The latest insights from UK Finance underscore a persistent and evolving challenge in the fight against financial crime. Despite consant efforts by banks and financial institutions to block illicit activities, fraudsters are demonstrating greater sophistication, leading to rising losses and a notable change in tactics.
The Annual Fraud Report 2026 reveals that payment fraud resulted in £1.28 billion in losses during 2025, marking a 4% increase from the previous year and the second year of consecutive growth.
This uptick reflects not just the volume of attempts but the ways in which organised crime groups leverage new technologies to outmanoeuvre traditional safeguards.
A key takeaway is the growing emphasis on human-targeted scams rather than purely technical breaches.
As institutions strengthen controls around accounts and transactions, criminals increasingly rely on psychological manipulation to trick individuals into voluntarily transferring funds.
The research report illustrates a clear split in fraud patterns. Unauthorised fraud, which involves criminals directly accessing accounts without the owner’s knowledge, fell by 5% to £703.4 million gross.
This decline demonstrates the effectiveness of ongoing investments in detection systems and preventive measures.
In contrast, Authorised Push Payment (APP) scams surged by 19% to £576.4 million.
These scams typically involve extended interactions where fraudsters build trust—often through fabricated romantic relationships, fake investment opportunities, or impersonation of trusted entities.
Perpetrators use compromised information, digital platforms, artificial intelligence for voice or text cloning, and real-time pressure tactics to persuade victims to authorise payments themselves.
This approach sidesteps many conventional security protocols, as the transaction appears legitimate from the bank‘s perspective.
Such developments signal a broader transition in the fraud ecosystem. What was once primarily a matter of monitoring devices and anomalous transactions has become equally about protecting customers from sophisticated social engineering.
Financial organisations must now prioritise understanding customer behaviour, spotting signs of coercion, and intervening before funds move.
The implications extend beyond statistics. Regulators, customers, and policymakers are raising expectations for quicker interventions, better victim support, and higher reimbursement rates.
Institutions can no longer rely solely on prevention metrics; they must excel in response, recovery, and collaboration.
Effective responses include several core areas. First, real-time detection of manipulation indicators during customer interactions.
Second, enhanced visibility into payment contexts, beneficiary risks, and customer intent to address gaps in rules-based systems.
Third, deeper intelligence sharing across banks, sectors, and borders, recognising that criminals operate internationally and share tactics.
Finally, a balanced framework that combines strong upfront defences with rapid response capabilities when incidents occur.
This integrated approach calls for moving away from isolated tools toward dynamic, data-driven models that harness collective analytics.
Cross-industry partnerships will be essential to track patterns, identify high-risk networks, and enable proactive interventions.
As threats grow more adaptive, success will depend on agility, shared knowledge, and technology that can keep pace with criminal innovation.
The UK Finance report serves as a timely call to action.
With fraud losses climbing and tactics shifting toward customer-authorised transfers, the sector faces a new phase requiring both technological advancement and heightened focus on human vulnerabilities. By embracing collaboration and evolving prevention frameworks, financial institutions can better safeguard customers and maintain resilience in an increasingly complex threat environment.