Authorized fraud has emerged as one of the most corrosive and structurally difficult threats facing the American banking system — and the industry's response, measured in budget allocations, is now unmistakable. According to the 2025 State of Fraud and Financial Crime in the United States, a PYMNTS Intelligence report, 68 percent of financial institutions increased their fraud-detection budgets year over year. That statistic alone tells a decisive story: the sector is no longer treating fraud as an occasional operational disruption. It is treating it as a permanent adversarial condition requiring sustained capital investment.

The category at the center of this escalation — authorized fraud — presents a fundamentally different challenge from the card-not-present fraud or account-takeover schemes that defined the prior decade of financial crime. In authorized fraud, more commonly known as authorized push payment (APP) scams, the victim is the one who initiates the transaction. The customer, deceived by an impersonator posing as a bank representative, a government official, a romantic partner, or a legitimate vendor, willingly transfers funds to a fraudster-controlled account. The payment is technically valid. The authentication checks pass. The money moves — and once it moves, recovery becomes extraordinarily difficult.

This is the crux of the problem that has sent fraud-detection budgets climbing across American financial institutions: the window between deception and financial loss is measured in seconds, not days. Traditional fraud controls were built on a model of post-transaction detection — flag an anomaly, freeze an account, reverse a charge. That architecture collapses when the customer has authorized the very transaction that destroys them. As the PYMNTS Intelligence report underscores, stopping a scam after the customer has sent the money is, in most cases, simply too late.

The Pre-Authorization Imperative

The logical response — and the one that the most forward-looking institutions are now pursuing aggressively — is to move intervention upstream. Rather than monitoring transactions for suspicious patterns after the fact, banks must build detection capabilities that trigger at or before the moment of authorization. This means integrating behavioral analytics, device intelligence, and social engineering signal detection into the payment initiation flow itself. A customer navigating to a payment screen while on an active phone call with an unknown number, transferring an atypically large sum to a first-time payee, outside of their normal banking hours — each of those contextual signals, individually weak, collectively powerful, must be synthesized in real time and acted upon before the confirmation button is pressed.

This is technically demanding and operationally sensitive work. Banks must intervene decisively enough to prevent fraud without generating so many false positives that legitimate customers are inconvenienced or alienated. The friction-versus-security tradeoff has never been more acutely felt than in the authorized fraud context, where the fraudster has invested considerable effort in making the customer's behavior appear normal and purposeful. Scam victims are often deliberately coached to dismiss bank warnings, told by their deceiver that the institution is untrustworthy or that delays will cost them money. The bank's warning, in that moment, competes directly with a highly rehearsed manipulation script.

A Regulatory Horizon Sharpens the Stakes

The budgetary escalation reflected in the PYMNTS Intelligence data is not occurring in a vacuum. Across the Atlantic, the United Kingdom's Payment Systems Regulator has already moved to mandate reimbursement for APP scam victims, placing direct financial liability on sending institutions. While American regulators have not yet enacted equivalent requirements, the direction of travel in consumer protection policy is widely understood within compliance circles. The Consumer Financial Protection Bureau and federal banking supervisors have signaled growing interest in the authorized fraud space. For American financial institutions, the question is not whether liability frameworks will tighten, but when — and whether their current investment levels will be sufficient when they do.

The 68 percent figure from the PYMNTS report therefore reflects something more than reactive spending. It reflects an industry that is, with varying degrees of urgency, trying to get ahead of a liability curve that regulatory momentum is pulling inexorably forward. Institutions that build robust pre-authorization intervention capabilities now will be better positioned — legally, reputationally, and operationally — than those that delay until mandated.

What This Means for the Sector

The authorized fraud epidemic is, at its core, a human engineering problem wearing a technology disguise. The payment rails function as designed. The authentication systems perform correctly. The failure is in the cognitive and emotional manipulation of the account holder — a vector that no purely technical control can fully address. The most effective institutional responses will combine real-time behavioral analytics with proactive customer education, friction-based delay mechanisms for high-risk transactions, and dedicated scam intervention protocols that treat at-risk customers as people who need to be reached, not just transactions that need to be flagged.

The fact that nearly seven in ten American financial institutions have already raised their fraud-detection spending signals that the sector understands the stakes. Whether that investment translates into meaningfully better outcomes for scam victims will depend on where exactly within the payment lifecycle that money is deployed — and whether banks prove willing to intervene at the most uncomfortable moment of all: before the customer has finished deciding to send.

Written by the editorial team — independent journalism powered by Codego Press.