Visa says AI fraud is no longer a niche threat, it is the main event
AI fraud is shifting from an occasional headline to the defining risk in everyday payments, according to Visa’s Spring 2026 Biannual Threats Report. The card network’s message is blunt: criminals are increasingly targeting people rather than systems, and artificial intelligence is helping them do it faster, cheaper, and at much larger scale. The result is a fraud landscape where the “tell” signs that once helped consumers and bank staff spot a scam, bad spelling, clunky emails, awkward scripts, are disappearing.
Visa’s own data underlines why it is raising the alarm now. In a press release accompanying the report, Visa says it detected about $1 billion in scam transactions in the latter half of 2025, calling scams “the single largest category of consumer payment fraud”. That is not a small, contained problem. That is a systemic one, and it lands right in the middle of the payments ecosystem: banks, merchants, platforms, and customers who think they are authorising something legitimate.
Two separate pieces of coverage, from Payments Dive and American Banker, point to the same core shift. It is not just “more fraud”. It is different fraud: behavioural manipulation, accelerated attack cycles, and what Visa executives describe as adversaries operating at machine speed. And yes, Visa also says it is using AI defensively. But that is the point. This has become an arms race.
The specific development: Visa’s Spring 2026 Biannual Threats Report and the $1 billion scam signal
The immediate news event is the publication of Visa’s Spring 2026 Biannual Threats Report, released in May 2026. Visa frames the report around a paradox: some payment threats show signs of slowing, yet the most damaging consumer fraud category is growing and evolving because scammers are leaning into social engineering and AI automation.
In the Payments Dive coverage, Visa’s chief risk and client services officer Paul Fabara describes the problem as “behavioural manipulation, ecosystem fragmentation, and accelerated attack cycles enabled by AI”. That phrasing matters. It suggests the bottleneck is not only technical controls, it is the messy reality of modern payments: multiple channels, multiple providers, and a customer journey that can be hijacked with a convincing message and a sense of urgency.
American Banker adds more colour from Visa’s operational risk leadership. Michael Jabbara, senior vice president of Payment Ecosystem Risk and Control, argues that AI “dramatically lowered the barrier to entry for fraud”, letting bad actors automate and scale attacks with less technical expertise than before. He also warns that attack timelines are compressing sharply. In his words, ransomware timelines that once unfolded over days can now be “compressed into minutes”. That is a big deal because many fraud controls, and many organisational processes, still assume there is time to investigate.
The report also touches ransomware trends. Visa says global ransomware attacks jumped 26% from 2024 to 2025, while 23% of victims paid ransoms. Among those who paid, Visa reports that ransom payment size plunged 66% between July and September 2025 compared with the prior three months. Visa declined to provide additional detail on ransoms paid, according to Payments Dive, which is worth noting because it limits how far outsiders can validate the underlying distribution of those payments.
How AI fraud works in 2026: social engineering at scale, deepfakes, and agentic automation
Visa’s warning is not simply “watch out for phishing”. The more unsettling claim is that generative AI and agentic AI are industrialising scams that used to require time, skill, and a fair bit of luck. American Banker reports that generative AI is being used to create personalised phishing messages and deepfake audio or video to impersonate executives or family members. The goal is not always to “hack” a bank. Often it is to persuade a customer to authorise a payment that looks completely normal in the transaction logs.
That last point is central to Visa’s framing. Jabbara calls out what he sees as the most dangerous fraud: “the one that looks completely legitimate, because the customer is the one authorizing it”. This is where classic fraud detection runs into a wall. If the customer passes authentication and initiates the transfer, many systems treat it as a valid instruction. And if the scammer has used AI to mimic a trusted voice, write a convincing message, or fabricate supporting documents, the human decision point becomes the weakest link.
American Banker also quotes Jim Mortensen, strategic advisor for fraud and the anti money laundering practice group at Datos Insights, who says “fraudsters are deploying agentic AI offensively”. Mortensen’s description is stark: agentic systems can automate the full fraud lifecycle, from generating synthetic identities to uploading fabricated documents in real time, learning from failed attempts, and continuously refining attacks without human intervention. In other words, the scam does not just get repeated, it gets better every time it fails.
