This website uses cookies

Read our Privacy policy and Terms of use for more information.

The frontier in the fight against digital financial fraud is the effort to stop bad actors in real-time, before a single cent changes hands. That fight is giving rise to another battle—for the companies that have positioned themselves on the front lines.

Visa’s recent $2.4 billion acquisition of security firm BioCatch underscores the pressure on payment giants to acquire advanced defenses against authorized payment fraud, a threat start-ups have proved uniquely adept at tackling.

“When institutions with real resources choose to acquire rather than build, it tells you something about how scarce and hard-won this expertise actually is,” said Soups Ranjan, CEO and co-founder of Sardine, a platform that works with banks and online retailers to prevent fraud and money laundering. “Fraud and identity capabilities have become critical enough to the business model that the largest players are willing to grow inorganically to get there faster.”

Americans lost approximately $68 billion to financial scams in 2025, according to a study released in June by the Stop Scams Alliance and Gallup. About 75% of victims who didn’t formally report their scam said they didn’t think reporting would help them recover their money and 64% said they didn’t believe that reporting would help prevent future scams, the national survey found. 

Photo by Sasun Bughdaryan on Unsplash

This leaves the field open for more acquisitions as payment networks work to close that gap in trust.

The Next Targets

John Meyer, a managing director at Cornerstone Advisors, whose experience includes work on developing product strategies for fraud detection for U.S. financial institutions, identified several start-up firms in the anti-fraud market that may be attractive buyout targets.

“In the continuous verification world, we see firms like Alloy and Socure gaining market share,” Meyer said. “For specific transaction monitoring and fraud detection, Actimize is for sale right now and wants a premium.” Meyer pointed to firms like Abrigo as alternative targets that could draw interest.

For smaller firms that are still under $1 billion in valuation, Meyer said, firms including REDi and Entersekt for card fraud are gaining popularity. Callsign’s partnership with Candescent for biometric verification is growing as a competitor against BioCatch in the digital bank area, he added.

There are currently no federal or state laws that require banks to reimburse customers for payments they later claim were the result of deception — a category known as authorized push payment (APP) fraud. Networks like Visa and Mastercard are then left to discern a user’s genuine intent in real time. 

‘A Very Difficult Game’

Banks are “investing more and more in fraud detection solutions that enable them to do a better job than they were yesterday of figuring out what the intent of that payment is," said Trace Fooshee, a strategic advisor on the Fraud & Anti-Money Laundering team at Datos Insights. “Not surprisingly, that’s still a very difficult game. That is a big part of the reason why Visa purchased BioCatch because fraud detection is all about what we call layered defense. You’re never going to buy just one fraud detection solution. You’re going to buy dozens of them.”

Photo by Jandra Sutton on Unsplash

Those layers increasingly lean on behavioral analytics from specialized firms like NeuroID, as well as enterprise risk engines from giants like Feedzai, TransUnion and LexisNexis Risk Solutions.

That vendor landscape makes the sector ripe for more deals. KPMG, in its global analysis of fintech funding published last month, forecast a “continued consolidation” of small cybersecurity firms in fintech as they “work to achieve scale or look to M&A as an exit strategy.” This is particularly relevant with the growing focus on both the risks and benefits that come from artificial intelligence.

“As AI continues to proliferate through financial services, data security and the security of AI-managed transactions is going to become a significant concern — for regulators, for traditional financial institutions, and for fintechs,” Charles Jacco, global lead of cyber, financial services cybersecurity and tech risk for KPMG in the U.S., wrote in the report. “We’re likely going to see a lot more attention being given to data and transaction security over the next six months, particularly when it comes to AI-driven activities.”

As the trend shifts toward intercepting fraudulent transactions before they happen, Ranjan, at Sardine, says more financial institutions are realizing they’re not built to handle such advancements in technology. Real-time transfers are now the norm and the victim of fraud is the one who’s initially authorizing the payment themselves.

“The industry has no choice but to move upstream: you have to intervene before the payment is sent, inside a milliseconds-long decision window, against an attacker who has shifted from breaking into accounts to manipulating the person who owns it,” Ranjan said. “That's a fundamentally different problem than the one most fraud infrastructure was built to solve, which is exactly why interception is moving earlier in the payment lifecycle rather than staying a post-transaction cleanup job.”

Reply

Avatar

or to participate

KEEP READING


VIEW MORE