By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FingerprintPublished September 19, 2025

TL;DR: Banks face rising pressure from peer-to-peer payment scams and account takeover fraud, while regulators demand faster controls and customers expect seamless authentication; Fingerprint says 71% of financial institutions now use AI and machine learning in fraud prevention. The real challenge is not adding more friction, but improving signal quality so fraud models can distinguish legitimate customers from fraudsters in real time.


At a glance

What this is: This is an analysis of why banks are struggling to balance P2P scam prevention, account takeover defence, biometrics, and AI-driven fraud detection while preserving customer experience.

Why it matters: It matters because fraud teams, IAM leads, and security architects need stronger identity verification and device signals without creating so much friction that legitimate payment flows break down.

By the numbers:

👉 Read Fingerprint's analysis of P2P scams, account takeovers, and biometric fraud controls


Context

Banks now sit at the intersection of fraud, identity verification, and customer experience. P2P scams, account takeover, and mule-account activity all exploit the same operational weakness: institutions must decide in real time whether a transaction or login is legitimate, often with incomplete signals and very little tolerance for delay.

The identity problem is broader than authentication alone. Stronger biometrics, device intelligence, and risk-based controls can reduce fraud, but only if they are paired with governance that understands when a customer session is normal, when it has been hijacked, and when automation is attempting to imitate legitimate behaviour.


Key questions

Q: How should banks reduce P2P scam losses without slowing down legitimate payments?

A: Banks should use adaptive decisioning that evaluates device reputation, session context, and transaction behaviour before authorising a payment. The goal is not to add friction everywhere, but to reserve stronger checks for unusual or high-risk activity. That approach reduces scam losses while preserving the fast experience customers expect in normal transactions.

Q: Why do bank impersonation scams still succeed even when MFA is enabled?

A: They succeed when the attacker captures the password and the one-time code in the same live phishing session, then uses weak recovery or reset flows to keep control. MFA that can be relayed or replayed does not stop a well-timed impersonation attack.

Q: What do teams get wrong about device intelligence in fraud prevention?

A: They often treat it as a standalone detector instead of an enrichment layer. Device intelligence is most useful when it helps confirm or weaken confidence in other signals such as velocity, geography, and account history. On its own, it rarely proves fraud; in combination, it improves decision quality.

Q: Who is accountable when payment scams occur on customer-friendly rails like P2P?

A: Accountability usually sits across fraud, payments, risk, and product teams, because the control failures span authentication, transaction monitoring, and customer remediation. Regulators increasingly expect banks to prove that they can detect scams in real time and apply proportionate controls without degrading legitimate access.


Technical breakdown

Why P2P fraud is hard to stop without real-time identity signals

Peer-to-peer payment fraud moves quickly because the attacker’s window is short and the victim often notices only after funds have left the account. In account takeover cases, stolen credentials may still look authentic to the bank unless the institution can test the session, device, and behavioural context against trusted signals. That is why identity proofing alone is insufficient. A bank needs layered decisioning that can distinguish a known customer using a normal device from a fraudster operating with valid credentials but abnormal context.

Practical implication: banks need real-time contextual scoring before authorising high-risk transfers, not only stronger login prompts.

How biometrics and device intelligence change the authentication model

Biometrics can improve the user experience because they bind access to a person’s physical traits, while device intelligence binds activity to a recognisable browser or endpoint pattern. Used together, they make it harder for fraudsters to replay stolen credentials at scale. The limitation is that neither control is perfect on its own. Biometrics need fallback and recovery processes, and device signals can be spoofed or masked. The governance challenge is to combine both into risk-based flows that raise assurance when the transaction is unusual and stay quiet when the customer behaviour is normal.

Practical implication: define step-up rules that combine biometrics with device reputation and transaction context.

Why AI fraud models depend on signal quality, not just model sophistication

AI and machine learning can improve fraud detection, but only when the training and decision data are timely, consistent, and tied to actual user behaviour. If banks feed models with noisy, delayed, or incomplete signals, the models will overfit on weak patterns and miss fast-changing scam tactics. High-latency detection is especially dangerous in P2P environments, where milliseconds matter. The technical issue is not that AI fails by design, but that it inherits the quality of the underlying identity and device telemetry.

Practical implication: invest in low-latency identity telemetry before expecting fraud models to deliver better outcomes.


Threat narrative

Attacker objective: The attacker’s objective is to monetise stolen access quickly by moving funds through apparently legitimate payment activity before detection or reversal.

  1. Entry begins when fraudsters obtain valid customer credentials through breach data, phishing, or other account compromise methods and attempt to log in through a normal-looking session.
  2. Escalation occurs when the attacker uses that authenticated access to move money, create mule accounts, or run payment scams that resemble legitimate customer activity.
  3. Impact lands when funds are transferred out before the account holder or bank can intervene, leaving the institution to absorb losses, disputes, and trust damage.

NHI Mgmt Group analysis

Fraud prevention is now an identity governance problem, not only a detection problem. P2P scams and account takeovers succeed when banks cannot separate legitimate customer activity from adversarial mimicry fast enough. That makes identity assurance, device context, and transaction governance part of the same control plane. For practitioners, the question is no longer whether to add more checks, but how to govern which signals deserve trust in each payment flow.

