The first 3 steps in the financial fraud rethink

by Hugo Remi, CEO, Cardaq

Share this post

Fraud refunds may protect consumers, but businesses often absorb the loss. Stronger collaboration and shared intelligence can help stop fraud before it happens.

For most people, fraud looks like a quick refund. For businesses, it can be the difference between profit and loss.

Take John, a budding musician who buys a new guitar. The next day, he spots an unfamiliar payment on his banking app and reports it. His bank cancels the card, flags the transaction, and reimburses him. Because the payment was authorised, the business absorbs the loss.

When consumers fall victim, banks and payment firms are set up to move fast, but for businesses, the picture is different. Friendly fraud, return fraud, chargeback abuse and synthetic identities are hard to evidence and recover; reimbursement rarely comes from the fraudster. Some losses are picked up by insurers or banks, but the process is onerous, and premiums can be prohibitive, so many firms chalk it up as an operating cost.

Consider the guitar shop. The order has already been packed, and the courier has already collected. Then the payment is reversed. The stock is gone, the revenue disappears, and the business absorbs the financial losses and admin costs.

That gap between what fraud feels like for people and what it costs businesses is one of the biggest blind spots in payments. According to the National Crime Agency, 86% of fraud goes unreported. At a global level, it’s considered a part of everyday operations. But one successful fraud after another quickly results in a deficit that damages whole economies. UK Finance’s 2024 report stated businesses lost £1.14 billion to fraud in 2024.

Step 1: Understanding innovations in financial crime 

A lie told twice is rarely believed, and fraud relies on successful deception. Fraud methods are constantly evolving, finding smarter ways to impact consumers and businesses.

An extreme, yet relevant example is AI deepfakes. Businesses have created specific identification systems and have adopted a heavy reliance on multi-factor authentication (MFA) to stave off the threat of fraudsters altering their faces and voices to bypass biometric recognition tests. The Arup HK incident is most famous—a finance employee sent in excess of +20million to a fraudster’s bank account after joining a virtual call of senior advisors. The senior advisers? AI deepfakes. The money? Unrecovered.

It’s not the only way fraudsters are diversifying. Social engineering, loyalty abuse, and stored-value draining are just a few other examples.

Methods of defence must equally cover as many bases as possible; trusted partners, trained staff, strong cybersecurity, and centralised real-time data can strengthen resilience. Even then, it’s still not enough.

Step 2: Dangers of data siloes

The Economic Crime Survey of 2024 reports that around 64% of all businesses have one or more fraud prevention measures in place. Yet over 27% of UK businesses reported an incident of fraud in the last 12 months. Despite fraud controls, siloed operations, and poor collaboration leave businesses blind to emerging threats.

Ultimately, business data is underutilised and fragmented. While data protection safeguards for consumers are critical, fraudsters are also immensely grateful for them. It’s difficult for a single organisation to collect patterns of identity and draw conclusions from financial data to expose individuals committing fraud.

Fraud is harder to spot when data is fragmented across disconnected systems. When payments, returns, and support systems operate in silos, businesses struggle to identify and prevent attacks. Consider a decentralised franchise targeted by receipt fraud. A fraudster could claim refunds at multiple locations in a single day, with each store unaware of the others. Without shared systems, warning signs go unnoticed, and the wider chain cannot respond before losses escalate. Imagine this dynamic on a scale that covers whole sectors and entire continents. This is our current approach to prevention.

Step 3: ‘Every man for himself’ mindset 

A business can strive for 360-degree protection, but without combined might, fraud will persist; it takes unification with businesses, financial institutions, and regulators, harnessing the collective power of their data, to achieve significant progress and prevent attacks before they happen. It turns fraud defence from reactive to proactive, giving authorities and financial institutions stronger grounds to freeze or block accounts.

That is the purpose of the first three steps: understanding how financial crime evolves keeps defences current; breaking down data siloes helps businesses spot threats sooner; and moving past an “every man for himself” mindset makes it harder for fraudsters to repeat the same playbook across merchants, banks and platforms.

This does not require reckless data sharing, and it should not come at the expense of customer protection. With the right governance—clear rules on what constitutes confirmed fraud, what signals can be shared, and how they are secured—the industry can shift from refunding fraud after the fact to preventing it.

The point is not simply that John gets his money back. The point is that the guitar shop does not have to take the hit in the first place.

Cardaq-logo-2025_w-descriptor-horizontal-
Article by Cardaq

Membership

Merchant Community Membership

Are you a member of The Payments Association?

Member benefits include free tickets, discounts to more tickets, elevated brand visibility and more. Sign in to book tickets and find out more.