Payment fraud rises, banking industry seeks joint response
Payment fraud is becoming increasingly serious, and the U.S. banking industry is brewing joint countermeasures. At the Nacha conference, Con Edison treasurer Frank D'Amadeo bluntly stated that banks need to take on more responsibility, sparking discussion. Federal Trade Commission data shows that consumer fraud losses increased 30% year-over-year to $8.8 billion in 2022, with bank transfer losses doubling to $1.6 billion. Nacha has proposed a new risk management framework for comment, but obstacles remain in data sharing among banks.

Last month, at the "Smarter, Faster Payments" conference hosted by Nacha, a fraud panel discussion scheduled near lunchtime stirred waves in the venue when one guest's remarks made an impact.
Frank D'Amadeo, treasurer of Consolidated Edison, directly addressed the bankers and payments professionals in the room while answering the moderator's question about "pain points" facing corporations. He oversees the utility company's treasury operations.
"Our country needs to stop fraud before it reaches us, and there is a lot of data showing that if the banking industry shared information, we could prevent a significant portion of fraud before it happens," D'Amadeo said. In an earlier panel discussion, he was even more explicit: "Banks need to do more." His words sent a clear signal at the annual conference in Las Vegas.
His remarks sparked a small debate in the venue: whether banks are already acting jointly enough to curb criminals who move between different banks seeking new victims.
JPMorgan Chase, the largest U.S. bank, did not respond to a request for comment, but Steven Bernstein, a JPMorgan executive director who moderated the panel D'Amadeo participated in, opened by saying: "Fraud is everywhere."
Fraud has become a major problem for payment participants, including banks, processors, card networks, and numerous intermediaries and fintech companies. Today, faster digital payments (includingthe upcoming launch of the Federal Reserve's FedNow real-time system) and artificial intelligence innovations could make the problem worse.
Thomas French, a senior fraud consultant at software company SAS Institute, described the current environment this way: "It's a basket of badness—scams, scams, and more scams. When scams meet faster payments, you get faster fraud."

French spent 27 years working in banks, including Bank of America, former Wachovia, and First Union. He said fraud has always existed but has noticeably worsened over the past 18 months. "It's the industrialization of fraud—different criminal gangs each playing their part," he said in an interview this month. "In my 30-plus-year career, I've never seen such sophistication, such speed, and such a landscape full of scammers."
Bank customers suffer alongside financial institutions. The Federal Trade Commission (FTC) said in February that fraud losses reported by U.S. consumers in 2022 jumped 30% from 2021, reaching $8.8 billion, with most fraud occurring through some part of the payment system. These frauds occur in scenarios such as business, shopping, investments, and online dating.
Payment fraud rises, bank channels surge
Annual fraud losses by payment category, 2019 to 2022
FTC data shows that among consumer fraud reports last year, 17% identified a payment method. Among recorded payment methods, bank transfers and payments saw the largest losses, doubling from $762 million in 2021 to nearly $1.6 billion. This payment channel has been the single largest area of fraud losses for three consecutive years.
Although losses through bank payments were the highest last year, FTC data shows that credit card fraud had the highest number of reports.
Businesses also caught up in losses
Such massive losses mean fraud targets not only consumers but also businesses of all sizes, including the utility company D'Amadeo serves, which covers the New York City area. On the collections side, the utility receives 500 to 600 fraudulent payments daily from valid debit accounts—accounts whose information may have been purchased by scammers on the dark web, sometimes even openly using Con Edison's account numbers. D'Amadeo said that relative to the company's 3 million customers, this type of fraud is relatively small.
But he is more concerned about the payments side. The company "constantly" faces email scams where fraudsters impersonate Con Edison executives or suppliers requesting payments, putting hundreds of millions of dollars at risk. For example, a supplier owed money by Con Edison might be hacked, and the hacker sends invoices to the utility with accurate information but altered bank account details, redirecting funds to the fraudsters.
"Our biggest concern is on the payment side—we could be tricked into changing payment instructions to counterparties. If we don't catch it within 24 hours, the money is gone," he said.
Small businesses are also targets. Las Vegas detective Jefferson Grace also spoke at the conference, describing a local business owner with 30 years in operation who went bankrupt after mistakenly transferring a $1.1 million payment to fraudsters impersonating a supplier. Grace explained how scammers take over or mimic email addresses and obtain executive names from social media like LinkedIn to send highly convincing emails.
Email scams tricking business executives into paying fraudsters have become a major obstacle. "We place too much trust in email, which was never designed for this," Grace said. Multiple speakers emphasized that executives should follow clear payment processing instructions to avoid fraud.
A large part of the problem lies in the malicious use of valid accounts. In the trend of "synthetic identity fraud," scammers use partially real information to create a facade of normalcy.
"Synthetic identity is a concerning and growing threat factor," said Dustin White, head of risk for Visa U.S., at the ETA Transact conference in Atlanta in April. "It's quite sophisticated and extremely damaging because it's not the $500, $1,000, or $2,000 small fraud that financial institutions deal with, but 'explosive' scams of $80,000, $100,000, or $150,000 each." White noted that the Boston Federal Reserve estimates synthetic identity fraud caused $20 billion in losses in the U.S. in 2021. "It's a very prevalent and growing threat vector."
The dilemma for payments and banking professionals is fixing fraud without introducing too much "friction." The industry has made significant progress in making digital payments easy for consumers, and banks and businesses are reluctant to remove features that facilitate commerce, especially online commerce.
Nacha turns to anti-fraud
Nevertheless, a consensus is forming: action must be taken. Industry organizations capable of uniting the banking and payments community are brewing new approaches. A Citi executive who participated in the debate at the Nacha conference said: "It's coming."
A key player in any new effort will be Nacha (formerly the National Automated Clearing House Association). In fact, it is quietly driving change within its community, including large bank operators, requiring financial institutions to take on more anti-fraud responsibility.
Earlier this month, Nachaissued a request for public commentoutlining a new "risk management framework" it is developing, saying fraud has entered a new era where funds are mistakenly "pushed" by users to accounts they should not go to. Nacha said the updated approach will address the growing fraud threats and attacks on ACH credits, wire transfers, cards, and other instant and digital payments.
"As a new risk management strategy, the framework aims to unite the ACH network and the broader payments community to address an emerging and important area of need and provide overall direction for new initiatives, guidance, rules, and industry tools," Nacha said in an executive summary on May 2.
Nacha said the framework's goals are to increase awareness of illegal push payment scams, reduce the success rate of such fraud attempts, and improve the chances of recovering funds after a scam occurs. Nacha spokesperson Dan Roth did not respond to multiple requests for comment.
Barriers to cooperation
Part of the challenge in solving the problem is that banks are reluctant to share customer data with each other—data that could aid anti-fraud efforts, said Mark Dixon, vice president of education at the New England Automated Clearing House Association in Burlington, Massachusetts. Banks have long been sensitive to any information sharing that could harm their proprietary interests, but that attitude may now be changing, at least slightly.
"The industry is looking at how to communicate more proactively," Dixon said, referring to Nacha's new framework concept and the Nacha Contact Registry designed to help institutions connect with each other. "The challenge is ensuring all institutions participate."
Adding to the difficulty, there are nearly 10,000 banks in the U.S., making it a daunting task to get them to communicate with each other. As part of the effort, Nacha developed the Contact Registry in 2020 and undertook the arduous work of requiring bank personnel to register. Currently, the registry has 45,000 contacts.
Nacha operating rules require financial institutions to provide contacts so that professionals at other institutions can reach them when needed, and all institutions should be willing to share information as a reciprocal condition for receiving it.
"The registry is designed to provide consistent, accurate information for financial institutions that may need to contact another financial institution for fraud scenarios such as business email compromise and supplier impersonation," said Jeanette Fox, senior director of risk investigations and ACH network risk management at Nacha, in an email statement.
Early Warning Services, operator of the bank-owned payment tool Zelle, also runs a national shared database to which the largest U.S. banks contribute account information, but professionals note that because smaller banks hold more than a quarter of accounts, the database has significant coverage gaps.
Banks launch another initiative
Other banking organizations are also brainstorming new anti-fraud approaches. According to an industry source who spoke on condition of anonymity, the American Bankers Association is working with Early Warning Services on a new anti-fraud prevention project. The source said the project currently involves only a few banks and is about to enter a pilot phase, but declined to provide more details.
American Bankers Association spokesperson Sarah Grano and Early Warning Services spokesperson Meghan Fintland both declined to comment.
Professionals from these organizations meet regularly to discuss fraud and risk, but French remains concerned that banks are not capturing and sharing as much information as possible. He noted that bankers are heavily influenced by policy and reluctant to share information with third parties. Additionally, some professionals say they are hesitant to publicize new technologies for fear of alerting scammers. "There is some sharing, but I think more sharing of different information is needed," said French, whose company sells fraud analytics software.
Nevertheless, in recent months, many companies have increased public promotion of new anti-fraud tools, including SAS Institute,card network Mastercard, credit bureau Experian, and a range of fintech companies launching new services and products.
Europe explores new paths
Across the Atlantic in Europe, there is more progress on collective industry responses. The new concept of "authorized push payment" has taken root, with banks bearing joint liability for erroneous payments, said Donna Turner, former chief operating officer of Early Warning Services and now a consultant at audit firm EY.
Turner said European financial institutions now bear as much fraud responsibility on the sending side as on the receiving side. With the push toward open banking following the EU'sSecond Payment Services Directive(PSD2) in 2016, data sharing among European banks has increased.
Turner said in an interview this month that banks and payment participants on both sides of a transaction have greater incentive to change behavior to combat fraud. "It's about protecting the ecosystem," she added.
Participants in the U.S. payments ecosystem may be starting to embrace the same approach as they seek to build a stronger industry-wide anti-fraud defense.
Caitlin Mullen contributed to this article.