Fraud is no longer best understood as a collection of isolated scams. Modern criminal networks combine social engineering, malicious communications, fraudulent digital platforms, compromised identities and money-mule infrastructure into interconnected operating models. A text message may begin the attack, an impersonation call may deepen the deception, a fake investment or marketplace may provide the payment narrative, and a mule account may enable the proceeds to disappear within minutes.
Six threats are particularly important within this environment: smishing, safe-account scams, investment fraud, romance fraud, money-mule recruitment and online shopping scams. Each uses a different pretext, but all exploit the same structural weaknesses—consumer trust, digital immediacy, fragmented data and the speed of modern payments.
For financial institutions, the strategic challenge is not simply identifying each typology. It is recognising how criminal groups move between them, reuse infrastructure and adapt their approach when one control introduces friction.
Listen the podcast
Watch the video
Why these six threats matter now
Fraud has become a technology-enabled, cross-sector threat. Europol’s 2026 Internet Organised Crime Threat Assessment describes online fraud as one of the fastest-growing areas of organised crime, supported by infrastructure that enables industrial-scale victim targeting, anonymity and rapid adaptation. Phishing, malicious advertising, SIM-box networks and increasingly personalised AI-assisted social engineering allow criminal groups to target large populations while operating across borders.
The financial impact remains substantial. UK Finance recorded £576.4 million in authorised push payment fraud losses during 2025, a 19% increase from 2024, across 248,070 confirmed cases. Its analysis found that 66% of APP fraud originated online and a further 17% through telecommunications channels. Purchase, investment and romance scams reached record loss levels, while traditional impersonation scams declined but continued to cause significant harm.
These figures illustrate a wider shift. Criminals are moving beyond single, high-volume scripts towards multi-stage manipulation supported by advertising platforms, messaging services, spoofed communications, synthetic content and professional laundering networks.
1. Smishing: industrialised social engineering through mobile channels
Smishing uses text messages to impersonate banks, delivery companies, government agencies, telecommunications providers or other trusted organisations. The message may direct the recipient to a phishing site, encourage a callback or create an urgent pretext for disclosing credentials, card data or one-time passcodes.
The threat is increasingly supported by dedicated telecommunications infrastructure. Europol reports that SIM farms can distribute thousands of messages, calls and social-media communications while masking the location and identity of the operators. SMS blasters and IMSI-catcher technology can also bypass conventional telecommunications routing, making malicious messages appear local and complicating attribution.
The objective may be account takeover, card enrolment into a criminally controlled digital wallet or preparation for a later impersonation call. The text is often only the first stage of the attack.
Institutions should therefore connect telecommunications intelligence with authentication and transaction monitoring. A suspicious link interaction followed by a password reset, new-device registration, beneficiary creation or unusual payment should be assessed as one sequence rather than as unrelated events.
2. Safe-account scams: authentic payments created through false authority
Safe-account scams occur when criminals impersonate bank employees, police officers or fraud investigators and convince victims that their money is at immediate risk. The victim is instructed to transfer funds to an account supposedly created to protect them. In reality, the receiving account is controlled by the criminal network.
The payment may be completed using the customer’s normal device and valid authentication credentials. This makes the transaction technically authorised even though the customer’s understanding of its purpose and recipient has been criminally manipulated.
UK Finance recorded £55.5 million in losses from police and bank impersonation scams during 2025 across 6,016 cases. Both figures declined from the previous year, reflecting the value of customer education and payment warnings, but the typology remains capable of causing severe individual losses.
Effective prevention requires more than generic warnings. Institutions should identify behavioural indicators such as sudden liquidation of savings, movement between a customer’s own accounts, first-time high-value beneficiaries, active telephone coaching and attempts to defeat staff intervention. Customers should also be given a secure method to terminate suspicious communications and reconnect with the institution independently.
3. Investment scams: digital credibility without an underlying investment
Investment fraud increasingly resembles a legitimate financial service. Criminals create professional websites, trading dashboards, mobile applications, social-media profiles and customer-support operations. Victims may initially see fabricated returns or be allowed to withdraw a small amount, reinforcing confidence before larger deposits are requested.
The investment may be presented as cryptocurrency, foreign exchange, property, commodities, bonds or an exclusive managed fund. Malicious advertising and cloned identities allow criminals to borrow the credibility of regulated firms, public figures and established media brands.
