Scams are an Iceberg, and Almost No Institution Measures Them Properly

TL;DR Fraud leaders have described scams as an iceberg for years, and the description is accurate. Much of the detection effort still sits at the point of payment, where the criminal has the most control and the data reveals the least. Scam and payment fraud losses have risen in the UK, the US and the EEA anyway. Detection learns from reported cases, and in the US only about 7% of consumer fraud victims are counted, so it only learns from a fraction of actual scam incidents.

Why are scam losses rising despite better detection?

Each wave of investment in fraud detection technology has been aimed at the moment of payment.I have watched three such waves pass through this industry: rules engines, then machine learning on transaction features, then behavioral and device signals. Each was a genuine improvement, but the payment is where the evidence about a scam is thinnest. By that point in an authorized push payment (APP) scam, the customer has logged in, passed authentication and approved the transfer, so the record appears to show legitimate activity.

I do not think aiming at the payment was a mistake at the time. The payment is where the data was cleanest, the labels were most reliable, and the return on a better model was easiest to prove. Every incentive pointed there.

Even so, losses rose. UK Finance recorded £576.4 million in APP scam losses across 248,070 cases in 2025, with losses up 19% and cases up 7%, so each case now costs more. Federal Trade Commission figures put US consumer losses paid by bank transfer and payment at $2.09 billion for 2024, up 13% and the largest single payment method. The European Central Bank and European Banking Authority measured €4.2 billion in EEA payment fraud for 2024, up 17%, with credit transfers alone up 24%.

Three markets, measured by three different bodies, show the same direction through years of detection investment.

What share of scams does the industry actually measure?

Roughly 7% of US consumer fraud victims are counted in FTC data, according to Consumer Federation of America analysis. The same analysis sets $20.8 billion in reported US consumer fraud losses against an implied $148.2 billion in actual losses. For most victims, there is no reported case at all.

For a detection team, that gap is a modeling problem. Systems are trained, tuned and prioritized against reported cases. If most victims never appear in the data, and the missing cases are not missing at random, every model built on that data inherits the same blind spot, and every roadmap built on those models reinforces it.

Gallup and the Stop Scams Alliance put US scam losses at $68 billion in 2025 across roughly 15 million adults, and 56% of reported scams cost $500 or less. Most individual cases look minor, even though they scale up to major losses, so a team that reviews cases one at a time sees little to prioritize.

Why do scams bypass controls at the point of payment?

In an APP scam, the criminal spends hours or days working toward a single outcome, which is getting the payer to press send. By the time the bank scores that payment, the credentials are correct, the device is one the bank recognizes, and the behavior matches the account's history, because the real customer has been persuaded to make a real payment.

Nearly half of scams run from first contact to payment inside 24 hours, according to research from the Global Anti-Scam Alliance and Feedzai, so a control that waits for the payment to be scored is already too late to detect the scam before the money moves. Real-time payment rails shorten that window further, and ACI Worldwide projects that 80% of APP scam value will move across those rails by 2028.

Is regulation pointing us at the tip as well?

Largely, yes: the main controls regulators have promoted check the payer's information at the moment of payment, for the same reason the industry did: that is where the data is cleanest. Pay.UK has operated Confirmation of Payee since 2020 as an account name-checking service "designed to help reduce misdirected payments." Over 300 organizations have implemented it, completing more than two million checks a day.

The European Union has now made the equivalent control a requirement. Article 5c of the Instant Payments Regulation requires payment service providers to offer payers a free service that verifies the payee before a credit transfer is sent.

Payee verification is a good control, but can easily be bypassed by a scammer supplying the genuine name on the receiving account, so the check returns a clean match and the payment proceeds. The control gives the payer better information at the moment of decision, yet the payer is the person the criminal has already persuaded.

Does reimbursement reduce push payment scam losses or move them?

In the UK, rules announced by the Payment Systems Regulator in 2023 and in force since October 2024 require banks to reimburse victims of authorized push payment scams, with the cost shared between the sending and receiving firms. The cost of a scam has therefore moved from the customer to the institution, which changes what leadership sees. In 2025, UK banks reimbursed £354.3 million to victims, roughly 61% of total losses.

Making institutions pay for these losses is the right decision, in my opinion. A customer deceived by a convincing impersonation should not carry the full cost alone. However this liability and reimbursement shift also changes what the institution can see. Before reimbursement, a scam loss sat with the customer and reached the institution as a complaint. After reimbursement, the same loss reaches the institution as a line on the P&L.

The number became visible without becoming smaller. I think parts of this industry have mistaken new visibility for new volume, and have put their effort into managing reimbursement instead of the scams generating more and more claims.

What percentage of your confirmed scam cases were linked to another case?

Almost no institution can say how many of its confirmed scams connect to others, even though the data needed is usually already accessible. The beneficiary accounts, device identifiers, onward transfers and account-opening records all sit in systems the institution already owns, but they are stored separately and rarely matched against each other. There isn't a reporting requirement and most board reports don't ask for that combined figure, so nobody does the matching.

I have asked this question in enough rooms to know the pattern. The first answer is usually an estimate. The second, once somebody checks, is that the query has never been run.

If the hidden part of the iceberg is as large as the industry says, the share of cases that connect to other cases is among the most useful numbers a fraud function could produce. Almost none of them produce it.

What would change if linkage were a reported metric?

Fraud teams would change what they invest in, and they would do it within a quarter, because leadership funds what its reports show. Counting incidents as a KPI makes tools that stop one case at a time look valuable. However, counting how cases connect would make tools that identify and expose the criminal group behind several cases more valuable.

Most fraud teams report four things to supervisors: case counts, loss values, detection rates and reimbursement timeliness. Each measures by single incident, and incident measures make a criminal group look like a series of unrelated events, so the group stays out of sight. Linkage reporting would change each of the four:

  • Instead of reported cases closed as individual write-offs, report the share of confirmed cases linked to at least one other case.
  • Instead of loss value per case, report loss value per identified criminal group.
  • Instead of detection rate at the payment alone, report detection rate on the receiving account as well.
  • Instead of reimbursement volume and timeliness alone, report repeat exposure to groups the institution has already seen and closed.

None of that requires new data to be collected. It does require a different approach to detection, one that compares records from separate systems in one place instead of reviewing each system alone. The starting point is entity resolution, which matches records that belong to the same person, account or device across the systems an institution already holds, and then reporting the result to people who can act on it.

I would expect two effects. Budget conversations would shift from buying another scoring tool to better analyzing the records the institution already pays to store. And closing a case wouldn't end the work of detection, because a case linked to four others describes a criminal group that stays active long after the individual write-off is booked.

What I expect to happen next

I expect two things, on different timelines. Payee verification will become normal across major markets. It will reduce misdirected payments and stop some impersonation attempts, but it will not effectively identify scams where the payer is given the genuine name. And within a few years, some regulator will ask an institution to report on network-level scam exposure instead of case-level losses. Reporting requirements usually start as an expectation, become a supervisory question, and end as a return with a deadline.

The institutions positioned to succeed in that environment will be the ones that began tracking linked cases before a regulator asked for them.

Counting linked cases starts with your own records. Seeing past them takes shared intelligence, which FraudNet's Global Anti-Fraud Network supplies by pooling anonymized fraud data from participating organizations. To see what sits beneath a reported payment, book a demo.

Table of Contents

You might be interested in…

Get Started Today

Experience how FraudNet can help you reduce fraud, stay compliant, and protect your business and bottom line

Recognized as an Industry Leader by