Why Payments Must Build for Fraud Rather than Wish it Away

UK payments fraud still costs close to £1.3 billion a year, even as banks stop more attempted fraud before any money moves, and criminals are now using artificial intelligence to scale their attacks.

Scott Dawson is CEO at DECTA UK

For one payments chief executive, the answer is not another round of controls aimed at an imagined zero, but the kind of adaptation thinking that climate policy has already been forced to adopt.

Scott Dawson is CEO at DECTA UK, part of DECTA, a global payment technology provider offering acquiring, issuing, processing, white label gateway and digital banking services. He has more than 20 years of experience in the payments industry and leads DECTA’s UK strategy, with a focus on growth and on supporting small and medium-sized businesses. In this contributed piece, he argues that payments firms should treat fraud as a standing condition to engineer around. The views expressed are his own.

Shortly after midday on 28 April 2025, the electricity grid serving Spain and Portugal collapsed. Within minutes, terminals in shops from Lisbon to Barcelona stopped talking to their acquirers, ATMs went blank, and across two countries cash briefly became the only thing that worked.

The instructive part of that afternoon was who carried on trading: some merchants had offline capability, backup power, a float in the till, and staff who had been told what to do when the screen goes dark. They kept taking money. Others had built an entire payment operation on an assumption that had held for the whole of their working lives, which is that the power stays on and the cloud is always overhead.

Britain too has been told, in unusually direct language, that its conditions have changed. The Climate Change Committee‘s latest assessment, A Well-Adapted UK, published in May 2026, concludes that the country was built for a climate that has already gone.

The instruction attached to that finding carries more weight than the finding. A further degree of warming is locked in whatever happens to emissions from here, so the Committee advises the UK to plan around roughly 2°C of warming by 2050, treating that number as a floor rather than a target.

This is a substantial change of frame, and it has gone through without much notice. For most of the past thirty years, the climate argument was an argument about prevention: how do we stop this happening. The Committee’s position is that prevention has run out of road for the next few decades, and that the useful question has become how we live with what is already on its way. Adaptation is where innovation now sits.

Why prevention eventually runs out of road

Payments should recognise the shape of that problem, because we have a version of it ourselves. Human beings are poor at heading off trouble we can watch approaching, and impressively good at absorbing it once it has landed.

UK Finance’s latest fraud report records losses of almost £1.3 billion across more than four million cases in a single year, which works out at something close to eight incidents a minute or £18.57 per UK resident. Volume is only half of it. Criminals have begun using artificial intelligence to industrialise the work, cloning voices, localising scripts across borders and reaching British victims at scale through global platforms. Those capabilities are now a permanent feature of the landscape.

These figures might look like a defeat, but I’d argue that they’re a reality. Over the same period, the banking sector stopped £1.68 billion of attempted fraud before any money moved. The effort is there and so is the investment, but what has changed is the opponent, which revises its methods faster than any single control can be rebuilt. UK Finance draws the conclusion that follows: the sector cannot go on being the only line of defence.

We’re familiar with the pattern. Strengthen authorised push payment controls and the pressure moves towards high volume, low value attacks on remote purchases. Close that route and it moves again. A prevention mindset treats each of those shifts as a breach to be sealed on the way to an imagined state of zero fraud. An adaptive mindset treats them as the ordinary weather of a live system and builds to absorb them.

Resilience is the product

Eliminating fraud altogether is about as realistic as reversing the warming already locked into the atmosphere. Managing the losses is entirely realistic, and it calls for a different discipline: layered controls, monitoring in real time, behavioural signals, and systems engineered to carry on trading while under attack instead of failing closed at first contact.

In practice, that means designing for the bad day instead of the good one. It means knowing which parts of the stack can fail without dragging the rest down with them, agreeing in advance what an acceptable level of loss looks like for each product, and being able to keep accepting payments when a provider, a network or a national grid stops behaving. Built properly, that capability is a commercial asset. Merchants remember which partners were still working on the afternoon that everything stopped.

Payments has already been handed its warnings. On 19 July 2022, the temperature in eastern England passed 40°C for the first time since records began, and cooling systems that had never been specified for that number quietly gave way. Shoppers saw it in the chillers and freezers at the supermarket, which simply cannot run above a certain temperature. Google and Oracle saw it in their London data centres, where parts of the estate were powered down to keep servers from overheating and a scattering of websites and services went dark alongside them. These were among the best resourced facilities in Britain. Their weakness was a design brief written for a climate that had since moved on.

There is a familiar instinct that mistakes refusal for seriousness: the argument that we should give up air conditioning as the planet heats, as though discomfort were itself a contribution. The same instinct in payments chases a zero fraud rate in place of building the machinery to withstand the fraud that is coming whether we like it or not. In both cases the posture feels principled while leaving you more exposed. The engineering that keeps a shop trading through a heatwave, or a merchant taking payment through a blackout, is the engineering that keeps a payments business ahead of a threat it will never fully remove.

None of this amounts to fatalism, and the Committee is careful on that point. Adaptation asks more of an organisation than prevention ever did, because it requires an honest account of the world as it is rather than the world you would prefer to still be operating in. Payments faces the same test. The threat environment has changed permanently, the tools that changed it are not going to be recalled, and the businesses that accept this early will handle fraud the way a well-adapted country handles its weather: as a standing condition to be engineered around, absorbed and outlasted.

The post Why Payments Must Build for Fraud Rather than Wish it Away appeared first on The Fintech Times.

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *