Glossary
Scams are social-engineering attacks in which fraudsters psychologically manipulate victims into voluntarily handing over money, sensitive information, or access, rather than breaking in technically. The target isn’t a system; it’s a person. And because the victim acts of their own accord, scams bypass most defenses built to stop unauthorized access.
Scams work because they attack the human layer, which is far harder to patch than software. As authentication and fraud detection have hardened, fraudsters have shifted to manipulating the legitimate user into doing the damage themselves.
Scammers exploit universal human triggers: urgency, fear, authority, greed, and trust. A convincing story ("your account is compromised, move your money now") short-circuits careful judgment. Generative AI has made scams sharper and more scalable: flawless phishing messages, cloned voices of loved ones or executives, and deepfake video that lends false credibility. The democratization of these tools means more scammers running more convincing scams than ever.
The defining challenge is that the victim is a willing participant. Controls that verify identity or block unauthorized access don’t fire, because the real customer is authenticating and authorizing. Traditional fraud detection asks the wrong question. Stopping scams requires detecting the manipulation (behavioral signs the customer is acting under coercion or a coached script, remote-access tools controlling their device, out-of-pattern payments to new payees) and intervening in real time with warnings or friction before the damage is done.
Because scams span channels and exploit the human layer, defense combines behavioral analytics (spotting coached or out-of-character activity), device and session intelligence (detecting remote access and manipulation), transaction monitoring (flagging risky payments as money moves), and real-time intervention (interrupting with a warning or step-up at the critical moment). Industry frameworks and regulations (anti-scam accords and reimbursement rules) are also mobilizing banks collectively. No single control stops scams; the layered, identity-and-fraud-fused approach that watches behavior across the lifecycle is what gives institutions a fighting chance against an attack aimed squarely at their customers’ minds.
Scams have grown from a nuisance into one of the defining fraud threats of the era. As banks hardened logins and payments against unauthorized access, fraudsters pivoted to the softer, unpatched target: the customer. Losses to scams now run into the tens of billions annually across major markets, and the trend is upward, not down. Two forces drive it. The shift of life and money online gives scammers endless reach, and the democratization of AI tools lets even unsophisticated criminals run convincing, scaled campaigns. Regulators have taken notice, which is why reimbursement rules and anti-scam accords are appearing: the losses have become too large and too visible to leave to individual vigilance.
A common instinct is to fight scams with customer education, warnings, awareness campaigns, "your bank will never ask you to…" messaging. Education helps at the margin, but it’s not a solution, and leaning on it too heavily shifts blame onto victims who were expertly manipulated. Scammers are professionals exploiting universal psychology, often against people in a moment of fear or urgency; expecting every customer to out-think them is unrealistic. The more durable approach treats protection as the institution’s job: detect the manipulation with behavioral and device signals, and intervene in real time, rather than relying on the victim to catch a con designed specifically to fool them. Education and protection work together, but technology that interrupts the scam mid-flight does the heavy lifting.
How big is the scam problem?
Scam losses run into the tens of billions annually across major markets and are growing, driven by digital life and AI-powered manipulation.
Is customer education enough to stop scams?
No. It helps marginally, but scammers exploit expert manipulation; real-time behavioral detection and intervention do the heavy lifting.
What is a scam in fraud terms?
A social-engineering attack that manipulates a victim into voluntarily giving up money, data, or access.
Why are scams so hard to prevent?
The victim willingly participates, so controls that block unauthorized access don’t trigger; you must detect the manipulation instead.
How is AI making scams worse?
Generative AI produces flawless phishing, cloned voices, and deepfakes, making scams more convincing and scalable.
How do you defend against scams?
Behavioral analytics, remote-access and device detection, real-time transaction monitoring, and timely intervention, plus industry anti-scam frameworks.
Related: Authorized Push Payment (APP) Fraud · Phishing · Social Engineering · Deepfakes · Behavioral Analytics · Scam-Safe Accord