Finance · Fintech
Authorized Fraud Outpaces Bot Attacks as Asia's Fastest-Growing Payment Risk
LexisNexis data shows login attacks surged 89% year-on-year, while financial institutions grapple with customers who approve transactions under scammer direction

KEY TAKEAWAYS
- ·Login attacks on existing accounts surged 89% year-on-year, with automated bot attacks up 59%, according to LexisNexis analysis of 116.1 billion transactions.
- ·Fraudsters now train bots to mimic human behavior and target browser channels as financial institutions concentrate defenses on mobile apps.
- ·Banks face a speed disadvantage, constrained by governance and regulatory frameworks while scammers iterate tactics within days and exploit customers who approve payments under direction.
The Paradox of Perfect Authentication
A payment clears every security layer. The login credentials match, the device is recognized, and the account holder taps confirm. The transaction is genuine in every technical sense, except for one detail: the person authorizing it is following instructions from a fraudster on the phone.
LexisNexis Risk Solutions analyzed 116.1 billion transactions for its 2026 Global Cybercrime Report and found that automated bot attacks climbed 59% year-on-year. More striking, login attacks on existing accounts jumped 89%, pointing to a tactical pivot. Fraudsters are no longer only targeting account creation or the initial breach. They are exploiting the trust layer that sits above authentication, the moment when a customer decides to act.
Interpol estimated global fraud losses at $442 billion in 2025, placing financial fraud among the top five global crime threats. Asia, with its rapid fintech adoption and mobile-first banking infrastructure, sits at the center of that pressure.
Bots Now Mimic Behavior, Not Just Credentials
Christopher Foye, Senior Director of Platforms at LexisNexis Risk Solutions, described how automated attacks have evolved beyond crude scripts. A few years ago, bot traffic was easy to identify. Now, attackers train bots to replicate human interaction patterns closely enough to evade behavioral defenses.
Fraud no longer concentrates at a single point in the customer journey. Account openings, logins, password resets, and payment initiation all present attack surfaces. Foye noted that as organizations fortified mobile apps, fraudsters shifted attention back to browser-based channels, which often receive less scrutiny and are easier to target with AI-driven tools.
The rise of agentic commerce, where AI agents conduct transactions on behalf of users, adds another layer of complexity. Attackers are beginning to simulate broader customer workflows, not just isolated actions, making detection harder without adding friction that drives legitimate users away.
Vertical-Specific Baselines Are the New Threshold
Eduardo de Abreu, Chief Product Officer of EBANX and CEO of EBANX Singapore, works with merchants across gaming, e-commerce, ride-hailing, and SaaS. He explained that a single fraud threshold cannot serve all verticals. What looks like a bot attack in a SaaS context may be standard behavior on a gaming platform during a product launch.
EBANX consolidates more than 100 data points into a unified behavioral view shared across merchants, payment processors, acquirers, and issuers. The goal is alignment: every party in the transaction chain holds the same understanding of expected activity and can adjust controls without degrading conversion rates.
De Abreu emphasized that friction translates directly into lost revenue in e-commerce, where checkout flows are optimized down to the click. Effective fraud prevention requires agreement on what normal looks like in each vertical, then setting thresholds that reflect that baseline.
Regulatory Lag in a Fast-Iteration Threat Environment
ChunHou Kok, Group General Counsel at DCS Group, highlighted the speed asymmetry between fraudsters and financial institutions. Scammers can test new tactics, discard failures, and iterate within a day. Banks operate under governance frameworks and risk assessment requirements that slow response times.
The Monetary Authority of Singapore issued draft guidelines on AI risk management late last year. Those guidelines distinguish between lower-risk applications, such as data aggregation and analysis, and higher-risk use cases, including AI embedded in transaction monitoring. Institutions deploying AI in deterministic controls face stricter oversight and cannot simply let models run unsupervised.
Liability further constrains speed. Banks have a duty to freeze suspicious accounts but also owe customers clear explanations. Kok noted that infrastructure for agentic payments is under development, with Visa and Mastercard piloting trusted agent-initiated transactions in Singapore. The regulatory framework, however, remains incomplete.
The Human Link Remains the Weakest
Khushwant Singh, Group Chief Risk and Credit Officer at NTT DATA Payment Services, pointed to a recent case in which a finance employee's compromised phone allowed a fraudster to send a WhatsApp message to an authorized signatory. The payment cleared, and a substantial sum left the company.
Singh argued that no system can survive a single clicked link. Advanced behavioral analytics and authentication layers matter less if the human on the other end of the transaction is deceived. Fraudsters target customers with thin digital footprints, including those new to a bank and older individuals less familiar with digital threats.
Banks are responding with adaptive authentication, including prompts that request PIN details in a different format before releasing high-risk payments. Singh credited AI-driven behavioral tools with progress but described the contest as ongoing. When a transaction falls outside a customer's usual pattern, the institution must intervene, balancing security with user experience.
Trust and Speed in Tension
Asia's fintech infrastructure has enabled rapid financial inclusion and mobile payment adoption. That same infrastructure now serves as the battlefield for a fraud arms race in which the attacker's speed of iteration consistently outpaces institutional response time.
Authentication can confirm who pressed the button. It cannot confirm that the person understood what they were approving. That gap, between technical verification and informed consent, is where billions in losses accumulate each year.
RELATED STORIES
Spot something wrong? Email editor@briefasia.com. We log every correction publicly.



