M2PBlog

Explore the Latest Thinking on Fintech Innovation

Beyond Card Fraud: Why Today's FRM Systems Need to Fight Tomorrow's War

Banking
Sep 07, 2026|8 min read
Beyond Card Fraud: Why Today's FRM Systems Need to Fight Tomorrow's War

Walk into most conversations about fraud and risk management, and you'll still hear the same vocabulary that's dominated the industry for two decades: chargebacks, card-not-present fraud, velocity checks, device fingerprinting. It's not wrong vocabulary — it's just increasingly incomplete.

The uncomfortable truth is that a meaningful share of the FRM industry is still optimized for a fraud landscape that peaked a decade ago. Card fraud hasn't disappeared, but in market after market, it's being overtaken by categories that most legacy fraud stacks were never built to catch: authorized scams, mule networks, fraud rings that operate with the sophistication of venture-backed startups, and — coming faster than most risk leaders expect — a world where AI agents, not humans, are the ones initiating payments.

This blog looks at four converging shifts that every risk leader should be thinking about right now — not as far-off, speculative trends, but as forces already reshaping what "fraud prevention" needs to mean.

Why Most FRM Vendors Are Still Fighting Yesterday's Fraud

For most of the last two decades, fraud prevention was built around a fairly clean mental model: a criminal steals a card number or account credential, and uses it to make an unauthorized transaction. Card networks, issuing banks, and FRM vendors built an entire architecture — 3D Secure, CVV checks, velocity rules, device fingerprinting, chargeback dispute workflows — around catching exactly this pattern.

That architecture worked. Card-not-present fraud rates, as a share of transaction volume, have been broadly declining across mature markets for years as this tooling matured. But the fraud that's replaced it doesn't fit the same mental model at all — and that's the problem.

Authorized push payment (APP) fraud — where the victim is deceived into initiating the payment themselves — doesn't look like fraud from a transaction-data perspective. The right cardholder authenticates with the right device from the right location and sends money to an account they were told, convincingly, was legitimate. Every signal a traditional fraud model was built to catch — mismatched device, unusual location, failed authentication — is absent. The fraud lives in the story the victim was told, not in the transaction's technical fingerprint.

Mule account networks are the second blind spot. Modern fraud rings no longer rely on a single stolen identity moving money in one shot. They recruit or fabricate dozens or hundreds of mule accounts, each one individually unremarkable, and move money through them in small, plausible-looking increments before it's laundered out. A fraud system scoring each transaction in isolation — the dominant architecture for most of the last decade — simply can't see this pattern. You need network-level analysis: who's sending to whom, how often, and whether the graph of relationships between accounts looks like an organic customer base or a laundering pipeline.

This is why the industry's obsession with model accuracy on historical fraud data is, in a real sense, backward-looking. A model tuned to catch card-present and card-not-present fraud with 99% precision can still be functionally blind to the categories now driving the majority of losses in many markets — because those categories were never in its training data to begin with, and they don't share the transaction-level signatures the model was built around.

What this means for FRM strategy: the shift isn't "add more rules." It's a structural one — from transaction-level scoring to behavioral and network-level detection. That means modeling the victim's behavior during a transaction (hesitation patterns, unusual call activity, first-time payee additions under time pressure), not just the transaction itself. It means building graph-based mule detection that looks at the relationships between accounts, not each account in isolation. Vendors and institutions that haven't rebuilt around this shift are, quite literally, optimizing for a fraud problem that's shrinking while the one that's growing goes unaddressed.

What Fraud Looks Like in an Agentic AI World

Here's a scenario that sounds speculative but is arriving faster than most risk teams have planned for: a consumer's AI agent — booking travel, managing subscriptions, comparison-shopping and checking out on their behalf — initiates a payment. No human clicks "buy." No human enters an OTP. The agent authenticates using credentials or delegated authority the consumer set up in advance, and the transaction completes autonomously.

This isn't a hypothetical for 2030. Agentic checkout flows, agent-to-agent commerce protocols, and AI-driven personal assistants with payment authority are already being piloted by major platforms and card networks. And it fundamentally breaks assumptions that almost every fraud model — and almost every regulation, including PSD2's Strong Customer Authentication requirements — was built around: that the entity present at the moment of transaction is the accountholder, and that human behavioral patterns (typing cadence, mouse movement, session behavior) are a reliable fraud signal.

When the "user" at checkout is an AI agent, several things change at once:

  • Behavioral biometrics stop working as a fraud signal. There's no human typing pattern or navigation behavior to analyze — an agent's "behavior" is deterministic, fast, and doesn't vary the way a human's does, which means an entirely new signal set is needed to distinguish a legitimate agent transaction from a compromised or spoofed one.

  • Authentication needs a new model entirely. SCA's "something you know, have, or are" framework assumes a human is present to know, hold, or be something. Agent authentication needs to prove delegated authority — that this specific agent, with this specific scope of permission, was genuinely authorized by the accountholder to make this specific class of transaction.

  • New attack surfaces emerge. If an agent can be manipulated — through a compromised instruction, a poisoned data source, or an impersonated merchant API — the fraud doesn't require stealing a credential at all. It requires tricking the agent, which is a fundamentally different threat model than tricking a human or stealing a card number.

  • Liability becomes genuinely unclear. If an AI agent makes an unauthorized or ill-advised purchase, who's liable — the consumer who delegated authority, the platform that built the agent, or the merchant that accepted the transaction? None of today's card network rules or regional payment regulations have a clean answer yet.

What this means for FRM strategy: risk teams don't need to solve this today, but they do need to start architecting for it — building fraud systems flexible enough to score a new category of "agent-initiated" transactions with their own signal set, rather than forcing agent transactions through a fraud model built entirely around human behavioral assumptions. The institutions that start this work now, before agentic commerce reaches meaningful volume, will have a multi-year head start over those that wait for the first major agentic fraud incident to force the issue.

