
Open Banking Fraud: Why Faster Payments Need Smarter Risk Controls
Open banking has changed the way people and businesses interact with services.
Customers can now link accounts start payments share details and use new financial products without always going through traditional banking channels. For banks, fintech companies and payment providers this opens the door to faster connected and more convenient services.
But there is another side to this transformation.
As payments become faster and more automated, fraud prevention becomes more difficult.
A traditional payment system may have given financial institutions more time to review unusual transactions. Modern open banking payments can move quickly through API-based journeys, while customers increasingly expect transactions to be completed almost instantly.
That creates a difficult challenge:
How can banks stop fraudulent payments without slowing down legitimate ones?
This question sits at the heart of open banking fraud prevention.
Recent data from Open Banking Limited shows that open banking fraud remains lower by transaction volume than fraud across the wider UK payments industry. However, fraud volumes increased during the first quarter of 2026, and Authorised Push Payment (APP) fraud accounted for more than two-thirds of reported open banking-related fraud cases. Open Banking Limited also reports that fraud techniques are becoming more sophisticated, including impersonation, phishing, smishing and fake-refund scams.
The answer is not just adding login screens or blocking more transactions.
Banks and fintechs need risk controls. These controls must understand the picture. Transaction context, customer behaviour, payment patterns and real-time fraud signals.
This article looks at why open banking fraud’s changing why faster payments make fraud harder to stop and how financial institutions can build a smarter way to protect payments.
What Is Open Banking Fraud?
Open banking fraud refers to fraudulent activity that occurs through open banking-enabled financial services, particularly account information and payment initiation services.
Open banking allows authorised third-party providers to connect with financial institutions through secure APIs. Depending on the service, customers can give permission for a third party to access account information or initiate payments from their bank account.
The model creates significant benefits.
For example, a customer might:
- Pay a merchant directly from a bank account.
- Connect multiple financial accounts to a budgeting application.
- Use a fintech platform to initiate payments.
- Give a financial service permission to analyse account information.
- Move money between accounts through an integrated financial platform.
However, every additional connection can introduce another point where fraudsters may attempt to manipulate a customer, compromise credentials or exploit weaknesses in the payment journey.
Importantly, open banking fraud is not limited to someone breaking into a bank account.
A fraudster may instead manipulate the customer into making a legitimate-looking payment.
This is particularly important in Authorised Push Payment fraud, where the customer authorises the payment themselves after being deceived.
Open Banking Limited’s latest fraud monitor found that APP fraud remains the dominant fraud category in open banking payments, accounting for more than two-thirds of reported cases.
That changes the fraud-prevention problem.
The system is no longer asking only:
“Is this customer authorised to make this payment?”
It also needs to ask:
“Does this payment make sense given the customer’s behaviour, transaction context and relationship with the recipient?”
Why Faster Payments Are Changing the Fraud Landscape
Speed is one of the biggest advantages of modern payments.
Consumers want instant confirmation. Businesses want faster settlement. Merchants want fewer abandoned transactions. Fintech platforms want seamless payment experiences.
But speed also reduces the time available for intervention.

Consider a simplified example.
A customer receives a convincing message claiming that their investment account requires an urgent payment. They follow a link, authenticate with their bank and send €10,000.
From a conventional authentication perspective, the transaction may look legitimate.
- The customer logged in.
- The customer authenticated.
- The customer approved the payment.
- The transaction was successfully initiated.
- The customer was manipulated.
This is one of the biggest challenges in modern payment security.
Fraudsters increasingly attack people and processes, not just technical infrastructure
Faster payments create several challenges:
| Challenge | Why It Matters |
|---|---|
| Instant execution | Less time to intervene before funds move |
| Social engineering | Customers may authorise fraudulent transactions themselves |
| API connectivity | More participants can interact with payment journeys |
| Automated fraud | Attackers can scale campaigns quickly |
| Cross-platform activity | Fraud signals may exist across multiple providers |
| Account takeover | Compromised accounts can be used for rapid transfers |
| Mule accounts | Fraudulent funds can move through legitimate-looking accounts |
The result is a shift from traditional transaction monitoring toward real-time payment risk management.
