Banking & Finance  March 29, 2026

Banks confront surge in AI-driven fraud risks

It is not surprising that the advent of artificial intelligence has amped up the threat level for banks and other financial institutions when it comes to fraud.

Scammers, hackers and fraudsters are taking advantage of the newest technological tools to not only scam bank customers but attempt to scam the institutions themselves.

“There are always threat actors at any given time targeting various institutions, companies and governments in the U.S. and abroad. Right now, we are seeing an amplification of everything that has been an issue before,” said Ahmed Hamza, an associate teaching professor in the computer science department in the College of Engineering & Applied Science at the University of Colorado Boulder.

Phishing scams are one of the top threats to bank employees and customers because they are easy to send out and easy to fall for, said Luke Brackin, information security officer for Alpine Bank.

Artificial intelligence is making these types of scams even more believable.

“Their phishing emails are getting quite a bit better. Some of them still have glaring issues that are never going to get through if they are doing it like that. We can see artifacts in the emails that make it obvious they used AI to do it, but the end user is never going to see those things,” he said.

The best way to combat this type of scam is to make sure the email never gets there in the first place, he said. “If it does, make sure you have a strong security culture, making sure you are thinking before you click; making sure the email even makes sense.”

Another scam that began appearing in Q4 of 2025 is malicious meeting invites. These invites get around traditional email security tools, Brackin said.

Scammers send a meeting invite with a meeting agenda attached. Behind the scenes, a calendar invite is placed on that person’s calendar awaiting their decision to accept it or not. Even if a bank or company’s email scans catch and stop the malicious email with the attachments, the calendar placeholder gets through and can cause havoc. The hackers want the recipient to click on the meeting agenda with a link that will take the person to a malicious website or download malware onto their computer.

Security vendors have responded to this new threat by not only quarantining suspicious emails but also searching for associated calendar invites associated with them.

Phone scams are rampant. Bank customers receive a phone call from what appears to be their bank, but the number has been spoofed. The person on the other end will use the name of a legitimate person in the bank’s fraud department and proceed to ask for an account number, saying they’ve detected fraud in their account.

“It gives a sense of urgency, once again. Some people do fall for that. It is a very blanket thing globally with most companies saying we’re not going to call you and ask for sensitive information, but in the moment, people aren’t thinking about that,” Brackin said.

His advice: Always hang up and call the organization the person is claiming to be from, on a number you know is legitimate.

Shawn Osthoff, president of Bank of Colorado, said that his bank works hard to educate customers and bank employees about the different scams that are out there. On the bank side, it is important that employees know who their customers are and who they are dealing with, which means finding multiple ways to confirm the identity of the person they are speaking, texting or emailing with. 

“Once you let your guard down and provide information you shouldn’t, it is too late,” he said.

It takes a lot of resources and time to combat this type of fraud. 

“We’re using AI to try and detect fraudulent activity on accounts,” he said. If the AI detects large transactions moving in or out of an account when that type of activity is not typical for that account, the bank will dig into it to make sure it is a legitimate transaction. The same with changed passwords. Banks want to make sure its customers are the ones that requested a change to their account information.

“It is just a constant battle. Once we get ahead of it, there are always workarounds bad guys think of, always trying to stay one step ahead,” Osthoff said.

Gerard Nalezny, chairman and CEO of Verus Bank of Commerce in Fort Collins, said he spent most of his career worrying about credit risk, but now, his No. 1 worry is cyber risk.

“It’s everywhere and has been directed at every bank in the state,” he said.

Fraudsters are getting more savvy because of the abundance of personal information available through the internet and on the dark web. Their scams have a ring of truth to them because AI can emulate real voices gleaned from voicemails and scammers throw out details that seemingly only their financial institution would know.

Hackers can take control of someone’s computer, get into their bank accounts and move money.

Banks have robust security and Nalezny said he isn’t aware of any scams in which the bank or financial institution was the source of the fraud. Most incidents originate with the bank customers themselves or a bank employee clicking on the wrong thing.

So much information is controlled by multifactor authentication, he said, and as long as a customer doesn’t give out that information, scammers can’t get into their account.

“They can’t break that unless you help them,” Nalezny said.

The biggest threat is when businesses rush to incorporate technology, Hamza said. Many of these networking interfaces are not configured properly, giving bad actors the ability to hack into them remotely at the interface level.

Banks and financial institutions need to be aware of “the technology they are incorporating and be very skeptical of bringing in new technology without having someone take a look at it externally,” Hamza said.

Medium- and large-sized businesses should consider bringing in security professionals to conduct penetration tests or test the defenses of a company. “That lets them know what their exposure is and what they would do if a hacker targeted their enterprise,” he said.

It is especially important for organizations to be wary of different developer tools that are out there, such as programming help agents, AI agents being installed in developer tools or people using browser extensions that offer improved productivity.

Hamza said that while these tools look great and may even come from an official source, ownership can change.

Employees can install something and not think about it. Then, a few months down the line, it gets bought out by a malicious actor that now has complete access to the code running in their browser, he said. “Just update the extension and all of a sudden you have a malicious implant totally legit and running in your computer.”

Similar to the health sector, a lot of private data in the finance world gets touched by or relegated to third party people.

“That is where a lot of attacks happen, those smaller players who get access to unencrypted private data,” he said.

One thing the financial sector can do to protect themselves and their customers is be very strict about data encryption and who gets access to that data. If they use a third party to manage their customer database, “whatever standards they apply to themselves they need to be applying to those guys so they don’t have to end up hiding their association when those companies get sued,” Hamza said. “It’s a tricky world we live in right now.”

Scammers, hackers and fraudsters are taking advantage of the newest technological tools to not only scam bank customers but attempt to scam the institutions themselves.

Related Posts

Sign up for BizWest Daily Alerts