The 43% of scam victims who pay fraudsters within an hour present banks with an obvious problem. There may be almost no time to stop the transaction.
The 18% who take at least two weeks present a different one.
The findings, conveyed in the September PYMNTS Intelligence report “Fraud’s Loyalty Tax: How Scams Cost Banks Their Customers,” showed that scam payments operate on different schedules. According to the report, 63% of victims paid within a day of first contact, but nearly 1 in 5 took two weeks or longer.
The slower cases are concentrated in some of the scams capable of producing large losses. Romance scams carried an average loss of $27,587, second only to travel scams at $35,272, while investment scams averaged $14,225. Only 16% of romance scam victims paid within a day, with a median of at least two weeks. For investment scams, 37% paid within a day.
What happens financially during the rest of that time is becoming important to banks.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
A Sept. 3 Financial Crimes Enforcement Network (FinCEN) analysis of suspected digital asset investment scams found that financial institutions can sometimes see victims assembling the money they eventually send to criminals, PYMNTS reported Sept. 4. FinCEN identified victims of cryptocurrency scams, for example, draining checking and savings accounts, liquidating investments and retirement accounts, opening home equity lines and using credit cards and personal loans. The cases give banks a sequence, something they do not necessarily have when a scam moves from first contact to payment in minutes.
Longer-Running Scams Give Banks More Signals to Connect
The extra days or weeks do not merely give the scammer more time to establish trust. They can also give a financial institution more customer activity to evaluate before the final payment, and to connect the dots between fragmented data points.
Banks have already been investing in that connective capability. The PYMNTS Intelligence report “State of Fraud and Financial Crime in the United States” found in December that that 70% of financial institutions surveyed use behavioral analytics for fraud detection, while 61% use machine learning or artificial intelligence. Such systems can identify departures from established customer behavior even when the customer has authenticated and personally authorized a transaction.
Authorized scams complicate the conventional fraud response because the person requesting the payment may insist that it proceed. Authentication can establish that the customer controls the account without establishing that the customer understands why the payment is being made. The September PYMNTS Intelligence report on fraud found that 11% of victims told no one they had been scammed, up 26% between July 2026 and September 2025. Among those who remained silent, 28% did not know reporting was an option and 18% said they lacked clear guidance on how to report.
Operation Shamrock Founder and CEO Erin West told PYMNTS this month about other areas of fragmentation. West described a fraud response in which banks, platforms and law enforcement can hold separate pieces of activity generated by organized scam enterprises.
Reducing that fragmentation requires putting those pieces into a form that can be acted on. Within financial institutions, that means escalation procedures that bring unusual activity across accounts and products into the same review before a large or atypical payment is completed. Between organizations, it means establishing ways to exchange relevant account identifiers, transaction patterns and other fraud indicators quickly enough to identify connections across cases. West has advocated pooling public- and private-sector information for that purpose.
The goal is not simply to collect more data, but to identify when information held by separate organizations points to the same accounts, fraudsters or infrastructure.