Why Open Banking Fraud Is Different
Open banking introduces a more connected financial ecosystem.
A payment journey can involve several parties, including:
- The customer
- The account-servicing payment service provider
- The payment initiation service provider
- The merchant
- The payment infrastructure
- Fraud detection systems
- Authentication services
Each participant may have information that another participant does not.
For example, a payment initiation provider may understand the merchant relationship, while the bank may have detailed knowledge of the customer’s historical behaviour.
If those signals remain isolated, fraud detection becomes weaker.
This is why data sharing and transaction context are becoming increasingly important.
Open Banking Limited has highlighted the importance of transaction-level information such as Transaction Risk Indicators (TRIs) and enhanced fraud data to strengthen open banking fraud prevention.
The goal is not simply to collect more data.
The goal is to collect the right data at the right moment.
The Growing Threat of Authorised Push Payment Fraud
Authorised Push Payment fraud deserves particular attention because it challenges traditional fraud models.
In an unauthorised transaction, a criminal may access an account and initiate a payment without the customer’s permission.
In APP fraud, the customer is manipulated into authorising the payment.
The fraud can therefore pass several traditional security checks.
Common APP fraud scenarios include:
- Investment scams
- Impersonation scams
- Romance scams
- Fake invoices
- Fake refunds
- Purchase scams
- Business email compromise
- Bank impersonation
- Government impersonation
- Cryptocurrency investment scams
Open Banking Limited reported that investment fraud remains one of the largest identified APP categories by value in its June 2026 fraud monitor.
This demonstrates why authentication alone cannot solve modern payment fraud.
A system can successfully confirm that the person making the payment is the account holder while still failing to determine whether the reason for the payment is fraudulent.
That is where smarter risk controls become valuable.
Common Types of Open Banking Fraud
Understanding the different forms of fraud is essential for designing effective controls.
1. Authorised Push Payment Fraud
The customer is manipulated into approving a fraudulent transaction.
The payment may appear completely legitimate from a technical perspective.
2. Account Takeover
A fraudster gains control of a customer’s account and uses it to initiate transactions.
Attack methods can include:
- Credential theft
- Phishing
- Malware
- SIM swapping
- Social engineering
- Stolen authentication information
3. Phishing and Smishing
Fraudsters use email or SMS messages to convince customers to visit fake websites or disclose information.
These attacks often imitate banks, payment companies, retailers or government services.
4. Impersonation Fraud
A criminal pretends to be a bank employee, business representative, government official or trusted individual.
The objective is often to convince the victim to transfer money.
5. Merchant Fraud
A fraudulent merchant may attempt to use payment services to receive money from customers or move illicit funds.
6. Money Mule Activity
Fraudsters may use accounts belonging to other people or businesses to receive and transfer stolen funds.
7. API and Integration Abuse
Open banking depends heavily on APIs.
Poorly secured integrations, compromised credentials or weak access controls can create opportunities for attackers.
Why Traditional Fraud Controls Are No Longer Enough
Traditional fraud detection often relies heavily on rules.
For example:
If transaction value exceeds €10,000, trigger an alert.
Or:
If a payment originates from a new device, require additional verification.
Rules can be useful.
But they can also be too rigid.
Imagine two customers making €10,000 payments.
Customer A
- Has made similar payments before.
- Sends money to an established beneficiary.
- Uses their normal device.
- Logs in from their normal location.
- Displays normal account behaviour.
Customer B
- Has never made a large payment before.
- Adds a new beneficiary.
- Logs in from a new device.
- Receives a suspicious message shortly before the transaction.
- Attempts several authentication failures.
- Suddenly transfers €10,000.
A simple rule may treat both transactions similarly.
A smarter system should not. It should evaluate the context around the transaction.
