Unbelievable: AI Scams Will Soon Dominate 90% of All Attacks — Here’s How to Fight Back

The digital frontier of finance is about to get a whole lot wilder. If you’re a financial institution, or even just a consumer, you need to pay attention to this: a recent report from Incode Technologies drops a bombshell, projecting that “agentic fraud”—scams orchestrated autonomously by artificial intelligence—will make up over 90% of all cyberattacks by 2028. Let that sink in for a moment. We’re not talking about human hackers using AI tools; we’re talking about AI systems running entire fraud operations on their own, mimicking human behavior so perfectly that our current defenses are essentially useless. It’s an alarming shift that demands immediate action, compelling financial institutions to re-evaluate their strategies and invest in the best fraud prevention tools for financial institutions 2028.

This isn’t some distant sci-fi scenario. Agentic fraud already accounted for 40% of all attacks in early 2026. The FBI reported a staggering $20.9 billion in US cyber-enabled losses in 2025, and payments to AI scam-service vendors have skyrocketed by an almost unbelievable 1,900% since 2021. These aren’t just numbers; they represent real money, real security breaches, and a fundamental challenge to the trust we place in digital transactions. Traditional security measures, designed to spot human anomalies or known attack patterns, simply can’t keep up with AI agents that learn, adapt, and operate with unprecedented speed and sophistication. So, what’s a bank or credit union to do? The answer lies in adopting AI-native defense mechanisms, focusing on advanced identity verification, and embracing a new generation of fraud prevention tools.

1. Behavioral Biometrics and Continuous Authentication: The New Gatekeepers

Forget static passwords or even one-time PINs; those are child’s play for an AI agent. The future of fraud prevention, particularly against agentic threats, lies in understanding and continuously verifying *how* a user interacts with a system. This is where behavioral biometrics shine. These systems analyze subtle, unconscious patterns in user behavior—things like typing rhythm, mouse movements, scroll speed, even how a person holds their phone. An AI agent, no matter how sophisticated, struggles to perfectly replicate the unique, almost subconscious nuances of human interaction.

Imagine a system that learns your unique digital fingerprint. It knows how quickly you type your password, the pressure you apply to your touchscreen, or the typical path your mouse takes across a page. If an AI agent attempts to log in, even with stolen credentials, its digital behavior will likely deviate from your established profile. This deviation triggers an alert, prompting additional verification or even blocking the transaction. Continuous authentication takes this a step further, constantly monitoring user behavior *after* login, ensuring the person interacting with the account remains the legitimate owner throughout the session. This makes it incredibly difficult for an AI to maintain a fraudulent session for any length of time, making it one of the best fraud prevention tools for financial institutions 2028. Related reading: a critical AI incident.

2. Advanced AI-Native Identity Verification (IDV): Beyond the Selfie

The days of simply taking a selfie with your ID are rapidly becoming obsolete. AI agents can generate deepfake images and videos that are virtually indistinguishable from real people to the human eye, and increasingly, to older IDV systems. The next generation of identity verification needs to be AI-native, meaning it’s designed specifically to detect AI-generated fakes and spoofing attempts.

This involves multi-modal analysis, combining liveness detection that checks for subtle biological signs (like micro-expressions, blood flow, or even reflections in the eyes) with advanced document verification that scrutinizes holograms, watermarks, and data consistency using machine learning. Furthermore, these systems are integrating passive behavioral signals during the enrollment process. For example, is the user holding their phone naturally? Are their eye movements consistent with a real person looking at a screen? These sophisticated layers of defense are critical for onboarding new customers securely and ensuring that the identity established is genuinely human, not an AI construct. (See: FBI Cyber Crime Division.)

3. Predictive Analytics and Anomaly Detection with Explainable AI (XAI): Seeing the Future of Fraud

Fraud prevention has always relied on identifying anomalies, but AI-driven fraud demands a far more sophisticated approach. Predictive analytics, powered by machine learning, can sift through vast datasets—transaction history, network patterns, device fingerprints, and external threat intelligence—to identify patterns that signal potential fraud *before* it occurs. This isn’t just about spotting unusual transactions; it’s about forecasting where the next attack might come from and what it might look like.

