Fraud at the Speed of Payments: Can Your Organisation Keep Up?
29 / 07 / 2026
Fraud has changed. It no longer looks like a stolen card or a suspicious login from an unusual device. Today's fraud is quieter, more human, and far more effective — and the regulatory and technological landscape is racing to catch up. At our recent Worldline webinar, we explored three forces reshaping the payments fraud landscape: a new face of fraud, the upcoming European regulation, and the role of AI in defending against it. Here's what every bank should be paying attention to.
The New Face of Fraud
Not so long ago, fraud detection relied in fraudsters fingerprints: a card used in two countries in the same hour, a login from an unknown device, a payment clearly initiated by someone who wasn't the account holder. Traditional defences were built exactly for that kind of attacker, and they worked well. So fraudsters did what fraudsters always do: they adapted. If breaking into the account was becoming too hard, why not simply convince the account holder to do the work for them? When we asked webinar attendees which type of payment fraud was putting them under the most pressure today, impersonation scams and AI-powered social engineering came out on top - a clear sign of how quickly this new wave of fraud is spreading.
Take as an example, Sarah. She's 42, lives in Lyon, and has been with her bank for 12 years. She has a clean history, no fraud alerts, no unusual behaviour, exactly the kind of profile a risk model would classify as safe. One afternoon her phone rings,the caller ID shows her bank's real number. A calm voice explains her account is being drained and she must move her money to a safe account immediately. Fear does the rest. Sarah opens her app, logs in, enters the IBAN she's given, validates with her OTP, and sends €8,400. A couple of minutes, start to finish. No system was breached. To the bank, it looks like a perfectly authorised payment.
Sarah's story isn't an exception nowadays. And it raises the question everyone in the industry is now asking: when this happens, who pays? Until recently, the answer was almost always Sarah. The UK was the first to challenge that assumption: since October 2024, its mandatory APP (Authorised Push Payment) reimbursement scheme has led to 88% of claims reimbursed and £173m paid out by UK PSPs (Payment Service Provider) in less than a year, with the "gross negligence" safeguard proving to be the exception rather than the rule. Europe is about to follow, and that is where the story really begins.
The Regulatory Response: PSR and PSD3
Europe's answer to this new reality is the upcoming payments package: PSD3, covering licensing and supervision, and the PSR, harmonising operational rules across the Union. Publication is expected by the end of 2026, with full applicability in 2028. It may sound distant, but the changes reach deep into systems, customer journeys and liability models, and the runway is much shorter than it looks.
At the heart of the reform lies one simple but powerful idea: strong authentication no longer equals authorisation when the customer has been manipulated. Payers gain stronger protection in impersonation scams, meaning a case like Sarah's would now entitle her to a refund. Payer PSPs must refund first and recover later, supported by real-time monitoring and impersonation safeguards. And for the first time, payee PSPs are pulled into the chain, required to monitor incoming flows, run Verification of Payee, and take part in fraud data-sharing schemes such as FRIDA — or bear the liability themselves.
The reform also goes beyond banks. TSPs (Technical Service Providers) can be held responsible when authentication fails, and telcos and social media platforms — the very channels used to reach victims like Sarah — must remove fraudulent content and cooperate with PSPs. Fraud becomes, for the first time, a shared responsibility across the entire ecosystem. But sharing responsibility only reduces losses if every actor can actually detect fraud in real time. That is where regulation ends, and technology takes over.
The AI Dimension: Fighting Fraud at Machine Speed
If regulation decides who pays, technology increasingly decides whether anyone has to. And fraud patterns no longer stand still long enough for traditional defences to catch them. Modus operandi change weekly, fake merchant sites appear and vanish within hours, and AI-generated voices and messages have made convincing scams cheaper and easier than ever. Static defences are obsolete the moment they are deployed.
This is why the debate between rules and AI misses the point. Both are needed. Rules capture human expertise and stop known patterns instantly. AI detects the unknown, learns continuously, and exploits every field of data, not just the handful an analyst would focus on. Alone, each has its limits. Together, they cover what is known, what is suspected, and what has not yet been seen.
Worldline has been applying AI to fraud detection for over 15 years, and has taken this logic one step further with the Auto Rule Creator: an AI engine that continuously extracts new fraud patterns, converts them into rules, and pushes them into production automatically. Protection continues overnight, on weekends and during holidays — precisely when fraudsters count on defences to slow down. And crucially, it frees analysts to focus on the complex cases only human judgement can crack. Because in the end, technology alone does not stop fraud. The right platform, the right models and the right people do — which is exactly why Worldline delivers all three together, in a managed service model.
Key Takeaways
Fraud has shifted from a technical problem to a human one, regulation is finally rebalancing responsibility across the ecosystem, and only the smart combination of rules and AI can keep pace with attacks that evolve by the day. When we asked attendees what would help them most over the next 12 months, their priorities lined up with exactly these themes: preparing for PSR and PSD3 compliance, modernising fraud rules, and strengthening AI-based detection. Payments are instant, fraud is instant, and neither is slowing down. The banks that stay ahead will be the ones that treat prevention as a continuous journey.
- Explore the webinar insights in depth.
- See how Worldline Payment Fraud Management can help banks to stay ahead of fraud.