What Smarter Risk Controls Look Like
Smarter risk controls combine multiple signals to determine whether a payment appears legitimate.
Instead of asking one question, the system evaluates the transaction as a complete behavioural event.
Important signals can include:
- Transaction amount
- Transaction frequency
- Customer history
- Beneficiary history
- Device information
- Login behaviour
- Geographic signals
- Authentication behaviour
- Payment purpose
- Account age
- Merchant information
- Previous fraud indicators
- Velocity patterns
- Relationship between sender and recipient
- Transaction risk indicators
The objective is to calculate a more accurate risk profile.
A low-risk payment can proceed with minimal friction.
A high-risk transaction can receive additional verification or intervention.
This creates a more balanced model:
Low risk → seamless payment
Medium risk → additional verification
High risk → intervention or transaction review
This is far more practical than simply blocking every unusual transaction.
The Role of Transaction Risk Indicators
One of the most interesting developments in open banking fraud prevention is the growing use of Transaction Risk Indicators (TRIs).
TRIs provide additional contextual information about a payment.
The Open Banking Standards’ current guidance includes transaction-level indicators that can help participants interpret payment context consistently.
Examples can include information related to:
- Payment purpose
- Payment category
- Relationship between parties
- Whether a transaction is a transfer to self
- Contractual relationships
- Context surrounding the payment
Why does this matter?
Because a payment amount alone tells you very little.
Imagine a €5,000 transaction.
The number does not explain:
- Why the payment is being made.
- Who is receiving the money.
- Whether the customer has paid the recipient before.
- Whether the transaction is consistent with previous behaviour.
- Whether the payment is associated with a known business relationship.
Context changes the risk assessment.
Open Banking Limited has reported that its work on Transaction Risk Indicators found them useful for identifying potentially fraudulent open banking payments while helping reduce false positives.
That is particularly important because excessive fraud controls can create another problem: customer friction.
How AI Is Changing Payment Fraud Detection
Artificial intelligence is becoming increasingly important in fraud prevention because modern fraud patterns can be difficult to detect using fixed rules alone.
AI-based fraud detection can analyse large volumes of transactions and identify relationships between signals.
For example, an AI system could detect that:
- A customer normally makes small domestic payments.
- A new beneficiary was added recently.
- The customer’s device has changed.
- Login behaviour is unusual.
- The payment amount is significantly higher than normal.
- The recipient has risk indicators associated with previous fraud.
- Multiple accounts are sending money to the same recipient.
Individually, each signal may not be enough.
Together, they can create a strong risk signal.
AI can support:
- Behavioural analysis
- Anomaly detection
- Transaction scoring
- Pattern recognition
- Customer risk profiling
- Network analysis
- Fraud classification
- Alert prioritisation
- Case investigation
- Real-time monitoring
AI does not eliminate fraud.
Instead, it gives financial institutions a way to process more information and identify complex patterns faster.
Real-Time Fraud Detection and Behavioural Analytics
Real-time fraud detection is particularly important for faster payments.
The system needs to make decisions while the payment is still in motion.
This creates a fundamental technical requirement:
Fraud detection must operate at payment speed.
A useful real-time fraud system can evaluate:
Customer + Device + Behaviour + Transaction + Beneficiary + Context + History
within milliseconds or seconds.
Behavioural analytics can make this more powerful.
Instead of establishing a generic customer profile, banks can build a dynamic understanding of normal behaviour.
For example:
A customer usually logs in from the same device, makes payments during the day, transfers relatively small amounts and frequently pays the same five beneficiaries.
A sudden €15,000 transfer to a newly added recipient from an unfamiliar device should receive a different risk score.
This is not because €15,000 is automatically fraudulent. It is because the transaction is behaviorally inconsistent. That distinction is critical.

Balancing Fraud Prevention With Customer Experience
There is a danger in making fraud controls too aggressive.
If banks challenge every unusual transaction, customers may become frustrated.
