Attempted impersonation scams at US financial institutions rose 130% between 2025 and 2026, according to data that fraud-prevention company BioCatch released on August 12, 2026. The figures come from its annual 2026 Digital Banking Fraud Trends in the U.S. report, which tracks how often these attempts show up in US digital banking channels. The report lands nine days after Visa agreed to buy BioCatch for $2.4 billion.
In an impersonation scam, the fraudster poses as someone the victim trusts, such as a bank, a government agency, a loved one, or a celebrity, and gets the victim to send the payment themselves.
The data comes from behavioral signals at 292 institutions
The study covers 292 US financial institutions serving a combined total of more than 280 million users, from June 2025 to May 2026. BioCatch works from behavioral analysis of banking sessions, meaning how a user handles their device while navigating. Across its whole business, the company says more than 370 financial institutions use its tools, which analyze 19 billion sessions a month and cover more than 760 million users on more than 1.8 billion devices.
Fraud is shifting to payments customers approve
Digital banking fraud falls into two broad types. In account takeover, the fraudster gains control of an account and acts in the account holder’s place. In an authorized push payment scam, the account holder makes the payment, deceived about who is receiving it or what it is for. BioCatch’s numbers point to growth in the second type, where no authentication rule is broken.
| Feature | Account takeover | Authorized push payment scam |
|---|---|---|
| Who initiates the payment | The fraudster, without the account holder’s knowledge | The account holder, under manipulation |
| Authentication | Bypassed, stolen, or hijacked | Passed, since the customer is the one acting |
| Useful signals | Unfamiliar device, geolocation, time of day | Typing rhythm, hesitation, remote-assisted session |
| Response | Block the session, reset credentials | Interrupt the flow and question the customer |
Location and login checks are losing their edge
Three findings show why these scams are hard to stop. Devices inside the US account for 83.9% of fraud attempts, which takes much of the value out of geolocation filters. About 70% of account takeover sessions happen after 5 p.m., when monitoring teams are thinner. And sessions using remote-access tools rose 45%: the scammer no longer needs to steal credentials, but watches and guides the victim, who does the work on their own device.
BioCatch’s US customers, which include three of the four largest banks by assets, reported $46 million in attempted investment fraud losses, $28 million in purchase scams, and $22 million in law enforcement and legal impersonation scams. “While impersonation scams were the most commonly reported scam type to the Federal Trade Commission last year, they were not the most costly,” said Gary Patterson, a fraud intelligence research analyst at BioCatch. Nationwide, the FBI estimated investment fraud losses at more than $8.6 billion in 2025.
Europe checks the payee name instead
The EU has taken a different route: payee verification. Since October 9, 2025, payment providers in the euro area must tell the payer whether the name entered matches the holder of the destination IBAN before a credit transfer goes out. The rule tackles authorized push payment scams with data rather than behavior, and it covers credit transfers only. Card payments and transactions made after a remote takeover of the device fall outside it.
The report comes as Visa absorbs BioCatch
Coming nine days after Visa announced the $2.4 billion acquisition, the report helps explain the deal. Visa wants signals it can read before a payment order even exists, at a stage where card authorization, its traditional territory, still sees nothing. But the numbers are attempts detected by a single vendor, not official statistics, and they should be treated with that caveat as a gauge of the US market.