← Back to News
Fraud

Impersonation scam attempts more than double at US banks

Attempted impersonation scams at US banks rose 130% in a year, BioCatch says, based on 292 institutions serving more than 280 million users. The data shows fraud moving toward payments that victims authorize themselves.

Networks mentioned

Attempted impersonation scams at US financial institutions rose 130% between 2025 and 2026, according to data that fraud-prevention company BioCatch released on August 12, 2026. The figures come from its annual 2026 Digital Banking Fraud Trends in the U.S. report, which tracks how often these attempts show up in US digital banking channels. The report lands nine days after Visa agreed to buy BioCatch for $2.4 billion.

In an impersonation scam, the fraudster poses as someone the victim trusts, such as a bank, a government agency, a loved one, or a celebrity, and gets the victim to send the payment themselves.

+130%
attempted impersonation scams, year over year
BioCatch, August 12, 2026
+50%
phishing scam attempts, year over year
BioCatch, August 12, 2026
+45%
banking sessions involving a remote-access tool
BioCatch, August 12, 2026
83.9%
of fraud attempts coming from devices inside the US
BioCatch, August 12, 2026

The data comes from behavioral signals at 292 institutions

The study covers 292 US financial institutions serving a combined total of more than 280 million users, from June 2025 to May 2026. BioCatch works from behavioral analysis of banking sessions, meaning how a user handles their device while navigating. Across its whole business, the company says more than 370 financial institutions use its tools, which analyze 19 billion sessions a month and cover more than 760 million users on more than 1.8 billion devices.

ℹ️
These are attempts, not losses
The published changes measure detected attempts, not actual losses. An increase can reflect more criminal activity, better detection, or new institutions joining the sample. Comparing them with loss data calls for caution.

Fraud is shifting to payments customers approve

Digital banking fraud falls into two broad types. In account takeover, the fraudster gains control of an account and acts in the account holder’s place. In an authorized push payment scam, the account holder makes the payment, deceived about who is receiving it or what it is for. BioCatch’s numbers point to growth in the second type, where no authentication rule is broken.

FeatureAccount takeoverAuthorized push payment scam
Who initiates the paymentThe fraudster, without the account holder’s knowledgeThe account holder, under manipulation
AuthenticationBypassed, stolen, or hijackedPassed, since the customer is the one acting
Useful signalsUnfamiliar device, geolocation, time of dayTyping rhythm, hesitation, remote-assisted session
ResponseBlock the session, reset credentialsInterrupt the flow and question the customer
Two types of fraud, two lines of defense
Banknotes and a payment transaction
In an authorized push payment scam, the payment order is technically valid: the check has to target intent, not identity.

Location and login checks are losing their edge

Three findings show why these scams are hard to stop. Devices inside the US account for 83.9% of fraud attempts, which takes much of the value out of geolocation filters. About 70% of account takeover sessions happen after 5 p.m., when monitoring teams are thinner. And sessions using remote-access tools rose 45%: the scammer no longer needs to steal credentials, but watches and guides the victim, who does the work on their own device.

BioCatch’s US customers, which include three of the four largest banks by assets, reported $46 million in attempted investment fraud losses, $28 million in purchase scams, and $22 million in law enforcement and legal impersonation scams. “While impersonation scams were the most commonly reported scam type to the Federal Trade Commission last year, they were not the most costly,” said Gary Patterson, a fraud intelligence research analyst at BioCatch. Nationwide, the FBI estimated investment fraud losses at more than $8.6 billion in 2025.

⚠️
Vendor data and FBI estimates don’t compare
The $46 million, $28 million, and $22 million figures describe attempts seen across one vendor’s customer base. The $8.6 billion figure is a national estimate for a single category. The two differ in both scope and method.

Europe checks the payee name instead

The EU has taken a different route: payee verification. Since October 9, 2025, payment providers in the euro area must tell the payer whether the name entered matches the holder of the destination IBAN before a credit transfer goes out. The rule tackles authorized push payment scams with data rather than behavior, and it covers credit transfers only. Card payments and transactions made after a remote takeover of the device fall outside it.

The report comes as Visa absorbs BioCatch

August 3, 2026
Visa agrees to acquire BioCatch
The network announces an all-cash deal to buy the Israeli behavioral biometrics company for $2.4 billion.
August 12, 2026
BioCatch publishes its annual US report
The study covers 292 institutions over the period from June 2025 to May 2026.

Coming nine days after Visa announced the $2.4 billion acquisition, the report helps explain the deal. Visa wants signals it can read before a payment order even exists, at a stage where card authorization, its traditional territory, still sees nothing. But the numbers are attempts detected by a single vendor, not official statistics, and they should be treated with that caveat as a gauge of the US market.

Provenance

Published August 12, 2026

4 sources, 3 distinct domains

↗ BioCatch, U.S. Financial Institutions Report 130% Spike in Attempted Impersonation Scams · biocatch.com↗ FinTech Global, US impersonation scam attempts surge 130% in a year · fintech.global↗ BioCatch newsroom · biocatch.com↗ Visa Investor Relations, Visa to Acquire BioCatch · investor.visa.com
← All news