Khurram Ahmed, Global Product Consultant, Fraud Management, BPC
In the 2006 thriller Firewall, Harrison Ford plays a bank security specialist forced to exploit the institution’s own systems and facilitate a fraudulent transfer from inside its trusted environment. At the time, the scenario felt like a cinematic warning about what could happen when criminals combined technical access, coercion and insider knowledge. In 2026, that combination no longer belongs only to fiction.
Modern fraud takes many forms. It may begin with phishing, account takeover, synthetic identities, authorised push-payment scams, card-not-present attacks, mule accounts or deepfake impersonation. It may also originate inside the institution through employee misconduct, privilege abuse, collusion or the misuse of legitimate credentials. The more authentic an operation appears, the less time a bank usually has to recognise and stop it. A transaction initiated from a familiar device, approved with valid credentials or supported by an employee’s access can move through systems with fewer warning signals than an obvious external attack.
This is why fraud management can no longer rely mainly on investigating incidents after funds have moved. Banks must recognise suspicious behaviour before it becomes a confirmed loss, connecting transaction data with devices, customer history, account relationships, authentication activity and internal access patterns. As the saying goes, the best defence is often a good offence. In modern fraud prevention, that means anticipating how attackers may act, identifying vulnerabilities before they are exploited and intervening while the payment or session is still active.
Fraud controls were traditionally reactive: criminals introduced a method, losses appeared, analysts investigated and another rule was added. That cycle is now too slow. In 2026, prediction and prevention offer greater protection than reaction, reimbursement and the difficult work of rebuilding customer trust after the damage is done.
Fraud is accelerating across Africa
The financial pressure is already substantial. Estimates cited by BioCatch and Juniper Research suggest that investment in fraud detection and prevention could reach USD 39.1 billion by 2030, while fraud losses may rise to USD 58.3 billion. Other projections place annual card-fraud losses above USD 41 billion by the end of the decade.
Africa’s figures make the threat more immediate. INTERPOL’s 2026 African Cyberthreat Assessment found that reported cybercrime-related losses more than doubled from USD 192 million in 2024 to USD 484 million in 2025. It estimates that cybercrime caused at least USD 5 billion in direct economic damage across the continent in 2025. More than half of reported cybercrime involved AI, and 72% of surveyed countries reported the presence of scam centres.
National banking data shows how rapidly this threat reaches institutions and customers. South African banks recorded almost 100 000 digital-banking fraud incidents in 2024, an 86% annual increase, while gross losses rose 74% to R1.888 billion. Banking apps accounted for 65.3% of incidents, and SABRIC found that social engineering, rather than the technical compromise of banking platforms, featured in all reported digital-banking cases.
Nigeria lost N52.26 billion to digital-payment fraud in 2024, including one incident valued at N31.1 billion. Losses declined to N25.85 billion in 2025, but the earlier spike demonstrates how one major control failure can overwhelm otherwise improving figures. In Ghana, fraud cases across banks, specialised deposit-taking institutions and payment providers rose 48% to 24,778 in 2025. Seventy-five bank and SDI employees were dismissed for fraud-related activity, including 44 cases connected to cash theft.
Operational failures can be exploited just as quickly as externally engineered attacks. According to TechCabal in 2024, technical problems during a major data migration at KCB Group allowed customers to withdraw more than their available balances, resulting in excess withdrawals of approximately KES 1 billion, or USD 7.7 million, between 11 and 31 October. The bank reportedly restricted the affected accounts and began seeking recovery of the funds.
Why reactive controls keep falling behind
Reactive systems work best when fraud repeats itself. Analysts investigate a confirmed incident, translate its characteristics into a rule and wait for the pattern to return. Modern attackers simply change the device, beneficiary, location, transaction value or payment channel, leaving the institution defending against the previous version of the attack.
Fragmented monitoring makes the gap wider. Card activity may sit in one platform, mobile banking in another and instant payments in a third. A newly registered device may appear harmless. So might a profile change or first-time beneficiary. When followed by an unusual transfer, however, the sequence may indicate account takeover. How can a bank recognise that relationship when each system holds only one part of the evidence?