However, with the complexity of AI comes the challenge of understanding *why* a system made a particular decision. This is where Explainable AI (XAI) becomes crucial. Financial institutions can’t simply trust a black box; they need to understand the reasoning behind a fraud alert to comply with regulations, refine their models, and build confidence. XAI provides transparency, allowing human analysts to understand the factors an AI model weighed when flagging a transaction or an identity, making it easier to adapt to evolving threats and validate the system’s effectiveness. These capabilities are non-negotiable for the best fraud prevention tools for financial institutions 2028. There’s a fuller look at upcoming cyberattack trends.

4. Real-time Transaction Monitoring with Contextual Intelligence: Instant Decisions, Deeper Insight

In a world where AI agents can initiate and complete fraudulent transactions in milliseconds, batch processing for fraud detection is a relic of the past. Financial institutions need real-time transaction monitoring systems that can analyze every single transaction as it happens, not hours or days later. This requires immense processing power and sophisticated algorithms that can make instant decisions without introducing unacceptable latency for legitimate customers.

But real-time isn’t enough; it needs contextual intelligence. This means integrating data from multiple sources: the user’s past behavior, their geographic location, the device being used, the merchant involved, known fraud typologies, and even external threat feeds. For instance, if a customer typically makes small purchases in their hometown, a sudden large transaction from a new device in an unusual location would be flagged with high severity. An AI agent might try to mimic a user’s typical transaction volume but struggle to replicate the full contextual profile, making this a powerful defense among the best fraud prevention tools for financial institutions 2028.

5. Secure Multi-Party Computation (MPC) and Federated Learning: Collaborative Defense

No single financial institution has all the data or all the answers when it comes to combating sophisticated, globally operating AI fraud rings. Secure Multi-Party Computation (MPC) and Federated Learning offer groundbreaking ways for institutions to collaborate on fraud detection without ever sharing sensitive customer data directly. This is a game-changer for collective security.

MPC allows multiple parties to compute a function over their combined inputs while keeping those inputs private. Imagine several banks wanting to identify common fraud patterns across their customer bases without revealing individual customer transaction details to each other. MPC makes this possible. Similarly, Federated Learning allows AI models to be trained on decentralized datasets (e.g., at individual banks) without the data ever leaving its source. The models learn from local data, and only the updated model parameters (not the raw data) are shared and aggregated. This means banks can collectively build more robust, intelligent fraud detection models that benefit from a wider array of threat intelligence, significantly enhancing their ability to identify and stop AI-driven attacks. (See: CDC on Cybersecurity Risks.)

6. Gartner’s Adaptive Security Architecture (ASA) Principles: A Holistic Approach

While not a single tool, Gartner’s Adaptive Security Architecture (ASA) principles are absolutely critical for guiding the implementation of any effective fraud prevention strategy in the age of AI. ASA moves beyond static, perimeter-based defenses to a continuous, adaptive approach. It emphasizes four key stages: Predict, Prevent, Detect, and Respond. For financial institutions grappling with AI fraud, this means constantly anticipating new threats, building preventative measures, rapidly detecting breaches, and having automated, agile response mechanisms in place.

Applying ASA to fraud prevention means regularly updating threat intelligence, leveraging AI to predict emerging fraud vectors, integrating preventative controls across all touchpoints (from onboarding to transactions), employing real-time detection tools, and establishing automated workflows to respond to detected fraud. It’s about creating a security posture that is resilient, flexible, and continuously evolving—just like the threats it faces. Without an overarching architectural strategy, even the best fraud prevention tools for financial institutions 2028 will operate in silos and fail to provide comprehensive protection.

7. Quantum-Resistant Cryptography Readiness: Future-Proofing Defenses

This might sound a bit like science fiction, but the threat of quantum computing breaking current encryption standards is very real, even if it’s a few years down the line. While today’s AI fraud isn’t directly leveraging quantum computers, the exponential growth in computational power, especially with the advancement of quantum algorithms, means that the cryptographic foundations upon which our digital security rests could eventually be compromised. Financial institutions need to start planning for quantum-resistant cryptography now. We covered impact of rogue AI in more detail.

This involves exploring and preparing for post-quantum cryptographic algorithms that can withstand attacks from future quantum computers. Implementing these new standards will be a massive undertaking, requiring significant infrastructure upgrades and changes to data encryption, digital signatures, and secure communication protocols. While it might not seem like a direct fraud prevention tool for 2028, laying the groundwork for quantum-resistant cryptography is a critical long-term strategy. It ensures that the integrity of data and the authenticity of transactions remain secure against future, even more powerful, AI-driven threats that could leverage quantum capabilities. Ignoring this now could leave institutions vulnerable to catastrophic breaches in the not-so-distant future.