Imagine receiving additional verification every time you:
- Buy something expensive.
- Travel internationally.
- Change devices.
- Send money to a new recipient.
- Make a large business payment.
Eventually, security becomes an obstacle.
This can lead to:
- Abandoned payments
- Customer complaints
- Lower conversion rates
- Increased support costs
- Reduced trust
- Customers moving to competitors
Data Sharing and Collaboration in Fraud Prevention
Fraud rarely stays inside one organisation.
A scammer may use:
- A fake website
- A compromised device
- A payment initiation service
- A mule account
- A social media platform
- A telecommunications service
- Multiple financial institutions
The fraud signals are distributed.
That makes collaboration important.
Open Banking Limited has repeatedly highlighted ecosystem collaboration and data sharing as important elements of fraud prevention.
Banks, fintechs and payment providers can benefit from sharing appropriate fraud intelligence while maintaining privacy, security and regulatory requirements.
Useful shared signals can include:
- Known fraudulent accounts
- Suspicious beneficiary patterns
- Transaction risk information
- Fraud typologies
- Device risk signals
- Scam indicators
- Suspicious payment patterns
Better information can produce better decisions.
However, data sharing must be implemented carefully.
Financial institutions need strong governance around:
- Data privacy
- Consent
- Access control
- Data quality
- Retention
- Regulatory compliance
- Security
Open Banking Fraud Prevention Strategies for Banks and FinTechs
There is no single technology that can eliminate open banking fraud.
A stronger strategy combines several layers.
- Build Real-Time Transaction Monitoring: Payments should be assessed as they occur rather than relying exclusively on after-the-fact investigations.
- Use Behavioural Analytics: Understand what normal customer behaviour looks like and identify meaningful deviations.
- Analyse Beneficiary Risk: A payment should not be evaluated only from the sender’s perspective. The recipient matters too.
- Use Transaction Risk Indicators: Payment context can help institutions distinguish legitimate activity from suspicious transactions.
- Strengthen Device Intelligence: Device changes, unusual login patterns and suspicious device behaviour can provide important signals.
- Detect Payment Velocity: Multiple rapid transactions can indicate account takeover, mule activity or automated fraud.
- Use AI and Machine Learning: learning can identify complex patterns that may be difficult to capture through static rules.
- Improve Customer Warnings: Warnings should be contextual rather than generic.
- Monitor Mule Accounts: Banks should identify accounts that behave differently from genuine customer accounts.
- Continuously Update Fraud Models: Fraud patterns evolve. A model that worked six months ago may not perform as well against new scam techniques.

The Role of Strong Customer Authentication
Strong Customer Authentication (SCA) remains an important component of payment security.
It can help verify that the person initiating a payment is authorised to use the account. However, SCA should not be treated as a complete fraud solution.
Why?
Because a fraudster may convince the genuine customer to authenticate the transaction.
That is why modern fraud prevention needs to combine authentication with:
- Behavioural analysis
- Transaction monitoring
- Beneficiary analysis
- Risk scoring
- Customer education
- Scam detection
- Contextual warnings
Open Banking, APIs and New Fraud Attack Surfaces
APIs are fundamental to open banking.
They enable financial institutions and authorised third parties to communicate securely. But APIs also expand the technology environment that banks must protect.
Security teams need to consider:
- API authentication
- Access permissions
- Token security
- Rate limiting
- Monitoring
- Third-party risk
- Data exposure
- Integration security
- Abnormal API activity
A secure API environment should not simply prevent unauthorised access.
It should also identify suspicious behaviour.
For example, an API integration suddenly generating an unusual number of payment requests should trigger investigation.
Similarly, repeated failed authentication attempts or unusual transaction patterns could indicate an attack.
How Banks Can Build a Modern Payment Risk Framework
A modern payment risk framework can be structured into five layers.
Layer 1: Identity
Determine who is initiating the transaction.
