Digital payments, instant lending and app-based banking have been the growth engine of financial services for a decade. Fraud has grown with them, and in 2025 and 2026 it crossed a line. Losses are now large enough to show up in national statistics, and regulators in India, the UK and Europe are moving more of the bill onto banks and payment firms. For a fintech or a bank, fraud controls have become part of the product, and a cost that decides margins.
The loss curve
The FBI's Internet Crime Complaint Center received more than a million complaints in 2025, close to 3,000 a day, with reported losses of US$20.9 billion. That is 26% more than in 2024 and about five times the 2020 figure. Over six years, reported losses add up to more than US$71 billion, and these are only the crimes people chose to report.
Reported cybercrime losses in the United States
US$ billion, complaints to the FBI's Internet Crime Complaint Center
Investment fraud, much of it involving cryptocurrency, was the costliest category at US$8.65 billion. Business email compromise cost US$3.05 billion and tech-support scams US$2.1 billion. People over 60 lodged about 201,000 complaints and lost US$7.75 billion, more than a third of the total.
Costliest fraud types in the US, 2025
US$ billion, reported losses
India: scale brings exposure
India's digital payments boom, which we looked at in our note on a decade of UPI, has a fraud counterpart. The Ministry of Home Affairs told Parliament that Indians lost about ₹22,846 crore to cyber fraud in 2024, three times the ₹7,465 crore of 2023, across 36.4 lakh complaints. The government's fraud reporting system stopped more than ₹5,489 crore from leaving victims' accounts that year.
Reported cyber fraud losses in India
₹ crore, calendar years
Inside the banking system, the Reserve Bank of India's 2025–26 annual report shows a different picture: the number of reported bank frauds fell 57% to 10,114, but the amount involved rose 46% to ₹48,021 crore, and about 85% of that related to loans rather than payments. Fewer, larger cases point to fraud in credit decisions as much as at the payment screen.
Regulators are moving the bill
The common thread in recent regulation is that the institution, not the customer, carries more of the loss when controls fail.
- October 2024 · United Kingdom. Mandatory reimbursement for authorised push-payment scams, up to £85,000 per claim, with the cost split equally between the sending and receiving payment firms.
- January 2025 · European Union. The Digital Operational Resilience Act applies to banks, insurers, payment firms and their critical technology suppliers, with rules on incident reporting, testing and third-party risk.
- April 2026 · India. RBI's directions on authenticating digital payments take effect: two factors for every transaction, at least one of them dynamic, with risk-based checks on top, and issuers must fully compensate customers for losses caused by non-compliance.
- October 2026 · India. Card issuers must have validation in place for non-recurring cross-border card-not-present transactions.
Where the opportunity sits
Fraud and identity technology is the most direct beneficiary: device binding, behavioural signals, real-time transaction scoring and shared intelligence between institutions.
High-growth digital payment markets, India and Southeast Asia in particular, are where volumes, new users and therefore exposure are rising fastest, and where new authentication rules create a compliance deadline that budgets cannot ignore.
Older customers in mature markets are where losses per victim are highest. Products and services that protect them, from banks, telecom operators and insurers, are an underserved line.
What this means for leaders
- Put fraud on the P&L. Reimbursement rules turn fraud from a customer problem into a direct cost. It should be forecast, owned and managed like credit losses.
- Design controls into the product. Friction placed in the right moments protects conversion better than blanket checks. That is a product decision, not just a risk one.
- Watch the credit book as well as the payment rail. In India the largest frauds by value sit in lending, where underwriting and monitoring matter more than authentication.
- Share intelligence. Fraud moves between institutions faster than any one of them can see. Industry data-sharing and government reporting systems are worth the integration effort.
In payments, growth and fraud ride the same rails. The firms that price in the second are the ones that keep the first.
Sources
- Federal Bureau of Investigation, Internet Crime Complaint Center: 2025 Internet Crime Report (April 2026) and earlier annual reports. ic3.gov
- Ministry of Home Affairs, Government of India: reply in the Lok Sabha on cyber fraud losses (2025). mha.gov.in
- Reserve Bank of India: Annual Report 2025–26 (May 2026). rbi.org.in
- Reserve Bank of India: Authentication Mechanisms for Digital Payment Transactions Directions, 2025. rbi.org.in
- Payment Systems Regulator (UK): Authorised push payment scams reimbursement requirement. psr.org.uk
- European Insurance and Occupational Pensions Authority: Digital Operational Resilience Act (DORA). eiopa.europa.eu
Figures are as published by the sources above at the time of writing. Forecasts and company guidance are labelled as such and will change.