search

LEMON BLOG

AI-Assisted Fraud Is No Longer Just Targeting Banks—It Is Targeting Their Customers

Artificial intelligence is changing cybercrime in a way that goes far beyond better phishing emails or more convincing scam messages. Attackers are increasingly using AI to plan, adapt and automate entire campaigns, while ordinary customers are becoming the easiest route into the financial system.

The threat is no longer limited to criminals trying to breach a bank's infrastructure directly. Instead, fraudsters are manipulating customers into approving payments themselves, handing over credentials or trusting fake voices and video calls that appear completely genuine.

For banks, this creates a difficult problem. A transaction may be properly authenticated, authorised by the customer and processed through legitimate banking channels—yet still be the result of psychological manipulation.

Agentic AI Is Beginning to Run Attacks on Its Own

A recent cyberattack known as "Jade Puffer" has been described as an example of an end-to-end intrusion orchestrated by agentic software.

Unlike a simple automated script, the AI system reportedly assessed targets, chose actions, documented its own reasoning and adjusted its approach when something failed.

In one example, the system encountered a failed login attempt, changed its parameters and found a working solution within 31 seconds.

This ability to adapt is what makes agentic AI particularly concerning. Traditional automation follows predefined instructions. Agentic systems can interpret results, decide what to try next and continue working toward an objective with far less human intervention.

That could allow attackers to scale operations that previously required skilled teams. Reconnaissance, credential testing, vulnerability exploitation and lateral movement may increasingly be handled by AI-driven tools capable of working around obstacles in real time.

Security teams are therefore facing a new reality: defending against automated attacks may eventually require equally adaptive defensive systems.

The Bigger Shift Is Happening Outside Bank Networks

Highly technical AI-driven intrusions attract attention, but the broader fraud problem is increasingly centred on customers rather than banking infrastructure.

Banks have spent years strengthening internal systems with encryption, multifactor authentication, transaction monitoring and layered security controls. Attacking those systems directly has become more difficult and expensive.

Customers, however, remain reachable through phone calls, messaging apps, social media, email and video conferencing.

Fraudsters do not always need to break through a bank's security when they can persuade the account holder to complete the transaction for them.

This is the defining feature of authorised push-payment fraud. The customer signs in using their genuine credentials, passes the bank's security checks and approves the transfer. Technically, the payment is authorised. In reality, the customer may have been deceived, threatened or emotionally manipulated.

Deepfake Scams Are Becoming Affordable

Deepfake technology was once associated with expensive, highly targeted attacks against wealthy individuals and large companies.

That is changing quickly.

Modern AI tools can generate convincing voices, faces and video content with far less time, skill and money than before. A fraudster can potentially recreate a person's appearance or speech using photographs, social media clips, old recordings and publicly available information.

This means attackers no longer need to reserve deepfake techniques for multimillion-dollar targets.

A criminal may impersonate:

The economics of impersonation have changed. When producing a convincing fake becomes cheap enough, fraudsters can use the technique against a much larger number of ordinary consumers.

Even Deceased People Can Be Impersonated

One of the more disturbing consequences of generative AI is the ability to recreate the voice or appearance of someone who has died.

Old family videos, voice messages and photographs may provide enough material for a model to imitate that person.

A scammer could use such material to target grieving relatives, create emotional pressure or revive a trusted identity that the victim would never expect to be used fraudulently.

This shows why traditional advice such as "recognise the caller's voice" is no longer sufficient.

A familiar voice, face or communication style should not be treated as absolute proof of identity. Families and organisations may need agreed verification methods, such as calling back through a known number or using a private phrase that has never been shared online.

Awareness Does Not Always Change Behaviour

One of the biggest challenges in fraud prevention is the gap between knowing that scams exist and recognising one while it is happening.

Research involving Malaysian university students illustrates this problem clearly.

Participants were presented with job offers containing warning signs linked to scams and money-mule recruitment. Despite many describing themselves as aware of fraud and money laundering, a large majority still selected the suspicious opportunities.

This suggests that general awareness is not enough.

People may know that scams exist but still believe a particular offer is genuine because it appears professional, arrives at the right moment or promises something they urgently need.

Scammers deliberately exploit emotions such as:

Once emotion takes over, logical warning signs become easier to ignore.