Persistent device intelligence is becoming a practical control for reducing false trust. Banks cannot rely on cookies or login state alone because fraudsters routinely clear, switch, or mask those indicators. A stable device identifier gives fraud teams a way to correlate behaviour across sessions and catch shared-device abuse, credential replay, and mule-account operations. The governance implication is that banks need an explicit model for signal confidence, not just more telemetry.

Biometric assurance must be paired with recovery and exception handling. Face and fingerprint authentication can raise assurance, but they also introduce failure modes around enrollment, fallback, and account recovery. If those paths are weak, attackers will target them instead of the primary biometric check. For banks, this means the true control boundary is the full identity lifecycle, not the biometric prompt alone.

AI-driven fraud detection is only as strong as the identity data feeding it. Models that learn from delayed or noisy signals cannot keep pace with scam velocity in payment environments. This creates a signal-quality gap that banks need to close with better device, session, and behavioural context. The practitioner takeaway is to treat data provenance and latency as fraud controls, not just analytics concerns.

Context-aware authentication is the right response to friction pressure. Blanket MFA is too blunt for high-velocity payment channels, but removing friction entirely raises fraud exposure. The better pattern is adaptive authentication that increases challenge only when the customer, device, or transaction context shifts in ways that merit scrutiny. Teams should therefore govern thresholds, exemptions, and escalation paths as carefully as they govern the authentication methods themselves.

What this signals

Banks that modernise fraud controls now need to think in terms of identity confidence rather than single-point authentication. The pressure is moving toward governance of signal quality, exception handling, and decision latency, especially where customer experience depends on instant authorisation.

Signal trust gap: the operational gap between having telemetry and being able to trust it fast enough to make a payment decision. Banks should expect more convergence between fraud teams, IAM teams, and product owners as this gap becomes a customer-impacting control issue.

As banks expand biometrics, device intelligence, and AI scoring, they should align those controls to NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls rather than treating fraud tooling as a separate silo.


For practitioners

  • Implement real-time payment risk scoring Score every P2P transfer using session, device, and behavioural context before release, and route only high-risk events into stronger step-up controls.
  • Bind authentication to stable device intelligence Use persistent device identifiers to link repeated logins, shared devices, and masked-browser activity so fraud teams can spot credential replay and mule-account behaviour.
  • Harden biometric fallback and recovery paths Review enrollment, reset, and recovery processes for biometric authentication so account recovery does not become the easiest path for takeover fraud.
  • Tune AI models around signal latency Measure how long it takes fraud telemetry to reach decisioning systems, then reduce latency where delayed signals are causing missed scams or false declines.
  • Govern authentication exemptions centrally Track where friction is waived for speed or conversion, and make those exceptions visible to fraud, IAM, and product teams so risk is not hidden in local workflows.

Key takeaways

  • P2P scams and account takeovers expose a control gap between identity assurance and transaction governance.
  • The scale problem is not just fraud volume, but the speed at which legitimate-looking activity can move money before detection.
  • Banks should combine biometrics, device intelligence, and AI scoring into a single adaptive risk model rather than relying on blunt MFA alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Authentication and access control are central to preventing account takeover and scam payments.
NIST SP 800-53 Rev 5IA-2Identity verification and authentication underpin the bank's ability to distinguish legitimate customers.
NIST SP 800-63SP 800-63BBiometric and authenticator assurance issues align with digital identity and authentication guidance.
GDPRArt.32Biometric and identity data used for fraud prevention require security and governance controls.

Map fraud-critical authentication paths to PR.AC-4 and tighten step-up rules around high-risk transactions.


Key terms

  • Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.
  • Device Intelligence: Device intelligence is the practice of interpreting signals from a device to assess whether a session or transaction is likely legitimate. It goes beyond fingerprinting by combining device context with behavioural, identity, and payment evidence to support a risk decision.
  • Risk-Based Authentication: An access model that changes verification requirements based on the estimated risk of the request. It combines identity assurance, device posture, application sensitivity, and contextual signals to decide whether to allow, block, or step up verification before access is granted.
  • Money Mule Account: A money mule account is an account used to receive and move stolen funds on behalf of a fraud network. Mule accounts help disguise the origin of illicit transfers, making them a central target for fraud teams trying to disrupt payment scams before the money is laundered onward.

What's in the full article

Fingerprint's full article covers the operational detail this post intentionally leaves for the source:

  • How its visitor ID and device intelligence approach works across browsers, cookie resets, and private browsing
  • Why banks use persistent device identifiers alongside existing fraud platforms to improve detection accuracy
  • How low-latency device signals support real-time P2P decisioning in high-velocity payment flows
  • What the article says about balancing checkout experience, false declines, and fraud controls

👉 Fingerprint's full article covers device intelligence, biometric authentication, and AI fraud model considerations in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle controls. It gives security practitioners a practical way to connect identity assurance to broader access and risk programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org