Hello Fraud Fighters!
Two reports dropped this past week putting a price tag on sophisticated identity fraud: it now costs 100x less to run than it did a few years ago. Elsewhere: Visa really wants to know what your fingers are doing (to the tune of $2.4 billion), a judge told Zelle its $1 billion fraud lawsuit isn't going away, Kalshi got hit with a $36 billion complaint from the New York AG less than a day after the CFTC tried to block it in federal court, and a new four-university study found AI chatbots now out-talk human scammers at their own game.
Let's get into it.
Nick
Big Story: The Price of Sophisticated Fraud Just Collapsed
Two vendor reports landed in my inbox this past week, and they tell the same story from different angles: running a sophisticated identity fraud attack has become more than 100 times cheaper than it was a few years ago.
Liminal and Unico's new Identity Fraud Intelligence 2026 report found that AI-assisted fraud now accounts for 23% of attacks globally, tied to losses exceeding $400 billion a year. The report sorts fraud into a sophistication ladder: physical presentation attacks — a printed photo, a face held up to a camera — make up 30.9% of classified attempts. Injection attacks, which hot-wire the camera feed instead of trying to trick it, are now the largest single category at 45.8%. Hybrid attacks combining deepfakes, injection, and physical manipulation make up the remaining 23.3%. Deepfake-specific fraud causes average annual losses over $280,000, and nearly one in five cases tops $500,000. Synthetic identity fraud is up eightfold year-over-year and now makes up 11% of global fraud. One institution in the dataset logged 8,065 deepfake verification attempts in eight months, tied to $347 million in confirmed losses. Jawdropping.
Days later, Point Predictive's Q2 2026 Fraud Risk Intelligence report put a retail price on the front end of that pipeline. Chief fraud strategist Matt Vega states that injection kits (the software that hot-wires a mobile device's camera feed or streams a deepfake directly into the verification process) now sell for about $30. Once a kit clears onboarding, the fraud doesn't stop there: synthetic identities take six to eighteen months to mature, using agentic AI to automate payments on secured cards and micro trade lines, quietly building a repayment history that pushes the fake profile into prime or super-prime territory.
So what for operators: static, point-in-time identity checks (verify once at onboarding, trust forever) are next to useless in the face of these fraud schemas. Fraud costs are falling as fast as defense costs are rising, and isolated, single-institution verification means every fraud ring gets to relaunch as a first-time customer at the next bank down the street. The fix is connected, continuous verification, and 76% of buyers in the Liminal / Unico survey already rank device fingerprinting as their single most effective control.
Quick Hit #1: Visa Pays $2.4 Billion to Watch You Type
Visa signed a definitive agreement to acquire BioCatch, the Tel Aviv-based behavioral biometrics firm, for $2.4 billion in cash, buying out Permira and other shareholders outright. BioCatch's whole pitch is continuous verification: instead of checking a document once at onboarding, it profiles keystroke cadence, touch pressure, and device handling across a session to flag account takeovers, scams, and mule activity before a payment clears. The company already runs behind more than 350 banks in 21 countries, protecting 760 million users and 1.8 billion devices, and CNBC reported the deal adds to Visa's fastest-growing division, value-added services, as it pushes further into fraud and cybersecurity software sold to financial institutions.
Permira bought a 60% stake in BioCatch just two years ago at a $1.3 billion valuation — Visa's all-cash exit price nearly doubles that in twenty-four months. That kind of markup is what happens when "detect fraud once at the door" stops being good enough and "detect it continuously, forever" becomes the price of entry (yes, we did just talk about this).
The largest card network on earth just decided the behavioral layer was worth owning outright rather than licensing, and every processor and core banking vendor watching this deal now has to decide whether to build that same layer or buy it before someone else does.
Quick Hit #2: Zelle Loses Its Get-Out-of-Discovery Card

A New York state judge refused to dismiss Attorney General Letitia James's lawsuit against Early Warning Services, Zelle's bank-owned operator, over more than $1 billion in alleged fraud losses, Reuters reported. Justice Phaedra Perry-Bond ruled that James adequately alleged Early Warning "prioritized accessibility, convenience, consumer adoption, and market dominance at the expense of consumer safety" in rushing Zelle to market over its own bank partners' objections, and noted Zelle still collects and retains fees on transactions later reported as fraudulent. Both of the state's fraud theories survive, including one that doesn't require proving Early Warning directly caused any individual loss.
The American Bankers Association and other banking trade groups had filed an amicus brief backing dismissal, warning the suit could unsettle the legal and compliance frameworks the whole payments industry operates under. The case, remanded from federal court earlier this year, now moves into discovery — meaning Early Warning's internal fraud-control decisions become subject to subpoena, and every real-time payment network gets to watch the "friction vs. liability" question finally get tested in court. Bring popcorn…
Quick Hit #3: Kalshi's $36 Billion Week
Letitia James wasn't done for the week. The New York attorney general filed a $36 billion civil enforcement action against Kalshi, alleging the prediction-market exchange has been running unlicensed gambling in the state — including letting 18-to-20-year-olds trade, below New York's 21-plus betting age. Under the state's Executive Law § 63(12), the disgorgement remedy has no obvious ceiling, and one gaming attorney stated the figure "may actually be understated" once Kalshi's full nationwide customer base is accounted for.
The action didn’t happen in a vacuum: the CFTC had filed an emergency motion in federal court the day before, seeking to block New York's suit on the theory that Kalshi's federal exchange license preempts state gambling law. It's the same jurisdictional fight that's already split the courts. The Third Circuit sided with Kalshi in April, a federal judge in the same Manhattan courthouse ruled the opposite way on July 7, and a different fight entirely from the Gabriel Perez insider-trading story that led our July 19 edition, which remains stuck in settlement talks.
Quick Hit #4: The Bots Are Buying, and the Bots Are Scamming
Researchers from four universities (Amrita Vishwa Vidyapeetham, Ca' Foscari Venice, Melbourne, and Ben-Gurion) built a simulation pitting AI chatbots against human scammers at the hardest part of a pig-butchering scam: the months-long trust-building conversation that precedes the investment ask, interviewing 145 people who'd worked inside or survived scam-compound operations in Cambodia, Myanmar, and Laos. The result, as SC Media reported: 46% of test subjects complied with an AI chatbot's request to download a follow-on app, versus fewer than one in five for a human scammer — the barrier to running a convincing long con dropping from a trafficked worker fluent enough to sustain months of conversation to an API key.

The same week, at VB Transform 2026, Mastercard's chief AI and data officer Greg Ulrich described the mirror image of that problem from the defense side: risk models that score 175 billion transactions a year in under a tenth of a second, tuned for years to treat bot-like behavior as the signature of a thief, now need to let a legitimate shopping agent through. "We need to enable the bot to transact," Ulrich said. And with only 32% of enterprises giving their AI agents a distinct, scoped identity, neither side of the transaction has caught up yet.
This Week in Fraud is a publication for fintech operators, fraud teams, and risk professionals. Have a tip or story? Reply to this email or drop Nick Holland [email protected] a note directly.