Authorised Payments Are Often Psychologically Engineered

When customers approve fraudulent transfers, it is tempting to say that they should have known better.

That view overlooks how carefully modern scams are constructed.

Fraudsters may spend days or weeks building trust. They may know the victim's name, employer, relatives, recent purchases or bank. AI can help them personalise the story and respond convincingly to questions.

By the time the payment is requested, the victim may believe they are protecting their account, completing a legitimate business transaction or helping someone they trust.

The transaction is authorised only in the technical sense. The decision behind it has been manipulated.

This distinction matters because banking controls are traditionally designed to detect unauthorised access. A genuine customer signing in from their normal device and approving a transfer may look completely legitimate to the system.

Targeted Education Can Make a Difference

Although awareness alone may fail, practical education can still improve outcomes.

When people are taught how specific scam patterns work, what warning signs mean and what consequences follow, their ability to reject fraudulent offers improves significantly.

Effective education should go beyond reminders such as "do not share your OTP" or "be careful online."

Customers need realistic examples showing:

Repeated scenario-based learning is more useful than one-time awareness campaigns because it prepares people to recognise the manipulation while it is happening.

Too Many Warnings Can Create Prompt Fatigue

Banks have responded to rising scam losses by adding more confirmation screens, alerts and transaction warnings.

These controls can help, but they also introduce another problem: customers become accustomed to clicking through them.

When every transfer produces several generic messages, users begin treating the warnings as routine obstacles rather than meaningful security checks.

This is similar to alert fatigue in cybersecurity operations. When people see too many low-value warnings, they are less likely to notice the important one.

A message saying "Are you sure you want to continue?" may have little effect if the customer has already seen it hundreds of times.

Better warnings should be contextual. For example:

"You are sending RM8,000 to a new recipient whose account was created recently. Scammers may ask you to transfer money to protect your account. A bank employee will never instruct you to move funds to a safe account."

A specific warning is more likely to interrupt the scammer's narrative.

Banks Need Intelligence Behind the Scenes

Customer prompts cannot carry the entire responsibility for preventing fraud.

Banks need stronger intelligence operating in the background, including information shared across the financial sector.

A single transaction may look ordinary to the sending bank. However, the receiving account may already have unusual activity, links to other mule accounts or a history of rapid withdrawals.

Industry-wide intelligence can help institutions identify patterns that would remain invisible if each bank looked only at its own data.

Useful signals may include:

Stopping scams increasingly requires cooperation between the sending bank, receiving bank, telecommunications providers, digital platforms and law-enforcement agencies.

Compensation Rules Change Bank Behaviour

Some markets have introduced stronger reimbursement requirements for victims of authorised payment scams.

The intention is to push financial institutions to invest more heavily in prevention rather than placing the entire loss on customers.

In certain cases, losses may also be divided between the bank that sent the payment and the bank that received it.

This creates an incentive for both sides to act.

The sending bank must identify when a customer is being manipulated. The receiving bank must detect when an account is being used to collect and move stolen money.

However, reimbursement policies are complex. They must protect genuine victims without creating opportunities for abuse or encouraging careless behaviour.

Banks need clear standards for negligence, customer cooperation, investigation and exceptional circumstances.

AI Inside Banks Must Be Auditable

As banks deploy their own AI systems, trust and governance become essential.

Any AI used for fraud detection, customer service, credit decisions or transaction monitoring should be auditable. The bank must know where the model is being used, what data it considers and whether its actions comply with internal policy and regulation.

It must also be trackable.

There should be a record showing how information moved through the system, what triggered the decision and what action followed.

Explainability is equally important. A bank cannot simply reject a customer, freeze an account or escalate a transaction and then claim that the algorithm made the decision.

Human reviewers, auditors and regulators need a meaningful explanation of the factors involved.

Banks Cannot Hide Behind the Algorithm

AI can process more transactions than a human team and detect patterns that would otherwise be missed. However, it can also make mistakes, reflect poor-quality data or create unfair outcomes.

A model may incorrectly classify a legitimate transaction as fraud or fail to detect a carefully designed scam.

Human accountability must remain in place.

That means defining:

Governance cannot be added after deployment. It must be designed into the system from the beginning.

