Authorised scams expose gaps in bank fraud controls
Banks must detect legitimate-looking scam payments whilst balancing customer friction, compliance costs, and security investment.
Thailand’s tighter digital banking security requirements are exposing a harder fraud problem for banks as scammers increasingly persuade customers to authorise payments themselves.
Mary Yan, Senior Director Analyst at Gartner, said the decline in money-draining app cases does not mean fraud has disappeared. Instead, criminals are shifting towards bank transfers, e-wallets, and card payments that customers approve after being deceived.
“The money has not disappeared, but the fraud has evolved,” she said.
The shift complicates fraud detection because transactions can appear legitimate even when customers are acting under a scammer’s direction. They may use their own devices, pass security checks, and authorise transfers themselves.
Yan said know-your-customer checks can verify an account holder’s identity but do not necessarily establish who is influencing the customer or the ultimate purpose of a payment.
Banks may therefore need to assess transaction behaviour, payment context, recipient risk, and unusual changes in customer activity alongside identity verification.
The challenge is strengthening controls without making legitimate digital payments unnecessarily difficult.
Yan said additional verification is more acceptable for higher-risk activity, including large payments, new recipients, or first-time devices. Applying the same authentication to routine transactions could create unnecessary friction and discourage digital banking use.
Warnings must also be targeted, as repeated or unclear alerts could cause customers to ignore them.
For smaller financial institutions, stronger controls can create additional costs. Yan said cloud services, modular tools, and managed services could allow banks, lenders, e-wallet providers, and fintech companies to introduce fraud controls progressively according to their risks and resources.
Regulators can meanwhile set minimum security and risk-management requirements whilst allowing institutions flexibility in implementation.
“The aim is to ensure the same level of protection, not to require every firm to use identical technology at the same implementation costs,” Yan said.
Commentary
Stablecoin payments are going mainstream. Hong Kong and APAC are showing how
Why digital assets are set to become mainstream in APAC
Bitcoin’s latest hacks expose where trust really sits in Asia
Singapore's next payments opportunity
DIFC's reforms open new doors for Asian businesses: Is yours ready?
Why Asia’s private wealth industry requires a new era of governance
APAC has mastered domestic payments. The next challenge is connecting them.
Why fragmented communications are becoming a hidden governance risk for Asia Pacific banks