Signals include:
- Authentication
- Account information
- Device identity
- Login behaviour
Layer 2: Behaviour
Understand whether the customer’s activity is normal.
Signals include:
- Transaction history
- Payment frequency
- Typical transaction size
- Usual beneficiaries
- Login patterns
Layer 3: Transaction
Analyse the payment itself.
Signals include:
- Amount
- Currency
- Payment type
- Purpose
- Timing
- Recipient
Layer 4: Network
Look beyond the individual transaction.
Analyse relationships between:
- Accounts
- Devices
- Merchants
- Beneficiaries
- IP addresses
- Payment providers
This can help identify fraud networks.
Layer 5: Decision
Combine the signals into an appropriate action.
Possible outcomes include:
- Approve
- Approve with additional verification
- Delay
- Request confirmation
- Reject
- Escalate for investigation
This layered approach creates a more flexible form of open banking risk management.
Challenges of Implementing Smarter Risk Controls
Although smarter controls provide major advantages, implementation is not simple.
1. Data Quality
Fraud models are only as effective as the data available to them.
Incomplete or inaccurate information can produce poor decisions.
2. False Positives
An overly sensitive system may incorrectly identify legitimate transactions as fraud.
This can damage customer experience.
3. False Negatives
The opposite problem can be even more expensive.
A sophisticated fraud attack may bypass poorly configured controls.
4. Legacy Infrastructure
Many financial institutions still operate a combination of modern APIs and older banking systems.
Connecting real-time fraud detection to legacy infrastructure can be difficult.
5. Privacy
Financial institutions must balance fraud intelligence with privacy requirements.
6. Model Explainability
When AI makes or influences a financial decision, institutions may need to understand why the system reached its conclusion.
7. Fraudster Adaptation
Fraudsters learn.
When one attack method becomes ineffective, criminals can change their approach.
This means fraud prevention cannot be a one-time project.
It must be a continuous process.
The Future of Open Banking Fraud Prevention
The future of open banking fraud prevention will likely be increasingly contextual.
Instead of evaluating payments individually, financial institutions will analyse the broader journey.
That means asking:
- What happened before the payment?
- What changed?
- Who is receiving the money?
- What does the customer’s history look like?
- Is the payment consistent with normal behaviour?
- What signals are coming from other participants?
- Does the payment resemble known fraud patterns?
This will push fraud detection toward real-time intelligence.
AI will likely play a growing role in detecting complex relationships between transactions, accounts and behaviours.
At the same time, new payment models will create new security challenges.
The rise of automated and AI-assisted financial interactions could make payment authorisation even more complex.
Financial institutions therefore need to think beyond today’s fraud models.
Why Smarter Risk Controls Are Becoming Essential
Open banking is not inherently unsafe.
In fact, current industry data shows that open banking fraud rates remain below wider payments-industry benchmarks by volume. Open Banking Limited’s June 2026 monitor reported approximately one fraudulent open banking payment in every 6,000 payments during 2025, compared with roughly one in every 2,500 payments across the wider payments industry.
The challenge is that the payment ecosystem is changing quickly.
Open Banking Fraud vs Traditional Payment Fraud
| Factor | Traditional Payment Fraud | Open Banking Fraud |
|---|---|---|
| Payment journey | Often controlled by established channels | Can involve multiple connected providers |
| APIs | Less central in some payment journeys | Fundamental to many open banking services |
| Customer authorisation | May be separate from fraud attempt | Customer can be manipulated into authorising payment |
| Fraud detection | Rules and transaction monitoring | Contextual and cross-party monitoring increasingly important |
| Payment speed | Varies | Often designed for fast execution |
| Key risk | Unauthorised activity | Authorised fraud and social engineering |
| Data requirement | Transaction data | Transaction + contextual data |
| Prevention | Authentication + monitoring | Authentication + behaviour + context + collaboration |
The important point is that open banking does not replace traditional fraud risks.
It adds new dimensions to them.
Key Benefits of Smarter Risk Controls
Risk controls when designed well can help financial institutions achieve goals at the same time.