Future Cryptographic Threats Are Already Influencing Crime

Banks are also preparing for the long-term possibility that quantum computing could weaken widely used encryption methods.

The immediate concern is not necessarily that criminals can break modern banking encryption today. It is that they may be collecting encrypted information now with the intention of decrypting it later.

This approach is often described as harvest now, decrypt later.

Threat actors may store stolen personal data, biometric information, encrypted communications and cryptographic material for future use.

If more powerful computing eventually makes some forms of encryption vulnerable, information stolen years earlier could become readable.

Banks must therefore consider the future lifespan of sensitive data and begin planning for post-quantum cryptography before current protections become obsolete.

Biometric Data Creates a Special Risk

Passwords can be changed. Fingerprints and facial characteristics cannot.

As biometric authentication becomes more common, protecting biometric templates becomes increasingly important.

If biometric information is stolen or reconstructed using AI, the customer cannot simply replace their face or fingerprint.

Banks should avoid storing raw biometric images whenever possible and use secure templates, hardware-backed protection and strong liveness detection.

Deepfake-resistant authentication will also become more important as synthetic faces and voices improve.

A system should not rely on appearance alone. Device trust, behavioural patterns, transaction context and cryptographic verification may all be needed.

Human Judgement Still Has a Critical Role

AI can respond instantly, process large amounts of data and work continuously. What it cannot always provide is patience, empathy and human judgement.

One reported banking case involved a fraud specialist spending three hours explaining a scam to a customer who remained convinced that the fraudulent story was genuine.

An automated system may have repeated the same warning several times before ending the interaction. A human adviser could listen, adapt the explanation and gradually rebuild the customer's understanding.

This matters because scam victims are not always lacking information. They may be emotionally trapped inside the fraudster's narrative.

Breaking that belief can require time, trust and compassion.

AI Should Support Fraud Teams, Not Replace Them

The most effective model is likely to combine automation with skilled human intervention.

AI can:

Human specialists can then handle cases requiring judgement, persuasion or emotional support.

The objective is not to remove people from fraud prevention. It is to direct their attention to the cases where they can make the greatest difference.

What Malaysian Banks Should Do Next

Malaysian financial institutions need a fraud strategy built for customer manipulation rather than only account compromise.

This includes improving cross-bank intelligence, strengthening mule-account detection and using transaction context to identify unusual behaviour before money leaves the customer's control.

Banks should also expand scenario-based education and make it easier for customers to reach a trained fraud specialist quickly.

Deepfake verification procedures should be introduced for high-risk interactions. Staff should be trained not to rely solely on voice or video, especially when approving urgent transfers or changes to payment information.

AI governance should also mature alongside deployment. Every model used in a high-impact decision should remain auditable, explainable and subject to human oversight.

The Customer Experience Cannot Be Ignored

Fraud controls that are too aggressive can damage legitimate banking activity.

Customers may become frustrated if ordinary transactions are repeatedly delayed, blocked or challenged.

Banks must therefore balance security with usability.

Risk-based controls are more effective than applying the same friction to every transaction. A transfer to a familiar beneficiary may require minimal intervention, while a large payment to a new account with suspicious characteristics may trigger stronger checks.

The goal is to introduce friction at the moment it is most valuable, not make every customer struggle through unnecessary warnings.

Final Thoughts

AI-assisted fraud is changing the centre of attack.

Instead of focusing only on breaching banks, criminals are increasingly targeting the people who use them. Deepfakes, personalised manipulation and agentic systems are making scams faster, cheaper and more convincing.

Banks cannot solve this problem by adding more generic warnings or expecting customers to recognise every new technique.

They need shared intelligence, adaptive detection, stronger mule-account controls, practical education and rapid access to human specialists.

At the same time, banks must ensure their own AI systems are auditable, trackable and explainable.

The future of fraud prevention will not be purely automated or purely human. It will depend on using AI to detect speed and scale while preserving human judgement for the moments when trust, empathy and persuasion matter most.

Spain Defeat Argentina to Win the FIFA World Cup 2...
Hospital at Home Could Help Malaysia Deliver Acute...

Related Posts

 

Comments

No comments made yet. Be the first to submit a comment
Monday, 20 July 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection