Fraud has never been cheaper or easier to commit. Fraud as a service and phishing as a service now sell ready-made attacks off the shelf, so an ordinary criminal can rent organised-crime capability without any skills of their own.
In episode #9 of Follow the Money, Pallavi Kapale, Senior Financial Crime Officer (2LOD) at Bank of China, and Salv’s Taavi Tamkivi describe a barrier to entry that has all but collapsed.
Inside financial institutions, though, the instinct runs the other way: we hesitate to share the very data that would stop it, and for good reason. Attackers collaborate freely; defenders hold back. The barrier to fighting back, both argue, isn’t the law or a lack of technology — it’s how confidently institutions use the rules and the data they already have.
Fraud has outgrown the department it started in
Fraud used to sit at the end of the process — a small team after KYC, working on a tick-box basis. That has changed. Fraud now accounts for around 45% of all financial crime in the UK, and, as Pallavi described, it has moved from an afterthought to a management-level strategy, backed by the UK fraud strategy and the FATF 2026–2028 Fraud Strategy.
The operating model has not caught up. Investigations, first-line fraud, and the beneficiary side still sit in separate boxes, each seeing only its own slice. Meanwhile the barrier to entry for criminals has collapsed. Fraud as a service and phishing as a service mean an ordinary criminal can now buy organised-crime capability at the click of a button. When the attackers are joined up and the defenders are not, the org chart is doing the fraudsters a favour.
Privacy is the new excuse, just like friction once was
The friction-versus-fraud debate has largely settled: healthy friction, in the right place, is accepted as useful. In its place a new blocker has appeared — privacy versus fraud — and it is being used the same way, as a reason not to act.
Most of the time, the privacy objection does not survive contact with the detail. To flag that a single transaction is probably fraudulent, a bank does not need to hand over a customer’s whole KYC profile. “You don’t even need to give the name of the customer,” Taavi noted. “You just need to refer to a transaction ID, or the IBAN, maybe the amount.” Some European data providers already treat an IBAN as shareable rather than sensitive; some banks still treat the same field as untouchable. The difference is interpretation, not law.
Pallavi made the point from lived experience. Before the pandemic she could call another bank about a mutual customer and ask a simple question — wages or benefits? — and start building a picture in two minutes. That was legal then. It is still legal now. What has changed is that the rules around it are clearer, with audit logging and four-eye checks. Those are extra steps, not a prohibition.
The infrastructure exists; the confidence is what’s new
The rails for compliant, encrypted, real-time collaboration exist. They have run in several countries for years, embedded in banks’ daily procedures. What has shifted recently is legal clarity. Estonia’s law from 1 July now states plainly that banks should exchange fraud intelligence and can slow or suspend an instant payment when fraud is suspected — following similar moves in Norway and France, and ahead of the EU Payment Services Regulation. One medium-sized EU country ran its entire tender in three months.
That clarity matters because it converts uncertainty into confidence. When a fraud team knows a concrete action — slowing a payment to buy time — is explicitly permitted, it is far more willing to automate real-time sharing rather than treat each case as a manual, one-off risk.
So what?
The honest starting point is internal. Most institutions cannot yet give their own crime fighters real-time access to the data they already hold, let alone data from the banks around them. Fix that first, and treat privacy as a design question rather than a veto. Otherwise the work simply gets displaced — close a mule in one bank and it reopens down the road, or the money moves cross-border, out of view. The collective network Pallavi predicted is no longer a someday idea. It is under construction, and the institutions that move now are the ones deciding to use the rules they already have.