Banking Fraud in the UK: 2026 Trends, Risks and What AML Leaders Need to Know
Banking fraud is no longer a narrow payments problem. It has become a broader financial crime challenge spanning customer identity, account takeover, social engineering, digital platforms, payment infrastructure and money laundering. The latest Banking fraud research briefing from the House of Commons Library, published on 29 July 2026, shows both the scale of the threat and the growing expectations placed on financial institutions to prevent, detect and disrupt fraud.
For AML compliance leaders, the message is clear: fraud controls and AML controls can no longer operate in isolation. Fraud proceeds can quickly enter accounts, move across institutions and jurisdictions, and become criminal property requiring intervention through the wider financial crime framework.
Banking fraud has reached a £1.28 billion scale
UK Finance estimates that criminals stole £1.28 billion through banking fraud and scams in 2025. Of this, £703 million was unauthorised fraud and £576 million was authorised fraud, including Authorised Push Payment (APP) scams.
The distinction is important.
Unauthorised fraud occurs when a criminal conducts a transaction without the account holder’s authorisation, often using stolen card details, compromised accounts or other credentials. Authorised fraud, particularly APP fraud, occurs when the victim is manipulated into sending money to an account controlled by a criminal. Common APP scam types include investment, purchase, impersonation and romance scams.
The scale is also visible in government statistics. The Crime Survey for England and Wales estimated 2.7 million bank and credit account fraud incidents in the year ending December 2025, a 15% increase over the previous year. That equates to 56 incidents per 1,000 adults aged 16 or over. Banking and other fraud accounted for more than 45% of crimes against individuals, while around one in 14 adults experienced some type of fraud during the period.
The government’s broader estimate puts the societal cost of fraud at at least £14.4 billion in 2023–24, including financial losses, victim support, recovery, investigation and prosecution.
The numbers reveal two different fraud problems
The 2025 data shows that unauthorised and authorised fraud require different control strategies.
| Fraud category | 2025 losses | Share of £1.28bn |
|---|---|---|
| Unauthorised fraud | £703m | ~55% |
| Authorised fraud / APP | £576m | ~45% |
| Total | £1.28bn | 100% |
The largest unauthorised category was remote purchase fraud at £423.5 million. Remote banking fraud contributed another £104 million, including £53 million through internet banking and £44 million through mobile banking.
Meanwhile, APP fraud losses increased 19%, from £484 million in 2024 to £576 million in 2025. The number of APP cases increased from 231,000 to 248,000.
Investment scams were particularly significant, generating £221.5 million in losses, up from £158 million in 2024. Investment scams alone therefore represented almost 39% of APP losses in 2025. Purchase scams accounted for £118 million, followed by advance-fee scams at £58 million and impersonation of police or bank staff at £55.5 million.
For AML teams, these figures demonstrate why transaction monitoring based solely on historical customer behaviour is insufficient. The risk may emerge from the origin of a payment, the beneficiary, the customer’s digital behaviour, social-engineering indicators or the relationship between multiple accounts.
Fraud is increasingly becoming an AML problem
The Commons Library places banking fraud within the wider economic crime landscape alongside money laundering, bribery and sanctions evasion.
This creates a critical compliance intersection. Fraud generates criminal proceeds; those proceeds can then be layered through bank accounts, moved through payment networks or transferred to other jurisdictions.
The UK’s legal framework already reflects this connection. Under the Proceeds of Crime Act 2002, financial institutions must submit Suspicious Activity Reports (SARs) when they suspect money laundering, including the possession or use of proceeds of fraud. Banks can also stop payment instructions where they believe criminal property is involved. The Money Laundering Regulations require customer due diligence and enhanced due diligence for higher-risk customers, while the Payment Services Regulations require strong customer authentication.
However, the effectiveness of the SAR regime remains an important concern. The briefing notes that historically the low threshold for filing SARs contributed to high volumes of low-quality reports. In 2023–24, SARs involving a Defence Against Money Laundering (DAML) prevented £240 million from reaching suspected criminals, demonstrating their value, but DAMLs represent only a small proportion of all SARs.
This highlights a key priority for AML leaders: better intelligence is more valuable than simply generating more alerts.
Technology is changing both fraud and fraud prevention
The UK’s 2026–29 Fraud Strategy identifies several trends that should be on every financial crime leader’s risk agenda.
Organised crime groups increasingly view fraud as a low-risk, high-reward activity. Generative AI, deepfakes, voice cloning and large language models are making fraud more sophisticated and credible. More than two-thirds of fraud cases have an international element, while technology is increasing the scale, speed and scope of criminal activity.
For financial institutions, this means fraud detection needs to move beyond static rules.
