HomeFeaturedNo Phishing Link. No Suspicious Email. Just a Request.

No Phishing Link. No Suspicious Email. Just a Request.

Every morning, a CFO somewhere approves a wire transfer that empties their company’s account.

Everything looked right, the email, the direct request, the tone of voice even the urgency felt familiar. A voice memo confirmed it, and it sounded exactly like the CEO. The approval chain was followed to the letter with no alerts fired. 

The fraud happened before the bank ever saw the transaction.

That is the defining shift in financial crime right now. The attacker did not break in. They did not need to. They just asked, convincingly enough, and the authorized person said yes.

Fraud Has Moved Upstream

It is no longer primarily about stolen credentials or bypassed systems. It is about persuasion, socially engineered at scale. Authorized push payment (APP) fraud, where victims initiate the transfer themselves, is rising sharply. The numbers put this into perspective: in the UK alone, losses from authorised push payment (APP) scams, where victims are tricked into transferring money directly to fraudsters, climbed 12% in the first half of 2025, with investment scams surging 55% year-on-year. Globally, APP scam losses across six major real-time payment markets (the US, UK, India, Brazil, Australia, and the UAE) are forecast to reach $7.6 billion by 2028, according to ACI Worldwide’s Scamscope report, and that figure represents just one category of fraud, across six countries.

Last chance: Get your tickets for Stockholm Fintech Week March 19

The technology driving this is no longer experimental. With as little as three seconds of audio harvested from a LinkedIn video, criminals can clone an executive’s voice with 85% accuracy. In 2024, the Financial Times reported that a finance worker at Arup authorized 15 transactions totalling $25 million after joining a video call where every face and every voice was artificially generated.

“Customers are manipulated into initiating transfers themselves and often do not realize they are part of a fraudulent scheme until the funds are irretrievable,” says Marco Gomes, Global Sales and Marketing lead at FraudAverse.

Traditional fraud controls were built to detect unauthorized access. They are increasingly unfit for a world where the authorized user is the one being deceived.

“Customers are
manipulated into
initiating transfers
themselves and often do
not realize they are part
of a fraudulent scheme
until the funds are
irretrievable.”
Marco Gomes
Global Sales and Marketing lead at
FraudAverse

A Governance Gap that Must be Addressed

Here is the uncomfortable structural reality. Banks are regulated. Criminal networks are not. Financial institutions run on governance cycles. Budget approvals, vendor reviews, compliance sign-offs, regulatory alignment. All necessary. All time consuming. Fraud networks operate on none of those timelines. They iterate, test, and deploy at the pace of a startup with zero oversight.

“By the time banks have secured budgets, completed vendor reviews, and aligned with regulatory requirements, fraudsters have already built and deployed their next attack. They do not operate under governance committees or compliance cycles.”  Malkit Chana, Global Solutions Consultant, Finastra

This is the gap that the Finastra and FraudAverse partnership was specifically designed to close. Rather than running a lengthy procurement cycle before seeing value, institutions get an accelerated path: start with a single channel such as Swift, prove the solution works, and expand without rebuilding anything. In a market where the cost of waiting is measured in unrecoverable losses, speed to value is critical.

Thirty Milliseconds

Payments infrastructure is getting faster, and that changes everything about when fraud can actually be caught. In Europe, the SEPA Instant Payments Regulation now requires banks and payment firms to complete euro transfers in under 10 seconds, around the clock, every day of the year. This means the window to detect a fraudulent payment before the money moves has effectively closed.

Real-time settlement is becoming the global standard. Cross-border interoperability is advancing. Stablecoins, CBDCs, and tokenized assets are moving from strategic conversations to operational reality. Each of these developments genuinely benefits customers at the expense of shrinings the detection window.

Gomes is direct about what that means in practice. “Systems need to respond within 30 milliseconds. That is the operational baseline of instant payment infrastructure. Once a payment clears and moves through interconnected networks, recovery becomes exponentially harder. The FraudAverse engine was built from the ground up for this constraint, connected directly into Finastra’s payment flow so the fraud decision is made before the transaction progresses” he stresses.

Siloed Controls Are Not a Solution

Most institutions still monitor risk in fragments. Card fraud in one environment. Instant payments in another. Cross-border flows somewhere else. Think about what that means in practice: a fraud pattern spanning two channels is completely invisible to a system that only looks at one.