Fraud-as-a-Service: When Organized Crime Runs Like a SaaS Business

If you want to understand why fraud has scaled so quickly in the last few years, look at how fraud rings now organize themselves — because it looks less like traditional organized crime and increasingly like a software business.

Fraud-as-a-Service (FaaS) platforms, sold and marketed on dark web forums and encrypted messaging channels, now offer productized fraud tooling with the same packaging conventions as legitimate SaaS: tiered pricing, customer support, regular feature updates, and even reviews from other criminal "customers." A prospective fraudster doesn't need technical skill anymore — they can rent phishing kits with ready-made bank login clones, subscribe to services that generate synthetic identities complete with fabricated credit histories, or buy access to botnets that automate account takeover attempts at scale. Some platforms offer deepfake-generation-as-a-service specifically for bypassing liveness-detection KYC checks.

This productization has three consequences that matter enormously for FRM strategy:

Speed and scale have decoupled from skill. A single low-skill operator can now launch attacks that would have previously required a technically sophisticated team. This means the volume of attempted fraud attacks is scaling far faster than the sophistication curve most fraud models were tuned to expect.

Attack patterns get shared and replicated instantly. When a FaaS platform's phishing kit successfully bypasses a particular bank's authentication flow, that exploit gets shared across the platform's entire customer base — potentially thousands of fraudsters — within days. A vulnerability that used to take months to spread through criminal networks now spreads at software-update speed.

Detection needs to shift from "known fraud patterns" to "criminal infrastructure fingerprints." Because so much fraud now runs on shared tooling, the same phishing kit, the same synthetic-identity generator, or the same botnet infrastructure shows up across seemingly unrelated fraud attempts against different institutions. This is exactly why cross-institution data sharing and consortium fraud intelligence — recognizing the infrastructure behind an attack rather than just the transaction pattern — is becoming one of the highest-leverage defenses available. A single institution seeing an attack in isolation is fighting blind; a network of institutions sharing infrastructure-level signals can identify a FaaS-powered attack wave before it reaches its second or third target.

What this means for FRM strategy: the response to an industrialized, productized fraud economy has to be equally systemic. That means investing in threat intelligence feeds that track known FaaS infrastructure (phishing domains, known botnet IP ranges, synthetic identity generation patterns), participating in consortium data-sharing arrangements where regulation allows, and treating fraud defense as an ecosystem problem rather than a single-institution one.

Quantum Computing and Fraud: Urgent Risk or Overhyped Threat?

No thought-leadership conversation about the future of fraud is complete without someone raising quantum computing — usually with either breathless urgency or dismissive skepticism. The honest answer sits in between.

The real risk is narrower than the headlines suggest, but it is real. A sufficiently powerful, fault-tolerant quantum computer could, in theory, break the asymmetric encryption (RSA and elliptic-curve cryptography) that underpins much of today's payment security — including TLS connections, digital signatures, and card network authentication protocols. This isn't the same thing as "quantum computers will let criminals hack your bank account next year." Current quantum computers are nowhere near the scale, error-correction capability, or stability needed to break production-grade encryption, and credible timelines from cryptography researchers generally place a genuine "cryptographically relevant" quantum computer somewhere in the 2030s at the earliest — with meaningful uncertainty even in that estimate.

The "harvest now, decrypt later" risk is the part worth taking seriously today. Encrypted data intercepted and stored now could, in principle, be decrypted once quantum capability matures — meaning sensitive financial data with long-term value (account numbers, identity documents, transaction histories) is already at theoretical future risk, even though the decryption capability doesn't exist yet. This is why NIST finalized post-quantum cryptography standards in 2024, and why major payment networks, cloud providers, and financial institutions have begun (slowly) planning migration paths to quantum-resistant encryption.

What this means for FRM strategy: this is not a "drop everything" emergency, but it is a "start the multi-year planning now" issue. Practical steps for risk leaders include asking technology and infrastructure vendors (including FRM vendors) about their post-quantum cryptography roadmap, prioritizing crypto-agility (the ability to swap encryption algorithms without a full system rebuild) in any new infrastructure investment, and treating long-lived sensitive data with an eye toward its multi-decade exposure window, not just its current-year risk. Institutions that wait until quantum computing is a proven, immediate threat will be starting a multi-year migration years too late.

The Common Thread: Fraud Prevention Has to Get Ahead of the Curve, Not Chase It

These four shifts — scams and mules outpacing card fraud, agentic AI breaking today's authentication assumptions, fraud-as-a-service industrializing attacks, and quantum computing reshaping the long-term cryptographic horizon — look unrelated on the surface. They share one underlying lesson: the fraud landscape is moving faster than the architecture most FRM systems were built around, and reactive tuning of yesterday's models isn't a strategy for tomorrow's threats.

The institutions that will manage this well aren't the ones with the single most accurate fraud model for today's known fraud patterns. They're the ones building FRM infrastructure flexible enough to extend to new signal types (behavioral, network, agent-authority, infrastructure-level) as fraud typologies shift — because in every one of these four areas, the next major fraud wave will look nothing like the last one.

See What a Forward-Built FRM System Looks Like

M2P's FRM system is built around exactly this principle — real-time network and behavioral analysis for scam and mule detection, an architecture flexible enough to extend to new transaction types as agentic commerce and new payment models emerge, and infrastructure designed for the kind of adaptability this fraud landscape demands.

If you're a risk leader trying to figure out whether your fraud stack is built for today's threats or still tuned to yesterday's, reach out to M2P to explore how our FRM system can help you get ahead of where fraud is actually headed.

Looking for something specific? Let’s Connect