Employment scam victims triple at banks in 21 countries
The number of people reporting employment scams to banks has more than tripled in a year, according to new figures from fraud-detection vendor BioCatch. The company compiled reports from more than 370 banks and other financial institutions in 21 countries that use its software.
Employment scam victims rose 258% over the past 12 months. That was the fastest growth of any scam type. Total reported scams across the same institutions rose 35%.
The data also shows where these scams happen. Nine out of 10 scam sessions now begin on a mobile device. For traditional unauthorized fraud, where a criminal operates the account without the owner's involvement, mobile accounts for 75% of cases.
Purchase scams lead in volume, investment scams in losses
Investment scams remained the most expensive category. The average case reached $6,600, close to five times the average across all scam types.
Purchase scams were again the most common, making up almost a third of reported cases. They also had the lowest average case value in each of the four regions the researchers examined: North America, Europe, Latin America and Asia Pacific.
Romance scams grew the least, with victims up 23%. In every region except Latin America, they also lasted the longest, often running for weeks or months.
Anatomy of a 15-minute scam session
To show where a bank can intervene before money leaves an account, the researchers broke down one scam session that lasted about 15 minutes.
When the customer logged in, they were on an active phone call and had remote access software installed. The researchers say the call alone is a weak indicator. On average, only 30% of activity reported as a social engineering voice scam involves an active call during the session, so most such cases would not be flagged by that check.
On the account overview pages, the customer stayed almost idle for two minutes. While adding a new payee, they entered the account number in groups of three digits, pausing briefly between each group. The researchers link this pattern to someone reading numbers aloud over the phone. The transfer was going to a first-time beneficiary, the amount was far outside the customer's usual behavior, and on the review screen touch events clustered in the same spot.
The bank pushed in-app warnings during the session. The customer pressed "back" on the review screen and abandoned the transfer before the bank had even requested a risk score.
The researchers argue that the customer needed to reach that decision on their own. Victims who are told directly that they are being scammed often resist, and scammers prepare them for exactly that moment: "The bank will try to stop you. Don't listen to them. They don't understand."
Small payments, mule accounts and sextortion
Erin West, a former prosecutor and founder of Operation Shamrock, visited Nigeria in July and warned that banks may be looking in the wrong places. Scam compound networks are already established there. In December 2024, Nigeria's Economic and Financial Crimes Commission arrested 792 people, including 148 Chinese nationals, at a crypto-investment and romance scam operation in a seven-story building on Victoria Island.
The older, local fraud West observed relies on gift cards, wire transfers, Venmo, Cash App and peer-to-peer payments broken into small amounts. The funds end up in mule accounts, including fintech wallets that can be opened with little more than a phone number.
The most harmful version targets children. In financial sextortion, a scammer persuades a boy, usually aged 13 to 17, to send a compromising photo, then demands $100, $200 or a gift card to keep it from his friends and family. FinCEN, the U.S. Treasury's financial crimes unit, has counted at least 36 U.S. teenagers who died by suicide since 2021 in cases linked to this crime. West considers that a minimum, since it covers only U.S. reports. NCMEC, the U.S. National Center for Missing & Exploited Children, now records 137 financial sextortion reports a day.
"Boys are dying over amounts of money no monitoring system was ever built to notice," West wrote.
She wants banks to monitor receiving accounts as closely as sending ones, because mule accounts take money in and move it out in a single session. Recovery is possible when that happens. One Nigerian investigator took an American police report on a pig butchering loss of about $50,000 and traced the money through five bank accounts to two trucks bought with the proceeds. He impounded the trucks and filed for civil forfeiture. The case is still on appeal.
Our Take
The BioCatch figures suggest that the fraud problem for banks is shifting from stolen credentials to manipulated customers. When the account owner logs in, passes authentication and approves the payment, many traditional controls have nothing to catch. The focus on behavioral signals such as idle time, digit-by-digit typing and clustered taps reflects that shift.
The mobile figures matter too. With most scam sessions starting on phones, the device has become the main battleground. This lines up with the steady stream of Android banking malware and remote access abuse aimed at mobile banking users.
West's point about small payments is probably the hardest to address. Thresholds built to catch large transfers will miss a $100 gift card demand, and fintech wallets with light onboarding remain an easy landing spot for mule money. It is worth watching whether banks and regulators begin treating inbound flows to newly opened accounts as a risk signal in their own right, and whether the employment scam surge continues into next year's figures.
