When The Customer Is Real But The Relationship Is Fraudulent

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Some of the most difficult fraud does not start by defeating the bank's technology. It succeeds by operating inside assumptions that the technology was never designed to test.

Shahen Minasyan is CTO at Twin Peaks Inc., with 15+ years in banking technology, AI, digital transformation and enterprise leadership.

GettyU.S. banks have never had more tools for establishing who is on the other side of a financial interaction. Identity verification has improved, multifactor authentication is common, device intelligence is more sophisticated and biometrics and behavioral analytics are increasingly part of the security stack. Yet fraud losses continue to rise.​

The FBI’s 2025 Internet Crime Report recorded more than 1 million complaints and $20.9 billion in reported losses, up 26% from 2024. The Federal Reserve’s “Report on the Economic Well-Being of U.S. Households 2025“ found that 20% of adults experienced financial fraud or scams in 2025 and an estimated $100 billion in non-credit-card fraud, with “$56 billion borne directly by consumers.” The OCC’s Spring 2026 Semiannual Risk Perspective likewise said, “banks continue to face challenges from both the elevated levels and rising sophistication of fraud and scams.​”

Those numbers do not mean identity controls are failing. In my experience in banking technology, some of the harder fraud problems begin after those controls have done exactly what they were designed to do.

The customer can be real. The identification can be genuine. The credentials can be valid. The customer can successfully authenticate and even initiate the activity. The risk is that the institution answers “Is this really our customer?” correctly and then treats that answer as evidence of legitimate intent.

Banks make several different risk decisions during a customer relationship. KYC and onboarding establish identity and eligibility. Authentication establishes whether the person interacting with the institution can demonstrate control of the account or credentials. Transaction monitoring evaluates whether an event looks unusual. Fraud and credit systems assess other forms of exposure.

Each control can be functioning correctly while the relationship tells a different story.​

Authentication is evidence of identity or control, not proof of intent. A transaction initiated by the authorized customer can still be part of activity the institution would not consider trustworthy if it could see the full context. Federal Reserve fraud-classification frameworks recognize this distinction. The FraudClassifier model distinguishes between payments initiated by authorized and unauthorized parties and explicitly recognizes situations in which an authorized party was manipulated or acted fraudulently. Federal Reserve Financial Services has also noted that scams can lead to authorized transactions made by the authorized account owner.​

For technology leaders, the architectural implication is significant. Trust cannot be a permanent status assigned during onboarding and refreshed only when a password, device or biometric challenge succeeds. It has to evolve as the relationship evolves.

The bank already sees relevant information over the customer lifecycle: authentication history, device changes, payment behavior, product usage, account relationships, service interactions, disputes and risk events. The problem is that those signals often live in different systems, are owned by different teams and are evaluated at different times.​

Federal regulators have acknowledged this fragmentation. In a 2025 joint request for information on payments fraud, the Federal Reserve, FDIC and OCC reported that losses associated with fraud involving payment apps or services, bank transfers or payments, wire transfers and checks rose approximately 271% between 2020 and 2024, from $806 million to $2.99 billion. The agencies also described payments-fraud data collection as “incomplete, non-standardized, ad hoc and fragmented,” specifically noting gaps involving authorized payments that are part of scams or fraud.​

That point deserves attention. An authorized payment is not automatically low risk. Authentication tells us who performed an action. It does not necessarily tell us whether the relationship or purpose behind that action remains legitimate.

This is where I see a more useful role for AI. Banks do not simply need another model producing another isolated fraud score. They need better correlation across weak signals. A change in behavior may be innocuous on its own. A new relationship may be legitimate. An unusual transaction may have a reasonable explanation. But several individually reasonable events, viewed together and over time, can tell an unreasonable story.

AI, graph analytics and entity resolution can help assemble that story, but the objective should be relationship intelligence, not alert volume. The question should move from “Is this transaction suspicious?” to “Has the total behavior of this customer relationship changed enough that we should reassess trust?”

Better correlation is still not enough. A bank can identify a meaningful risk pattern and lose if the information does not reach someone with authority to act before the outcome becomes irreversible.

Fraud architecture is therefore not only a data and AI problem. It is also an operating-model problem. Institutions need a defined path from signal to correlation, risk decision, intervention, investigation and feedback. If signals are available but disconnected, there is a data problem. If the picture is understood but nobody owns the next decision, there is an ownership problem. If the information arrives too late, there is a workflow problem.

One useful metric for banking leaders may be time to intervention: the time between the first meaningful combination of risk signals and an action that can change the outcome. Improving that interval may matter as much as improving another model’s accuracy.

The industry should continue investing in identity verification, authentication and biometrics. These controls solve important problems. But they should not be confused with a complete determination of trust.

The broader question for CIOs, CTOs, CISOs, fraud executives and risk leaders is whether their architecture can detect when a verified relationship is no longer behaving as the relationship they originally approved.

That requires connecting identity, authentication, behavior and relationship context across the customer lifecycle, then giving the resulting intelligence a clear path to action.

Some of the most difficult fraud does not start by defeating the bank’s technology. It succeeds by operating inside assumptions that the technology was never designed to test.

Sometimes the customer is real, the authentication is valid and the control worked exactly as designed.

The relationship can still be fraudulent.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/24/when-the-customer-is-real-but-the-relationship-is-fraudulent/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Crime