8. Employee Training and AI Literacy: The Human Firewall

Even with the most advanced technological defenses, the human element remains a critical vulnerability. AI-driven social engineering attacks are becoming incredibly sophisticated, mimicking voices, crafting hyper-realistic phishing emails, and even simulating video calls with uncanny accuracy. Employees, from front-line tellers to senior executives, need to be trained not just on traditional security awareness, but specifically on AI literacy related to fraud. (See: New York Times on AI and Cybersecurity.) (game-changing cybersecurity stats)

This means understanding how deepfakes work, recognizing the subtle tells of AI-generated communication (even when they’re very good), and knowing the protocols for verifying unusual requests, especially those involving financial transfers or sensitive data. Training should incorporate simulated AI phishing and vishing (voice phishing) exercises to build practical resilience. A well-informed human workforce acts as a crucial layer of defense, capable of spotting anomalies that even the best algorithms might miss, particularly when an AI agent attempts to bridge the digital and physical worlds. The best fraud prevention tools for financial institutions 2028 include empowering your people.

9. Regulatory Compliance and Ethical AI Use: Building Trust and Avoiding Pitfalls

As financial institutions adopt more powerful AI tools, navigating the complex landscape of regulatory compliance and ethical AI use becomes paramount. Regulations like GDPR, CCPA, and upcoming AI-specific laws (like the EU’s AI Act) mandate transparency, fairness, and accountability in how AI systems are developed and deployed. For fraud prevention, this means ensuring models don’t inadvertently discriminate against certain customer segments or lead to false positives that unfairly impact legitimate users.

Financial institutions need robust governance frameworks for their AI systems, documenting model training data, biases, decision-making logic (where XAI plays a key role), and impact assessments. Regular audits of AI models are essential to ensure they remain compliant and fair as they learn and evolve. Building public trust in AI-powered fraud prevention also hinges on transparent communication with customers about how their data is protected and how AI is used responsibly. Ignoring these ethical and regulatory considerations could lead to significant fines, reputational damage, and a loss of customer confidence, undermining the very purpose of implementing these advanced tools.

The rise of agentic fraud isn’t just another challenge; it’s a fundamental paradigm shift in cybersecurity. The old playbook is being rewritten by AI, and financial institutions have no choice but to adapt with equal, if not greater, speed and intelligence. By investing in these next-generation, AI-native fraud prevention tools for financial institutions 2028, from behavioral biometrics to quantum-resistant cryptography, we can hope to stay one step ahead of the autonomous adversaries lurking in the digital shadows.

Frequently Asked Questions

What is agentic fraud in cyberattacks?

Agentic fraud refers to scams orchestrated autonomously by artificial intelligence, where AI systems run entire fraud operations independently, mimicking human behavior. This type of fraud is projected to dominate over 90% of all cyberattacks by 2028, posing significant challenges to current security measures.

How much have AI scam-service payments increased?

Payments to AI scam-service vendors have surged by an astonishing 1,900% since 2021. This dramatic increase highlights the growing sophistication and prevalence of AI-driven fraud, making it a critical concern for financial institutions and consumers alike.

What can financial institutions do to combat AI scams?

To combat AI scams, financial institutions should adopt AI-native defense mechanisms, implement advanced identity verification methods, and focus on behavioral biometrics and continuous authentication. This proactive approach is essential to stay ahead of evolving threats from agentic fraud.

Why are traditional security measures ineffective against AI fraud?

Traditional security measures, such as static passwords and known attack pattern detection, are ineffective against AI fraud because they cannot adapt to the learning and evolving tactics of AI agents. These agents operate with unprecedented speed and sophistication, rendering conventional defenses obsolete.

What are behavioral biometrics and how do they help in fraud prevention?

Behavioral biometrics involve continuously verifying how a user interacts with a system, rather than relying on static credentials. This method enhances fraud prevention by identifying unusual patterns and behaviors that may indicate fraudulent activity, making it a crucial tool against AI-driven scams.

What's your take on this? Share your thoughts in the comments below — we read every one.

Choose your Reaction!