In 2025, UK Finance recorded £221.5 million in APP investment-scam losses, an increase of 40%, across 14,893 cases. Investment scams accounted for 38% of all APP losses reported by its members. The FCA separately issued 2,329 warnings concerning unauthorised or potentially fraudulent firms during 2025, demonstrating the continuing scale of false and unregulated investment propositions.
Detection should focus on the complete journey: advertising source, beneficiary risk, payment escalation, cryptocurrency conversion, customer behaviour and links to previously reported recipients. A customer repeatedly increasing payments after receiving supposed profits may be demonstrating manipulation rather than genuine investment activity.
4. Romance scams: long-term manipulation and repeated victimisation
Romance fraud is based on relationship development rather than immediate urgency. Criminals create fabricated identities, establish frequent contact and gradually build emotional dependency. Requests for money may relate to medical emergencies, travel, customs fees, business problems or an investment opportunity.
The harm is both financial and psychological. Victims may continue to trust the offender after warnings from family members, banks or law enforcement. They may provide misleading payment explanations because the criminal has coached them to do so or because they fear the relationship will end.
UK Finance recorded £39.2 million in romance-scam losses during 2025 across 6,335 cases—the fifth consecutive annual increase in case volumes. The average case involved 9.7 payments, the highest frequency among the APP scam categories in its report, demonstrating how criminals build trust and escalate demands over time.
Romance fraud may also evolve into money laundering. FATF has documented cases in which victims disclosed online-banking credentials or received third-party payments, allowing their accounts to be used to move proceeds from other victims. A customer can therefore be both a fraud victim and an unwitting mule.
5. Money-mule recruitment: the financial infrastructure behind the scams
Every successful fraud operation requires a mechanism for receiving and dispersing funds. Money mules provide that mechanism. They may knowingly sell or lease their accounts, be recruited through fake employment opportunities, or be manipulated through romance, investment and social-media scams.
Once funds arrive, they may be fragmented across multiple accounts, withdrawn in cash, transferred through payment providers or converted into virtual assets. Some account holders retain control and follow instructions, while others surrender cards, credentials, tokens or full online-banking access.
FATF identifies individual mule accounts as common first-layer recipients for phishing, telecommunications impersonation and romance-fraud proceeds. Funds are then rapidly layered through pass-through accounts across institutions and jurisdictions. Short account-usage windows and genuine customer onboarding can make this activity particularly difficult to distinguish from legitimate behaviour.
Controls should combine early-life monitoring, inbound-payment analysis, device intelligence and network analytics. Closing the first account is not enough; investigators should identify shared devices, phone numbers, addresses, introducers, beneficiaries and cash-out routes connected to the wider network.
6. Shopping scams: high-volume fraud through digital marketplaces
Shopping scams exploit the normality of online commerce. Criminals advertise nonexistent products, vehicles, tickets, holidays or services through cloned retail sites, social-media advertisements and marketplace listings. Victims may be persuaded to move away from protected platform payment methods and pay by bank transfer.
The individual losses are often lower than those associated with investment or impersonation fraud, but the scale is significantly greater. UK Finance recorded 175,809 purchase-scam cases during 2025, representing 71% of all APP scam cases, with total losses of £118.1 million. Both the loss value and case volume were the highest recorded in the series.
Shopping scams also generate valuable criminal data. Payment information, contact details and behavioural responses can be reused in later phishing, recovery or impersonation campaigns. A person who reports a purchase scam may subsequently be contacted by a criminal claiming to recover the lost money.
Financial institutions should assess merchant and beneficiary history, repeated low-value incoming transfers, payment references, complaint clusters and rapid dispersal. Platforms and payment providers also need effective information-sharing mechanisms to remove fraudulent sellers and identify recurring infrastructure.
Why the threats converge
The six typologies are different manifestations of a shared criminal ecosystem. Smishing creates initial access. Safe-account impersonation converts fear into an authorised transfer. Fake investments and relationships sustain long-term manipulation. Shopping scams generate high-volume payments and consumer data. Mule accounts connect every scheme to the laundering and cash-out process.
Criminals can also transition between narratives. A failed delivery message may become a bank-security call. A romance relationship may develop into a fraudulent investment. An investment victim may later be approached through a recovery scam or persuaded to receive funds on behalf of the supposed adviser.