Manual investigation creates another bottleneck. Analysts face expanding alert queues, repetitive case reviews and constant pressure to revise rules. Delays give criminals more time to move funds, while poorly calibrated controls create false positives and disrupt legitimate customers. The institution is pushed towards the wrong choice: tolerate more fraud or introduce more friction.
Authentication alone is also insufficient. In authorised push-payment fraud, customers may pass every technical check while acting under deception. Mule accounts can behave normally until activated, while insider fraud may originate behind valid credentials. Authentication remains essential, but it must operate alongside behavioural, device and relationship intelligence.
What proactive fraud management changes
A proactive platform does not wait for another confirmed loss before improving. It evaluates historical and live data continuously, identifies weaknesses and recommends changes as customer behaviour and criminal methods evolve.
This requires a unified view of financial and non-financial events. Transactions should be assessed alongside device signals, authentication activity, location, profile amendments, beneficiary history and typical customer behaviour. Rules remain necessary for known scenarios, but machine-learning models can identify anomalies before analysts have formalised a new rule.
Behavioural profiles establish normal activity for customers, accounts, cards, merchants, devices and beneficiaries. Link analysis then reveals relationships that isolated alerts cannot show, including shared devices, coordinated accounts, mule networks and suspicious money flows. Automation must remain governed: systems can recommend rules, model adjustments and investigation priorities, while analysts approve significant changes and retain accountability.
From fraud detection to adaptive defence
As fraudsters use AI to scale attacks, financial institutions need technology capable of learning and responding at comparable speed. Self-adapting platforms are therefore becoming an operational layer for investigation, decisioning and continuous improvement rather than another isolated security application.
BPC SmartVista Fraud Management provides enterprise-wide monitoring across digital banking, instant payments, issuing, acquiring, e-commerce, core banking, wallets and account-based payments. It combines configurable rules, dynamic thresholds, geographic and velocity checks, behavioural profiles, AI and ML scoring, analytics, reporting and case management. Historical transactions and confirmed fraud can be used to recommend detection rules, while configurable workflows and automated notifications support consistent action.
Its language-model-based AI assistant can summarise cases, compare patterns across investigations, identify anomalies and generate prioritisation insights. This is particularly relevant to mule networks, coordinated account takeover and evolving authorised-payment scams. Automating rule recommendations and routine case analysis reduces the exposure created by manual updates and investigation delays. Analysts remain in control, but can concentrate more of their time on governance, complex investigations and fraud strategy.
Proactive protection in practice
Several institutions have already replaced channel-specific controls with broader, real-time defence. In Mauritania, BIMBANK connected cards, core banking and digital channels, giving analysts a consolidated risk view with adaptive scoring, immediate alerts and case management while meeting local data-sovereignty requirements.
FirstBank Nigeria extended enterprise-grade protection across transactional services, mobile, its super app, e-wallet, USSD and checkout journeys. BPC reports that the bank has blocked more than one billion fraud attempts across its channels and prevented over USD 6 million in losses. The result demonstrates why omnichannel visibility matters: fraud does not follow a bank’s internal product boundaries.
The same principle applies at national scale. EthSwitch now processes more than one million EthioPay-IPS transactions in a single day, with daily value exceeding ETB 5 billion. Enterprise-grade fraud management covers interoperability transactions across the shared national environment, helping protect participating banks, payment providers, businesses and customers as one connected ecosystem rather than as isolated institutions.
Outside Africa, Samba Bank Pakistan brought cards and digital channels into a real-time framework using adaptive scoring, biometric checks and immediate alerts. Malaysia’s Co-opbank Pertama combined behavioural profiling, machine learning and centralised case management, using historical fraud data to refine detection.
Takeaways
Fraud prevention must now learn as quickly as fraud changes. Real-time visibility, behavioural intelligence, relationship analysis and governed automation allow financial institutions to intervene before suspicious activity becomes a loss. Those that remain dependent on disconnected rules and retrospective investigation may still detect fraud—but increasingly, they will detect it too late.

