The next generation of payment fraud doesn’t seem very suspicious. In fact, it already sounds like a familiar customer, types at a perfectly ordinary pace and navigates a banking application without triggering a single behavioral warning.
Findings in the September 2026 edition of the Payments Innovation Tracker® Series, a PYMNTS Intelligence report done in collaboration with Paymentology, highlight that the industry is confronting a shift from isolated fraudulent transactions toward persistent identity-based attacks that can begin long before a payment is initiated thanks to advances in artificial intelligence.
And that’s creating a new problem for financial institutions: The signals traditionally used to distinguish legitimate customers from automated attackers are becoming easier to reproduce.
PYMNTS Intelligence research found that unauthorized-party schemes accounted for 71% of fraud incidents and dollar losses in 2025, compared with 48% the previous year.
Account takeover, synthetic identities and AI-assisted social engineering increasingly target the customer relationship itself. By the time a suspicious payment reaches authorization, the attacker may already have acquired the credentials or apparent identity needed to pass conventional checks.
Banks Need a New Way to Know Who Is Real
Traditional authentication rests partly on a distinction between human and machine behavior. Voice recognition verifies familiar speech patterns, selfies and video checks establish apparent physical presence, while behavioral biometrics examine typing cadence, session duration and navigation patterns.
But artificial intelligence is eroding the certainty of biomarkers. Voice authentication is already particularly vulnerable to synthetic impersonation. Visual verification faces similar challenges as AI-generated imagery becomes more convincing. Behavioral authentication presents a subtler problem. Automated systems can simulate the pauses, movements and interaction patterns that financial institutions associate with legitimate customers.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
The difficulty is not simply detecting a machine masquerading as a person. It is identifying an impostor whose activity resembles the legitimate behavior an institution has spent years learning to recognize. For issuers, the challenge is therefore twofold: detect more sophisticated impersonation without turning every legitimate interaction into an obstacle course.
Read the report: When Fraud Becomes the Customer: The Next Battlefront for Issuers
A system designed primarily to identify anomalous transactions can miss attacks that successfully establish a credible identity beforehand. Meanwhile, aggressive authentication can penalize legitimate customers.
One emerging response is to replace reliance on individual authentication events with continuous, risk-based verification. Rather than determining whether someone is genuine based on a single selfie, voice sample or login, institutions can evaluate a broader history of interactions, transaction patterns and contextual signals, turning trust into something that is cumulative rather than binary.
The authentication problem becomes more complicated as AI agents begin making purchases on customers’ behalf. PYMNTS Intelligence found that 68% of high-customer-lifetime-value card issuers consider stronger security and fraud prevention necessary for agentic commerce. One answer is to give tokenization a broader role in fraud prevention. Instead of exposing unrestricted payment credentials, issuers can provision tokens with defined spending limits, merchant restrictions and permitted uses.
The emerging architecture separates three questions that traditional authentication often treated together: Who is initiating the interaction, how much confidence should the institution place in that identity, and what financial authority has actually been granted?
For issuers, that separation may prove more consequential than developing another biometric check. As machines become better at imitating people, the future of payment security will depend less on whether an interaction appears human and more on whether the action behind it can be independently trusted and controlled.
At PYMNTS Intelligence, we work with businesses to uncover insights that fuel intelligent, data-driven discussions on changing customer expectations, a more connected economy and the strategic shifts necessary to achieve outcomes. With rigorous research methodologies and unwavering commitment to objective quality, we offer trusted data to grow your business. As our partner, you’ll have access to our diverse team of PhDs, researchers, data analysts, number crunchers, subject matter veterans and editorial experts.