“The landscape is not becoming simpler; it is becoming more complex. As complexity increases, so do the potential vulnerabilities embedded within the system.” Malkit Chana

Last chance: Get your tickets for Stockholm Fintech Week March 19

The Finastra and FraudAverse approach was built on a simple principle: a customer should never need separate fraud silos for each payment type. Finastra’s infrastructure spans Swift, domestic rails, and cross-border channels, giving FraudAverse’s detection a consistent pathway across all of them. Customers start in one place, prove the solution delivers, and extend it using the same setup, with message processing and fraud detection scaling independently without impacting one another.

Rules Cannot Catch What Looks Intentional

Rule-based detection looks for anomalies: unusual access patterns, authentication failures, thresholds being broken. It does not cope well with socially engineered transactions, because those transactions often look completely normal. A corporate treasury moves large sums internationally every week. A new beneficiary might be a legitimate acquisition. No rule flags it.

What catches it, is behavioral context built over time.

“We create and extract features in real time, store these features as behavioral profiles, and compare individual transactions against those profiles instantaneously.”  Marco Gomes

FraudAverse maintains in-memory profiles tracking not just individual accounts, but networks of beneficiaries. When a payment routes toward a cluster linked to suspicious activity elsewhere on the platform, the system recognizes it, even on first encounter. Finastra’s deployment across thousands of institutions is what makes this possible. That cross-institutional data becomes the foundation on which the AI models sharpen continuously, something no single institution building controls in isolation could replicate.

“The same tools AI is being
used for by fraudsters,
cloning a voice to request
a payment, those are the
same tools we are going
to be using to combat it.”
Malkit Chana
Global Solutions Consultant, Finastra

AI on Both Sides of the Fight

Deepfake attacks against businesses surged 3,000% in 2023. Voice cloning fraud rose 680% in a single year. Synthetic voice fraud attempts in banking jumped 149%, with over 10% of banks reporting deepfake losses exceeding $1 million per incident.

“The same tools AI is being used for by fraudsters, cloning a voice to request a payment, those are the same tools we are going to be using to combat it.”  Malkit Chana

For the FraudAverse, Finastra paratnership, this means giving institutions the flexibility to deploy AI models rapidly, including models their own data science teams have already built. In highly digital markets like the Nordics, where transaction volumes are high and the behavioral data trail is deep, that capability translates directly into faster and more accurate detection.

This Is the Simple Version

Chana’s closing point deserves to land without softening. Where the industry is today is considerably simpler than where it is heading.

Stablecoins at scale. Interoperable real-time rails spanning multiple jurisdictions. Autonomous agents initiating transactions without human review. Each new layer introduces vulnerabilities and complexities that current fraud prevention frameworks were not designed to handle. Gomes frames the FraudAverse position as asset agnostic: because Finastra has already standardized across payment rails, FraudAverse can focus entirely on detecting fraud for each asset type, whether stablecoin, CBDC, or traditional Swift transaction, without rebuilding infrastructure each time.

Last chance: Get your tickets for Stockholm Fintech Week March 19

Horizon scanning, continuously evaluating emerging payment models to identify vulnerabilities before they are exploited, is not a future commitment. It is what the partnership is already doing.

The daily CFO scenario is a pattern, and it is growing. Authorized deception is increasing. Payment velocity is rising. AI is bringng the cost of sophisticated fraud toward zero.

The question is not whether the industry has fraud controls, but whether they were designed to get ahead of criminal behavior as opposed to simply log the damage after the funds have gone. The window for intervention sits earlier in the process flow, before settlement, before the chain disperses the funds beyond retrieval.

That is where the work is being done.

Prevention must be real time. Detection must be contextual. Visibility must reach across every channel. The payments ecosystem is not slowing down, and neither are the people looking to exploit it.

NFM Publishing Team
NFM Publishing Team
Got a Nordic fintech story to share? We're all ears! At NFM, we're all about embracing the latest trends, innovations, and industry buzz ? Send us your PR, news stories, or anything that's rocking the Nordic fintech scene at hey@nordicfintechmagazine.com. Let's amplify your voice and think bold together! ? Stay tuned for mind-blowing articles, exclusive interviews, and thought leadership that'll keep you on the edge of your seat. Join us as we shape the future of fintech in the Nordic region.