And then there is the simple reality that the old tells are fading. As Cornerstone Advisors director Lindsay Hooks notes in American Banker, traditional indicators like poor grammar are rapidly disappearing as attackers use AI to produce polished communications across email, websites, and messaging platforms. That is not exactly groundbreaking as a concept, but it is devastating in practice. Many consumer education campaigns still implicitly teach people to look for sloppy writing. AI makes “sloppy” optional.
Who is involved: Visa’s role, the wider payments ecosystem, and why banks are nervous
Visa sits in a particular position in global payments. It is not a bank, but it operates the network rails and risk systems that connect issuers, acquirers, merchants, and consumers. That gives it visibility across a huge volume of transactions and fraud patterns, and it also means its warnings carry weight. When Visa says scams are the top form of consumer payment fraud, it is speaking from network level detection and reporting, not a single institution’s casework.
The report also reflects a broader tension: financial institutions are rolling out new forms of AI for customer service, underwriting, operations, and fraud detection, while simultaneously worrying that the same technology is empowering criminals. American Banker notes that the “artificial intelligence wave in banking” is boosting fraud risk, with AI “playing on both sides of the battle”. That is not a rhetorical flourish. It is a strategic problem: the more digital and automated payments become, the more valuable it is for criminals to automate deception.
There are also signs of high level concern beyond Visa. American Banker reports that the CEOs of Bank of America, Citi, Goldman Sachs, Morgan Stanley, and Wells Fargo recently met with Anthropic to discuss Claude Mythos, an AI that detects security vulnerabilities in software but could also help crooks find vulnerabilities. The detail that matters here is not the product name, it is the dynamic: major banks are actively engaging AI labs about dual use risks. They are not treating this as a back office IT issue anymore.
Meanwhile, the payments industry’s own experts are increasingly blunt about the need to fight AI with AI. Payments Dive quotes Matt Vega, chief fraud strategist at Sardine, saying companies are in a situation where “you really need AI to fight AI”. That is a pragmatic view, and fair enough. But it also implies costs, complexity, and a skills gap, especially for smaller institutions and merchants that do not have large fraud teams.
What this means for payments and fraud teams: the AI vs AI arms race gets real
Visa’s report lands at a moment when many organisations are still catching up to the last wave of fraud evolution, account takeover, credential stuffing, mule networks, and platform based scams. The new twist is speed. Visa argues that “slow moving patterns and manual review are no match for threat actors using machines”. If a fraud operation can test and refine tactics in near real time, then static rules and periodic reviews become less useful. They are not wrong. A rule that gets tuned weekly is not much help against an adversary that iterates hourly.
Real time payments make the problem sharper. Mortensen warns in American Banker that instant payments compress the detection window to near zero, and Datos Insights research finds that 58% of financial crime leaders cite inadequate institutional detection capabilities for instant payments as a significant issue. The operational implication is uncomfortable: if money moves instantly, then prevention has to happen before authorisation, not after settlement. That pushes banks and payment providers toward behavioural analytics, device intelligence, and network level signals, which in turn raises questions about data sharing and privacy expectations.
There is also a strategic shift in what “fraud detection” even means. Mortensen says the question has moved from “Who is this customer?” to “What AI capabilities are being employed in this interaction, and what are their intentions?” That is a profound change. It suggests fraud teams may need to detect automation patterns, synthetic sessions, and agent behaviour, not just identity and transaction anomalies. And it implies new tooling, new expertise, and likely new partnerships across the ecosystem.
Visa’s own stance is that collaboration is essential. Fabara says addressing the shift toward people targeted scams requires “continuous innovation at the network level” and “close collaboration across banks, merchants, policymakers and the broader payments ecosystem”. That is the right direction, but it is also where things get messy. Collaboration sounds great until it runs into competitive dynamics, regulatory boundaries, and inconsistent technical standards. Ecosystem fragmentation, one of Fabara’s core points, is both a cause of the problem and a barrier to fixing it.
