Article

Rethinking data sharing for modern fraud detection

Stephanie Mitchell
Data center network infrastructure with connected Ethernet ports

The global payments industry continues to expand, projected to grow at around 5% year over year until 2028, according to data from McKinsey. This growth reflects rising digital adoption, sustained investment in real-time technologies and ongoing innovation across the financial ecosystem. Yet this progress is increasingly at risk of being overshadowed by another trend that is growing just as quickly: the rise in fraud.

McKinsey's report on Guardrails for Growth: Building a Resilient Payments System highlights how the payment landscape's expansion has been accompanied by an equally aggressive escalation in criminal activity, creating significant operational pressure for banks and payment providers.

The European Banking Authority's Joint EBAECB Report on Payment Fraud found that annual fraud losses in Europe alone reached 4.2 billion euros in 2024, representing both direct losses and broader operational costs associated with fraud management.

Although these figures remain small relative to the overall value of the global payments market, estimated by Mordor Intelligence at $64 trillion in 2025, the financial impact of fraud is becoming much harder for institutions to absorb. Juniper Research estimates that losses could reach $58.3 billion globally by 2030 driven in large part by the growth of synthetic identities and advanced attack methods that exploit fragmented data environments.

As digital payment volumes accelerate, fraudsters continue to probe vulnerabilities, adapt techniques, and use automation to test multiple institutions simultaneously. The result is a threat landscape where attacks scale quickly, and banks often struggle to respond at the same pace.

Regulators have begun to intervene more directly in how liability is shared across the ecosystem. The UK's updated rules for Authorised Push Payment fraud require financial institutions to reimburse victims up to £85,000 per claim unless the customer was grossly negligent. Similar reforms are advancing in the EU and are expected to take effect soon. These measures reshape the economic calculus for banks.

Fraud prevention is no longer simply about protecting customers and reducing operational losses. It now includes direct financial responsibility for reimbursement. It is therefore unsurprising that nearly 90% of banking executives surveyed in a recent report prioritising immediate investment in fraud mitigation and security capabilities. Yet sophisticated tools alone cannot resolve the foundational challenge: strict data protection requirements limit the ability of institutions to share information, leaving each bank with a narrow view or emerging threats while criminals exploit gaps between organisations.

More data encourages stronger fraud detection

Modem fraud detection relies heavily on dynamic pattern recognition and the rapid identification or anomalies. These systems perform best when trained on broad, diverse datasets that allow them to distinguish unusual activity from ordinary customer behaviour.

A useful parallel can be seen in consumer health technology. As Lisa Eadicicco reported for CNN Business, the Oura Ring collects behavioural insights from millions or users, enabling the system to detect deviations from population-level norms and provide early alerts to individuals. The accuracy of these insights is made possible not because or any single data point but because of the sheer volume or aggregated information that defines typical behaviour.

Fraud detection systems operate similarly. Institutions with access to large and varied datasets have a far greater ability to identify suspicious activity, especially when fraud patterns shift quickly across geographies or channels. Global card networks illustrate this advantage clearly. With insight into transactions across multiple markets, they can detect coordinated attacks and identify new fraud types before they become widespread. This broad vantage point fosters rapid, preventative action.

Many banks, however, rely on institution specific datasets. Their fraud models are trained only on the behaviour of their own customer base, which creates inherent limitations. Attacks that appear isolated within one bank may form part of a larger pattern only visible when data is aggregated across institutions. Criminals understand this fragmentation and frequently exploit it, testing their methods at different banks to identify which controls can be bypassed. The result is a reactive environment where institutions often become aware of new threats only after experiencing losses themselves.

Overcoming regulatory hurdles in data sharing

Financial institutions face stringent privacy and security requirements. Regulations such as GDPR restrict how personal and transactional information can be shared or processed, ensuring strong protections for consumer data. However, these same regulations also limit collaboration between banks, preventing the sharing of information that might reveal early signs of coordinated fraud campaigns. While necessary from a privacy standpoint, the restrictions create structural challenges for fraud detection.

To navigate these constraints, banks are adopting approaches that preserve data privacy while still supporting ecosystem level defense. One strategy is the sharing of anonymised insights instead of raw customer data. Institutions can exchange risk scores, behavioural markers, fraud typologies and confirmed fraud indicators. These signals provide a broader understanding of emerging threats while ensuring that sensitive information remains protected within each institution. Yet this approach remains fundamentally reactive. Insights tend to reflect fraud that has already occurred and do not always offer visibility into early indicators of new attack patterns.

Federated learning presents a more adaptive solution. Under this model, customer data remains securely within each institution, where it is used to train local fraud detection models. Instead of sharing any underlying data, institutions share only the model's learned parameters or summaries of emerging patterns. These aggregated insights help create a stronger global model that improves detection capabilities across all participating institutions. Federated learning, therefore, enables collaborative intelligence without compromising privacy or violating regulatory standards.

Recent EU guidance increasingly supports these anonymised and aggregated data-sharing techniques. Regulators now emphasise that privacy preserving collaboration is not only permissible under GDPR but increasingly essential for addressing the scale and sophistication of financial crime. This shift reflects a broader recognition that fraud is not an isolated problem. It is an ecosystem issue that demands ecosystem solutions.

As fraud continues to evolve, financial institutions will need to strengthen analytical capabilities, adopt more collaborative models and integrate technologies that adapt as quickly as the attackers they face. Responsible data sharing, supported by robust privacy frameworks, offers one of the most promising paths forward.

This article was previously published by IBS Intelligence Fintech Journal.

Written By

Stephanie Mitchell
Stephanie Mitchell is the global head of product, financial messaging at Finastra.