers, but it treats the symptom rather than the disease. The money still entered the criminal ecosystem.
 
Intervention must happen upstream to stop the deception before the payment is authorised. That means introducing smart friction during account access and high-risk transactions, intercepting the fraudster before money leaves the account.
 
But many fraud and risk teams still rely solely on mobile numbers to verify these critical checkpoints. That worked when possession of a number was a stronger proxy for identity, but it’s now far less reliable because fraudsters can hijack numbers via SIM swaps and porting attacks.
 
Real-time mobile-network data can add that missing context by checking:
 
• whether the SIM changed recently
• whether the subscriber details match the identity presented
 
These checks can expose account-takeover or identity risk. For APP fraud, banks also need signals that indicate whether the customer is being coached through a payment, such as live calling-line data.

Fraud Prevention Must Become a Shared Responsibility

UK Finance is calling for closer cooperation and real-time data sharing between every organisation involved in the fraud journey: financial institutions, technology companies, telecom providers, and regulators. Pooling the warning signals each organisation sees would expose patterns that no single organisation can detect in isolation.
 
The information used to assess each payment must become richer as well. Any business handling digital identity or payments can’t just rely on validating credentials — they need real-time, network-level signals that reveal who is actually controlling the account or the device at the moment of payment.

How Mobile Intelligence Can Help

Credentials only show what was entered, not who entered it. For instance, a one-time passcode can seem entirely legitimate even while a victim is being coached through a scam on a live call.
 
Mobile intelligence reads the live state of the network so that risk decisions are not based on the validity of the text string alone.

 
JT’s suite of services applies that intelligence at several points in the customer journey:


●    SIM Swap checks when a SIM card and phone number were last paired to flag recent changes. Through JT, you can access real-time data from UK and international mobile operators to assess whether a transaction may be linked to an account takeover attempt.

●    Scam Signal uses real-time calling-line data to detect if a customer is trapped on a live voice call with a fraudster during a high-risk payment journey. You can integrate this telecom data into your existing fraud engines to flag suspicious behaviour and take action.

●    Know Your Customer matches customer-submitted details against verified mobile operator records during onboarding. This real-time access to operator-level customer data allows you to verify the identity of new customers without adding extra friction to the account opening process.

●    Silent Authentication+ uses cryptographic technology and device binding to authenticate customers without relying on passwords or SMS one-time passcodes, which can be stolen or intercepted.
 
These mobile intelligence capabilities can add mobile-network data to onboarding and payment decisions, giving you the real-time context needed to know if a criminal is manipulating the interaction — while there is still time to stop the transfer.

Secure the New Front Line

Since most APP fraud cases originate on digital and telecom platforms long before a transfer occurs, reducing losses requires technical interventions much earlier in the customer journey.
 
Schedule a meeting with one of our experts to see how JT’s real-time telemetry can close the blind spots in your existing defence.