Attempted banking scams increased 35% across more than 370 financial institutions covered by BioCatch’s 2026 Global Scams report, while mobile devices accounted for nine out of ten scam sessions. The institutions serve more than 760 million users in 21 countries, giving the dataset scale but not making it a census of global banking fraud.
The growth rate slowed from the 65% increase reported in the previous edition. BioCatch attributes part of that deceleration to banks’ use of behavioral intelligence, but the dataset cannot establish causation. Every sampled institution is a BioCatch customer, and changes in client mix, detection coverage, reporting, criminal targeting, or bank controls can affect the comparison.
The category mix shows why scam prevention cannot rely on one control. Purchase scams represented 33% of attempts, employment-scam victims increased 258%, and investment scams produced the highest average attempted value at $6,600. Romance-scam attempts rose 23%, a slower rate than in the prior report but still an increase.
Mobile Is the Main Environment for Authorized Scams
BioCatch found that 90% of scam sessions originated on mobile devices, five percentage points more than a year earlier. Conventional unauthorized fraud had a lower mobile share of 75%. The comparison suggests that scams are especially tied to the device through which customers communicate, receive instructions, and approve payments.
That is different from an account takeover in which a criminal acts without the customer’s knowledge. In an authorized push-payment scam, the real account holder may log in, pass authentication, add a beneficiary, and send the funds. Passwords and one-time codes can work exactly as designed while the payment intent has been manipulated.
BioCatch’s case study looks for context around that apparently legitimate session: whether a phone call is active, whether remote-access software is running, how the beneficiary is added, how the customer navigates, and whether behavior changes under pressure. FinanceFeeds described the same problem when Revolut introduced an in-app call-identification warning designed to intervene while a customer is speaking to an impersonator.
The mobile concentration also increases the importance of device integrity. A FinanceFeeds review found that 34 Android malware families targeted 1,243 banking and fintech applications. Scams and malware are distinct threats, but remote access can connect them: the victim may be persuaded to install software that gives the criminal visibility or control.
Investment Scams Produce the Largest Attempted Values
The $6,600 average attempted value for investment scams was five times the average across all categories. Purchase scams are more frequent, but investment schemes create a larger financial exposure per case because they persuade victims to transfer savings, liquidate assets, or make repeated deposits.
The result is consistent with the industrialisation of investment fraud. FinanceFeeds reported on a network accused of processing €100 million a month through 20 call centres. The operating model combined fake advisers, online advertising, scripted contact, and follow-up fraud aimed at people who had already lost money.
Romance scams can converge with the same investment funnel. A relationship is established first, then the victim is directed toward a fake trading platform or crypto opportunity. FinanceFeeds found that UK romance-fraud losses reached about £280,000 a day, with long grooming periods contributing to the loss size.
The distinction between attempted and completed value remains important. BioCatch’s $6,600 figure is not an average confirmed loss. It measures the value associated with attempted investment scams in its monitored population. Successful intervention may prevent the transfer, and some losses may occur outside the institution’s view.
Employment Scams Are Growing From a Different Entry Point
The 258% rise in reported employment-scam victims was the fastest growth in the report. Job scams can begin on recruitment sites, social networks, messaging applications, or unsolicited texts. The victim may be asked to pay for training, equipment, background checks, or task-based work. In other cases, the false job is used to recruit a money mule.
That entry point sits outside the bank. Financial institutions see the payment and device session near the end of the process, after manipulation has taken place elsewhere. The same limitation applies to purchase, romance, and investment scams. Effective prevention therefore depends on intelligence sharing among banks, payment networks, telecom providers, online platforms, and law enforcement.
BioCatch has pursued that network approach through integrations. FinanceFeeds covered its partnership with Nasdaq Verafin, which combines behavioral and device signals with consortium-level financial-crime data. The goal is to connect what happens during the customer session with what is known about the receiving account and wider network.
A Slower Increase Is Not a Victory Yet
BioCatch’s findings arrive after Visa agreed to buy the company for $2.4 billion. FinanceFeeds analyzed how behavioral signals can detect manipulation that static identity checks miss. That transaction underlines the value payment companies place on session-level intelligence as generative AI makes messages, voices, documents, and personas cheaper to produce.
The report’s slower growth rate can support cautious optimism, but not a claim that scams are under control. A 35% increase remains substantial, mobile activity is becoming more dominant, and high-loss investment scams continue to exploit the gap between authenticated identity and genuine intent.
The operational lesson is that banks must detect coercion before authorization, assess the destination of funds, and keep monitoring after payment. The analytical lesson is narrower: BioCatch’s figures describe attempted scams observed among its customers. They show direction and composition across a large network, but they do not measure total global losses or prove that any single control caused the slowdown.
