Banks are spending more on fraud detection because stopping a scam after the customer has sent the money is often too late.
Sixty-eight percent of financial institutions increased their fraud-detection budgets year over year, according to the 2025 “State of Fraud and Financial Crime in the United States,” a PYMNTS Intelligence report produced in collaboration with Block. That spending comes as 46% of institutions report increasingly sophisticated fraud schemes, up from 35% a year earlier. At the same time, the share citing the cost of adopting new fraud technology as a primary challenge fell to 36% from 60%.
The spending is also changing what banks can look for. Behavioral analytics were used by 70% of institutions surveyed, while 61% reported using machine learning or artificial intelligence. Those technologies allow fraud systems to compare a transaction with a customer’s previous behavior and look for combinations of unusual activity rather than relying only on fixed rules or authentication.
Authorized scams are difficult precisely because many of the usual fraud checks work. The customer has the right credentials. The customer may personally visit the branch. The customer confirms the transaction. What the bank has to detect is whether something outside that authentication process suggests the customer is being manipulated.
PYMNTS Intelligence found that 70% of institutions said machine learning supports a combination of proactive and reactive fraud defenses. Another 25% said AI makes their approach predominantly more proactive, compared with 5% that said it primarily strengthens reactive defenses.
A lawsuit against PNC Bank shows what that problem can look like at the branch level.
Jeffrey Maas, a New Jersey retiree, alleges that scammers posing as PayPal and PNC representatives convinced him that money had mistakenly been deposited into his accounts and had to be returned. He says he was instructed to use his own money to purchase gold and then turn the gold over to couriers.
According to Maas’ complaint, he went to a PNC branch where he had banked regularly for years and sought help wiring $300,000 to purchase gold. The complaint alleges that Maas sat with a PNC banker while remaining on the phone with one of the scammers.
The employee, the complaint alleges, “asked no questions of Mr. Maas.” It further alleges that the banker did not ask why Maas wanted to spend most of his savings on gold, why he remained on the phone throughout the transaction or who was on the other end. Maas returned the next day and sent another $90,000 for gold.
The complaint alleges that the two transactions represented a major departure from Maas’ previous banking activity and that PNC failed to act on signs that he could be under another person’s influence. It argues that the bank’s security procedures were not commercially reasonable as applied to the transactions, citing what it calls “material deviations from Plaintiff’s banking history” among the indicators that should have prompted scrutiny.
The allegations against the bank have not been proven.
The case has nevertheless survived PNC’s effort to end it at the pleading stage. New Jersey Superior Court Judge Aldo J. Russo late last month denied the bank’s motion to dismiss, meaning the claims against PNC can proceed. That ruling is not a finding that PNC was negligent or that banks generally have a duty to block authorized transactions. It means those issues were not disposed of on PNC’s motion.
The technology issue does not depend on how the litigation ultimately turns out.
A fraud model can tell an employee that a transaction deserves another look. A customer who rarely makes large wires suddenly requesting one is information. A second large transaction the following day is more information. A new recipient, an unusual purpose, rapid depletion of a longstanding balance or other behavior outside the customer’s history can add to the signal.
A behavioral alert is useful only if the institution has decided what happens next: whether the employee asks additional questions, brings in a supervisor, contacts the fraud department or uses another procedure permitted by the bank’s policies and applicable law. The PYMNTS data suggests banks are spending heavily on the technology needed to produce those warnings. The harder part of authorized fraud comes immediately afterward.