A modern fraud and AML framework should combine:
Customer and beneficial-owner risk intelligence
Transaction and behavioural monitoring
Device and digital identity signals
Beneficiary and account-level risk
Network and relationship analysis
Adverse media and external intelligence
Real-time screening and intervention
Cross-channel case investigation
High-quality SAR generation
The objective is not simply to identify suspicious transactions after they occur. It is to identify the network, behaviour and context that make a transaction suspicious before funds leave the institution.
The UK is giving banks more tools to intervene
Regulatory changes are increasingly supporting proactive intervention.
Confirmation of Payee (CoP) provides a name-checking mechanism that warns customers when the payee name does not match the account details. Following regulatory expansion, CoP coverage reached 99% of Faster Payments transactions.
Payment service providers were also given more time to investigate suspected fraud. Since October 2024, banks and other PSPs can delay certain suspicious payments for up to four business days, compared with one business day previously. The change recognised that complex fraud cases often cannot be adequately assessed within a single day.
Mandatory APP reimbursement represents another major shift. Since October 2024, PSPs have been required to reimburse eligible victims for APP fraud losses of up to £85,000 per fraud, subject to defined exceptions.
The first 15 months produced encouraging results: 88% of APP scam losses were reimbursed, compared with 65% under the voluntary CRM code in 2024, although the briefing cautions that the figures are not directly comparable. The first year recorded 269,000 claims, while only 3% were rejected because customers had not taken sufficient care.
An independent review published in July 2026 estimated that APP fraud losses fell 21%, equivalent to £73 million annually, following the reimbursement requirement. It also estimated additional costs of £44–£56 million per year for banks and PSPs. UK Finance disputed the direction of the trend, noting that its own data showed APP fraud increasing.
For compliance leaders, the lesson is not simply about reimbursement. Financial incentives are increasingly being linked to the effectiveness of fraud prevention.
Intelligence sharing is becoming a competitive advantage
The financial sector is already investing in collaborative fraud prevention.
The Banking Protocol rapid-response scheme, which trains bank staff to identify customers who may be falling victim to scams, reportedly prevented £59 million of fraud in 2025. Industry collaboration with law enforcement and intelligence-sharing initiatives saved the sector and its customers an estimated £273 million in 2025, up from £65 million in 2024.
At the national level, the government’s Fraud Strategy 2026–29 proposes a public-private Online Crime Centre designed to facilitate data sharing and coordinated interventions against online fraud.
This reinforces an important direction for AML programmes: isolated institutional intelligence has limited value when criminal networks operate across institutions and borders.
The next priority: stop fraud before it reaches the bank
A major weakness in the current ecosystem is that financial institutions can bear the cost even when fraud originates elsewhere.
The briefing notes that social media platforms and telecommunications providers are increasingly important because criminals use them to identify, contact, and manipulate victims. The Online Safety Act requires social media companies to reduce the risk of their services being used for illegal activity, including fraud. Telecom providers must also block certain spoofed international calls displaying UK landline numbers.
A July 2026 review recommended extending corporate fraud-prevention liability to online platforms whose infrastructure facilitates fraud and proposed an anti-fraud levy on digital and communications infrastructure providers. The objective is to address a system in which banks currently carry significant reimbursement costs while platforms hosting fraudulent content may avoid direct liability.
What AML compliance leaders should do next
The banking fraud landscape suggests five priorities for financial crime programmes:
Connect fraud and AML intelligence rather than treating them as separate risk domains.
Prioritise real-time detection for suspicious payments, beneficiaries and account behaviour.
Move from alert volumes to intelligence quality, particularly for SAR and transaction-monitoring workflows.
Use network analysis to identify linked accounts, mule activity and interconnected fraud patterns.
Build collaborative intelligence capabilities that can incorporate external data, law-enforcement information and emerging threat indicators.
The scale of the challenge is significant: £1.28 billion stolen in one year, 2.7 million bank and credit account fraud incidents, and a broader societal cost of at least £14.4 billion.
But the most important shift is strategic. Banking fraud is moving from a transaction-level problem to a data, identity, behavioural and network-risk problem.
For AML compliance leaders, the future of fraud prevention will therefore depend not only on stronger rules but also on connecting fragmented intelligence quickly enough to identify criminal behaviour before it becomes irreversible financial crime.
Source: Banking Fraud Report
Please read about our product: Dragnet Alpha
Click here to book a free demo
- #AML
- #AntiMoneyLaundering
- #FinancialCrime
- #Compliance
- #RiskManagement
- #KYC
- #TransactionMonitoring
- #FinancialIntelligence
- #FraudPrevention
- #RegTech