Europol describes online fraud networks as efficient transnational industries that combine technical, logistical and financial capabilities. Generative AI strengthens this model by improving localisation, language quality and personalisation, while crime-as-a-service providers supply communications infrastructure, malicious advertising, fake accounts and laundering capabilities.
What a resilient control stack looks like
The first layer is cross-channel behavioural detection. Institutions should connect login activity, devices, communications, internal transfers, beneficiary creation and outbound payments. Risk frequently becomes visible through the sequence of events rather than through one transaction.
The second layer is typology-specific intervention. A warning for a purchase scam should address off-platform payments and unavailable goods. An investment intervention should test regulation, expected returns and withdrawal experience. A safe-account intervention should state clearly that legitimate organisations do not require customers to transfer money for protection.
The third layer is receiving-account intelligence. Firms should monitor unexpected inbound payments, rapid pass-through activity, fan-out transfers, shared devices and links to known fraud reports. Network analytics can reveal mule clusters that transaction-by-transaction reviews miss.
The fourth layer is ecosystem collaboration. Banks see payments, telecommunications firms see calls and messages, platforms see advertisements and accounts, and law enforcement sees reports across multiple victims. FATF emphasises that social-media, e-commerce and telecommunications providers possess digital and payment information that can help identify the perpetrators and infrastructure behind cyber-enabled fraud.
Finally, confirmed incidents should feed directly into control improvement. Fraudulent domains, telephone numbers, beneficiaries, devices, advertising accounts and scam scripts should be converted into actionable intelligence before the same infrastructure is used against another customer.

What this means for financial crime leaders
The six threats should not be governed as separate consumer-awareness topics. They represent a connected operating model spanning fraud prevention, AML, digital identity, cybersecurity, payments, customer vulnerability and external intelligence sharing.
Leaders should ask whether their controls can follow a fraud journey across channels, whether receiving-account risk receives the same attention as outbound payments, and whether information from confirmed cases is distributed quickly enough to prevent repeat victimisation.
The central objective is not to predict every story a fraudster may tell. It is to recognise the behavioural and financial structure beneath the story: manufactured urgency, unexpected authority, implausible returns, emotional dependency, off-platform payment requests and rapid movement through mule accounts.
Criminal narratives will continue to change. The most resilient institutions will be those that connect the signals, disrupt the infrastructure and intervene before trust is converted into an irreversible payment.
What Financial Institutions Should Consider
- Connect Cross-Channel Behavioural Signals
- Apply Typology-Specific Customer Interventions
- Strengthen Receiving-Account Monitoring
- Detect Mule Networks Through Graph Analytics
- Combine Device, Authentication and Transaction Intelligence
- Monitor Early-Life Account Activity
- Identify Escalating and Repeated Payment Patterns
- Improve Fraud, AML and Cyber Collaboration
- Strengthen Intelligence Sharing With External Ecosystem Partners
- Convert Confirmed Fraud Into Actionable Intelligence
- Focus on Criminal Infrastructure, Not Only Scam Narratives
- Improve Protection for Vulnerable Customers
- Detect Fraud Journeys Across the Full Customer Lifecycle
- Build Faster Feedback Loops Into Fraud Controls
Download the briefing
Six Emerging Fraud Threats Reshaping the Financial Crime Landscape




The six fraud threats examined in this article should not be treated as isolated typologies. Smishing, impersonation, investment fraud, romance scams, shopping fraud and mule recruitment increasingly operate as connected components of the same criminal ecosystem. Each plays a different role in the fraud lifecycle, from victim acquisition and trust-building to payment execution, laundering and cash-out.
This convergence changes the control challenge for financial institutions. Effective prevention depends less on recognising a single scam narrative and more on identifying the behavioural, transactional and infrastructural patterns that persist across multiple fraud models. These include manufactured urgency, new or unusual beneficiaries, escalating payments, unexplained changes in account behaviour, shared devices and rapid movement through mule networks.
A resilient response therefore requires integrated intelligence across fraud, AML, payments, cybersecurity, digital identity and customer vulnerability teams. It also depends on timely collaboration with telecommunications providers, online platforms, payment firms and law enforcement, because no single organisation can see the entire attack chain.
Ultimately, criminal narratives will continue to evolve, but the underlying operating model remains identifiable. Institutions that connect weak signals, disrupt receiving-account infrastructure and convert confirmed incidents into rapid control improvements will be better positioned to prevent losses, protect vulnerable customers and reduce the profitability of organised fraud.