- Better Fraud Detection: More signals can help spot transactions earlier.
- Fewer False Positives: Contextual analysis can tell unusual but normal behaviour from real suspicious activity.
- Decisions: Real-time risk engines can assess transactions without causing extra delays.
- Customer Experience: Low-risk customers can finish transactions with little hassle.
- Stronger Compliance: Risk-based controls can help meet governance rules.
- Improved Operational Efficiency: AI and automation can prioritize alerts so fraud teams can focus on the highest-risk cases
A Practical Checklist for Open Banking Fraud Prevention
Financial institutions evaluating their current fraud controls should ask:
Customer Risk
- Do we understand normal customer behaviour?
- Can we detect unusual activity?
- Are high-risk customers monitored appropriately?
Transaction Risk
- Can we analyse payments in real time?
- Do we consider transaction context?
- Can we identify unusual payment amounts or velocity?
Beneficiary Risk
- Do we assess new recipients?
- Can we identify risky beneficiary patterns?
- Can we detect mule-account relationships?
Device Risk
- Can we identify unusual devices?
- Do we monitor suspicious login behaviour?
- Can we detect compromised devices?
Data
- Are relevant transaction risk indicators available?
- Can different systems share fraud signals?
- Is our fraud data accurate and timely?
AI
- Are we using machine learning where it adds value?
- Are models continuously monitored?
- Can analysts understand important risk decisions?
Customer Experience
- Are fraud warnings understandable?
- Are legitimate customers being challenged unnecessarily?
- Can intervention be targeted according to risk?
Conclusion
Open banking has made financial services more connected, accessible and convenient. However convenience cannot come at the expense of trust and security. As payments become faster and more digital fraud prevention also needs to become smarter and more adaptive.
Traditional security measures, such as rules-based monitoring and authentication remain important. They are increasingly only part of the solution. A stronger approach combines real-time payment monitoring, behavioral analytics, transaction context, AI, beneficiary intelligence, risk-based authentication and collaboration.
The goal is simple: protect customers without making legitimate payments unnecessarily difficult.
The future of open banking fraud prevention will therefore not be defined by how many transactions banks can block. It will increasingly depend on how they can identify which transactions represent genuine risk.
For banks and fintech companies smarter risk controls are not simply a security upgrade. They are becoming a part of delivering trusted, scalable, secure and customer-friendly open banking experiences.
Next action: Create a downloadable DOCX file here, in this chat containing the editable prose above
Frequently Asked Questions
What is open banking fraud?
Open banking fraud is fraudulent activity associated with open banking-enabled financial services, particularly payment initiation and account connectivity. It can include authorised push payment fraud, impersonation, phishing, account takeover and other forms of payment abuse.
Why is open banking fraud a growing concern?
Open banking is expanding the number of connected financial services and payment journeys. Faster transactions and API-based integrations can reduce the time available to identify suspicious activity, while social engineering can cause customers to authorise fraudulent payments themselves.
What is Authorised Push Payment fraud?
Authorised Push Payment fraud occurs when a customer is deceived into authorising a payment to a fraudster. The customer may complete authentication successfully, which makes the transaction difficult for traditional security systems to identify.
How can banks prevent open banking fraud?
Banks can combine real-time transaction monitoring, behavioural analytics, transaction risk indicators, device intelligence, beneficiary risk assessment, AI-based fraud detection, customer warnings and industry collaboration.
What are Transaction Risk Indicators?
Transaction Risk Indicators are contextual data points associated with a payment. They can provide information that helps payment providers and account-servicing institutions better understand the nature and circumstances of a transaction.
Open Banking Standards provide guidance on various transaction risk indicators and their use in payment journeys.
Can AI prevent payment fraud?
AI can improve payment fraud detection by identifying behavioural patterns, anomalies and relationships across large amounts of transaction data. However, AI is not a standalone solution. It works best as part of a broader fraud risk framework.