Historical context: from card skimming to authorised push payment scams, and why AI changes the economics
Payments fraud has always evolved with the technology of the day. Card skimming thrived when magnetic stripes were easy to copy. E commerce fraud surged as online card not present transactions became normal. Then EMV chip adoption pushed criminals toward other channels, including social engineering and account takeover. The pattern is consistent: when defences harden in one area, attackers pivot to the next weakest point.
Visa’s 2026 warning fits that historical arc, but with an important twist. AI does not just create a new channel, it changes the economics of fraud. Jabbara’s point about lowering the barrier to entry is key. If sophisticated phishing, document fabrication, and impersonation can be generated cheaply and quickly, then more criminals can participate, and they can run more experiments. That tends to increase overall attack volume and diversity, which makes detection harder because there are more “variants” to catch.
Another historical shift is the move from exploiting technical weaknesses to exploiting human trust. Visa’s language is explicit: criminals are targeting people rather than technology, using deception and urgency. That is not entirely new, scams have always existed, but AI makes them more believable and more personalised. A scam that references the right merchant, the right family detail, or the right corporate context is more likely to succeed. And AI makes that personalisation scalable.
Finally, ransomware trends provide a useful comparison point. Visa reports a 26% jump in global ransomware attacks from 2024 to 2025, but a relatively low payment rate of 23%. That suggests some organisations are learning, hardening, and refusing to pay. But scams are different. They are distributed, consumer facing, and often involve authorised transactions. There is no single corporate policy that stops them. The defence has to be layered across education, product design, and real time risk controls.
What This Means For You
For consumers, the uncomfortable takeaway is that “looks legit” is no longer a useful safety check. AI generated messages can be grammatically perfect, politely written, and tailored to the moment. So the practical habit shift is towards verification by a second channel. If a message claims to be from a bank, a delivery firm, a colleague, or even a family member, the safest move is to pause and verify using contact details found independently, not the ones provided in the message. That sounds basic, but it directly counters the urgency lever that scammers rely on.
For small businesses and finance teams, the risk is not only losing money, it is losing money quickly. Visa and Datos Insights both highlight compressed timelines. That means businesses should treat payment controls as a front end process, not a back office reconciliation task. Simple steps help: dual approval for new payees, call backs for bank detail changes, and tighter limits on instant transfers where possible. And if a supplier asks to change bank details, it should be verified using a known number, not an email reply chain that could be compromised.
For banks, fintechs, and merchants, Visa’s report is basically a warning about operating models. Manual review and static rules are increasingly outpaced by machine speed attacks. The implication is investment in real time detection, better customer warnings at the point of payment, and stronger collaboration on threat intelligence. It also means being honest with customers about authorised scams. If the customer is being manipulated into authorising the transfer, then the user experience, prompts, friction, and education at the moment of decision become part of fraud prevention, not an afterthought.
Closing thoughts: Visa’s warning is about trust, not just technology
Visa’s Spring 2026 Biannual Threats Report is not simply another “fraud is rising” bulletin. It is a statement that the centre of gravity has moved. Scams are now the largest category of consumer payment fraud in Visa’s reporting, with about $1 billion in scam transactions detected in the second half of 2025. And the mechanism is increasingly AI enabled social engineering, which is harder to spot, faster to execute, and easier to scale.
The industry response is also clear: AI will be used to fight AI, and network level collaboration will matter more than ever. But the hardest part is cultural, not technical. Payments work because people trust them. If AI makes deception cheap and convincing, then protecting trust becomes the real product. And that requires banks, networks, merchants, and policymakers to move at something closer to machine speed, without breaking the customer experience in the process. Not easy. But ignoring it is worse.
Visa’s executives are essentially saying the same thing in different ways: security measures are improving, but adversaries are changing the game. In 2026, that game is persuasion at scale. The sooner the ecosystem treats that as the primary threat model, the better.





