Fraud as a service outpaces banks stuck in silos

fraud

Fraud has never been cheaper or easier to commit. Fraud-as-a-service and phishing-as-a-service now sell ready-made attacks off the shelf, letting an ordinary criminal rent organised-crime capability without any skills of their own.

In episode nine of Follow the Money, Bank of China senior financial crime officer (2LOD) Pallavi Kapale and Salv CEO Taavi Tamkivi described a barrier to entry that has all but collapsed.

Inside financial institutions, though, the instinct runs the other way: banks hesitate to share the very data that would stop it. Attackers collaborate freely; defenders hold back. Both argue the obstacle to fighting fraud is not the law or a lack of technology, but how confidently institutions use the rules and data they already have.

Fraud used to sit at the end of the process, a small team working on a tick-box basis after KYC. That has changed. Fraud now accounts for around 45% of all financial crime in the UK, moving from an afterthought to a management-level strategy backed by the UK fraud strategy and the FATF 2026–2028 Fraud Strategy.

The operating model has not caught up, with investigations, first-line fraud and beneficiary teams still working in separate silos, each seeing only its own slice.

A new blocker, privacy versus fraud, is now used the same way friction once was, as a reason not to act. Most of the time it does not survive contact with the detail. Salv CEO Taavi Tamkivi said, “You don’t even need to give the name of the customer,” adding, “You just need to refer to a transaction ID, or the IBAN, maybe the amount.”

Some European data providers already treat an IBAN as shareable rather than sensitive; some banks still treat the same field as untouchable.

The rails for compliant, encrypted, real-time collaboration already exist, embedded in banks’ daily procedures across several countries. What has shifted is legal clarity.

Estonia’s law from 1 July now states plainly that banks should exchange fraud intelligence and can slow or suspend an instant payment when fraud is suspected, following similar moves in Norway and France, and ahead of the EU Payment Services Regulation. One medium-sized EU country ran its entire tender in three months.

The honest starting point is internal: most institutions cannot yet give their own crime fighters real-time access to the data they already hold, let alone data from banks around them. Fix that first, and treat privacy as a design question rather than a veto. Otherwise the work simply gets displaced elsewhere.

The collective network is no longer a someday idea; it is under construction, and the institutions that move now are the ones deciding to use the rules they already have.

Read the full Salv post here. 

Stay ahead of the institutions redrawing the rules of fraud prevention. Subscribe to the FinTech Global newsletter for the strategic intelligence and early insight that decision-makers rely on.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.